Draft template — not legal advice. This is generic privacy-policy language for a hospitality-management SaaS platform, provided as a starting point. Have it reviewed by a qualified lawyer for your jurisdiction (and any data-protection law that applies to you, e.g. India's DPDP Act) before relying on it.
Privacy Policy
Last updated: 6 October 2026
1. Who this policy covers
This Privacy Policy explains how Hotezo ("we", "us", "our") handles personal data for two groups of people: hotel staff who use the platform to manage their property, and guests who search for or book a stay through a hotel's public page. It's written by [Company Legal Name].
2. Information we collect
From hotel staff accounts:
- Name, email, phone number, and role, used to create and manage your account and control what you can access.
- Login activity (timestamps, and IP address for security purposes such as detecting repeated failed logins).
From guests booking a stay:
- Name, mobile number, and email address, used to create and confirm your booking and let the hotel contact you about your stay.
- Stay details you provide (dates, number of guests, any special requests) and the corporate/agent access code you enter, if any.
- We don't store full payment card details — the Service doesn't currently process online payments; where a payment step exists, it's handled at the property or through a third-party payment provider under its own privacy terms.
3. How we use this information
- To operate the Service — creating accounts, processing bookings, and showing the right rates/availability to the right audience.
- To communicate with you about your account or booking (confirmations, changes, cancellations).
- To maintain security — detecting and preventing fraud, abuse, and unauthorized access.
- To meet legal and tax obligations (for example, GST-related invoice records).
We don't sell personal data, and we don't use guest booking information for third-party advertising.
4. Who we share it with
- The hotel you're booking with (or that you work for) — a booking or staff account inherently belongs to that property.
- Online travel agencies (OTAs) and travel agents, only for a booking actually made through that channel, and only the details needed to fulfill it.
- Service providers who help us run the platform (e.g. hosting, email delivery), bound to use data only to provide that service to us.
- Authorities, where required by law or a valid legal request.
5. Cookies and sessions
We use a session cookie to keep you logged in and to remember booking progress (such as a held room during checkout). We don't use third-party advertising cookies.
6. How long we keep data
Booking and account records are kept for as long as needed to provide the Service and to meet legal/tax record-keeping requirements (commercial and tax records are commonly kept for several years under Indian law), after which they're deleted or anonymized.
7. Your rights
Subject to applicable law, you can ask us to access, correct, or delete your personal data, or ask what we hold about you. Contact us using the details below and we'll respond within a reasonable time. If you're a guest, some requests (like deleting a completed booking's financial record) may be limited by our legal obligation to keep it.
8. Security
We use reasonable technical and organizational measures to protect personal data (for example, encrypting stored credentials and access codes) — but no system is completely secure, and we can't guarantee absolute security.
9. Children
The Service isn't directed at children, and we don't knowingly collect personal data from children beyond what a booking guest provides about accompanying minors (e.g. a child's age for occupancy/pricing purposes).
10. Changes to this policy
We may update this policy from time to time; the "Last updated" date above reflects the most recent change. Material changes will be highlighted on this page.
11. Grievance officer / contact
For privacy questions or to exercise the rights above, contact [Grievance Officer Name] at hello@hotezo.com.
Back to home