Privacy Policy

Last updated: 16 August 2026 · RoomFlow (roomflow.cc), operated from Sweden · [email protected]

1. Who we are and the two roles we play

RoomFlow provides booking software to hostels and small hotels. We handle personal data in two different roles. As controller— for data about our own customers (hotel owners and staff): account name, email, password hash, and billing details — and, for properties onboarded in person, the signed onboarding form with a copy of the signing owner’s ID document, kept securely as contract evidence and deleted 12 months after the agreement ends. We decide how this data is used. As processor— for data about hotel guests (names, contact details, stay dates, booking and payment status). Here the hotel you booked with is the controller, and we process guest data only on the hotel’s behalf and instructions, under a Data Processing Agreement.

2. What we collect and why

Hotel accounts: name, email, hashed password, role, property configuration — to provide the service (contract). Guest data (on behalf of hotels): name, email, phone, stay dates, room assignment, charges and payment status, booking source — to operate reservations, check-in and billing. Technical logs: minimal server logs for security and troubleshooting (legitimate interest). We do not store payment-card numbers. Card payments are handled by payment providers in their own secure environments; OTA bookings arrive with card details masked.

3. Immigration reporting (TM30)

Properties in Thailand are legally required to report foreign guests to the Immigration Bureau (the “TM30” notification under the Immigration Act). Where a hotel uses RoomFlow’s TM30 feature, it records for each foreign guest: passport number, nationality, gender and — optionally — date of birth. We process this data as processor, solely so the hotel can fulfil this legal obligation. It is visible only to the hotel’s authorized (non-housekeeping) staff, never appears on printouts or public pages, is exported only in the official immigration-portal format at the hotel’s request, and is deleted together with the booking data under the retention rules below. Thai nationals are not reported and no passport data is required for them.

The duty covers foreign guests of any age, so this data can concern a child travelling with their family. The lawful basis is the hotel’s legal obligation, not consent — which means we do not ask a parent to agree to it, because agreement is not what makes the processing lawful and asking would misrepresent a choice that does not exist. Nothing beyond what the immigration form requires is recorded about a minor, and we do not knowingly collect personal data from children through the booking page itself: a reservation is made by the adult booking the stay.

4. Cookies and local storage

RoomFlow uses only strictly necessary cookies: a session cookie to keep you signed in, and security verification (Cloudflare Turnstile) on forms. Interface preferences (such as dark mode) are stored locally on your device and never sent to us. We use no analytics, advertising or tracking cookies, which is why we do not show a cookie-consent banner. If this ever changes, we will ask for consent first and update this policy.

5. Where data lives and our sub-processors

Data is hosted in the European Union (database: AWS eu-west-1, Ireland, via Supabase). Our sub-processors: Supabase (database hosting, EU); Vercel (application hosting, EU region); Channex.io (channel-manager synchronization with OTAs); Resend (transactional email delivery — it receives the recipient’s name, email address and the contents of booking confirmations, password-reset and address-verification messages); and Cloudflare (Turnstile bot protection on public forms — it receives the visitor’s IP address). Each is bound by a data-processing agreement, and where one processes data outside the EU/EEA that transfer is covered by Standard Contractual Clauses. We will update this list before adding sub-processors.

6. How long we keep data

Hotel account data: for the life of the account and up to 12 months after termination, then deleted. Guest booking data (including TM30 details): the hotel decides. It stays in the system until the hotel deletes it — any booking can be corrected or deleted at any time — and we delete a property’s entire dataset within 30 days of a verified deletion request. We do not currently apply an automatic age-based deletion to booking records, so the bookkeeping and immigration-law retention periods that apply to a hotel remain that hotel’s to observe. Cleaning photographs are the exception: they are deleted automatically seven days after they are taken. A verified deletion request is carried out by a RoomFlow administrator using an internal tool built for exactly this, not by hand-written database commands: it removes every booking, guest record, TM30 entry, staff login and other row tied to the property in a single action, and keeps a permanent record of when the deletion happened, who requested it, and who carried it out — kept separately from the data it describes, since that data no longer exists to keep the record with.

7. Your rights

Under the GDPR you can request access, rectification, erasure, restriction, portability, and object to certain processing. If you are a hotel guest: contact the hotel you booked with first — they are the controller of your booking data, and we act on their instruction. If you contact us directly at [email protected], we will forward your request to the hotel and support its fulfilment. If you are a RoomFlow customer: to delete your property and all its data, contact [email protected] or see our data-deletion page. We verify the request, export your data to you on request, and delete within 30 days. You may lodge a complaint with the Swedish Authority for Privacy Protection (IMY, imy.se) or your local supervisory authority.

8. Security

Measures include: encrypted transport (HTTPS), hashed passwords (bcrypt), signed session cookies, role-based access, tenant isolation between properties, EU data hosting, restricted diagnostic endpoints, and security review as part of our release process. When you choose a password we check it against the Have I Been Pwned breach corpus; this is done by sending the first five characters of a hash of the password, never the password itself, so the service cannot learn what you chose. No card data is stored. In case of a personal-data breach we will notify affected controllers without undue delay and support their notification duties (72 hours to the authority where required).

9. Changes

We will announce material changes to this policy by email or in-app notice before they take effect.

Questions about these documents: [email protected]. Material changes are announced by email or in-app notice before they take effect.