Security
Version: 19 September 2026
What we do to keep a hotel's figures and its guests' details safe, in plain words. Ask us for anything a security questionnaire needs that is not here.
Separation between customers
Every table that holds a property's data is protected by row-level security in the database itself, not only in the application: a signed-in user can read a row only if they are a member of that property or its organization. The rules are tested automatically against a fresh copy of the database on every change.
Guest names
Names and contact details live in one place, are used once for matching, and are then deleted: 7 days after upload by default, and never more than 14 days beyond the period the property has set. Reports, exports and the AI analyst cannot read them. What remains cannot be turned back into a name.
Who at our company can see your data
Staff access is by role. Support can read a customer's reports to help with a problem and cannot read guest names. The one exception is the Managed plan, where you ask us to load your files for you: the staff who do that handle the files as you sent them, names included, until the names are deleted after matching. Billing staff cannot read hotel data at all. Staff access to a customer's data is logged, and the log is available to you on request.
Sign-in
Sign-in is by emailed link, or Google or Microsoft where offered, so there is no password of ours to steal or reuse. The sign-in form checks that a request comes from a person, and the number of sign-in emails is rate-limited. Staff accounts that can reach customer data must use an authenticator app.
Encryption, location, backups
Traffic is encrypted with TLS; data and backups are encrypted at rest. Everything is stored and processed in the United States. The database is backed up daily and backups are kept for 7 days.
Uploaded files
Files are kept only as long as a load may need to be checked or repeated: 30 days after a successful load, 7 days after a failed, rolled-back or unfinished one. They are never part of a report.
How we build
Every change to the database is reviewed, applied to a separate copy first and checked there before it reaches production. Every change to the code is built and tested automatically before it can be released.
Reporting a problem
If you believe you have found a vulnerability, write to legal@hotelreports.ai. We answer within two working days, and we will not take action against someone who reports in good faith and does not access other people's data.