Hotel+ Logo

Privacy Policy

How Hotel+ handles the data of hotels, their guests and visitors to hotelplus.ai.

Privacy Policy

Last updated: 29 September 2026

This Privacy Policy explains how Hotel+ (hotelplus.ai, "Hotel+", "we", "us") handles personal data when you use hotelplus.ai, including the Hotel+ hotel panel (hotelplus.ai/panel) and the guest pages that hotels publish with Hotel+ (hotelplus.ai/h/…). If you have a question, write to us at info@hotelplus.ai.

1. The short version

  • Hotels use Hotel+ to publish a guest page that guests open by scanning a QR code, and to receive guest requests, room-service orders and survey answers.
  • Guests do not create an account. We do not ask guests for their name or email address. A room number is needed for orders; a phone number is always optional.
  • Room numbers and phone numbers are removed after 90 days. Guest messages, requests, orders and survey answers are deleted after 365 days.
  • The hotel panel and guest pages use no analytics or advertising cookies. On our marketing pages, Google Analytics and Microsoft Clarity are loaded only if you accept them.
  • We do not sell personal data and do not use it for advertising.
  • Payments are processed by Paddle. Card details never reach Hotel+.

2. Who is responsible for your data

  • Hotel accounts and website visitors: Hotel+ decides how this data is used and is the controller.
  • Data that guests send to a hotel through its guest page (messages, requests, orders, survey answers, room number, phone number): the hotel is the controller and Hotel+ processes this data on the hotel's behalf, to provide the service to the hotel. If you are a guest, the hotel is your first point of contact for questions about this data; we will help the hotel answer you.
  • Content a hotel publishes (descriptions, menus, prices, opening hours, photos, contact details) is the hotel's own content and responsibility.

3. Hotels and hotel staff (panel users)

DataWhy we use it
Email address, password, account ID, email verification statusTo create your account and sign you in. Sign-in is handled by Google Firebase Authentication: your password is sent from your browser directly to Google and our servers never receive it. Verification and password-reset emails are sent by Firebase. You must verify your email address before you can publish your guest page or upload images.
Hotel content: hotel name, description, phone number and website shown to guests, venues, menus and prices, opening hours, FAQs, surveys, photosTo build and publish your guest page, and to translate it into the languages you choose.
Setup information: the hotel name you search for, your approximate location if you choose "use my location", the website address and notes you give to the AI setup assistantTo find your hotel in OpenStreetMap and prepare a draft guest page. Your location is taken only with your browser's permission, rounded to about 100 metres and not stored. Our server reads a few pages of the website you enter to prepare the draft and keeps only the draft you save.
Subscription status: trial end date, paid-until date, planTo run the free trial and your subscription. Payment and billing details are handled by Paddle (see section 8).
Sign-in sessionA sign-in token is kept in your browser tab's session storage and is removed when you close the tab. You can sign out of all devices from the panel.
Emails you send usTo answer your request.

4. Hotel guests

When you open a hotel's guest page, you do not create an account and we do not ask for your name or email address.

DataWhy it is used
Messages and requests, room-service orders (items and quantities, room number, optional phone number and note), survey answers and ratings, the language of the pageTo deliver them to the hotel so it can respond. The room number is required for orders so the hotel knows where to deliver; the phone number is optional.
The hotel's replyTo show it to you under "My requests" on the same device. Replies are translated into your language.
A random device identifier stored in your browser (not linked to your identity)To show "My requests" (your requests from the last 30 days, up to 20) only on the device you sent them from, and to prevent the same survey from being answered twice.
Page opens (including from the QR code), which sections are opened, the page languageTo give the hotel usage statistics. These records do not include who you are.
Your IP address, converted into a one-way salted codeTo limit abuse (for example, automated flooding). The raw IP address is not stored in our database; the code is deleted after one day.

Before a message reaches the hotel, it is checked automatically (see section 6). A message that does not pass the check is not delivered to the hotel and is not shown under "My requests".

Guest pages set no cookies and use no analytics, advertising or location services. Only the hotel's authorised panel user can see what you send to that hotel. Hotel+ staff access this data only where needed to provide support, keep the service secure or comply with the law.

5. Visitors to hotelplus.ai

  • Server logs. The server that hosts hotelplus.ai records technical request data (such as IP address, browser type, requested address and time) for security and troubleshooting.
  • Analytics, only with your consent. If you click "Accept" in the cookie banner, our marketing pages load Google Analytics and Microsoft Clarity, which collect information such as the pages you visit, clicks and scrolling, device and browser type and approximate location derived from your IP address. Clarity can also record how you interact with a page (mouse movements, clicks, scrolling) to help us improve the site. If you click "Reject", or do not choose, these tools are not loaded. You can change your choice at any time with "Cookie settings" at the bottom of every page. They are never loaded in the hotel panel or on guest pages. See our Cookie Policy.
  • Language. If you choose a language, we remember it in a cookie so the site opens in that language next time.
  • Images. Some marketing pages show images loaded from Unsplash (images.unsplash.com); your browser connects to Unsplash to load them, so Unsplash receives your IP address.
  • Email. If you write to info@hotelplus.ai, we use your message and address to reply.

6. AI and automated processing

Hotel+ uses AI models, reached through the model gateways OpenRouter and NitroRouter, for the features below. We send only the text or image the feature needs. Room numbers and phone numbers are never sent to AI models.

FeatureWhat is sentModels
Setup assistant: a draft guest page from your website, notes or map listing (started by the hotel)Text read from the hotel's website, the hotel's notes, public OpenStreetMap detailsXiaomi MiMo, with Google Gemini as a fallback (via OpenRouter)
Menu from text or a photo (started by the hotel)The menu text or photoXiaomi MiMo or Google Gemini; photos Google Gemini (via OpenRouter)
Survey suggestions, reply suggestions and insight summaries (started by the hotel)Guest message text, survey answers and ratings, ordered items, language, venue nameXiaomi MiMo, with Google Gemini as a fallback (via OpenRouter)
TranslationHotel content (into the languages the hotel chooses), a guest message (when the hotel asks for a translation), the hotel's reply (into the guest's language)Anthropic Claude (via NitroRouter)
Automatic content checksHotel content (text and images) before it is published; guest messages before they are deliveredAnthropic Claude (via NitroRouter), with OpenAI GPT-4o mini as a fallback (via OpenRouter)

Content checks first apply fixed rules (for example links, personal email addresses or phone numbers inside the text, well-known brand names, and requests for passwords or payment details) and then an AI model. They run without human review. The only effects are that hotel content is not published or a guest message is not delivered; they do not produce decisions with legal or similarly significant effects on you. A hotel's reply to a guest is checked with the same fixed rules, so, for example, a reply that asks for passwords or card details is blocked. If you believe something was blocked by mistake, contact info@hotelplus.ai.

AI output can be wrong. Suggestions made for hotels are drafts: the hotel reviews and edits them before saving or sending.

7. Legal bases

Where the EU or UK General Data Protection Regulation (GDPR) or Türkiye's Personal Data Protection Law No. 6698 (KVKK) applies, we rely on:

  • Contract: to provide the hotel account, the service and the subscription.
  • Legitimate interests: security, abuse prevention, automatic content checks, rate limiting, server logs and usage statistics for hotels.
  • Consent: analytics on our marketing pages, and your location if you choose "use my location". You can withdraw consent at any time.
  • Legal obligations: for example responding to lawful requests from authorities.

For guest data that we process on a hotel's behalf, the hotel determines the legal basis.

8. Service providers

We use the following providers to run Hotel+. They receive only the data needed for their task.

ProviderWhat they do for usData involved
SupabaseDatabase, image storage and server functionsAll service data described in sections 3 and 4
Amazon Web ServicesHosting of the hotelplus.ai websiteWebsite requests and server logs
Google Firebase AuthenticationHotel sign-in, verification and password-reset emailsEmail address, password, account ID
OpenRouter (model providers: Xiaomi, Google, OpenAI)Access to AI models (section 6)Text and images needed for the feature
NitroRouter (model provider: Anthropic)Access to AI models for translation and content checksText and images needed for the feature
Photon (komoot) and Nominatim (OpenStreetMap Foundation)Hotel search during setupSearch text and, if you allow it, rounded location. Requests go through our server, so your IP address is not sent to them.
RevenueCatSubscription statusA customer ID in the form hotel_<id> and purchase status
PaddleCheckout, payment, invoicing, tax and the subscription management portal. Paddle is the Merchant of Record for Hotel+ subscriptions.Payment and billing details you give to Paddle; Paddle's own privacy notice applies
Google AnalyticsWebsite analytics, only with your consentSee section 5 and the Cookie Policy
Microsoft ClarityWebsite analytics, only with your consentSee section 5 and the Cookie Policy
UnsplashImages on some marketing pagesYour IP address when your browser loads an image

We may also disclose data where the law requires it, or to protect the rights and safety of users and Hotel+.

9. International transfers

Our database and image storage are hosted in the European Union (Ireland) and the website is hosted in the European Union (Stockholm, Sweden). Some providers listed above, such as Google, Microsoft, RevenueCat and the AI model gateways and providers, may process data in other countries, including the United States. Where the law requires safeguards for these transfers, we rely on the transfer mechanisms it provides, such as standard contractual clauses.

10. How long we keep data

DataHow long
Hotel account and hotel content (including photos)Until you delete them or delete your account. They are not deleted automatically when a trial or subscription ends.
Room number and phone number sent by a guestRemoved 90 days after they were sent
Guest messages, requests, orders, survey answers and the hotel's repliesDeleted 365 days after they were sent
"My requests" on a guest's deviceShows the last 30 days
Usage statistics (page opens, language)90 days
IP address codes used to limit abuse1 day
AI insight summaries90 days
Server logs and database backupsA limited period, after which they are overwritten
Analytics data (only with consent)According to the retention settings of Google Analytics and Microsoft Clarity
Payment recordsKept by Paddle and RevenueCat under their own legal obligations

Automatic deletion runs regularly, so data may remain for a short time after the period ends.

11. Deleting a hotel account

You can delete your account at any time in the panel: Account → Delete account and hotel. You will be asked for your password again. This permanently deletes your hotel, venues, menus, surveys, guest messages, requests and orders, statistics and all uploaded images, and then your sign-in account. Your guest page and QR code stop working. This cannot be undone.

If you have a subscription that will renew, cancel it first in the Paddle customer portal (Panel → Subscription → Manage subscription); the panel will not delete the account while a renewing subscription exists. A cancelled subscription whose paid period is still running does not block deletion. Deleting the account does not refund the remaining period. You can also ask us to delete your account by writing to info@hotelplus.ai from the account's email address.

12. Your rights

Depending on where you live, you have the right to access your personal data, correct it, delete it, restrict or object to its use, receive it in a portable format, and withdraw consent. Under KVKK (Article 11) you can also ask whether your data is processed, for what purpose, and to whom it has been transferred. You can also complain to a supervisory authority, such as the data protection authority in your EU country, the UK Information Commissioner's Office or Türkiye's Personal Data Protection Authority (KVKK).

To use your rights, write to info@hotelplus.ai. We may ask you to confirm your identity and will reply within the time the law requires (usually within one month). Hotels can see and change most of their data directly in the panel.

Guests do not have an account, so please tell us the hotel's name, the approximate date and time and what you sent, so we can find it. Because the hotel is responsible for guest data, we will handle your request together with the hotel.

13. Security

Connections are encrypted (HTTPS). Each hotel's data is separated at the database level so one hotel cannot see another's. Passwords are handled by Google Firebase and never reach our servers. Panel sessions end when the tab is closed, you can sign out of all devices, and deleting an account requires your password again. IP addresses are stored only as one-way codes. No system is completely secure; if a personal data breach affects you, we will inform you and the authorities as the law requires.

14. Children

The hotel panel is for businesses. Guest pages are information pages for a hotel's guests and are not directed at children. We do not knowingly collect personal data from children.

15. Changes to this policy

We may update this policy when the service or the law changes. The date at the top shows the latest version. If the changes are significant, we will take reasonable steps to let hotel account holders know before they take effect.

16. Contact

Hotel+ (hotelplus.ai) — info@hotelplus.ai