This Privacy Policy explains how FDS Cards Ltd ("we", "us", "our") collects, uses, shares and safeguards personal data when you use the Hotel Loyalty mobile app, the Hotel Staff mobile app, and the related Hotel Tech web platform at loyalty.hotel-tech.ai (together, the "Service"). By using the Service you agree to the practices described below.
FDS Cards Ltd is the data controller for personal data processed through the Service.
For stays at a specific hotel, the hotel itself is a joint controller of your reservation, guest profile and any chat messages you exchange with that hotel's team. The hotel is identified inside the app (under your bookings and chat threads).
| Category | Examples |
|---|---|
| Account | Name, email, phone (optional), password (stored hashed only), profile photo |
| Membership | NFC loyalty card UID (used purely as a member identifier), QR member code |
| Reservations | Stay dates, room or service selected, party size, special requests, payment status |
| Communications | Messages you send to the hotel team via in-app chat, support emails |
| Preferences | Language, push-notification preferences, marketing opt-ins |
| Category | Examples |
|---|---|
| Loyalty activity | Points earned and redeemed, tier progression, redeemed offers |
| Stay history | Past and upcoming bookings, check-in / check-out events |
| Notifications | Apple Push Notification token (member app only) so we can send reminders |
| Technical | IP address (for rate-limiting and abuse prevention), user agent, app version |
| Diagnostics | Server-side error logs (no third-party crash analytics SDKs are bundled) |
| Purpose | Legal basis |
|---|---|
| Run your loyalty membership and process your reservations | Contract (UK GDPR Art. 6(1)(b)) |
| Send transactional emails and push notifications (booking confirmations, points balance, reservation reminders) | Contract (UK GDPR Art. 6(1)(b)) |
| Send marketing communications (only if you opt in) | Consent (UK GDPR Art. 6(1)(a)) |
| Prevent fraud, secure the Service, debug technical issues | Legitimate interests (UK GDPR Art. 6(1)(f)) |
| Comply with tax, accounting and consumer-protection laws | Legal obligation (UK GDPR Art. 6(1)(c)) |
We do not sell your data. We share it only with the categories of recipients below, all of whom are bound by confidentiality and data-processing agreements:
| Recipient | Purpose | Region |
|---|---|---|
| The hotel(s) you stay at | Run your reservation, recognise you on arrival, deliver loyalty perks | Hotel's location (typically EU/UK) |
| DigitalOcean | Hosting and database storage | EU |
| Smoobu (Bookingsync GmbH) | Property-management synchronisation when your stay involves a Smoobu-managed unit | EU (Germany) |
| Stripe Payments Europe Ltd | Process payments you make through the Service | EU (Ireland) |
| OpenAI Ireland Ltd | Generate chatbot replies when you message the hotel via the AI chat (only message content is sent โ never your account credentials) | EU / US (with EU-US Data Privacy Framework safeguards) |
| Anthropic, PBC | Power the staff-side admin assistant. Member personal data is sent only when a staff user explicitly queries that member's record. | US (Standard Contractual Clauses) |
| Apple Inc. / Google LLC | Deliver push notifications via APNs and FCM | US (SCCs / DPF) |
| Tax authorities, regulators, courts | When legally compelled | Jurisdiction-dependent |
Where data is transferred outside the UK / European Economic Area, we rely on the EU-US Data Privacy Framework (where applicable), the UK International Data Transfer Addendum, or Standard Contractual Clauses adopted by the European Commission.
| Data | Retention |
|---|---|
| Account profile | For the lifetime of your account, then 30 days after a deletion request |
| Booking and payment records | 7 years (statutory accounting requirement under UK Companies Act 2006) |
| Loyalty points ledger | While the account exists; an immutable audit trail is kept for 7 years for tax purposes |
| Chat messages with the hotel team | 12 months from last activity |
| Server logs (IP, user agent, request paths) | 90 days |
| Marketing-consent records | 3 years after withdrawal of consent |
Under UK GDPR and the EU GDPR you have the following rights, exercisable free of charge:
To exercise any of these rights, email vitaly@fds-cards.co.uk. We will respond within one calendar month.
You can also delete your account directly from inside the Hotel Loyalty mobile app: Profile โ Account โ Delete Account.
The Service is intended for users aged 16 and over. We do not knowingly collect personal data from anyone under 16. If you believe a minor has provided personal data to us, contact vitaly@fds-cards.co.uk and we will delete it.
Our mobile apps do not use browser cookies. The web admin panel sets a single first-party
session cookie (laravel_session) that is strictly necessary for authentication
and is not used for tracking or advertising.
Neither app uses Apple's App Tracking Transparency framework because we do not track you across other apps or websites. Both apps declare "Data Not Used to Track You" on their App Store privacy nutrition label.
We may update this Policy when our practices change or when required by law. Material changes will be communicated to active users through an in-app notice or email at least 14 days before they take effect. The "Last updated" date at the top of this page indicates the most recent revision.
Questions, concerns or requests about this Privacy Policy or your personal data should be sent to vitaly@fds-cards.co.uk.