Privacy Policy

Last updated: April 1, 2025

Hotel Systems (a Multisystems.ai product) is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your personal information when you use our platform and services.

1. Introduction

Hotel Systems, a product of Multisystems.ai ("Hotel Systems," "we," "us," or "our"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website (hotelsystems.ai), use our AI-powered hotel management platform, or interact with our services (collectively, the "Service").

This policy applies to all users of the Service, including hotel operators ("Customers"), their staff, and website visitors. For hotel guests whose data is processed through our platform on behalf of Customers, our Customers act as data controllers, and Hotel Systems acts as a data processor.

By using the Service, you consent to the data practices described in this Privacy Policy. If you do not agree with this policy, please do not use the Service.

2. Information We Collect

We collect the following categories of information:

a. Information You Provide Directly

  • Account Information: Name, email address, phone number, job title, company/hotel name, and billing address when you create an account or subscribe to the Service.
  • Payment Information: Payment card details and billing information, which are processed securely by our third-party payment processors. We do not store full payment card numbers on our servers.
  • Communications: Information you provide when you contact our support team, respond to surveys, or communicate with us through any channel.
  • Messaging Consent Records: Records of opt-in and opt-out consent for SMS/text messaging communications.

b. Hotel Operational Data (Processed on Behalf of Customers)

  • Guest names, contact information, and reservation details
  • Check-in/check-out dates and room assignments
  • Guest preferences, requests, and communication history
  • Review and feedback data from various platforms
  • Revenue and occupancy data

c. Information Collected Automatically

  • Usage Data: Pages visited, features used, click patterns, time spent on pages, and other interaction data within the Service.
  • Device & Browser Information: IP address, browser type and version, operating system, device type, screen resolution, and language preferences.
  • Log Data: Server logs including access times, error logs, and referral URLs.
  • Cookies & Similar Technologies: Information collected through cookies, pixel tags, and similar tracking technologies (see Section 9).

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing the Service: To operate, maintain, and deliver the features and functionality of the platform, including AI-powered guest communication, channel management, and analytics.
  • Account Management: To create and manage your account, process payments, and communicate with you about your subscription.
  • AI & Machine Learning: To train, improve, and operate our AI models using anonymized and aggregated data. We do not use identifiable guest data to train AI models without explicit Customer consent.
  • Communication: To send you transactional messages (account notifications, billing receipts, security alerts), and with your consent, marketing communications about new features and product updates.
  • SMS/Text Messaging: To send operational messages (booking confirmations, check-in reminders, guest communications) via SMS on behalf of Customers who have enabled messaging features and obtained proper recipient consent.
  • Analytics & Improvement: To understand usage patterns, diagnose technical issues, and improve the Service's performance and user experience.
  • Security & Fraud Prevention: To detect, prevent, and respond to security incidents, fraud, and abuse.
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, and government requests.

4. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

  • Service Providers & Subprocessors: We share data with trusted third-party providers who assist us in operating the Service, including:
    • Supabase: Database hosting and backend infrastructure
    • AI Providers: OpenAI, Anthropic, and other AI model providers for natural language processing and AI-powered features
    • Payment Processors: For secure payment processing
    • SMS/Messaging Providers: For delivering text messages through 10DLC-compliant channels
    • Zoho SalesIQ: For live chat and customer engagement on our website
    • Google Fonts: For web font delivery
    • Analytics Providers: For website and product analytics
  • Business Transfers: In connection with a merger, acquisition, sale of assets, or similar business transaction, your information may be transferred as part of the transaction. We will notify you of any such change.
  • Legal Requirements: We may disclose information if required by law, subpoena, court order, or government regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
  • With Your Consent: We may share your information with third parties when you have given us explicit consent to do so.

5. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Specific retention guidelines include:

  • Account Data: Retained for the duration of your active account and for up to 30 days after account closure to allow for data export requests.
  • Billing & Transaction Records: Retained for up to seven (7) years to comply with tax and accounting obligations.
  • Usage & Analytics Data: Retained in identifiable form for up to twenty-four (24) months, after which it is anonymized or deleted.
  • Hotel Operational Data: Retained on behalf of Customers for the duration of their subscription. Upon termination, data is available for export for 30 days, then deleted within 90 days.
  • SMS/Messaging Consent Records: Retained for the duration required by applicable law (typically at least five years after the last message sent).
  • Support Communications: Retained for up to three (3) years to improve our support quality and resolve recurring issues.

When data is no longer needed, we securely delete or anonymize it using industry-standard practices.

6. Data Security

We implement robust technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption: Data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption.
  • Access Controls: Role-based access controls, multi-factor authentication for administrative access, and principle of least privilege.
  • Infrastructure Security: Our infrastructure is hosted on enterprise-grade cloud platforms with SOC 2 compliant data centers.
  • Monitoring & Incident Response: Continuous monitoring for security threats and a documented incident response plan for promptly addressing any breaches.
  • Employee Training: Regular security awareness training for all employees with access to personal data.
  • Vendor Security: Due diligence and contractual safeguards for all third-party subprocessors.

While we strive to protect your personal information, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incidents. If a data breach occurs that affects your personal information, we will notify you in accordance with applicable law.

7. Your Rights

Depending on your location, you may have certain rights regarding your personal information:

a. Rights for All Users

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete personal information.
  • Deletion: Request deletion of your personal information, subject to legal retention requirements.
  • Opt-Out of Marketing: Unsubscribe from marketing communications at any time by clicking the "unsubscribe" link in our emails or contacting us.
  • SMS Opt-Out: Reply STOP to any SMS message to opt out of text messaging. You may also text HELP for assistance or contact us directly.

b. California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share it.
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
  • Right to Opt-Out of Sale: We do not sell your personal information. However, you have the right to opt out if this ever changes.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
  • Right to Correct: You may request correction of inaccurate personal information.
  • Right to Limit Use of Sensitive Personal Information: If applicable, you may limit our use of sensitive personal information to purposes necessary to provide the Service.

To submit a CCPA request, contact us at contact@hotelsystems.ai. We will verify your identity before processing your request and respond within forty-five (45) days.

c. European Economic Area (EEA) & UK Residents (GDPR)

If you are located in the EEA or UK, you have rights under the General Data Protection Regulation (GDPR):

  • Legal Basis for Processing: We process your data based on: (i) your consent; (ii) performance of a contract; (iii) our legitimate interests; or (iv) legal obligations.
  • Right to Access, Rectification, and Erasure: You may request access to, correction of, or deletion of your personal data.
  • Right to Restriction and Objection: You may request restriction of processing or object to processing based on legitimate interests.
  • Right to Data Portability: You may request your personal data in a structured, machine-readable format.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority.

To exercise your GDPR rights, contact us at contact@hotelsystems.ai.

8. Children's Privacy

The Service is designed for use by businesses and is not directed at individuals under the age of eighteen (18). We do not knowingly collect personal information from anyone under 18 years of age. If we become aware that we have collected personal information from a person under 18 without verified parental or guardian consent, we will take immediate steps to delete that information.

If you believe we have inadvertently collected information from a child under 18, please contact us immediately at contact@hotelsystems.ai.

9. Cookie Policy

We use cookies and similar tracking technologies to enhance your experience on our website and platform. The categories of cookies we use include:

  • Strictly Necessary Cookies: Required for the basic functioning of the website and platform, including authentication, security, and session management. These cannot be disabled.
  • Functional Cookies: Enable enhanced features and personalization, such as remembering your preferences and settings.
  • Analytics Cookies: Help us understand how visitors interact with our website by collecting and reporting usage data anonymously.
  • Marketing Cookies: Used to track visitors across websites to display relevant advertisements. We only use these with your consent.

You can manage your cookie preferences through your browser settings. Most browsers allow you to block or delete cookies. However, disabling certain cookies may affect the functionality of the Service. For more information about the specific cookies we use, please contact us.

10. Third-Party Services

Our Service integrates with and uses the following third-party services that may collect or process data:

  • Zoho SalesIQ: Provides live chat functionality on our website. May collect visitor browsing data and chat transcripts. Subject to Zoho's privacy policy.
  • Supabase: Provides database hosting and authentication services. Data is stored in Supabase-managed infrastructure with encryption at rest and in transit.
  • Google Fonts: Used for web font delivery. Google may collect IP addresses and browser information when fonts are loaded.
  • AI Providers (OpenAI, Anthropic, etc.): Power our AI features including guest communication tools and analytics. Data sent to AI providers is processed under our data processing agreements and is not used to train their general models.
  • SMS/Messaging Providers: Facilitate delivery of text messages through 10DLC-compliant infrastructure. Subject to applicable telecommunications regulations.

Our website and platform may contain links to third-party websites and services. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party services you interact with.

11. International Data Transfers

Hotel Systems is based in the United States. If you are accessing the Service from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.

For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on the following safeguards:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements (DPAs) with all subprocessors that include appropriate transfer mechanisms
  • Supplementary technical and organizational measures to ensure adequate protection of personal data

By using the Service, you acknowledge and consent to the transfer, storage, and processing of your information in the United States. To request a copy of the applicable data transfer safeguards, contact us at contact@hotelsystems.ai.

12. SMS & Text Messaging

When you provide your telephone number in a form on this website (for example, when booking a demo) and check the SMS consent box, you consent to receive calls and text messages from Multisystems. Providing a phone number and opting in to SMS is entirely optional and is never a condition of purchasing any goods or services. Message frequency may vary. Message and data rates may apply. You can opt out at any time by replying STOP to any message, and reply HELP for help. Opt-in and opt-out are handled on the same phone number.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.

If you or your hotel guests interact with our SMS/text messaging features, the following additional disclosures apply:

  • Opt-In: SMS messages are only sent to recipients who have provided prior express consent. Our Customers are responsible for collecting and maintaining proof of consent from their guests.
  • Message Types: Messages may include booking confirmations, check-in/ check-out reminders, guest service communications, and other operational messages related to a hotel stay.
  • Opt-Out: Recipients can opt out at any time by replying STOP to any message. Opt-out requests are processed immediately and automatically.
  • Help: Recipients can reply HELP to any message for assistance or contact us at contact@hotelsystems.ai.
  • Message Frequency: Message frequency varies based on hotel interactions and service needs.
  • Carrier Costs: Standard message and data rates may apply depending on your mobile carrier plan.
  • Data Sharing: Phone numbers and messaging data are not shared with third parties for marketing purposes. Data is shared only with messaging delivery providers as necessary to transmit messages.

We retain messaging logs and consent records in accordance with TCPA requirements and carrier regulations. For questions about our messaging practices, contact contact@hotelsystems.ai.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Post the revised policy on our website
  • Notify you via email or in-app notification for material changes
  • Where required by law, obtain your consent before applying material changes to how we process your personal data

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of the Service after changes to this policy constitutes your acceptance of those changes.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

  • Company: Hotel Systems (a Multisystems.ai product)
  • Email: contact@hotelsystems.ai
  • Address: 1505 Greenland Dr, Murfreesboro, TN 37130
  • Website: hotelsystems.ai

For GDPR-related inquiries or to reach our Data Protection Officer, please email contact@hotelsystems.ai with the subject line "Data Protection Inquiry."

If you are in the EEA and believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local supervisory authority.