Privacy policy

Version: 19 September 2026

DMV Tech LLC, doing business as CreateMyExcel operates HotelReports.Ai. This policy covers two kinds of personal data: the account details of the people who use HotelReports.Ai, for which we are responsible, and the guest and player details inside the files a hotel uploads, which belong to the hotel and which we handle only on the hotel's instructions (see Data processing).

People who use the service

We keep your email address, your name if you or your sign-in provider gave it, your role in each organization and property, when you last signed in, and a record of what you did that changes data, such as uploads, rollbacks and changes to users. We use these to run the service, to keep it secure and to answer support requests. Our legal ground is the agreement with your organization and our legitimate interest in running a secure service.

We send you emails the service needs: sign-in links, invitations, notices about your uploads and your plan. We do not send marketing email to account addresses without your consent.

Signing in with Google or Microsoft

You can sign in with an emailed link, or with your Google or Microsoft account where that is offered. If you choose Google or Microsoft, they tell us your name, your email address, your profile picture if you have one, and an identifier for your account. We ask for nothing else: we cannot see your password, your mail, your calendar, your contacts or your files, and we do not request access to them.

We use what they tell us for one purpose: to create your account and sign you in to it. We do not sell it, do not use it for advertising, do not share it with anyone except the providers listed under Data processing who host the service, and do not use it to train AI models.

HotelReports.Ai's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect HotelReports.Ai at any time in your Google or Microsoft account's security settings, and you can ask us to delete your account at legal@hotelreports.ai.

Cookies and the sign-in check

We use cookies only to keep you signed in and, for a few minutes, to remember which page you were heading to. There are no advertising cookies and no third-party analytics.

The sign-in form uses Cloudflare Turnstile to check that a request comes from a person and not a script. Cloudflare receives your IP address and technical signals from your browser for that check.

Guests and players in uploaded files

Names, postal codes and, where a file carries them, email, phone, address and player number are used for one thing: recognising that two stays belong to the same guest, and matching stays to a casino's player records.

Names and contact details are then deleted from our systems: 7 days after the upload by default (a property can set its own period), and at the latest 14 days after that if the matching has not finished. What remains is a one-way code that cannot be turned back into a name, the postal area for the guest-origin report, a player number where the hotel uploads one, and the stay and revenue figures.

Reports and exports never contain names or contact details, and the AI analyst never receives them.

The files you upload are kept so that a load can be checked or repeated, then deleted: 30 days after a successful load, 7 days after a failed, rolled-back or unfinished one.

The AI analyst

The AI analyst is an add-on; it is off unless your organization has it. When you ask it a question, the question and the report figures needed to answer it (totals, averages and breakdowns such as occupancy by segment) are sent to Anthropic. Guest names and guest-level rows are never sent. Anthropic does not use this data to train its models.

Where data is kept, and for how long

Everything is stored and processed in the United States: the database and uploaded files with Supabase on Amazon Web Services in Virginia, the application server with Hostinger in Boston. Some of our staff work outside the United States; they reach the service remotely, under the controls described on the Security page, and the data stays where it is stored.

Account details are kept while the account exists. An organization's data is kept for the life of its subscription and 90 days after it ends, then deleted. Backups are kept for 7 days.

Your rights and choices

You can ask us what we hold about you, to correct it, to delete it, or to stop using it, at legal@hotelreports.ai; we answer within 30 days. Depending on where you live you may also have the right to complain to your data protection authority.

An organization admin can ask for an export of the organization's data, and for its deletion, at any time. People whose details are in an uploaded file should contact the hotel, which decides about that data; we help the hotel answer within 30 days.

We do not sell personal data, and the service is not directed to children.

Changes

When this policy changes in a way that matters we post the new version here with its date and tell organization admins by email. Questions: legal@hotelreports.ai.