Privacy Policy
Last updated 30 September 2026
Draft
ChimeBee is software that hotels and other businesses use to take guest requests and run their team. This page explains what personal data is involved and who is responsible for it. It is provided by the company that operates this ChimeBee service (“we”).
If you are a guest
The hotel (or other business) you are staying with decides what it records about you and why, so it is the data controller. We process that data on the hotel's behalf, as its processor, only to run the service. For questions about your stay, or to see or delete your data, contact the hotel first; they can download or erase it in ChimeBee. You can also contact us at the contact address below and we will pass your request on.
What the hotel may record about you in ChimeBee:
- your name, and your email and phone number if you give them at check-in;
- your room and stay dates;
- requests you make, notes you type, and ratings and comments you leave;
- technical details needed for security: when you used the guest page, your browser type, and your IP address in rate-limiting counters (kept for minutes, not stored).
Hotels choose how long guest details are kept after checkout (one year unless they change it); after that the name, contact details and typed notes are removed automatically. Emails sent to you are deleted after 90 days.
If you are a hotel team member or account owner
For your own account we are the controller. We hold your name, work email, a secure hash of your password (never the password itself), your two-step login settings if you turn it on, and a record of important actions you take in the audit log, including the IP address and browser used. We use this to run your account, keep it secure, and send you account and service emails. The legal basis is performing our contract with your employer and our legitimate interest in keeping the service secure.
Who else handles the data
- Our hosting providers: Vercel (application) and Supabase (database).
- Resend, to send emails, if email is switched on.
- Google, only if you choose “Continue with Google”: Google tells us your name and email address. We don't receive your Google password or keep any Google access to your account.
- Anthropic (Claude), only if the hotel switches on AI routing or AI translation: the text of a request a guest writes in their own words, and messages between guests and staff, are sent to classify and translate them. Under Anthropic's commercial terms it isn't used to train models.
- Speaking instead of typing uses your browser's own speech recognition. ChimeBee never receives or keeps audio; depending on the browser, your browser's maker may process it (for example Google, in Chrome).
- Upstash, for short-lived rate-limit counters, and Sentry, for error reports (which never include form contents or cookies), if used.
Some of these providers store data outside your country. Where the law requires it, we rely on the providers' standard contractual safeguards. We never sell personal data or use it for advertising.
Security
Data is encrypted in transit, each business's data is kept separate, passwords are hashed, links and codes are single-use and stored only as hashes, and access is limited to the people a business adds to its team.
Your rights
Depending on where you live (for example under Sri Lanka's Personal Data Protection Act, No. 9 of 2022, or the EU/UK GDPR), you may have the right to access, correct, delete or restrict the use of your data, to object, and to complain to your data protection authority. Contact the contact address below to use them. We answer within one month.
Changes
If we change this policy in a way that matters, we will tell account owners by email before it takes effect.
the company that operates this ChimeBee service