Skip to content
Data Accommodation

Legal

Acceptable Use Policy

Version 2026-10-09 · Effective 9 October 2026

This policy applies to every person who uses Data Accommodation — the people who sign up a hotel, the staff they invite, and anyone else given access. It forms part of our Terms of Service. A hotel (the “customer”) is responsible for making sure the people it invites follow it. If you are unsure whether something is allowed, ask us first through our contact form (choose “Privacy, data and legal requests”) or email support@datadoodlestech.com.

1. Treat guest and staff data with care

  • Record personal data only for a genuine hotel, restaurant or business purpose, and only what you need for it.
  • Record identity document, visa and date-of-birth details only where your property needs them — for example, where the law requires guest registration — and use the encrypted identity fields for them, not free-text notes.
  • Do not put health, religious, political or other sensitive information in notes or preferences unless it is genuinely needed to serve the guest (such as a food allergy) and you are permitted to record it.
  • Never enter payment card numbers, card security codes or online banking passwords anywhere in the platform. Card and wallet payments are made on the payment provider’s own page.
  • Reveal, export or print guest data only when your work requires it. Revealing a full identity number and exporting data are recorded in the audit log.

2. Keep accounts secure

  • Each sign-in belongs to one person. Do not share your password, sign-in or API key with anyone, including colleagues.
  • Use a strong, unique password, and turn on two-factor authentication — especially if your role can see guest identity details, money or settings.
  • Grant colleagues only the roles their job needs, and remove access promptly when someone leaves.
  • Tell us straight away if you suspect someone else has used an account.

3. Send only lawful, wanted messages

  • Use email and SMS features for messages about a guest’s booking, stay or order, or for marketing only where the guest has agreed to receive it and the law allows.
  • Do not send spam, misleading messages or content that is unlawful, harassing, defamatory or infringes someone else’s rights.
  • Do not impersonate another person, hotel or brand.

4. Respect the platform and other customers

You must not, and must not help anyone else to:

  • try to access another customer’s data, another property you have not been given, or any part of the service you are not authorised to use;
  • bypass, disable or test the limits of access controls, two-factor authentication, rate limits or other security measures;
  • upload viruses or other malicious code, or interfere with the service’s operation or other customers’ use of it;
  • scrape the service, or send automated requests other than through the API with a key issued for that purpose;
  • copy, modify, resell, sublicense or rent the service, or reverse engineer it except where the law expressly allows;
  • use the service to build a competing product, or to break any law that applies to you or your business.

5. QR ordering and guest pages

Room and table QR codes, booking pages and guest portals are meant for the hotel’s guests. Do not use them to place false orders, to try other rooms’ or tables’ codes, or to access another guest’s booking.

6. The live demo

The live demo is a shared, fictional hotel that is reset regularly and can be seen by other visitors. Do not enter real guest, staff or payment details into it. Some actions — such as sending real messages or connecting real payment accounts — are switched off in the demo.

7. Reporting security issues

If you find a vulnerability, report it to us through the contact form and give us a reasonable time to fix it before telling anyone else. While investigating, do not access, change or keep data that is not yours, and do not degrade the service for others. See our security page for how the platform is protected.

8. If this policy is broken

We may remove content, suspend a user, an API key or — where the customer’s account puts the service or other customers at risk — the account, as described in our Terms of Service. Where we can, we will tell the customer first and explain why. We may also report unlawful activity to the authorities.

Portions of this document are adapted from the Master Services Agreement and Terms of Use templates (use restrictions) published by General Legal, PC under CC0 1.0. General Legal has not reviewed, and takes no position on, this adaptation, and its templates are not legal advice.