Privacy Policy
Occupancy PMS
Effective Date: September 1, 2026 Last Updated: September 1, 2026
This Privacy Policy explains how Occupancy PMS ("Occupancy", "we", "us", "our") collects, uses, shares, and protects personal data in connection with the Occupancy PMS platform (the "Service"). It applies to our website, web application, and APIs.
1. Who We Are and How to Reach Us
Data controller: Occupancy PMS, Tirana, Albania.
| Purpose | Contact |
|---|---|
| Privacy questions and rights requests | support@occupancypms.com |
| Data Protection Officer / privacy contact | support@occupancypms.com |
| Security vulnerability reports | support@occupancypms.com |
| General support | support@occupancypms.com |
If you are a hotel guest whose data appears in the Service, please read §3 first — in most cases your request must go to the hotel that holds your reservation, not to Occupancy.
2. Definitions
| Term | Meaning |
|---|---|
| Personal data | Any information relating to an identified or identifiable natural person. |
| Customer | The hotel or hospitality business that holds an account for the Service. |
| Authorized User | An individual who accesses the Service under a Customer's account — typically staff of the hotel. |
| Guest Data | Personal data about hotel guests that a Customer enters into or syncs through the Service. |
| Controller | The party that determines the purposes and means of processing personal data. |
| Processor | The party that processes personal data on behalf of, and on the documented instructions of, a controller. |
| Sub-processor | A third party engaged by Occupancy to process personal data in the course of providing the Service. |
3. Our Two Roles: Controller and Processor
This distinction determines who is responsible for what, and who you should contact.
3.1 We are a controller for the account and business data of our Customers and their Authorized Users — the people who sign up for and use Occupancy. This includes account credentials, billing records, support correspondence, and product usage. This policy governs that processing in full.
3.2 We are a processor for Guest Data. Hotels decide what guest information to collect, why, and for how long; Occupancy only stores and processes it to provide the Service on their instructions. The hotel is the controller.
3.3 What this means for guests. If you are a hotel guest and you want to access, correct, or delete your data, contact the hotel that took your booking. If you contact us directly, we will forward your request to the relevant Customer and assist them in responding, but we cannot act on Guest Data on our own initiative.
3.4 Processor terms. Section 16 sets out the data processing terms that apply where Occupancy acts as a processor for a Customer. Those terms are incorporated into the Terms and Conditions.
4. Personal Data We Collect
4.1 Data you give us — account and business data (we are controller)
| Category | Examples | Source |
|---|---|---|
| Identity and account data | Name, username, email address, hashed password, role | You, at sign-up |
| Authentication data | Session tokens, two-factor authentication secrets, backup codes, OAuth identifiers from Google sign-in | You and your identity provider |
| Legal acceptance records | Timestamp of your acceptance of the Terms and this Policy | Recorded automatically at sign-up |
| Property and business data | Property names, addresses, room and rate configuration, currency, timezone | You, in the app |
| Billing data | Subscription plan, billing status, Stripe customer identifier, invoice history | You and Stripe |
| Support data | Messages, attachments, and correspondence you send us | You |
We do not receive or store full payment-card numbers. Card details are entered directly into Stripe's systems (see §7).
4.2 Data collected automatically — usage and technical data (we are controller)
| Category | Examples |
|---|---|
| Device and connection data | IP address, browser type and version, operating system, language |
| Approximate location | Country or region derived from IP address, used for security and audit purposes. This lookup is performed locally within our own infrastructure and is not sent to a third-party geolocation service. |
| Usage data | Pages and features accessed, timestamps, API endpoints called, request outcomes |
| Security and audit logs | Sign-in attempts, two-factor events, password and email changes, session revocations, rate-limit triggers |
4.3 Guest Data — processed on behalf of our Customers (we are processor)
Hotels may record the following about their guests. Which fields are used is entirely the hotel's decision; none are required by Occupancy:
- Identity: first and last name, date of birth, nationality;
- Contact: email address, phone number, postal address, city, country, postal code, preferred contact method, language;
- Identity documents: passport number, other identity-document type and number;
- Business details: company name, tax identification number;
- Stay data: reservations, arrival and departure dates, room assignments, rates, payment status, loyalty programme number, VIP status;
- Preferences and notes: special requests, dietary requirements, emergency contact name and phone number, internal status flags recorded by the hotel.
Special categories. Some of these fields can reveal sensitive information — for example, dietary requirements may indicate religious belief or a health condition, and identity-document data is treated as sensitive in several jurisdictions. Occupancy does not require hotels to complete these fields. Where a hotel chooses to use them, the hotel is responsible for establishing a lawful basis and, where necessary, obtaining explicit consent.
Guest data from OTAs. Where a hotel connects a channel manager, guest and reservation data flows into the Service from online travel agencies through that integration. The categories are those listed above, as supplied by the channel.
4.4 Data we do not collect
We do not operate advertising or behavioural-remarketing technology, we do not sell personal data, and we do not use Guest Data to train machine-learning models.
5. Why We Process Personal Data, and Our Legal Bases
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Creating and administering your account | Identity, account, authentication data | Performance of a contract |
| Providing the Service and its features | Account, property, and usage data | Performance of a contract |
| Processing subscriptions and payments | Billing data | Performance of a contract; legal obligation (tax and accounting) |
| Sending transactional email — verification, password reset, two-factor codes, billing notices | Email address, account data | Performance of a contract |
| Securing the Service — authentication, fraud prevention, rate limiting, abuse investigation | Authentication, technical, and audit data | Legitimate interests (protecting the Service and its users) |
| Recording acceptance of the Terms and this Policy | Acceptance timestamp, account identifier | Legal obligation; legitimate interests (demonstrating compliance) |
| Maintaining, debugging, and improving the Service | Usage and technical data, in aggregate wherever possible | Legitimate interests (operating and improving a service our customers rely on) |
| Providing customer support | Support correspondence, account data | Performance of a contract; legitimate interests |
| Complying with legal obligations and responding to lawful requests | Any relevant data | Legal obligation |
| Service-related announcements — material changes, incidents, maintenance | Email address | Legitimate interests; performance of a contract |
| Optional product or marketing emails, where offered | Email address, name | Consent (withdrawable at any time) |
For Guest Data, the legal basis is determined by the hotel as controller, not by Occupancy.
6. Cookies and Similar Technologies
The Service uses only cookies and browser storage that are strictly necessary for it to function. We do not use advertising, remarketing, or cross-site tracking cookies.
| Cookie / storage | Type | Set by | Purpose | Retention |
|---|---|---|---|---|
| Session cookie | Strictly necessary | Occupancy | Keeps you signed in and identifies your authenticated session | Session lifetime, per §8 |
| Two-factor challenge cookie | Strictly necessary | Occupancy | Holds a short-lived pending two-factor challenge between the password step and code verification | Minutes; cleared on completion |
| OAuth state / PKCE cookie | Strictly necessary | Occupancy | Protects the Google sign-in redirect against cross-site request forgery | Minutes; cleared on callback |
| Stripe checkout cookies | Strictly necessary | Stripe | Fraud prevention and completion of a payment session | See Stripe's cookie policy |
Because these cookies are strictly necessary for a service you have requested, they do not require consent under the ePrivacy Directive and no cookie banner is presented. Blocking them will prevent sign-in from working.
Do Not Track. The Service does not respond to browser "Do Not Track" signals, because it does not perform the cross-site tracking those signals are designed to limit.
7. How We Share Data — Sub-processors and Recipients
We do not sell personal data and we do not share it for cross-context behavioural advertising. We share it only as described below.
7.1 Sub-processors
| Sub-processor | Function | Data shared | Where processed |
|---|---|---|---|
| Stripe, Inc. | Payment processing and subscription billing | Customer name, email, billing address, subscription and transaction data. Card details go directly to Stripe and are never received by us. | United States and EU; PCI-DSS Level 1 certified |
| Resend | Transactional email delivery (verification, password reset, two-factor and billing notices) | Recipient email address, name, message content | United States |
| Channex | Channel manager and OTA synchronization, where a Customer enables it | Reservation and guest records required for the sync, room and rate inventory | United Kingdom and European Union |
| Google LLC | "Continue with Google" sign-in, where a Customer enables it | Google account identifier, email address and name, received from Google at sign-in | United States and EU |
| Railway Corporation | Application hosting and managed database | All Customer Data at rest, in its capacity as hosting provider | European Union (EU region) |
Each sub-processor is engaged under a written contract that limits its use of the data to providing its service to us, and imposes confidentiality and security obligations.
Changes to sub-processors. Where we add or replace a sub-processor that processes Guest Data, we will notify affected Customers at least 30 days in advance at the account email address, giving a reasonable opportunity to object.
7.2 Other recipients
- Other Authorized Users on your account. Data entered into your account is visible to your colleagues according to the roles you assign.
- Professional advisers. Lawyers, auditors, and accountants under duties of confidentiality, where necessary.
- Authorities. Where we are required by law, court order, or a valid request from a competent authority. We assess each request, require it to be lawful and specific, and will notify the affected Customer unless legally prohibited.
- Corporate transactions. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy continuing to apply to the transferred data and to advance notice where legally required.
8. Retention
We keep personal data only as long as necessary for the purposes it was collected for, then delete or anonymize it.
| Data | Retention |
|---|---|
| Account and profile data | For the life of the account, then 30 days after termination to allow export |
| Guest Data | For as long as the Customer's account is active and as instructed by the Customer; deleted or returned on termination per §16.6 |
| Billing and invoice records | 7 years, or as required by applicable tax and accounting law |
| Security and audit logs | 12 months |
| Application and error logs | 30 days |
| Backups | Purged on their ordinary rotation cycle, within 35 days |
| Terms-acceptance records | For the life of the account plus 6 years, as evidence of consent |
| Support correspondence | 24 months after the matter is closed |
Data may be retained longer where necessary to establish, exercise, or defend legal claims, or to comply with a legal obligation.
9. International Transfers
Our infrastructure and sub-processors may process data outside your country, including in the United States. Where personal data is transferred out of the European Economic Area, the United Kingdom, or Switzerland, we rely on an appropriate safeguard, which will be one of:
- an adequacy decision by the European Commission or the relevant authority;
- the European Commission's Standard Contractual Clauses, together with the UK Addendum where the UK GDPR applies; or
- another lawful transfer mechanism recognized under applicable law.
We assess the circumstances of each transfer and apply supplementary technical measures — encryption in transit and at rest, and access controls — where appropriate. A copy of the relevant safeguards is available on request at support@occupancypms.com.
10. Security
We maintain technical and organizational measures appropriate to the risk, including:
- Encryption in transit. All traffic is served over HTTPS/TLS.
- Encryption at rest. The managed database and its backups are encrypted at rest by our hosting provider.
- Credential protection. Passwords are stored only as salted, computationally expensive hashes — never in plaintext or reversible form.
- Two-factor authentication. Available on all accounts, using time-based one-time passwords with recovery backup codes.
- Access control. Application routes are authenticated by default and gated by role; internal access to production data is restricted to personnel who need it, and is logged.
- Rate limiting and abuse protection. Authentication and sensitive endpoints are rate-limited to resist brute-force and credential-stuffing attacks.
- Transport and header hardening. Standard security headers are applied to all responses.
- Audit logging. Authentication and account-security events are recorded.
- Backups. Routine automated backups of the production database, retained per §8.
No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for protecting your credentials and for the access you grant to your Authorized Users.
Breach notification. If a personal-data breach affecting your data occurs, we will notify the competent supervisory authority within 72 hours where required, and will notify affected Customers without undue delay, with the information needed for them to meet their own notification duties.
11. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access — obtain confirmation of whether we process your data, and a copy of it;
- Rectification — correct inaccurate or incomplete data;
- Erasure — request deletion where the data is no longer necessary or processing was unlawful;
- Restriction — limit how we process your data while a dispute is resolved;
- Object — object to processing based on legitimate interests, and to direct marketing at any time and unconditionally;
- Portability — receive data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
- Withdraw consent — where processing is based on consent, without affecting the lawfulness of processing before withdrawal;
- Not be subject to automated decision-making producing legal or similarly significant effects — we do not carry out such processing; and
- Complain to your local data-protection supervisory authority. In the EEA, this is the authority in your country of residence, work, or the place of the alleged infringement.
Making a request. Write to support@occupancypms.com. We will verify your identity before acting, and will respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. Requests are free unless manifestly unfounded or excessive.
Guest requests. For Guest Data, contact the hotel holding your reservation (see §3.3).
12. California Privacy Rights (CCPA/CPRA)
This section applies to California residents and supplements the sections above.
12.1 Categories collected. In the 12 months preceding the effective date, we collect the following CCPA categories:
| CCPA category | Collected | Examples |
|---|---|---|
| A. Identifiers | Yes | Name, email, username, IP address, account identifiers |
| B. Customer records (Cal. Civ. Code §1798.80) | Yes | Name, contact details, billing information |
| C. Protected classifications | Only if a hotel records them as Guest Data (e.g. nationality, dietary requirements) | Not collected by Occupancy for its own purposes |
| D. Commercial information | Yes | Subscription plan, transaction and billing history |
| E. Biometric information | No | — |
| F. Internet or network activity | Yes | Usage data, API calls, log data |
| G. Geolocation data | Yes, coarse only | Country or region derived from IP address |
| H. Sensory data | No | — |
| I. Professional or employment information | Yes | Business name, role within the account |
| J. Non-public education information | No | — |
| K. Inferences | No | We do not build profiles or draw inferences about individuals |
12.2 Sources. Directly from you; automatically from your use of the Service; from our sub-processors (for example, billing status from Stripe); and, for Guest Data, from our Customers and their connected channels.
12.3 Business purposes for use. Providing and securing the Service, billing, support, debugging and quality assurance, legal compliance, and protecting against fraud and abuse — as detailed in §5.
12.4 Disclosure for business purposes. We disclose the categories above to the sub-processors listed in §7.1, each under contract restricting use to providing their service to us.
12.5 No sale or sharing. We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA. We have not done so in the preceding 12 months, including with respect to consumers under 16.
12.6 Sensitive personal information. We do not use or disclose sensitive personal information for purposes other than those permitted under CCPA §7027(m), and we therefore do not offer a "Limit the Use of My Sensitive Personal Information" option.
12.7 Your CCPA rights. Right to know, right to delete, right to correct, right to opt out of sale or sharing (not applicable, per §12.5), and the right not to receive discriminatory treatment for exercising any right. We will not deny service, charge different prices, or provide a different level of quality because you exercised a right.
12.8 Exercising your rights. Email support@occupancypms.com with "CCPA Request" in the subject line. We will verify your identity against information already in our records, and will respond within 45 days, extendable once by a further 45 days with notice. An authorized agent may submit a request on your behalf with written, signed permission.
12.9 Shine the Light. California Civil Code §1798.83 permits residents to request information about disclosure of personal information to third parties for their direct marketing purposes. We do not make such disclosures.
13. Other Regional Disclosures
13.1 United Kingdom. Where the UK GDPR applies, references to the GDPR in this Policy include the UK GDPR, and complaints may be made to the Information Commissioner's Office.
13.2 Switzerland. Where the Swiss FADP applies, complaints may be made to the Federal Data Protection and Information Commissioner.
14. Children
The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18 as an account holder. Where a hotel records details of a minor as part of a family reservation, that data is Guest Data controlled by the hotel, and the hotel is responsible for the lawful basis for processing it. If you believe a child has created an account, contact support@occupancypms.com and we will delete it.
15. Automated Decision-Making
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not perform profiling for marketing purposes.
16. Data Processing Terms (Occupancy as Processor)
These terms apply where Occupancy processes Guest Data on behalf of a Customer, and form part of the agreement between Occupancy and that Customer.
16.1 Subject matter and duration. Processing of Guest Data for the term of the Customer's subscription and the post-termination period in §16.6.
16.2 Nature and purpose. Storage, organization, retrieval, transmission to enabled integrations, backup, and deletion, solely to provide the Service.
16.3 Categories of data subjects and data. Hotel guests and the Customer's Authorized Users; the data categories listed in §4.3.
16.4 Instructions. Occupancy processes Guest Data only on the Customer's documented instructions, which comprise the Terms and Conditions, this Policy, and the Customer's use of the Service's features. Occupancy will inform the Customer if an instruction appears to infringe applicable data-protection law.
16.5 Obligations. Occupancy will: (a) ensure personnel with access are bound by confidentiality; (b) implement the measures described in §10; (c) engage sub-processors only under §7.1 and remain liable for their performance; (d) assist the Customer, taking into account the nature of processing, with data-subject requests, breach notification, data protection impact assessments, and prior consultation; and (e) make available the information necessary to demonstrate compliance and allow for audits by the Customer or an independent auditor, no more than once per year absent an incident, on reasonable notice and subject to confidentiality.
16.6 Return and deletion. On termination, Occupancy will make Guest Data available for export for 30 days, then delete it, except where retention is required by law. Backups are purged on their ordinary rotation.
17. Links to Other Sites
The Service may link to third-party sites and integrations. This Policy does not apply to them. We encourage you to read the privacy policy of any site or service you connect to or visit.
18. Changes to This Policy
We may update this Policy. We will change the "Last Updated" date above and, for material changes, notify Customers by email or in-product notice at least 30 days before the change takes effect. Where a change requires it, we will seek renewed acceptance. Continued use after the effective date constitutes acceptance of the updated Policy.
19. Contact Us
Occupancy PMS Tirana, Albania Website: https://occupancypms.com Privacy: support@occupancypms.com Security: support@occupancypms.com Support: support@occupancypms.com