Inn · LEGAL
Privacy Policy
Effective August 24, 2026
1. Who we are
Inn is a hotel operations platform built by Palterion. This Privacy Policy explains what data we collect from hotels and their staff who use Inn, why we collect it, and the choices you have.
Account deletion and password requests
Inn is provided by Inn LLC. To request that we delete your Inn account and associated data, or for password / sign-in help, email innsince2026@gmail.com from the address on your account.
·
How to request deletion — send an email with the subject “Delete my Inn account.” Signed-in owners can also delete the account from Settings in the app.
·
What we delete — your account, hotel operational data (rooms, reservations, guests, staff records, work orders, logs), and stored photos tied to that hotel.
·
What we may keep, and for how long — if you cancel first, we keep hotel data for 90 days so you can restore it, then delete it when you request. Audit logs may be retained for up to one year where required for security. We complete deletion requests within 30 days.
2. What we collect
We only collect what we need to run the product:
·
Account info — name, email address, hotel name, and role (owner, manager, front desk, housekeeping, maintenance). Provided when you sign up or are added as staff by an admin.
·
Authentication credentials — passwords are never stored by us. They are handled by our authentication provider. Staff PINs are stored as a salted SHA‑256 hash.
·
Operational data you create — rooms, reservations, guest profiles, housekeeping tasks, maintenance work orders, cash counts, store sales, schedule entries, and time‑tracking entries.
·
Billing data — subscription status, plan, room count, invoice history, and the email used for billing receipts. Card numbers and CVV go directly to our payment processor; we never see or store them.
·
Location data — when a non‑admin staff member opens the app, the device reports a single coordinate so we can confirm they are at the hotel before allowing them to perform on‑site actions (clock in, mark a room clean). We store the most recent location and the time it was checked, never a movement trail. Admins and users with remote access are exempt and never share location.
·
Push tokens — if you opt in to notifications, we store the Expo push token for your signed‑in devices so we can deliver schedule and assignment alerts.
·
Audit logs — every meaningful action (creating a reservation, refunding a payment, changing a role) is recorded for security and accountability.
3. Why we collect it
·
To run the app and keep your hotel’s data isolated from other hotels.
·
To process subscription billing.
·
To enforce hotel policy — geofenced staff access, role‑based permissions, and the audit log.
·
To send transactional emails and push notifications you have opted into.
·
To respond to your support requests.
We do not use your data for advertising. We do not sell your data. We do not run third‑party trackers in the app.
4. Sub‑processors
We rely on a small number of trusted providers to operate the service:
·
Authentication provider — sign-in, passwords, and user accounts.
·
Cloud hosting — database, application server, and real‑time sync.
·
Payment processor — subscriptions, invoices, and the billing portal.
·
Email delivery — transactional email (receipts, password reset, etc.).
·
Push delivery — notifications to iOS and Android devices.
·
AI assistant provider — optional in-app support chat. Conversations are not used to train models.
5. How long we keep it
Operational data lives in your hotel’s account for as long as the account is active. When you cancel your subscription, we keep your data for 90 days so you can restore it, then delete it on request. Audit logs are retained for one year. Backups follow our hosting provider’s standard rolling retention.
6. Your choices
·
Access & export — admins can export reservations, guests, and financial reports from the Reports screen at any time.
·
Correction — admins can edit any record from the relevant screen.
·
Deletion — email innsince2026@gmail.com from the address on your account and we will fully delete your hotel’s data within 30 days. Signed-in owners can also delete the account from Settings.
·
Push notifications — toggle off in your device’s system settings or in the app’s notification preferences.
·
Location — staff who do not want their device location checked can be granted remote‑access by an admin (their on‑site actions will then bypass the geofence). System location permission can be revoked at any time in iOS/Android settings.
7. Children
Inn is a business tool. It is not directed at children under 16, and we do not knowingly collect data from anyone under 16. If you believe a minor’s data has been submitted, contact us and we will delete it.
8. International transfers
We are based in Canada and our hosting providers operate primarily in the United States. By using the service you consent to your data being processed in those jurisdictions, with the protections required by applicable law.
9. Security
Data is transmitted over TLS, secrets are stored in our hosting provider’s key management, passwords and PINs are never stored in plaintext, and every privileged action is logged. No system is perfectly secure, but we work hard to make sure yours is.
10. Changes to this policy
We will update this page and revise the effective date when our practices change. For material changes we will email account admins.
11. Contact us
Account deletion, password, and data requests: email innsince2026@gmail.com. Other questions: tech@palterion.com.
© 2026 Palterion. All rights reserved.
Terms of Service →
Checkout
Extend Stay
Add Charges
Check-In