Privacy Policy
Last updated: 9 July 2026
The short version: guests can use the concierge chat without creating an account. We do not require guests to provide an email address, phone number, or password, and we never read guest identities out of hotel systems. Chat messages are processed to answer the guest, maintain the conversation, and create staff tickets. Hotel staff accounts hold an email address, a role, and a securely hashed password.
1. Who we are
GuestBridge is an early stage service operated by its founder ("we", "us"). Full legal provider details will be published here once business registration is complete. You can reach us at [email protected].
2. Our role: controller or processor
When a hotel uses GuestBridge to talk to its guests, the hotel decides why and how guest data is used. For guest chat data the hotel is therefore the data controller and we act as its data processor. Our Data Processing Agreement applies to every hotel customer and forms part of the service agreement.
For hotel staff accounts, billing contacts, and visits to this website, we are the data controller.
3. What we collect
From hotel guests using the chat:
- The messages you type. These may include personal data you choose to share, such as your name or room number when you place a request.
- Requests and tickets created from your messages, and any star rating you leave.
- A random session identifier, your language choice, and a local copy of the chat transcript, stored in your browser so the chat remembers you during your stay.
- Technical data such as your IP address, used only for security controls like rate limiting and abuse prevention.
We do not ask guests to register or require an email address or phone number. If you choose to include contact details in a message, they are stored as part of the chat and may also be copied into the staff ticket so the hotel can handle your request. Where a hotel connects its property management system, we read hotel facts such as room types and stay dates. We never retrieve guest names or contact details from those systems.
From hotel staff: email address, role, a securely hashed password (we never store the password itself), login sessions, and team invitations.
From website visitors: standard server logs and the security filtering applied by our infrastructure providers. We use no advertising or analytics cookies.
4. How we use data, and on what legal basis
- To answer guests and route their requests to hotel staff: performance of the service the hotel has contracted (GDPR Art. 6(1)(b) and, for guest data, the hotel's instructions to us as processor).
- To secure the platform, including rate limiting and abuse prevention: our legitimate interest in running a safe service (Art. 6(1)(f)).
- To email hotel staff about new guest requests: performance of the contract with the hotel.
We do not sell personal data and we do not use it for advertising.
5. AI processing
Guest messages and relevant hotel information are sent to OpenAI's API to generate concierge replies. Under OpenAI's API terms, data submitted through the API is not used to train their models. Replies are generated automatically, but no decision with legal or similarly significant effect is ever made about a guest.
6. Service providers (subprocessors)
| Provider | Purpose |
|---|---|
| Railway | Application hosting and database |
| OpenAI | Generating AI concierge replies |
| Resend | Delivering staff notification emails (email may be processed in the United States) |
| Cloudflare | DNS, content delivery, and security filtering |
Where a provider processes data outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision such as the EU-US Data Privacy Framework.
7. How long we keep data
- Guest chats, tickets, and ratings on our systems: kept for as long as the hotel's account is active, or until the hotel deletes them. Hotels can request deletion of guest data at any time.
- The browser's local chat copy remains until the guest clears the chat or removes the site's browser data.
- Staff accounts: until the account is removed by the hotel or the contract ends.
- Security logs: kept for a short period consistent with their purpose.
- Database backups are retained on a rolling basis and expire automatically.
8. Your rights
Under the GDPR you can ask for access to your data, correction, deletion, restriction, portability, and you can object to processing based on legitimate interest. Guests should contact their hotel first, since the hotel controls guest data; we support hotels in answering these requests. You can also contact us directly at [email protected].
You have the right to lodge a complaint with your supervisory authority. In Hungary this is the NAIH (Nemzeti Adatvédelmi és Információszabadság Hatóság, naih.hu).
9. Cookies and local storage
- Staff dashboard: one essential session cookie that keeps staff logged in.
- Guest chat: browser local storage holding a random session identifier, your language choice, and the chat transcript. The guest can remove this with the Clear chat control or by clearing the site's browser data.
Neither is used for tracking or advertising, so no cookie consent banner is required.
10. Security
Data is encrypted in transit (HTTPS). Passwords are stored as salted hashes. Hotel integration credentials are stored encrypted. Each hotel's data is isolated per tenant, access is role based, and the platform applies rate limiting, login lockouts, and spending caps. No system is perfectly secure, but we treat security as a first-class feature.
11. Changes
If this policy changes in a meaningful way, we will update this page and revise the date at the top. Significant changes affecting hotel customers are announced to them directly.
12. Contact
Questions about privacy: [email protected].