How Innspot collects, uses, and protects information across our website, Innspot Panel, and Innspot Operation.
Innspot ("we", "us", "our") provides a hotel property management platform consisting of Innspot Panel, a web application, and Innspot Operation, a mobile application. This policy explains what information we handle and why. Where we process data on behalf of a hotel using our platform, that hotel is the data controller and we act as processor under our agreement with them.
Information you give us. Name, work email, company or property name, room count, and anything written into a contact form or support request.
Information from platform use. Account identifiers, actions taken in the product such as task completions and status changes, device and browser type, IP address, and timestamps. This operational logging is what makes the audit trail and activity log features possible.
Guest data held for customers. Where a hotel stores guest records in Innspot, we process that data only to provide the service and under that hotel's instructions.
To operate and secure the platform; to provide support and respond to enquiries; to maintain the audit and activity records customers rely on operationally; to improve product performance and reliability; and to send service communications such as release and maintenance notices. We do not use customer or guest data to train models, and we do not sell personal information.
Where applicable law requires a legal basis, we rely on performance of a contract, legitimate interests in securing and improving the platform, consent where you have given it, and compliance with legal obligations.
We share data with service providers who support our operations — hosting, error monitoring, and communications — under contractual confidentiality and processing terms. We may disclose information where required by law or to protect the rights and safety of our users. We do not sell personal information to third parties.
Account and operational data is retained for the duration of the customer contract plus the period required for audit and legal obligations. Contact-form submissions are retained for up to 24 months. On termination, customer data is deleted or returned according to the terms of the relevant agreement.
We apply administrative, technical, and physical safeguards including encryption in transit, role-based access control, per-action audit logging, and continuous backup. No system is perfectly secure, but we work to industry standards and review our controls regularly.
Depending on your jurisdiction you may have the right to access, correct, delete, or port your personal information, and to object to or restrict certain processing. Where a hotel is the controller of the data in question, we will direct your request to them and support them in responding.
Our website uses cookies necessary for basic functionality and, where permitted, analytics cookies that help us understand which pages are useful. You can control cookies through your browser settings.
We may process data in countries other than where you are located. Where we do, we apply appropriate safeguards for the transfer as required by applicable law.
We may update this policy from time to time. Material changes will be communicated to account administrators and reflected in the date above.
Questions about this policy or a privacy request can be sent to [email protected], or through our contact page.