Privacy Policy

Occupancy PMS

Effective Date: September 1, 2026 Last Updated: September 1, 2026

This Privacy Policy explains how Occupancy PMS ("Occupancy", "we", "us", "our") collects, uses, shares, and protects personal data in connection with the Occupancy PMS platform (the "Service"). It applies to our website, web application, and APIs.


1. Who We Are and How to Reach Us

Data controller: Occupancy PMS, Tirana, Albania.

PurposeContact
Privacy questions and rights requestssupport@occupancypms.com
Data Protection Officer / privacy contactsupport@occupancypms.com
Security vulnerability reportssupport@occupancypms.com
General supportsupport@occupancypms.com

If you are a hotel guest whose data appears in the Service, please read §3 first — in most cases your request must go to the hotel that holds your reservation, not to Occupancy.


2. Definitions

TermMeaning
Personal dataAny information relating to an identified or identifiable natural person.
CustomerThe hotel or hospitality business that holds an account for the Service.
Authorized UserAn individual who accesses the Service under a Customer's account — typically staff of the hotel.
Guest DataPersonal data about hotel guests that a Customer enters into or syncs through the Service.
ControllerThe party that determines the purposes and means of processing personal data.
ProcessorThe party that processes personal data on behalf of, and on the documented instructions of, a controller.
Sub-processorA third party engaged by Occupancy to process personal data in the course of providing the Service.

3. Our Two Roles: Controller and Processor

This distinction determines who is responsible for what, and who you should contact.

3.1 We are a controller for the account and business data of our Customers and their Authorized Users — the people who sign up for and use Occupancy. This includes account credentials, billing records, support correspondence, and product usage. This policy governs that processing in full.

3.2 We are a processor for Guest Data. Hotels decide what guest information to collect, why, and for how long; Occupancy only stores and processes it to provide the Service on their instructions. The hotel is the controller.

3.3 What this means for guests. If you are a hotel guest and you want to access, correct, or delete your data, contact the hotel that took your booking. If you contact us directly, we will forward your request to the relevant Customer and assist them in responding, but we cannot act on Guest Data on our own initiative.

3.4 Processor terms. Section 16 sets out the data processing terms that apply where Occupancy acts as a processor for a Customer. Those terms are incorporated into the Terms and Conditions.


4. Personal Data We Collect

4.1 Data you give us — account and business data (we are controller)

CategoryExamplesSource
Identity and account dataName, username, email address, hashed password, roleYou, at sign-up
Authentication dataSession tokens, two-factor authentication secrets, backup codes, OAuth identifiers from Google sign-inYou and your identity provider
Legal acceptance recordsTimestamp of your acceptance of the Terms and this PolicyRecorded automatically at sign-up
Property and business dataProperty names, addresses, room and rate configuration, currency, timezoneYou, in the app
Billing dataSubscription plan, billing status, Stripe customer identifier, invoice historyYou and Stripe
Support dataMessages, attachments, and correspondence you send usYou

We do not receive or store full payment-card numbers. Card details are entered directly into Stripe's systems (see §7).

4.2 Data collected automatically — usage and technical data (we are controller)

CategoryExamples
Device and connection dataIP address, browser type and version, operating system, language
Approximate locationCountry or region derived from IP address, used for security and audit purposes. This lookup is performed locally within our own infrastructure and is not sent to a third-party geolocation service.
Usage dataPages and features accessed, timestamps, API endpoints called, request outcomes
Security and audit logsSign-in attempts, two-factor events, password and email changes, session revocations, rate-limit triggers

4.3 Guest Data — processed on behalf of our Customers (we are processor)

Hotels may record the following about their guests. Which fields are used is entirely the hotel's decision; none are required by Occupancy:

  • Identity: first and last name, date of birth, nationality;
  • Contact: email address, phone number, postal address, city, country, postal code, preferred contact method, language;
  • Identity documents: passport number, other identity-document type and number;
  • Business details: company name, tax identification number;
  • Stay data: reservations, arrival and departure dates, room assignments, rates, payment status, loyalty programme number, VIP status;
  • Preferences and notes: special requests, dietary requirements, emergency contact name and phone number, internal status flags recorded by the hotel.

Special categories. Some of these fields can reveal sensitive information — for example, dietary requirements may indicate religious belief or a health condition, and identity-document data is treated as sensitive in several jurisdictions. Occupancy does not require hotels to complete these fields. Where a hotel chooses to use them, the hotel is responsible for establishing a lawful basis and, where necessary, obtaining explicit consent.

Guest data from OTAs. Where a hotel connects a channel manager, guest and reservation data flows into the Service from online travel agencies through that integration. The categories are those listed above, as supplied by the channel.

4.4 Data we do not collect

We do not operate advertising or behavioural-remarketing technology, we do not sell personal data, and we do not use Guest Data to train machine-learning models.


5. Why We Process Personal Data, and Our Legal Bases

PurposeData usedLegal basis (GDPR Art. 6)
Creating and administering your accountIdentity, account, authentication dataPerformance of a contract
Providing the Service and its featuresAccount, property, and usage dataPerformance of a contract
Processing subscriptions and paymentsBilling dataPerformance of a contract; legal obligation (tax and accounting)
Sending transactional email — verification, password reset, two-factor codes, billing noticesEmail address, account dataPerformance of a contract
Securing the Service — authentication, fraud prevention, rate limiting, abuse investigationAuthentication, technical, and audit dataLegitimate interests (protecting the Service and its users)
Recording acceptance of the Terms and this PolicyAcceptance timestamp, account identifierLegal obligation; legitimate interests (demonstrating compliance)
Maintaining, debugging, and improving the ServiceUsage and technical data, in aggregate wherever possibleLegitimate interests (operating and improving a service our customers rely on)
Providing customer supportSupport correspondence, account dataPerformance of a contract; legitimate interests
Complying with legal obligations and responding to lawful requestsAny relevant dataLegal obligation
Service-related announcements — material changes, incidents, maintenanceEmail addressLegitimate interests; performance of a contract
Optional product or marketing emails, where offeredEmail address, nameConsent (withdrawable at any time)

For Guest Data, the legal basis is determined by the hotel as controller, not by Occupancy.


6. Cookies and Similar Technologies

The Service uses only cookies and browser storage that are strictly necessary for it to function. We do not use advertising, remarketing, or cross-site tracking cookies.

Cookie / storageTypeSet byPurposeRetention
Session cookieStrictly necessaryOccupancyKeeps you signed in and identifies your authenticated sessionSession lifetime, per §8
Two-factor challenge cookieStrictly necessaryOccupancyHolds a short-lived pending two-factor challenge between the password step and code verificationMinutes; cleared on completion
OAuth state / PKCE cookieStrictly necessaryOccupancyProtects the Google sign-in redirect against cross-site request forgeryMinutes; cleared on callback
Stripe checkout cookiesStrictly necessaryStripeFraud prevention and completion of a payment sessionSee Stripe's cookie policy

Because these cookies are strictly necessary for a service you have requested, they do not require consent under the ePrivacy Directive and no cookie banner is presented. Blocking them will prevent sign-in from working.

Do Not Track. The Service does not respond to browser "Do Not Track" signals, because it does not perform the cross-site tracking those signals are designed to limit.


7. How We Share Data — Sub-processors and Recipients

We do not sell personal data and we do not share it for cross-context behavioural advertising. We share it only as described below.

7.1 Sub-processors

Sub-processorFunctionData sharedWhere processed
Stripe, Inc.Payment processing and subscription billingCustomer name, email, billing address, subscription and transaction data. Card details go directly to Stripe and are never received by us.United States and EU; PCI-DSS Level 1 certified
ResendTransactional email delivery (verification, password reset, two-factor and billing notices)Recipient email address, name, message contentUnited States
ChannexChannel manager and OTA synchronization, where a Customer enables itReservation and guest records required for the sync, room and rate inventoryUnited Kingdom and European Union
Google LLC"Continue with Google" sign-in, where a Customer enables itGoogle account identifier, email address and name, received from Google at sign-inUnited States and EU
Railway CorporationApplication hosting and managed databaseAll Customer Data at rest, in its capacity as hosting providerEuropean Union (EU region)

Each sub-processor is engaged under a written contract that limits its use of the data to providing its service to us, and imposes confidentiality and security obligations.

Changes to sub-processors. Where we add or replace a sub-processor that processes Guest Data, we will notify affected Customers at least 30 days in advance at the account email address, giving a reasonable opportunity to object.

7.2 Other recipients

  • Other Authorized Users on your account. Data entered into your account is visible to your colleagues according to the roles you assign.
  • Professional advisers. Lawyers, auditors, and accountants under duties of confidentiality, where necessary.
  • Authorities. Where we are required by law, court order, or a valid request from a competent authority. We assess each request, require it to be lawful and specific, and will notify the affected Customer unless legally prohibited.
  • Corporate transactions. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy continuing to apply to the transferred data and to advance notice where legally required.

8. Retention

We keep personal data only as long as necessary for the purposes it was collected for, then delete or anonymize it.

DataRetention
Account and profile dataFor the life of the account, then 30 days after termination to allow export
Guest DataFor as long as the Customer's account is active and as instructed by the Customer; deleted or returned on termination per §16.6
Billing and invoice records7 years, or as required by applicable tax and accounting law
Security and audit logs12 months
Application and error logs30 days
BackupsPurged on their ordinary rotation cycle, within 35 days
Terms-acceptance recordsFor the life of the account plus 6 years, as evidence of consent
Support correspondence24 months after the matter is closed

Data may be retained longer where necessary to establish, exercise, or defend legal claims, or to comply with a legal obligation.


9. International Transfers

Our infrastructure and sub-processors may process data outside your country, including in the United States. Where personal data is transferred out of the European Economic Area, the United Kingdom, or Switzerland, we rely on an appropriate safeguard, which will be one of:

  • an adequacy decision by the European Commission or the relevant authority;
  • the European Commission's Standard Contractual Clauses, together with the UK Addendum where the UK GDPR applies; or
  • another lawful transfer mechanism recognized under applicable law.

We assess the circumstances of each transfer and apply supplementary technical measures — encryption in transit and at rest, and access controls — where appropriate. A copy of the relevant safeguards is available on request at support@occupancypms.com.


10. Security

We maintain technical and organizational measures appropriate to the risk, including:

  • Encryption in transit. All traffic is served over HTTPS/TLS.
  • Encryption at rest. The managed database and its backups are encrypted at rest by our hosting provider.
  • Credential protection. Passwords are stored only as salted, computationally expensive hashes — never in plaintext or reversible form.
  • Two-factor authentication. Available on all accounts, using time-based one-time passwords with recovery backup codes.
  • Access control. Application routes are authenticated by default and gated by role; internal access to production data is restricted to personnel who need it, and is logged.
  • Rate limiting and abuse protection. Authentication and sensitive endpoints are rate-limited to resist brute-force and credential-stuffing attacks.
  • Transport and header hardening. Standard security headers are applied to all responses.
  • Audit logging. Authentication and account-security events are recorded.
  • Backups. Routine automated backups of the production database, retained per §8.

No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for protecting your credentials and for the access you grant to your Authorized Users.

Breach notification. If a personal-data breach affecting your data occurs, we will notify the competent supervisory authority within 72 hours where required, and will notify affected Customers without undue delay, with the information needed for them to meet their own notification duties.


11. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access — obtain confirmation of whether we process your data, and a copy of it;
  • Rectification — correct inaccurate or incomplete data;
  • Erasure — request deletion where the data is no longer necessary or processing was unlawful;
  • Restriction — limit how we process your data while a dispute is resolved;
  • Object — object to processing based on legitimate interests, and to direct marketing at any time and unconditionally;
  • Portability — receive data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
  • Withdraw consent — where processing is based on consent, without affecting the lawfulness of processing before withdrawal;
  • Not be subject to automated decision-making producing legal or similarly significant effects — we do not carry out such processing; and
  • Complain to your local data-protection supervisory authority. In the EEA, this is the authority in your country of residence, work, or the place of the alleged infringement.

Making a request. Write to support@occupancypms.com. We will verify your identity before acting, and will respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. Requests are free unless manifestly unfounded or excessive.

Guest requests. For Guest Data, contact the hotel holding your reservation (see §3.3).


12. California Privacy Rights (CCPA/CPRA)

This section applies to California residents and supplements the sections above.

12.1 Categories collected. In the 12 months preceding the effective date, we collect the following CCPA categories:

CCPA categoryCollectedExamples
A. IdentifiersYesName, email, username, IP address, account identifiers
B. Customer records (Cal. Civ. Code §1798.80)YesName, contact details, billing information
C. Protected classificationsOnly if a hotel records them as Guest Data (e.g. nationality, dietary requirements)Not collected by Occupancy for its own purposes
D. Commercial informationYesSubscription plan, transaction and billing history
E. Biometric informationNo
F. Internet or network activityYesUsage data, API calls, log data
G. Geolocation dataYes, coarse onlyCountry or region derived from IP address
H. Sensory dataNo
I. Professional or employment informationYesBusiness name, role within the account
J. Non-public education informationNo
K. InferencesNoWe do not build profiles or draw inferences about individuals

12.2 Sources. Directly from you; automatically from your use of the Service; from our sub-processors (for example, billing status from Stripe); and, for Guest Data, from our Customers and their connected channels.

12.3 Business purposes for use. Providing and securing the Service, billing, support, debugging and quality assurance, legal compliance, and protecting against fraud and abuse — as detailed in §5.

12.4 Disclosure for business purposes. We disclose the categories above to the sub-processors listed in §7.1, each under contract restricting use to providing their service to us.

12.5 No sale or sharing. We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA. We have not done so in the preceding 12 months, including with respect to consumers under 16.

12.6 Sensitive personal information. We do not use or disclose sensitive personal information for purposes other than those permitted under CCPA §7027(m), and we therefore do not offer a "Limit the Use of My Sensitive Personal Information" option.

12.7 Your CCPA rights. Right to know, right to delete, right to correct, right to opt out of sale or sharing (not applicable, per §12.5), and the right not to receive discriminatory treatment for exercising any right. We will not deny service, charge different prices, or provide a different level of quality because you exercised a right.

12.8 Exercising your rights. Email support@occupancypms.com with "CCPA Request" in the subject line. We will verify your identity against information already in our records, and will respond within 45 days, extendable once by a further 45 days with notice. An authorized agent may submit a request on your behalf with written, signed permission.

12.9 Shine the Light. California Civil Code §1798.83 permits residents to request information about disclosure of personal information to third parties for their direct marketing purposes. We do not make such disclosures.


13. Other Regional Disclosures

13.1 United Kingdom. Where the UK GDPR applies, references to the GDPR in this Policy include the UK GDPR, and complaints may be made to the Information Commissioner's Office.

13.2 Switzerland. Where the Swiss FADP applies, complaints may be made to the Federal Data Protection and Information Commissioner.


14. Children

The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18 as an account holder. Where a hotel records details of a minor as part of a family reservation, that data is Guest Data controlled by the hotel, and the hotel is responsible for the lawful basis for processing it. If you believe a child has created an account, contact support@occupancypms.com and we will delete it.


15. Automated Decision-Making

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not perform profiling for marketing purposes.


16. Data Processing Terms (Occupancy as Processor)

These terms apply where Occupancy processes Guest Data on behalf of a Customer, and form part of the agreement between Occupancy and that Customer.

16.1 Subject matter and duration. Processing of Guest Data for the term of the Customer's subscription and the post-termination period in §16.6.

16.2 Nature and purpose. Storage, organization, retrieval, transmission to enabled integrations, backup, and deletion, solely to provide the Service.

16.3 Categories of data subjects and data. Hotel guests and the Customer's Authorized Users; the data categories listed in §4.3.

16.4 Instructions. Occupancy processes Guest Data only on the Customer's documented instructions, which comprise the Terms and Conditions, this Policy, and the Customer's use of the Service's features. Occupancy will inform the Customer if an instruction appears to infringe applicable data-protection law.

16.5 Obligations. Occupancy will: (a) ensure personnel with access are bound by confidentiality; (b) implement the measures described in §10; (c) engage sub-processors only under §7.1 and remain liable for their performance; (d) assist the Customer, taking into account the nature of processing, with data-subject requests, breach notification, data protection impact assessments, and prior consultation; and (e) make available the information necessary to demonstrate compliance and allow for audits by the Customer or an independent auditor, no more than once per year absent an incident, on reasonable notice and subject to confidentiality.

16.6 Return and deletion. On termination, Occupancy will make Guest Data available for export for 30 days, then delete it, except where retention is required by law. Backups are purged on their ordinary rotation.


17. Links to Other Sites

The Service may link to third-party sites and integrations. This Policy does not apply to them. We encourage you to read the privacy policy of any site or service you connect to or visit.


18. Changes to This Policy

We may update this Policy. We will change the "Last Updated" date above and, for material changes, notify Customers by email or in-product notice at least 30 days before the change takes effect. Where a change requires it, we will seek renewed acceptance. Continued use after the effective date constitutes acceptance of the updated Policy.


19. Contact Us

Occupancy PMS Tirana, Albania Website: https://occupancypms.com Privacy: support@occupancypms.com Security: support@occupancypms.com Support: support@occupancypms.com