Skip to content
Hotelia
  • Features
  • Pricing
  • About
  • Contact
Start free trial

Legal

Privacy Policy

What we collect, why we collect it, and what you can ask us to do with it.

Last updated 1 August 2026

Two different roles

Hotelia handles two kinds of personal data, and our responsibilities differ for each. This distinction runs through the whole policy.

  • Your account. When you sign up as a hotel owner or operator, we decide what to collect and why. We are thecontroller of that data.
  • Your guests. When you enter a guest's details into Hotelia, you decide what to record and why. You are the controller; we are a processor acting on your instructions. We do not use guest data for our own purposes, and we never sell it.

What we collect

Account data

  • Your email address, and your name if your sign-in provider supplies it.
  • An authentication identifier from Firebase Authentication. If you sign in with Google or Apple we receive your email address and name from them — we never receive your password.
  • Your hotel's name, address, country, currency and check-in times.
  • Your in-app preferences.

We do not collect payment card details. Card data is handled entirely by Paddle (see below) and never reaches our servers.

Guest and operational data you enter

  • Guest name, and email address and phone number where you record them.
  • Booking details: dates, rooms, number of guests, board basis, meals, services and charges.
  • Payment records, and any payment slip images you upload. Slip images are stored on our server and served only to signed-in users of the hotel that owns them.
  • Housekeeping task status.

Hotelia does not ask for passport numbers, national identity numbers or other government identifiers, and we would advise against putting them in free-text fields.

Technical data

  • App usage events and crash reports, used to find bugs and understand which features are used. On the web version we do not collect crash reports.
  • Standard server logs, which include IP addresses, for security and debugging.

We do not use advertising cookies or third-party tracking pixels on this website.

Why we are allowed to process it

PurposeLawful basis
Providing the service you signed up forPerformance of a contract
Billing and tax recordsLegal obligation
Security, fraud prevention and debuggingLegitimate interests
Product analyticsLegitimate interests
Guest data you enterProcessed on your documented instructions

Who we share it with

We do not sell personal data and we do not share it for advertising. We use these providers to run the service:

ProviderWhat it does
Google (Firebase)Sign-in, account profile storage, analytics, crash reporting and push notifications
Paddle.com Market LtdSubscription payments. Paddle is the merchant of record and handles card details and sales tax
Oracle CloudServers and database hosting

We may also disclose data where the law requires it, or to establish or defend a legal claim.

Where data is stored

Our database and uploaded payment slips are held on our hosting provider's infrastructure. Our sign-in, analytics and crash-reporting providers process data on servers outside your country, including in the United States. Where such transfers are subject to European or United Kingdom data protection law, they rely on the European Commission's standard contractual clauses.

How long we keep it

  • While your account is open: for as long as you keep it. You control your guest and booking records and can delete them at any time.
  • After you delete your account: your hotel, booking, guest, payment and housekeeping records are deleted from our database, and your sign-in account is removed. Backups are overwritten on their normal rotation.
  • Billing records: retained by us and by Paddle for as long as tax law requires, typically six to ten years.

Deleting your account

You can delete your account and all of its data yourself, fromSettings → Delete account in the app. It is permanent and it is not reversible — there is no recovery window, so export anything you need first. You can also email us atsupport@hotelia.app and we will do it for you.

Your rights

Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to how we use it, receive it in a portable format, or complain to your data protection authority. To exercise any of these, emailsupport@hotelia.app. We will respond within one month.

If you are a guest of a hotel that uses Hotelia and you want your data corrected or removed, please contact that hotel directly. They control it; we act on their instructions.

Security

Traffic is encrypted in transit. Access to hotel data requires a signed-in account, and every request is checked against the hotel that owns the record. We do not store your password — sign-in is handled by Firebase Authentication.

No system is perfectly secure. If you believe you have found a vulnerability, please emailsupport@hotelia.app before disclosing it publicly.

Children

Hotelia is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16 as an account holder.

Changes

If we change this policy materially we will update the date at the top and notify account holders by email before the change takes effect.

Contact

Hotelia, Colombo, Sri Lanka.
support@hotelia.app

Hotel management that stays out of the way.

Product

  • Features
  • Pricing
  • Sign in

Legal

  • Privacy
  • Terms
  • Refunds

© 2026 Hotelia. All rights reserved.