Skip to content
Data Accommodation

Legal

Privacy Policy

Last updated 29 September 2026

This policy explains what personal data Data Accommodation handles, why, and what choices you have. It covers our public website and the Data Accommodation platform used by hotels and other hospitality businesses (“customers”). If anything here is unclear, use our contact form.

1. Who is responsible

Website and sales. For information you give us on this website — for example through the contact or demo forms — Data Accommodation decides how it is used and is responsible for it.

Inside the platform. Hotels use Data Accommodation to manage their guests, staff and business. The hotel decides what guest and staff data to record and why; we process that data on the hotel’s behalf and according to its instructions. Guests with questions about their data should contact the hotel first; we will help the hotel respond.

2. What we collect

  • Enquiries: your name, email, and optionally phone number, company, role, country, property details and message, when you submit a form. We also record the IP address, browser user agent and time of submission to protect the forms from abuse.
  • Account data: for people who use the platform — name, email, password (stored only as an argon2id hash), role, two-factor settings, sessions, and a record of sensitive actions in the audit log.
  • Customer data: what hotels record in the platform, such as reservations, guest profiles, identity document numbers (stored encrypted), folios, invoices, payments, orders, tasks and messages.
  • Technical data: server logs with IP addresses, request identifiers and error details, used to operate and secure the service.

3. How we use it

  • To answer enquiries and arrange demonstrations you ask for.
  • To provide, secure and support the platform for our customers.
  • To prevent abuse, investigate security events and keep an audit trail.
  • To bill customers for their subscription and meet legal and tax obligations.

4. Cookies

The public website does not use advertising or analytics cookies.

The platform uses strictly necessary cookies to keep you signed in: an httpOnly access-token cookie, a refresh-token cookie limited to the authentication endpoints, and a CSRF-protection cookie. They are not used for tracking.

5. Service providers and sharing

We do not sell personal data. Some features send data to third parties chosen by, and configured for, the customer:

  • Payment providers (eSewa, Khalti, Fonepay, Stripe) when a guest pays online — payment details are entered on the provider’s own page.
  • Channel partners (Channex) and calendar feeds (iCal) when a hotel connects its distribution channels.
  • Nepal’s Inland Revenue Department (CBMS) for invoice reporting, when the hotel enables it.
  • Email (SMTP) and SMS (Sparrow SMS) providers to deliver messages.
  • Anthropic, when the operations assistant is enabled, receives the question and the summarised figures needed to answer it.

We may disclose data when the law requires it, and we will tell the affected customer unless we are prohibited from doing so.

6. Security

Customer data is separated by organisation in the data layer, access is controlled by roles and permissions, passwords are hashed with argon2id, identity numbers are encrypted, and sensitive actions are recorded in an append-only audit log. Read more on our security page.

7. How long we keep data

Enquiries are kept for as long as needed to respond and to follow up on the conversation you started, and deleted on request.

Customer data is kept for the life of the customer’s account. Hotels can export their data at any time and can anonymise individual guest profiles; financial records that the law requires to be kept are retained. When an account closes, we agree with the customer how and when their data is returned and deleted.

8. Your choices and rights

You can ask to access, correct or delete personal data we hold about you as a website visitor or platform user, or object to how it is used. Send the request through our contact form. If your data was recorded by a hotel, please contact the hotel; we will support it in answering you.

9. Changes to this policy

We will update this page when our practices change and revise the date at the top. Significant changes affecting customers will also be communicated to account owners.