Privacy Policy
Last updated: 3 August 2026
The short version: guests can use the concierge chat without creating an account. Chat messages are processed to answer the guest, maintain the conversation, and create staff tickets. If a guest chooses digital check-in/out, messaging, or an upsell, we also process the booking and contact details they provide for that feature. Payment-card details are entered directly into Stripe Checkout and are not stored by us. Hotel staff accounts hold an email address, a role, and a securely hashed password.
1. Who we are
GuestBridge is an early stage service operated by its founder ("we", "us"). Full legal provider details will be published here once business registration is complete. You can reach us at [email protected].
2. Our role: controller or processor
When a hotel uses GuestBridge to talk to its guests, the hotel decides why and how guest data is used. For guest chat data the hotel is therefore the data controller and we act as its data processor. Our Data Processing Agreement applies to every hotel customer and forms part of the service agreement.
For hotel staff accounts, billing contacts, and visits to this website, we are the data controller.
3. What we collect
From hotel guests using the chat:
- The messages you type. These may include personal data you choose to share, such as your name or room number when you place a request.
- Requests and tickets created from your messages, staff replies, request status, and any star rating you leave.
- For digital check-in/out: details you submit such as your name, room number, booking reference, stay timing, party size, email address, phone number, preferences, acknowledgements, and notes.
- For paid extras: the item, amount, currency, order and payment status, provider reference, and receipt link. Payment-card details are handled directly by Stripe and are not stored by GuestBridge.
- For SMS or WhatsApp: your phone number, channel consent or opt-out status, message content, and delivery status.
- A random session identifier, your language choice, and a local copy of the chat transcript, stored in your browser so the chat remembers you during your stay.
- Technical data such as your IP address, used only for security controls like rate limiting and abuse prevention.
We do not ask guests to create an account. Email addresses, phone numbers, and booking references are requested only when needed for an optional feature selected by the guest or hotel, such as digital check-in/out or lifecycle messaging. If you include contact details in a message, they are stored as part of the conversation and may be copied into the staff ticket. Where a hotel connects its property management system, the exact data accessed depends on that hotel's configuration and provider permissions.
From hotel staff: email address, role, a securely hashed password (we never store the password itself), login sessions, and team invitations.
From website visitors: standard server logs and the security filtering applied by our infrastructure providers. We use no advertising or analytics cookies.
4. How we use data, and on what legal basis
- To answer guests and route their requests to hotel staff: performance of the service the hotel has contracted (GDPR Art. 6(1)(b) and, for guest data, the hotel's instructions to us as processor).
- To process digital check-in/out, guest purchases, receipts, and related hotel workflows: performance of the requested service and the hotel's instructions to us as processor.
- To send opted-in lifecycle messages through email, SMS, or WhatsApp and record delivery outcomes: consent where required and the hotel's documented instructions. Guests can opt out of messaging; SMS recipients can reply STOP.
- To secure the platform, including rate limiting and abuse prevention: our legitimate interest in running a safe service (Art. 6(1)(f)).
- To email hotel staff about new guest requests: performance of the contract with the hotel.
We do not sell personal data and we do not use it for advertising.
5. AI processing
Guest messages and relevant hotel information are sent to OpenAI's API to generate concierge replies. Under OpenAI's API terms, data submitted through the API is not used to train their models. Replies are generated automatically, but no decision with legal or similarly significant effect is ever made about a guest.
6. Service providers (subprocessors)
| Provider | Purpose |
|---|---|
| Railway | Application hosting and database |
| OpenAI | Generating AI concierge replies |
| Resend | Delivering staff notification emails (email may be processed in the United States) |
| Twilio (when enabled by the hotel) | Sending and receiving SMS or WhatsApp messages and reporting delivery status |
| Stripe (when paid extras are enabled) | Hosted checkout, payment processing, and payment-status webhooks |
| The hotel's configured PMS provider (when enabled) | Providing reservation or property context within the permissions selected by the hotel |
| Cloudflare | DNS, content delivery, and security filtering |
Where a provider processes data outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision such as the EU-US Data Privacy Framework.
7. How long we keep data
- Guest chats, tickets, ratings, stay-flow records, orders, messaging consent, and delivery logs: kept for as long as the hotel's account is active, according to the hotel's retention instructions, or until the hotel deletes them. Hotels can request deletion of guest data at any time.
- Payment records retain order and payment-status information needed for reconciliation; full card details are not stored by us.
- The browser's local chat copy remains until the guest clears the chat or removes the site's browser data.
- Staff accounts: until the account is removed by the hotel or the contract ends.
- Security logs: kept for a short period consistent with their purpose.
- Database backups are retained on a rolling basis and expire automatically.
8. Your rights
Under the GDPR you can ask for access to your data, correction, deletion, restriction, portability, and you can object to processing based on legitimate interest. Guests should contact their hotel first, since the hotel controls guest data; we support hotels in answering these requests. You can also contact us directly at [email protected].
You have the right to lodge a complaint with your supervisory authority. In Hungary this is the NAIH (Nemzeti Adatvédelmi és Információszabadság Hatóság, naih.hu).
9. Cookies and local storage
- Staff dashboard: one essential session cookie that keeps staff logged in.
- Guest chat: browser local storage holding a random session identifier, your language choice, and the chat transcript. The guest can remove this with the Clear chat control or by clearing the site's browser data.
Neither is used for tracking or advertising, so no cookie consent banner is required.
10. Security
Data is encrypted in transit (HTTPS). Passwords are stored as salted hashes. Hotel integration credentials are stored encrypted. Each hotel's data is isolated per tenant, access is role based, and the platform applies rate limiting, login lockouts, and spending caps. No system is perfectly secure, but we treat security as a first-class feature.
11. Changes
If this policy changes in a meaningful way, we will update this page and revise the date at the top. Significant changes affecting hotel customers are announced to them directly.
12. Contact
Questions about privacy: [email protected].
Provider and contact details
GuestBridge
Founder: Pintér Márton
https://guestbridge.net
[email protected]
+36 30 951 8798
Full legal provider details are pending and will be published here when confirmed. For provider information or a signed agreement, please contact the founder.