GDPR & CCPA
Fully compliant with global data protection regulations.
PRIVACY · SECURITY · DATA PROTECTION
Transparent. Enterprise-grade. Dedicated to protecting the integrity of global hospitality data. Last Updated: May 24, 2024.
Fully compliant with global data protection regulations.
AES-256 at rest and TLS 1.3 in transit for all data.
Deterministic processing with no model training on client data.
Strict least-privilege access controls across all systems.
Welcome to HospitalityOS. We are committed to protecting your personal data and your right to privacy. If you have any questions or concerns about our policy, or our practices with regards to your personal information, please contact us at support@hospitalityos.com.
This Privacy Policy governs the privacy practices of HospitalityOS (referred to as 'we', 'us', or 'our') and applies to all users of our platform, software, and services (collectively, 'Services'). We collect information that you provide directly to us when you register for an account, use our Services, or communicate with us.
PERSONAL DATA
BUSINESS DATA
TECHNICAL DATA
HospitalityOS utilizes proprietary Machine Learning (ML) and Optical Character Recognition (OCR) models to automate property management workflows. Our commitment to privacy in AI includes:
No Model Training
We never train our foundation models on your proprietary business data or guest information.
PII Redaction
Our OCR engine automatically identifies and redacts sensitive PII from document images before long-term storage.
Local Inference
Where possible, AI inference happens within your regional data center to prevent cross-border transfers.
Explainable AI
Every automated decision made by our platform is logged with a confidence score and audit trail.
| PROVIDER CATEGORY | PRIMARY ENTITY | PURPOSE |
|---|---|---|
| Cloud Infrastructure | Amazon Web Services (AWS) | Data hosting and system redundancy. |
| Payment Gateway | Stripe, Inc. | Transaction processing and fraud detection. |
| Authentication | Okta / Auth0 | Secure login and multi-factor authentication. |
| Analytics | PostHog / Mixpanel | Product usage metrics and UI optimization. |
Strict internal access protocols managed via SCIM.
Role-Based Access Control for all user accounts.
Military-grade AES-256 for all persistent storage.
Immutable trail of all data access events.
Real-time threat detection and response.
Automated hourly snapshots in isolated VPCs.
Request a full export of all personal data we hold about you in a machine-readable format.
Request that we delete your personal data (the "Right to be Forgotten") subject to legal retention obligations.
Transfer your data directly from Hospixo to another service provider without hindrance.
Withdraw consent for specific processing activities like direct marketing or profiling.
Data is stored primarily in AWS regions corresponding to your business headquarters (e.g., US-East, EU-Central, or AP-Southeast).
Deleted records are purged from active databases immediately and cleared from backups within 30 days.
Hospixo is PCI-DSS Level 1 compliant. We never see or store your full card numbers; all handling is done by Stripe.
Yes, Enterprise clients can toggle off specific AI-driven features in the Admin Console, though this may limit platform functionality.
Our Data Protection Officer can be reached directly at dpo@hospixo.com for all formal regulatory inquiries.
No. Hospixo does not sell, trade, or rent personal or business data to third parties for advertising purposes.
Our dedicated privacy and security teams are available 24/7 to address any concerns regarding how your information is handled.
Contact Support