Skip to main content

Privacy Policy

Last updated 7 October 2026

Applies to: hotelierkit.com, app.hotelierkit.com, mcp.hotelierkit.com, preview and demo sites on myhotelierkit.com, and the HotelierKit platform generally.


1. Who we are

HotelierKit is a trading name of Hy Group Co., Ltd., a company registered in Thailand.

  • Registered office: 709/23 Soi Onnut 7, Sukhumvit 77 Road, Onnut, Suanluang, Bangkok 10250, Thailand
  • Email: [email protected]
  • Phone: +66 2 460 9544

Hy Digital, a hotel marketing agency, belongs to the same group. Where a hotel engages Hy Digital for marketing services, Hy Digital may also work inside that hotel's HotelierKit account. This policy covers HotelierKit; Hy Digital's own services are covered by its own agreements.

We are the "data controller" under Thailand's Personal Data Protection Act B.E. 2562 (PDPA) and, where it applies, the EU and UK General Data Protection Regulation (GDPR), for the personal data described in sections 3.1 and 3.2. For hotel guest data (section 3.3) we act as a "data processor" on behalf of the hotel.

Privacy contact: [email protected] (marked "Privacy"). We have assessed that we are not currently required to appoint a data protection officer; see section 12.

2. Who this policy is for

HotelierKit sits in three different relationships, and the rules differ for each:

You are What HotelierKit is Which sections apply
A visitor to hotelierkit.com, or someone who requests a demo or contacts us Controller 3.1, 4, 5, 6, 7, 8, 9, 10
A hotel that subscribes to HotelierKit, or a member of staff (or agency) who signs in to the dashboard Controller for account, billing and usage data 3.2, 4, 5, 6, 7, 8, 9, 10
A guest or visitor of a hotel website that runs on HotelierKit Processor. The hotel is the controller. 3.3, 11

If you are a hotel guest and have a question about your data, the hotel you dealt with is the right first contact. Its privacy policy is linked from its website. We will help the hotel respond, and if you contact us directly we will pass your request to the hotel without delay.

3. What we collect

3.1 Visitors to hotelierkit.com and people who contact us

  • Technical data when you load a page. Our content delivery network (Cloudflare) and our web server record the IP address, browser type, requested page, referrer and timestamp of each request for security, abuse prevention and troubleshooting. Public pages of hotelierkit.com do not set a session cookie.
  • Your cookie choice. If you make a choice in the cookie banner we store it in a cookie_consent cookie on your device (one year) and record the choice, with your IP address (encrypted), a one-way hash of your IP address, your country, browser type and the banner version, in our consent log. See section 5.
  • Analytics and advertising data, only if you consent to it in the banner. hotelierkit.com uses Google Tag Manager to load Google Analytics 4 (pages viewed, approximate location, device and browser, and how you move through the site), Google Ads conversion tracking (whether a visit led to a demo request or enquiry) and the Meta Pixel (so we can measure and target our advertising on Meta platforms). None of these load until you accept the relevant category in the banner. See section 5.
  • Demo requests and contact messages. The "Book a demo" form asks for your name, role, hotel name, email, phone (optional), current website (optional) and notes. The contact form asks for your name, email, hotel name (optional) and message. We store the submission in our database, encrypted at rest, together with your IP address (encrypted), browser type and the page you sent it from, and we email it to [email protected].

3.2 Hotel customers, their staff and agencies using the dashboard

  • Account data. Name, email address, password (stored as a one-way hash), optional two-factor authentication secret and recovery codes, the team(s) you belong to and your role in each, your language and interface preferences, and the time you last used the dashboard.
  • Sign-in security events. For each sign-in, failed sign-in, password change, password reset and email change we record the event, your IP address, browser type and time. We keep these for 12 months so you and we can spot sign-ins that should not have happened. You can see your recent sign-ins on your profile page.
  • Activity log. Actions taken in the dashboard (for example publishing a page, exporting a report, removing a team member, or an AI agent calling a tool) are recorded with the user who did them, the time and what was affected. Tool arguments and content are not written to this log.
  • Content you add. Pages, images, videos links, forms, redirects, brand settings, custom code, booking-engine settings, integration keys (Google Tag Manager and Analytics IDs, Turnstile keys, Mapbox tokens), and anything else you put into your site. Integration secrets are encrypted at rest.
  • Connected Google services. If you connect Google Analytics 4 or Google Search Console, we store the OAuth access and refresh tokens Google issues (encrypted at rest) and the read-only, aggregated reporting data we fetch each day (page views, sessions, search impressions and clicks). We request read-only scopes only. HotelierKit's use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.
  • AI agent connections. If you connect an AI assistant such as Claude or ChatGPT through our MCP connector, we record the client you authorized, the sites and scopes you granted, the tokens issued (access tokens expire after one hour, refresh tokens after 30 days), and each tool call the agent makes on your behalf. You can revoke a connection at any time from the Agents page.
  • Billing and contract data. The legal name, billing address, tax ID and contact details of the hotel, the signed service agreement, invoices and payment records. Billing is handled outside the platform: we issue invoices by email and keep these records in our business and accounting systems.
  • Support correspondence. Emails and messages you send us.

3.3 Hotel guests and visitors of hotel websites (we are the processor)

When you visit a hotel's website that runs on HotelierKit, the hotel decides what data is collected and why. HotelierKit processes the following on the hotel's behalf:

  • Technical data when you load a page: IP address, browser type, requested page, referrer, timestamp, held in Cloudflare and web-server logs. Public pages do not set a session cookie.
  • Form submissions. Whatever fields the hotel has placed on its enquiry, booking-request, contact or other forms (typically name, email, phone, dates, number of guests, message). We store the submission encrypted at rest with your IP address (encrypted), browser type and the page it was sent from, and we email it to the addresses the hotel has chosen.
  • Reviews. If the hotel enables review capture, your name, rating, review text, email address (encrypted) and IP address (encrypted), plus your tick in the consent box. Approved reviews are shown publicly with your name and text; your email is never shown.
  • Cookie consent choice. Your cookie_consent cookie and a consent record as described in section 5.
  • Booking click-throughs. When you click "Book now" the hotel's booking engine opens. We attach your consent choice to that link as a short, non-identifying parameter so the booking engine does not need to ask again. We do not receive your booking details; the booking engine is a separate service with its own privacy policy.
  • Tracking the hotel has configured. Google Tag Manager, Google Analytics, Google Ads, Meta Pixel and similar tags that the hotel has chosen to run. These load only with the consent signals described in section 5, where the hotel has enabled the consent banner.

4. Why we use personal data and the legal basis

Purpose Data Legal basis (PDPA / GDPR)
Responding to demo requests and enquiries 3.1 form data Steps before entering a contract (PDPA s.24(3); GDPR Art 6(1)(b)); legitimate interests for follow-up
Running and securing the website and platform (logs, rate limiting, bot protection) Technical data, sign-in events Legitimate interests (PDPA s.24(5); GDPR Art 6(1)(f))
Providing the service to a hotel customer, including the dashboard, hosting, publishing and support 3.2 account, content, activity Performance of the contract (PDPA s.24(3); GDPR Art 6(1)(b))
Account security: sign-in history, two-factor authentication, token revocation Sign-in events, 2FA secrets Legitimate interests and legal obligation to keep data secure (PDPA s.37)
Keeping an audit trail of who changed what Activity log Legitimate interests; legal obligation (PDPA s.39 records)
Billing, accounting and tax Billing data Contract; legal obligation (Thai Revenue Code)
Measuring and improving hotelierkit.com with analytics or advertising tags Cookies, usage data Consent (PDPA s.19; GDPR Art 6(1)(a) and ePrivacy rules). Only if you opt in.
Keeping proof of your cookie choice Consent log Legal obligation to demonstrate consent (PDPA s.19; GDPR Art 7(1))
Sending service emails (team invitations, password resets, submission notifications, SEO reports) Email address Contract; legitimate interests
Improving hotel website copy with AI on request Page text the hotel chooses to rewrite Contract. No guest data is sent.
Processing hotel guest data (3.3) All guest data We act on the hotel's documented instructions under our Terms of Service and, where the hotel has signed one, our Data Processing Addendum. The hotel determines its own legal basis.

We do not sell personal data, and we do not use personal data for automated decisions that have legal or similarly significant effects on you.

5. Cookies and similar technologies

5.1 On hotelierkit.com

Cookie Set by Purpose Duration Category
cookie_consent HotelierKit Remembers your cookie choices 1 year Necessary
__cf_bm, cf_clearance Cloudflare Bot management and security challenges Up to 30 minutes Necessary
_ga, _ga_* Google Analytics 4 (loaded by Google Tag Manager) Distinguishes visitors and sessions for site analytics Up to 2 years Analytics. Only with consent.
_gcl_au, _gcl_aw, _gcl_gs Google Ads (loaded by Google Tag Manager) Measures whether a visit from a Google ad led to a demo request or enquiry Up to 90 days Marketing. Only with consent.
_fbp, _fbc Meta Pixel (loaded by Google Tag Manager) Measures and targets our advertising on Facebook and Instagram Up to 90 days Marketing. Only with consent.

All analytics and advertising tags on hotelierkit.com are loaded through Google Tag Manager. Our banner sets Google Consent Mode v2 to "denied" for analytics and advertising storage before any tag loads, and updates it when you make a choice. The Google Analytics and Google Ads tags fire only when the matching consent is granted, and the Meta Pixel fires only after you accept marketing cookies. If you do not make a choice, analytics and advertising storage stay denied and none of these tags load. You can change your choice at any time via the "Cookie settings" link in the footer.

5.2 In the dashboard (app.hotelierkit.com)

The dashboard sets only strictly necessary cookies: a session cookie (hotelierkit-session, 2 hours of inactivity), a CSRF protection cookie (XSRF-TOKEN), and a "remember me" cookie if you tick that box at sign-in. Preview and share links on myhotelierkit.com set a short-lived preview cookie. The dashboard loads its interface fonts from Bunny Fonts (bunny.net), which receives your IP address to serve the font files and sets no cookies. We do not run analytics or advertising tags in the dashboard.

5.3 On hotel websites

Each hotel decides which tags run on its site and whether to enable the HotelierKit cookie banner. When the banner is enabled, it works as described in 5.1 and records consents in the hotel's consent log. The hotel's own privacy and cookie policy, linked from its banner, lists the cookies that site uses. Hotel pages may also load Google Fonts, Google Maps, Mapbox maps and YouTube videos; video and map embeds are blocked until you accept the relevant category where the banner is enabled.

6. Who we share data with

We do not sell or rent personal data. We share it only with the service providers below (our "sub-processors" when we act for a hotel), with the hotel you are dealing with, with professional advisers under confidentiality, and with authorities where the law requires.

6.1 Sub-processors

Each provider below processes data for us under its own data processing terms, which are the contractual safeguard shown in the last column.

Provider What they do for us Where data is processed Safeguard
Cloudflare, Inc. (USA) Content delivery, DNS, TLS certificates, web application firewall, bot management, Turnstile form protection, image resizing, custom-domain hosting (Cloudflare for SaaS), and object storage (R2) for site images and compiled stylesheets Global edge network; R2 objects are stored in a Cloudflare storage region selected by Cloudflare rather than pinned to one country Cloudflare Data Processing Addendum with EU Standard Contractual Clauses; EU-US Data Privacy Framework
The Constant Company, LLC (Vultr) (USA) Virtual server and managed PostgreSQL database that run the platform and store all platform data, with encrypted automated backups Singapore Vultr's data processing terms and Data Processing Addendum; encryption at rest and encrypted backups
Plus Five Five, Inc. (Resend) (USA) Sends our transactional email: team invitations, form-submission and review notifications to hotels, SEO reports, demo-request notifications United States Resend Data Processing Addendum with Standard Contractual Clauses; EU-US Data Privacy Framework
Anthropic, PBC (USA) AI model (Claude) used when a hotel asks us to rewrite page text, and during the one-time migration to turn a hotel's existing website into HotelierKit pages. No guest data is sent. United States Anthropic commercial terms. API inputs and outputs are not used to train Anthropic's models and are retained by Anthropic only for a limited period for trust and safety purposes.
Google LLC (USA) Google Analytics 4 and Search Console reporting APIs (read-only, only if the hotel connects them); Google Fonts and Google Maps on hotel sites; Google Tag Manager, Analytics and Ads tags on hotelierkit.com (only with your consent) and on sites where the hotel has configured them United States and global Google Ads Data Processing Terms / Google API terms; EU-US Data Privacy Framework
Meta Platforms, Inc. (USA) Meta Pixel on hotelierkit.com, loaded only after you accept marketing cookies, and on hotel sites where the hotel has configured it United States Meta business tools terms and data processing terms; EU-US Data Privacy Framework
Mapbox, Inc. (USA) Interactive maps on hotel sites that use the Mapbox map block. Mapbox receives the visitor's IP address and one anonymous usage event per map load. United States Mapbox privacy policy and terms
Google LLC (YouTube) Video embeds on hotel sites, loaded only after consent where the banner is enabled United States Google terms
BunnyWay d.o.o. (Bunny Fonts) (Slovenia) Interface fonts for the dashboard only EU-based CDN No personal data stored; IP address used to serve the request

We will give customers at least 30 days' notice before adding or replacing a sub-processor that processes hotel guest data, by email to the account owner and by updating this list (section 6.1 of this policy, published at https://hotelierkit.com/privacy).

6.2 Hotels and agencies

When a guest submits a form or review on a hotel's site, the data goes to that hotel (and to any agency, such as Hy Digital, the hotel has given dashboard access to). The hotel is responsible for how it uses the data after that.

6.3 Booking engines and other third parties the hotel chooses

Booking engines (for example Cloudbeds, Mirai or WeTravel), social media links and any script the hotel adds to its site are operated by third parties under their own policies. We pass only the non-identifying consent parameter described in 3.3 to booking engines.

6.4 Legal requirements and business transfers

We may disclose personal data where required by Thai law or a lawful request from a court or authority, or to protect our rights or safety. If Hy Group is involved in a merger, acquisition or sale of assets, personal data may be transferred as part of that transaction and this policy will continue to apply.

7. International transfers

Hy Group is in Thailand. Our servers and database are in Singapore, and several of our providers are in the United States. This means personal data leaves the country where you are.

  • From Thailand. Transfers out of Thailand are made under the PDPC Notifications issued under sections 28 and 29 of the PDPA (in force 24 March 2024), using contractual safeguards recognized by the PDPC, which include the EU Standard Contractual Clauses and the ASEAN Model Contractual Clauses, or another permitted basis such as your consent or necessity for the contract.
  • From the EEA, UK and Switzerland. Thailand and Singapore do not currently hold an EU adequacy decision. Where we process personal data from the EEA or UK on behalf of a hotel, our Data Processing Addendum (available on request) incorporates the EU Standard Contractual Clauses (Commission Decision 2021/914) and, for UK data, the UK International Data Transfer Addendum, together with the technical measures described in section 9. Our US providers are certified under the EU-US Data Privacy Framework or offer Standard Contractual Clauses in their data processing terms. Hotel customers can request a copy of our transfer terms.
  • EU and UK representative. We are not established in the EEA or the UK. We do not currently target EEA or UK residents, and our processing of their personal data is occasional and incidental to the services we provide to hotels, so we have assessed that we are not required to appoint a representative under Article 27 of the GDPR or the UK GDPR. We keep this under review. EEA and UK residents can contact us about their data at [email protected] (marked "Privacy") or by post at the address in section 15.

8. How long we keep data

Data How long we keep it How this is applied
Cookie consent records 12 months from the choice. The consent cookie itself lasts 1 year, so you are asked again annually. Deleted automatically (daily job)
Sign-in security events (IP, browser, time) 12 months Deleted automatically
Security log files 30 days Deleted automatically
Application log files 14 days for file-based application logs. Logs captured by our hosting platform's container runtime are kept only for a limited period for troubleshooting and are not archived to a separate log service. Rotated automatically
Rejected guest reviews 90 days after rejection, together with the related audit entries Deleted automatically
Approved and pending guest reviews Until the hotel deletes them or the hotel's contract ends Controlled by the hotel
Form submissions (guest enquiries) Until the hotel deletes them (individually or in bulk from the dashboard) or the hotel's contract ends, when they are handled as described in the "after the contract ends" row. We do not delete guest submissions automatically. Controlled by the hotel
Demo requests and contact messages sent to us For as long as we need them to deal with your enquiry and, if you become a customer, for the life of the relationship. We delete enquiries that did not lead to a customer relationship no later than 24 months after our last contact with you, or earlier on request. Deleted by us on review or on request
Dashboard activity log For the life of the hotel's account, so the hotel has a complete record of who changed what; then handled as described in the "after the contract ends" row. Entries may identify a user by name or email address. We anonymize a former user's entries on request. Kept for the account term; anonymized on request
Analytics summaries fetched from Google While the hotel's Google connection is active. They are not deleted automatically when the connection is removed; the hotel can ask us to delete them, and they are deleted with the rest of the hotel's data when the contract ends. Deleted on request or at contract end
Account data of a staff user For the life of the account. You can delete your own account from Settings: the account record is removed and your sign-in events are stripped of your email address. Audit entries recorded for the hotel's account are kept so the hotel's history stays complete; they may identify you by name or email address, and we will anonymize them on request. Self-service deletion; anonymization on request
Hotel site content and guest data after the contract ends Retained for 30 days after the contract ends so the hotel can export it, then deleted from our live systems within a further 30 days and purged from backups as they expire on their normal rotation (database backups are kept for a limited rotation period). Deleted by us after the export window
Billing and tax records As long as Thai accounting and tax law requires (generally at least 5 years) Kept in our accounting records

9. How we protect data

  • All traffic is encrypted in transit (TLS, with HTTP Strict Transport Security).
  • Form submissions, review email addresses, visitor IP addresses in the consent log, Google OAuth tokens and integration secrets are encrypted at rest in the database using application-level encryption, in addition to the full-disk encryption and encrypted backups of our managed database provider.
  • Passwords are stored as bcrypt hashes. Production accounts require passwords of at least 12 characters. Two-factor authentication is available to every user; we strongly recommend it for everyone and expect hotels to require it for owners and admins.
  • Access to a hotel's data is restricted by team and role. Exports of consent records with raw IP addresses are limited to account owners and are written to the audit log.
  • AI agent access uses short-lived OAuth tokens scoped to the sites and actions you approve, and is revoked automatically when a user leaves a team.
  • Public form endpoints are protected by rate limiting and, where the hotel has configured it, Cloudflare Turnstile.
  • Our production database is hosted by Vultr in Singapore with encryption at rest and automated, encrypted daily backups with point-in-time recovery.
  • Production access is limited to a small number of Hy Group engineers.

No system is perfectly secure. Where we are the controller, if we learn of a personal data breach that is likely to result in a risk to you, we will notify the Office of the PDPC within 72 hours of becoming aware of it, as the PDPA requires, and tell you directly where the risk to you is high. Where we are a processor for a hotel, we will notify the hotel without undue delay and in any event within 72 hours of confirming a breach affecting its data, so the hotel can meet its own obligations to its guests and regulators.

10. Your rights and how to exercise them

Under the PDPA, and under GDPR where it applies, you have the right to:

  • access the personal data we hold about you and receive a copy;
  • correct data that is inaccurate or incomplete;
  • delete or anonymize your data where we no longer need it or you withdraw consent;
  • restrict or object to processing in certain cases, including direct marketing;
  • withdraw consent at any time where we rely on consent (for example cookies), without affecting earlier processing;
  • data portability of data you gave us, in a machine-readable format;
  • complain to a supervisory authority: in Thailand, the Office of the Personal Data Protection Committee (PDPC); in the EU or UK, your local data protection authority.

To exercise a right, email [email protected] with "Privacy" in the subject line and enough detail for us to find your data. We may ask you to verify your identity. We respond within 30 days; if a request is complex we may extend by a further 30 days and will tell you why.

If you are a hotel guest, please contact the hotel first; they control your data and we may not be able to identify you without them. If you contact us, we will forward your request to the hotel within 5 business days and help them respond.

Dashboard users can update their name, email and password, review recent sign-ins, manage two-factor authentication and delete their own account from Settings. Account owners can export form submissions, reviews, consent logs and redirects as CSV from the dashboard.

11. When we act as a processor for hotels

When a hotel uses HotelierKit to run its website, the hotel is the controller of its guests' data and HotelierKit is the processor. In that role we:

  • process guest data only on the hotel's documented instructions, which are set out in section 7 of our Terms of Service and, where the hotel has signed one, our Data Processing Addendum (available on request from [email protected]);
  • keep guest data confidential and apply the security measures in section 9;
  • use only the sub-processors listed in section 6.1 and give notice of changes;
  • help the hotel respond to guest requests and to data breaches, and notify the hotel of a personal data breach affecting its guest data without undue delay and in any event within 72 hours of confirming it;
  • delete or return guest data at the end of the contract, at the hotel's choice, within the windows set out in section 8;
  • keep records of our processing activities, as section 40(3) of the PDPA requires of processors.

Hotels are responsible for publishing their own privacy notice, choosing a lawful basis for the data their forms collect, enabling the cookie banner where their visitors' law requires it, avoiding the collection of sensitive data (such as health or dietary needs) without a proper basis, and responding to their guests' requests.

12. Data protection officer

Under the PDPC Notification on Data Protection Officers (in force 13 December 2023), a DPO is required where an organization's core activity involves regular monitoring of personal data on a large scale (for example 100,000 or more data subjects, or behavioral advertising). HotelierKit's core activity is hosting hotel websites. We have assessed that this threshold is not currently met and have not appointed a DPO. We will review this assessment as the platform grows and will appoint a DPO if the law requires one. Questions about this policy or your data go to [email protected] (marked "Privacy") or by post to the address in section 15.

13. Children

HotelierKit is a business service and hotelierkit.com is not directed at children. Hotel websites are intended for adults making travel arrangements. We do not knowingly collect personal data from children under 13, or under the age at which parental consent is required in your country (20 for minors in Thailand under the PDPA unless the person has legal capacity, 16 under GDPR unless a member state sets a lower age). If you believe a child has given us personal data, contact us and we will delete it.

14. Changes to this policy

We may update this policy as the platform or the law changes. We will post the new version here with a new "last updated" date and, for material changes affecting hotel customers, email the account owner at least 30 days before the change takes effect.

15. Contact

Hy Group Co., Ltd. (HotelierKit) 709/23 Soi Onnut 7, Sukhumvit 77 Road, Onnut, Suanluang, Bangkok 10250, Thailand [email protected] +66 2 460 9544