Privacy Policy

Last updated 4 September 2026

1. Two kinds of people in this policy

  • Hotel staff — the owner and employees who sign in to AATITHIYA. We decide what we collect about them to run the service.
  • Hotel guests — the people a hotel checks in. The hotel decides what it records about them; we only store and process it on the hotel’s instructions.

2. What we store about hotel staff

  • Name, email address and mobile number (both are sign-in identifiers).
  • A bcrypt hash of the password — never the password itself.
  • Session records: when you signed in, from which IP and browser, and when the session expires.
  • Sign-in attempts, so we can rate-limit brute-force attacks.
  • An audit trail of the sensitive actions you take inside your hotel.

3. What a hotel stores about its guests

Typically name, mobile number, email, address, an ID type and number if the hotel collects one, plus the stay, orders, payments and invoices. The hotel chooses what to record; AATITHIYA does not require an ID document.

4. Ordering from a QR code on a restaurant table

When a restaurant asks for your mobile number as you confirm an order from its table, that number and the name you give are the only things collected — no address, no date of birth, no email, no location. They are kept so the restaurant can recognise you on a later visit and greet you by name instead of asking again; your number is shown back to you masked, and a guest is never told anything about another guest.

Your number is not used for marketing, and nothing about you is shared with another hotel or another restaurant of the same hotel — a restaurant greets you only where you have ordered before. You can order without giving a number by asking a member of staff to take your order instead; ask them to remove your details and they can.

5. Why we hold it

  • To run the service the hotel signed up for: rooms, stays, bills and invoices.
  • To keep accounts secure — hashing, sessions, rate limiting and the audit log.
  • To meet the record-keeping the hotel itself is subject to (invoices, tax).
  • To answer support requests you send us.

6. Keeping hotels apart

Every record belongs to exactly one hotel, and every request is scoped to the hotel of the signed-in user. There is no shared list of guests, rooms or bills across hotels. Uploaded files and invoice PDFs are served only after the same check.

7. Who else sees it

  • Nobody outside your hotel, except our infrastructure providers (hosting and database) acting on our instructions.
  • Our support staff, only with time-limited support access, and every action is written to your audit log.
  • Authorities, if the law requires it.
  • We never sell personal data, and we do not use guest data to advertise to anyone.

8. How long we keep it

Operational and financial records are kept while the hotel’s account exists, because invoices, payments and the audit trail must remain intact (nothing important is hard-deleted). If a subscription lapses, data is kept — not deleted — so the hotel can come back. After an account closes we keep the data for a reasonable window so the hotel can export it, then delete it on request.

9. Security

  • Passwords hashed with bcrypt; sessions are server-side and revocable.
  • Role-based permissions, so staff only reach what their role allows.
  • HTTPS in transit, CSRF protection on every change, and validation on every input.
  • An append-only audit log of sensitive actions.
  • Guest details are kept out of application logs.

10. Cookies

AATITHIYA sets one essential cookie to keep you signed in. There are no advertising or third-party tracking cookies on the app or on this website.

11. Your choices

Hotel staff can ask us to correct or delete their own account details. Guests should contact the hotel they stayed at — the hotel holds that record and can correct or archive it. If a hotel asks us for help fulfilling such a request, we assist.

12. Messages you send us

If you write to us through the contact form, we use your name, email, optional phone number and message only to reply.

13. Changes

We will tell hotels before material changes to this policy take effect.

14. Contact

Privacy questions: support@hotelio.app.