Privacy Policy
How GrandStay handles personal data — both our customers' account data and the guest data hotels entrust to us.
Last updated
1. Who controls which data
GrandStay is a property management system sold to hotels and to the regional partners who resell it. That creates two distinct relationships, and your rights depend on which one applies to you.
Guest data — the hotel is the controller, we are the processor. When a hotel stores a reservation, a guest profile, an identity document or a folio in GrandStay, the hotel decides what is collected and why. We process it only on that hotel's documented instructions, which are the actions its staff take in the product. If you are a hotel guest, direct requests to the property you stayed at; we will support them in responding, and will forward any request we receive directly.
Account data — we are the controller. Information about the hotels, partners and staff users who hold GrandStay accounts — names, work email addresses, roles, billing details, support correspondence and product usage — is ours to control, and this policy governs it directly.
2. What we collect
From account holders:
- Name, work email address, phone number and job role.
- Property or partner organisation details, including country and currency.
- Billing contact and subscription history. Card numbers are handled by our payment providers and never reach our servers.
- Authentication data, including session timestamps and the audit trail of actions taken in the product.
- Optional staff photographs, where a property enables photo-based sign-in.
On behalf of hotels, about their guests:
- Name, contact details, nationality and stay history.
- Reservation, folio and payment records.
- Identity documents, where the property collects them — commonly a legal requirement for hotel registration.
- Service requests and messages exchanged through the guest portal.
We do not sell personal data, and we do not use guest data to train AI models.
3. Why we process it, and on what basis
- To provide the service — performance of our contract with the hotel or partner.
- To take payment — performance of a contract, and compliance with tax and accounting obligations.
- To keep the system secure and available — our legitimate interest in operating a reliable, non-abused service. This covers error monitoring, rate limiting and the audit log.
- To support you — performance of our contract, and our legitimate interest in answering questions well.
- To send product and marketing email to account holders — consent, withdrawable from any message.
Guest identity documents are processed solely on the hotel's instruction and for the purpose the hotel states, which is typically a legal obligation to register guests.
4. Who else processes it
We use the following subprocessors. Each is bound by contract to process data only on our instructions and to protect it appropriately.
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Application database, authentication, and file storage (including guest ID documents). | All hotel, staff, guest and reservation records. |
| Stripe | Card payments and subscription billing. | Payment amount, currency and billing contact. Card numbers go to Stripe directly and never reach our servers. |
| PayPal | Alternative payment method for hotel bookings and subscriptions. | Payment amount, currency and the payer's PayPal account reference. |
| Resend | Transactional email — booking confirmations, invitations, invoices, password flows. | Recipient name and email address, and the contents of the message. |
| Anthropic | The in-product AI assistant and copilot features. | The text of the question asked and the operational context needed to answer it. Not used to train models. |
| Meta (WhatsApp Business) | WhatsApp notifications, where a property enables them. | Recipient phone number and message contents. |
| Sentry | Error monitoring and crash diagnostics. | Technical error data — stack traces, browser and route. Scrubbed of record contents. |
Where a property connects its own payment gateway or channel manager, that provider becomes a further recipient under the property's own arrangement with them. Credentials for those integrations are stored encrypted and are never displayed back in full.
5. International transfers
GrandStay is sold internationally, and our infrastructure and subprocessors operate across multiple regions. Where personal data moves out of its country of origin we rely on the transfer mechanisms our subprocessors offer, including the EU Standard Contractual Clauses where they apply. A property with data-residency requirements should raise them with us before onboarding, as region choice is made at provisioning time and is not something we can change silently afterwards.
6. How long we keep it
- Guest and reservation records — for as long as the hotel keeps them. Deletion is the hotel's decision; we act on its instruction.
- Identity documents — these are the most sensitive data in the system, and properties should delete them once the legal retention period in their jurisdiction has passed.
- Financial records — retained as long as tax and accounting law requires, typically several years, even after an account closes.
- Audit logs — retained for the life of the account. They are tamper-evident by design and are not editable, including by us.
- Account data — deleted or anonymised within 90 days of an account closing, except where the above requires otherwise.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to receive it in a portable form, and to withdraw consent. You also have the right to complain to your local data protection authority.
For account data, write to privacy@grandhms.com and we will respond within one month.
For guest data, contact the hotel — it decides what happens to its records. If you are not sure who that is, write to us and we will route your request to the right property.
8. Security
Every record in GrandStay is scoped to the property that owns it and enforced in the database, not merely in the interface. Payment gateway credentials are encrypted at rest, the audit log is hash-chained so tampering is detectable, and sensitive operations are gated by role on the server. Our Security page describes these controls in detail.
9. Children
GrandStay is a business tool and is not directed at children. We do not knowingly collect data from children through our own accounts. Guest records created by a hotel may include minors travelling with their family; that data is the hotel's to control and should be handled under its own policy.
10. Changes to this policy
We will update this page when our practices change, and will move the "last updated" date above. Material changes affecting account holders are announced by email before they take effect.
11. Contact
[REGISTERED COMPANY NAME]
Sorkallegatan 19A, 451 41, Sweden
privacy@grandhms.com