Privacy Policy

Hotel Tech platform ยท Hotel Loyalty + Hotel Staff mobile apps
Last updated: May 1, 2026 ยท Effective: May 1, 2026

This Privacy Policy explains how FDS Cards Ltd ("we", "us", "our") collects, uses, shares and safeguards personal data when you use the Hotel Loyalty mobile app, the Hotel Staff mobile app, and the related Hotel Tech web platform at loyalty.hotel-tech.ai (together, the "Service"). By using the Service you agree to the practices described below.

TL;DR: we collect the data needed to run your loyalty membership and your hotel stays โ€” name, email, phone, booking history, points. We do not sell your data, do not track you across other apps, do not run advertising SDKs. You can delete your account at any time and we'll erase your data within 30 days, except where law requires us to keep it longer (e.g. financial records).

1. Who is the data controller?

FDS Cards Ltd is the data controller for personal data processed through the Service.

For stays at a specific hotel, the hotel itself is a joint controller of your reservation, guest profile and any chat messages you exchange with that hotel's team. The hotel is identified inside the app (under your bookings and chat threads).

2. What data we collect

2.1 Data you provide directly

CategoryExamples
AccountName, email, phone (optional), password (stored hashed only), profile photo
MembershipNFC loyalty card UID (used purely as a member identifier), QR member code
ReservationsStay dates, room or service selected, party size, special requests, payment status
CommunicationsMessages you send to the hotel team via in-app chat, support emails
PreferencesLanguage, push-notification preferences, marketing opt-ins

2.2 Data generated by your use of the Service

CategoryExamples
Loyalty activityPoints earned and redeemed, tier progression, redeemed offers
Stay historyPast and upcoming bookings, check-in / check-out events
NotificationsApple Push Notification token (member app only) so we can send reminders
TechnicalIP address (for rate-limiting and abuse prevention), user agent, app version
DiagnosticsServer-side error logs (no third-party crash analytics SDKs are bundled)

2.3 What we do NOT collect

3. Why we use the data (legal bases under UK & EU GDPR)

PurposeLegal basis
Run your loyalty membership and process your reservations Contract (UK GDPR Art. 6(1)(b))
Send transactional emails and push notifications (booking confirmations, points balance, reservation reminders) Contract (UK GDPR Art. 6(1)(b))
Send marketing communications (only if you opt in) Consent (UK GDPR Art. 6(1)(a))
Prevent fraud, secure the Service, debug technical issues Legitimate interests (UK GDPR Art. 6(1)(f))
Comply with tax, accounting and consumer-protection laws Legal obligation (UK GDPR Art. 6(1)(c))

4. Who we share data with

We do not sell your data. We share it only with the categories of recipients below, all of whom are bound by confidentiality and data-processing agreements:

RecipientPurposeRegion
The hotel(s) you stay at Run your reservation, recognise you on arrival, deliver loyalty perks Hotel's location (typically EU/UK)
DigitalOcean Hosting and database storage EU
Smoobu (Bookingsync GmbH) Property-management synchronisation when your stay involves a Smoobu-managed unit EU (Germany)
Stripe Payments Europe Ltd Process payments you make through the Service EU (Ireland)
OpenAI Ireland Ltd Generate chatbot replies when you message the hotel via the AI chat (only message content is sent โ€” never your account credentials) EU / US (with EU-US Data Privacy Framework safeguards)
Anthropic, PBC Power the staff-side admin assistant. Member personal data is sent only when a staff user explicitly queries that member's record. US (Standard Contractual Clauses)
Apple Inc. / Google LLC Deliver push notifications via APNs and FCM US (SCCs / DPF)
Tax authorities, regulators, courts When legally compelled Jurisdiction-dependent

Where data is transferred outside the UK / European Economic Area, we rely on the EU-US Data Privacy Framework (where applicable), the UK International Data Transfer Addendum, or Standard Contractual Clauses adopted by the European Commission.

5. How long we keep the data

DataRetention
Account profileFor the lifetime of your account, then 30 days after a deletion request
Booking and payment records7 years (statutory accounting requirement under UK Companies Act 2006)
Loyalty points ledgerWhile the account exists; an immutable audit trail is kept for 7 years for tax purposes
Chat messages with the hotel team12 months from last activity
Server logs (IP, user agent, request paths)90 days
Marketing-consent records3 years after withdrawal of consent

6. Your rights

Under UK GDPR and the EU GDPR you have the following rights, exercisable free of charge:

To exercise any of these rights, email vitaly@fds-cards.co.uk. We will respond within one calendar month.

You can also delete your account directly from inside the Hotel Loyalty mobile app: Profile โ†’ Account โ†’ Delete Account.

7. Security

8. Children

The Service is intended for users aged 16 and over. We do not knowingly collect personal data from anyone under 16. If you believe a minor has provided personal data to us, contact vitaly@fds-cards.co.uk and we will delete it.

9. Cookies and similar technologies

Our mobile apps do not use browser cookies. The web admin panel sets a single first-party session cookie (laravel_session) that is strictly necessary for authentication and is not used for tracking or advertising.

10. Tracking transparency (Apple ATT)

Neither app uses Apple's App Tracking Transparency framework because we do not track you across other apps or websites. Both apps declare "Data Not Used to Track You" on their App Store privacy nutrition label.

11. Changes to this Policy

We may update this Policy when our practices change or when required by law. Material changes will be communicated to active users through an in-app notice or email at least 14 days before they take effect. The "Last updated" date at the top of this page indicates the most recent revision.

12. Contact us

Questions, concerns or requests about this Privacy Policy or your personal data should be sent to vitaly@fds-cards.co.uk.