This Privacy Policy explains how [Company Legal Name] (“iSuites”, “we”, “us”, or “our”) collects, uses, and protects information when you use the iSuites hotel management platform — our website, our staff-facing application, and any related mobile or AI assistant features (together, the “Service”).
iSuites is used by hotels and hospitality businesses (“Customers”) to manage bookings, guests, staff, and payments. This policy covers both the information we collect directly from Customers and their staff, and the guest information Customers enter into the Service to run their property.
1. Information We Collect
1.1 Account & staff information
When a Customer registers a company on iSuites, or invites a staff member to join one, we collect information such as name, email address, phone number, role, and a password (stored in hashed form — we never store or have access to a plain-text password). If a staff member signs in with Google, we receive the basic profile information Google shares with us (name, email address, profile photo) to authenticate the account.
1.2 Guest information entered by Customers
To create a reservation or check a guest in, our Customers' staff may enter guest details into the Service, which can include: full name, email address, phone number, occupation, arrival/departure information, means of travel, purpose of visit, and next-of-kin contact details. This information is entered and controlled by the Customer (the hotel), not by the guest directly or by us — see “Our Role vs. Our Customers' Role” below.
1.3 Company & property information
We collect information about the property itself: company name, logo, currency, room and rate configuration, booking policies, and any custom fields or email/SMS templates a Customer sets up.
1.4 Payment & billing information
The Service records how a guest paid for a stay (for example, cash, card terminal, bank transfer, or online) as part of a reservation's folio. We do not store full card numbers. Subscription billing for a Customer's use of iSuites itself is handled by [payment processor name], who processes payment details directly — we do not store your card details on our servers.
1.5 Usage & device information
Like most web and mobile applications, we automatically collect some technical information when the Service is used — such as IP address, browser or device type, pages viewed, and timestamps — to help us operate, secure, and improve the Service.
1.6 Cookies & local storage
We use browser local storage to keep you signed in between visits (an authentication token), and cookies where needed for core site functionality. We do not currently use cookies for third-party advertising.
2. Our Role vs. Our Customers’ Role
When a hotel (“Customer”) uses iSuites to manage its guests, the Customer is the data controller for that guest information — they decide what guest data to collect and why, in line with their own privacy notices and legal obligations to their guests. iSuites acts as a data processor: we host and process that information on the Customer's behalf, under their instructions, in order to provide the Service. If you are a hotel guest with a question about your personal data, please contact the hotel you stayed with directly, or contact us at [support email] and we will do our best to direct you appropriately.
3. How We Use Information
- To provide, operate, and maintain the Service — including bookings, check-in/check-out, housekeeping, and billing.
- To send transactional communications — such as booking confirmations, receipts, password resets, and staff invitations.
- To provide the Suites AI assistant feature, where enabled by a Customer.
- To detect, prevent, and address fraud, abuse, security incidents, and technical issues.
- To communicate with Customers about their account, and, where permitted, about product updates.
- To comply with legal obligations, and to enforce our Terms of Service.
4. How We Share Information
We do not sell personal information. We may share information with:
- Service providers who help us run the Service, such as email delivery, cloud file storage (for uploaded logos and documents), and payment processing providers, under contracts that limit their use of the information to providing services to us.
- Authentication providers (such as Google), if you choose to sign in that way.
- Other staff within the same company account, as appropriate to their role, since iSuites is a shared, multi-staff tool.
- Legal or regulatory authorities, where required by law, or to protect the rights, property, or safety of iSuites, our Customers, or others.
- A successor, in the event of a merger, acquisition, or sale of assets — we will notify affected users if this results in a materially different use of their information.
5. Data Retention
We retain account, reservation, and guest information for as long as a Customer's account is active, and for a reasonable period afterward to comply with legal, accounting, or reporting obligations, resolve disputes, and enforce our agreements. Customers can request deletion of specific records subject to these obligations — see “Your Rights” below.
6. Data Security
We use technical and organizational measures designed to protect information against unauthorized access, alteration, disclosure, or destruction — including encrypted passwords, access controls scoped to each Customer's own data, and encrypted connections. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Your Rights
Depending on where you are located, you may have rights to access, correct, export, or request deletion of your personal information, or to object to or restrict certain processing. Staff users can update most account information directly in the Service; for other requests, or if you are a hotel guest, contact us at [support email], or contact the relevant hotel directly for guest-data requests.
8. International Data Transfers
iSuites and our service providers may process and store information in countries other than the one where a Customer or guest is located. Where this happens, we take steps intended to ensure information continues to receive an appropriate level of protection.
9. Children’s Privacy
The Service is intended for business use by adults working at or operating a hotel or hospitality property. It is not directed at children, and we do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date above and, where appropriate, notify Customers directly.
11. Contact Us
If you have questions about this Privacy Policy or how we handle information, contact us at [support email].