Legal

Privacy Policy

Last updated: September 7, 2026

This Privacy Policy explains how Hotel IT Passport collects, uses, discloses, and protects information when you visit our websites, request information, create an account, subscribe, or use the Hotel IT Passport service.

1. Information we collect

We may collect account and profile information such as name, business email, organization name, role, authentication status, and access permissions. We also process Customer Data that authorized users enter or upload, including hotel records, technology inventories, network documentation, vendor contacts, contracts, renewal information, procedures, reports, and related documents.

When you subscribe, our payment processor handles payment credentials. Hotel IT Passport may receive billing-related information such as customer identifiers, subscription identifiers, plan, quantity, invoice status, billing email, renewal dates, cancellation state, and limited payment metadata. We do not intentionally store full payment-card numbers in Hotel IT Passport.

2. Website, marketing, and support information

If you submit a readiness check, walkthrough request, contact form, or other website form, we may collect your name, email, company, role, number of properties, message, readiness results, page path, and campaign/source parameters. We may also process technical information such as IP-derived request fingerprints, browser or device information, timestamps, and security logs to prevent abuse and operate the Service.

3. How we use information

We use information to provide and secure the Service; authenticate users; provision organizations and subscriptions; enforce property and access limits; process billing events; import or synchronize authorized third-party data; generate reports and readiness results; send account, security, billing, reminder, and support communications; respond to inquiries; prevent fraud and abuse; troubleshoot problems; and improve the reliability and usability of Hotel IT Passport.

4. Service providers and integrations

We use service providers to operate Hotel IT Passport. Depending on the feature you use, these may include hosting and deployment providers, database and authentication providers, payment processors, email-delivery providers, and authorized technology integrations. Current examples include Vercel, Supabase, Stripe, Resend, and UniFi-related services when an organization chooses to connect them. These providers process information only as needed to perform their services and are subject to their own contractual and privacy obligations.

5. Organization access and sharing

Customer Data is made available to users and service providers according to the organization and property permissions configured in Hotel IT Passport. Organization Owners and Administrators can manage users and access. You should only invite people who are authorized to view the applicable hotel records. We do not sell Customer Data or personal information to advertisers.

6. Credentials and highly sensitive information

Hotel IT Passport is not designed to store actual passwords, private keys, door PINs, payment-card numbers, or authentication secrets in ordinary records. Customers should use a dedicated secure credential-management system for those secrets and use Hotel IT Passport only to document the approved credential location or access process.

7. Cookies and authentication technologies

The Service may use cookies or similar browser storage that are necessary for authentication, session continuity, security, preferences, and application operation. We may also use limited website analytics or campaign parameters to understand how visitors reach and use public pages. We do not use these technologies to sell personal information.

8. Data retention

We retain information for as long as reasonably necessary to provide the Service, maintain account and billing records, satisfy legal or accounting obligations, resolve disputes, prevent fraud, and protect the security of the Service. Retention periods may differ by data type. When an account or subscription ends, some records may remain for a limited period for backup, audit, billing, security, or legal purposes.

9. Security

We use administrative, technical, and organizational safeguards intended to protect information, including role- and property-scoped access controls, authentication protections, server-side handling of sensitive integration secrets, and encrypted transport. No system can guarantee absolute security, and customers remain responsible for maintaining secure user accounts and endpoint devices.

10. Your choices and rights

Depending on where you are located, you may have rights to request access, correction, deletion, restriction, portability, or other actions regarding personal information. Organization administrators can update much of the operational data directly in the Service. For privacy requests that cannot be completed in the application, contact us through the link below. We may need to verify your identity and authority before acting on a request.

11. Children

Hotel IT Passport is a business service and is not directed to children. We do not knowingly solicit accounts from individuals under 18.

12. Changes to this Policy

We may update this Privacy Policy as the Service, our providers, or applicable requirements change. We will post the updated version and effective date and may provide additional notice for material changes.

13. Contact

Privacy questions or requests can be submitted through our Contact page. For account-specific requests, use the email associated with your Hotel IT Passport account when possible.