UnlockInn Privacy Policy
Last modified: August 25, 2026 · Effective date: September 1, 2026
1. Introduction & Scope
UnlockInn Inc. (“UnlockInn”, “we”, “us”, or “our”) provides a multi-tenant cloud-based property management system (PMS) and guest operating software designed for boutique hotels, resorts, homestays, and bed & breakfasts.
This Privacy Policy describes how we collect, store, process, and protect information when you visit our website (unlockinn.com), register for an account, or utilize our web application and API services.
2. Information We Collect
We distinguish between two primary categories of data: Tenant Account Data and Hotel Guest & Reservation Data.
A. Tenant Account Data
When property owners or staff create an account, we collect names, work email addresses, telephone numbers, property registration details, and billing details processed securely via PCI-compliant payment gateways.
B. Hotel Guest & Reservation Data
When you input bookings, reservations, room folios, and guest communication into UnlockInn, you act as the Data Controller and UnlockInn acts as the Data Processor. We process guest names, email addresses, phone numbers, passport/ID numbers (if required by local hospitality law), check-in dates, and payment history solely to fulfill your property management operations.
3. How We Protect Your Data
We implement state-of-the-art technical and organizational safeguards:
- Strict Tenant Isolation: Every database query in our systems is scoped strictly to your unique Property Tenant ID with verified row-level security.
- Encryption: All data transmitted over public networks is encrypted using Transport Layer Security (TLS 1.3). Sensitive database storage is encrypted at rest using AES-256.
- Payment Tokenization: We do not store raw credit card numbers or CVVs on UnlockInn servers. All payment handling is delegated to PCI-DSS Level 1 certified partners (Stripe, Khalti, eSewa).
- Role-Based Access Control: Hoteliers can set granular employee permissions so housekeepers, front desk agents, and accountants only access appropriate data fields.
4. Data Retention and Deletion
We retain your property and reservation records for as long as your account remains active. Property administrators can export complete booking and guest records in standard CSV/JSON formats at any time.
Upon account termination or verified GDPR “Right to be Forgotten” request, all identifiable guest records and tenant credentials are permanently purged or anonymized within 30 days, subject to mandatory local tax or financial audit regulations.
5. GDPR & International Privacy Rights
If you or your guests are located in the European Economic Area (EEA), United Kingdom, or California, you retain statutory rights to access, rectify, port, restrict, or delete your personal data.
To exercise any privacy rights on behalf of your property or a guest, please contact our Data Protection Officer at privacy@unlockinn.com.
Contact Our Privacy Team
UnlockInn Inc. · Data Protection & Legal Compliance
Kathmandu, Nepal & Wilmington, Delaware, USA
Email: privacy@unlockinn.com