Back to Home

Privacy Policy

Last updated: 23 July 2026

Your privacy is important to vGuest, operated by Okami DevOps Ltd. ("vGuest", "we", "our", or "us"), a company registered in Israel (company no. 516663770). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you access our website, chatbot, and associated services (collectively, the "Services"). By using the Services, you acknowledge that you have read and understood this Policy.

Our role. For personal data of hotel guests processed through our platform, the hotel is the data controller and vGuest acts as a data processor on the hotel's behalf, under a Data Processing Agreement. For data of website visitors and prospective customers who contact us directly, vGuest is the controller. For details on our GDPR practices, EU data residency and sub-processors, see our GDPR page.

1. Scope

This Policy applies to any visitor, prospective guest, or partner ("user", "you") who interacts with the Services. It does not apply to third-party websites or services that may be linked from our platform.

2. Information We Collect

CategoryExamplesHow We Collect
Personal DataName, email address, phone number, booking details, preferencesForms, live chat, bookings, support tickets
Usage DataPages viewed, chatbot prompts, clicks, referring URLs, timestampsAutomated tracking tools, cookies, server logs
Device & TechnicalBrowser type, operating system, device identifiers, IP address, approximate locationAutomated tracking tools
Cookies & Similar TechSession cookies, analytics tags, marketing pixelsYour browser or device when you visit our site

3. How We Use Your Information

  • Service Delivery: To provide, operate, and maintain our Services, including processing bookings and responding to inquiries.
  • Communication: To send you service-related communications, updates, and promotional materials (with your consent).
  • Improvement: To analyze usage patterns and improve our Services, including AI chatbot responses and user experience.
  • Security: To detect, prevent, and address technical issues, fraud, and security threats.
  • Legal Compliance: To comply with applicable laws, regulations, and legal processes.

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), we process your personal data based on:

  • Contractual Necessity: Processing necessary to perform our contract with you.
  • Legitimate Interests: Processing necessary for our legitimate business interests.
  • Consent: Processing based on your explicit consent, which you may withdraw at any time.
  • Legal Obligation: Processing necessary to comply with legal requirements.

5. Data Sharing and Disclosure

We may share your information with:

  • Sub-processors: A small set of vetted providers who help us operate the Services — cloud infrastructure and databases (Google Cloud, EU), WhatsApp Business message delivery (Meta), and AI model providers (OpenAI, Anthropic, Google, xAI) used to generate assistant responses. AI providers operate under enterprise API terms and do not train their models on your data. Our current sub-processor list is published on our GDPR page.
  • Hotels and properties: Where you interact with a hotel that uses our platform, we process your data on that hotel's behalf and make it available to that hotel's authorised staff.
  • Legal Requirements: When required by law, court order, or governmental authority.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets.

We do not sell your personal information, and we do not store payment-card or credit-card numbers on our systems (card payments, where offered, are handled by PCI-compliant payment providers).

6. Special-Category (Sensitive) Data

Guests sometimes volunteer sensitive details in a message — for example health-related needs such as allergies, accessibility requirements, or dietary and medical restrictions. Under the EU GDPR and Israel's Privacy Protection Law (including Amendment 13), this is special-category (sensitive) data. Where it occurs, we process it only as the hotel's processor and solely to act on the guest's request, apply heightened safeguards, and do not use it for any other purpose. We ask guests to share no more health or sensitive information than necessary.

7. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to remember your preferences, authenticate users, analyze site traffic, and deliver targeted content. You can control cookies through your browser settings.

8. Data Retention

  • Account Data: Retained for the duration of your account plus 3 years after closure.
  • Transaction Records: Retained for 7 years for tax and legal compliance.
  • Chat Logs: Retained for 2 years for service improvement and dispute resolution.
  • Analytics Data: Aggregated and anonymized data may be retained indefinitely.

9. Data Security

All production infrastructure — application servers, databases and queues — runs in the Google Cloud region europe-west3 (Frankfurt, Germany). We implement appropriate technical and organizational measures to protect your personal information, including encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control with strict per-hotel tenant isolation, multi-factor authentication, least-privilege access, and audit logging of administrative changes.

10. Your Rights

Depending on your location, you may have rights to access, rectify, erase, restrict, port, or object to processing of your personal data. Where vGuest processes guest data on a hotel's behalf, we will support or forward your request together with that hotel as controller. To exercise these rights, contact us at privacy@vguest.ai. We will respond within 30 days.

11. International Data Transfers

Guest data is stored in the European Union (Frankfurt). Some processing may occur outside the EEA — in particular, API calls to AI model providers are used solely to generate a response, under commercial terms that exclude training on your data and apply short retention windows. Where a transfer outside the EEA occurs, it is covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses or the EU-US Data Privacy Framework.

12. Children's Privacy

Our Services are not intended for children under 16. We do not knowingly collect personal information from children.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Policy on this page.

14. Contact Us

Privacy & data protection: privacy@vguest.ai | Support: support@vguest.ai | General: info@vguest.ai

Okami DevOps Ltd. (vGuest), company no. 516663770, Israel.