GuestFlow - AI Guest Assistant

Data & Security

Last updated: July 2026

Built for hospitality buyers

Hotels and vacation rentals in the EU often ask where guest chat data goes before they buy. This page answers those procurement questions. For the full legal notice, see our Privacy Policy.

Where data is hosted

Application data (accounts, properties, knowledge, chat sessions, analytics) is stored in PostgreSQL on our cloud database provider. Production deployments typically run on Vercel with a managed Postgres (e.g. Supabase/Neon) in a region you configure with us. Ask support for the current primary region for your account.

What guest chat data we keep

  • Guest chat sessions and messages tied to a property — so owners can review what the AI said
  • Optional guest session token in the browser to continue a conversation
  • QR scan metadata (approximate time, optional IP/user-agent for abuse prevention)
  • Recommendation click events when guests open tip links
  • We do not require guests to create accounts or provide email to chat

AI processing

Guest questions and retrieved property knowledge are sent to our AI provider (OpenAI) to generate replies. Prompts are built from content you uploaded and configured — not from unrelated internet browsing. Do not put secrets in knowledge that must never leave your systems.

Retention

Chat and analytics data remain while your account is active so you can audit guest conversations and usage. After account deletion or upon a verified erasure request, we delete or anonymize personal data within a reasonable period unless law requires longer retention (e.g. billing records).

Subprocessors (typical)

  • Cloud hosting & CDN — application delivery
  • PostgreSQL host — primary database
  • OpenAI — AI completions and embeddings
  • Stripe — subscription payments (card data stays with Stripe)
  • Email provider (e.g. Resend) — transactional mail
  • File uploads (e.g. UploadThing) — property images and documents

GDPR & DPA

If you are a controller of guest data and GuestFlow processes chat content on your behalf, we can provide a Data Processing Agreement (DPA) on request. Contact support@guestflow.in.net"
with your company details. EU hospitality teams should also review our Privacy Policy for rights requests and contact emails.

Security practices

  • HTTPS in production; secrets stored as environment variables
  • Password hashing; optional 2FA for owner accounts
  • API keys for Business integrations; outbound webhook HMAC signatures
  • Role-based access (owner dashboard vs platform admin)

Contact

Security & privacy: privacy@guestflow.in.net
Support / DPA requests: support@guestflow.in.net"

Legal: legal@guestflow.in.net

← Kembali ke beranda

Data & Security — GuestFlow