Privacy Policy
What HoteFlow stores
HoteFlow coordinates short-term-rental cleaning. We store: your account email and display name; the organisations you belong to and your role in them; property operational data entered by your organisation (addresses, rooms, checklists, notes); cleaning-mission records (statuses, timestamps, checklist responses, photos of the property, reported issues, corrections); in-app notifications addressed to you; and — only if you apply to be verified — the identity, business-registration and insurance documents you send us, together with the legal name, SIREN, SIRET and VAT number you declare. Verification is optional: nothing about the service depends on it, and if you never apply we hold none of it.
What HoteFlow never stores: guest data
We import booking calendars only to schedule cleaning. By construction, our calendar import reads only check-in/check-out times and an opaque event identifier — guest names, contact details, payment information, and reservation messages have no path into our systems.
Property access codes
Door, lockbox, alarm, and Wi-Fi details are encrypted (AES-256-GCM) with a key held outside the database. They are revealed only to the person assigned to a cleaning, only during the active mission window, and every reveal is permanently logged. They are never included in emails or notifications. Workers: this reveal log means your access to codes is recorded — it exists to protect you and the property owner alike.
Photos
Evidence photos of the property are stored in private storage and served only through short-lived signed links to people involved in the mission. Photograph the property, not people.
Cookies
We use only strictly-necessary cookies: your sign-in session, your selected organisation, and your chosen language. There is no advertising, analytics, or cross-site tracking.
Your rights
From your account page you can correct your display name, export a copy of your personal data as JSON, and erase your account. Erasure removes your memberships, notifications, and identifying profile data immediately; anonymised operational history (e.g. "a cleaning was approved on this date") is retained because organisations need their audit trail — it can no longer be attributed to you.
Processors & hosting
Your data is stored and processed by a small number of specialist providers, each under written data-protection terms no less protective than this policy, and we remain responsible to you for what they do. For European customers we deploy in EU regions. We will name them, with each one's purpose and location, in writing on request.