01. Scope & Fundamental Commitment
This Privacy Policy applies to personal information processed by Bang Tech Inc. (“Bang Tech”, “Company”, “we”, “us”, or “our”) in connection with the ChatBeds™ In-Chat Property Management System, accessible via chatbeds.app, bangtech.io, associated conversational interfaces (WhatsApp, Telegram), mobile web applications, and backend synchronization APIs.
02. Data Controller vs. Data Processor Roles
Under global data protection regulations including the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), data responsibilities depend on the nature of the data relationship:
For our direct business customers (Hotel Operators, General Managers, staff administrators), we act as a Data Controller regarding your account credentials, subscription billing information, contract details, and support inquiries.
When processing Guest Lodging Data (guest folios, names, phone numbers, passport copies, stay notes, room charges), the Hotel Customer is the Data Controller, and Bang Tech Inc. acts strictly as a Data Processor carrying out instructions under our Data Processing Addendum (DPA).
If you are a hotel guest with inquiries regarding your reservation record or wishing to exercise privacy rights, please contact the hotel property directly. We assist hotel operators with fulfilling verified guest data requests.
03. Categories of Data We Collect
Depending on how you interact with ChatBeds, we collect and process the following categories of data:
- Hotel Operator Account & Staff Data: Full name, professional email address, mobile phone number, WhatsApp account ID, property name, role within the property (e.g., General Manager, Housekeeper, Front Desk), IP address, and role-based access tokens.
- Guest Reservation & Folio Data (Processed on Hotel's Behalf): Guest name, phone number, email address, arrival and departure timestamps, room tier, occupancy count, dietary or room preferences, loyalty IDs, and incidental charges recorded in the folio ledger.
- Conversational Operational Logs: Text messages, dispatch commands, shift handover notes, and status updates submitted through WhatsApp or Telegram to manage daily property workflows.
- Multimodal Audio & Visual Inputs: Ephemeral voice notes sent by staff (transcribed for maintenance tickets or commands), and photographs uploaded for housekeeping room quality verification, damage reporting, or expense receipts.
- Property Accounting & Revenue Metadata: Daily revenue totals, RevPAR, ADR, occupancy percentages, USALI sub-account allocations, and night audit balancing logs.
- Payment & Billing Records: Subscription billing contact, company billing address, payment token identifiers generated by Stripe Inc. (we never store raw credit card numbers or CVV codes), and invoice history.
- Technical & Usage Information: Device type, browser user-agent, operating system, API latency metrics, error telemetry, and session logs.
04. How We Use Your Data
We process collected information under lawful bases including contractual necessity, legitimate business interest, and legal compliance, specifically to:
05. AI Voice & Vision Processing Guardrails
ChatBeds incorporates enterprise AI technologies, including voice transcription powered by Groq Whisper and visual room inspection powered by Gemini Vision. We adhere to rigorous privacy guardrails:
Your hotel proprietary operational data, guest conversations, voice notes, and inspection images are never used to train, retrain, or improve foundational third-party public AI models. All AI inference is executed under zero-data-retention enterprise enterprise agreements.
Audio recordings submitted via staff voice notes are transcribed to text via Groq Whisper in ephemeral memory buffers. Once the operational command is transcribed and logged, raw audio recordings are purged from active memory.
Room inspection and receipt photos analyzed by Gemini Vision are processed exclusively within isolated sandboxes. Analysis focuses solely on physical room readiness parameters (bedding, linen, minibar, fixture damage) and optical character recognition for vendor receipts.
06. Messaging Channels & Carrier Privacy
When hoteliers and staff communicate with ChatBeds via WhatsApp or Telegram, message transport is subject to the privacy architectures of the respective messaging platforms:
- WhatsApp Business API: Messages delivered between authorized staff and ChatBeds Cloud are transmitted over TLS-encrypted connections via Meta Platforms' Cloud API endpoints. Meta’s handling of technical routing metadata is governed by Meta’s WhatsApp Business Privacy Policy.
- Telegram Bot API: Transmission of Telegram bot messages is handled via Telegram Messenger Inc.'s encrypted server infrastructure.
- Anti-Spam Adherence: Hoteliers agree to comply with carrier opt-in regulations, the Telephone Consumer Protection Act (TCPA), and CAN-SPAM requirements before initiating unsolicited notifications to guests.
07. Payments & PCI-DSS Tokenization
All payment card transactions—both for ChatBeds subscription fees and guest credit card processing via hotel booking engines—are facilitated through certified PCI-DSS Level 1 compliant payment service providers, primarily Stripe, Inc.
Bang Tech Inc. servers never receive, store, or transmit raw credit card primary account numbers (PAN), expiration dates, or CVV/CVC security codes. All payment interactions utilize secure client-side tokenization and encrypted webhooks, ensuring strict compliance with PCI-DSS guidelines.
08. Subprocessors & Service Providers
We engage vetted third-party service providers (“Subprocessors”) to assist in infrastructure hosting, messaging delivery, and security. All subprocessors are bound by rigorous data protection agreements ensuring equivalent security standards:
| Subprocessor | Purpose | Data Location |
|---|---|---|
| Stripe, Inc. | Payment tokenization & billing infrastructure | United States / EU |
| Meta Platforms, Inc. | WhatsApp Business Cloud API messaging conduit | United States / Global |
| Cloudflare, Inc. | DDoS protection, Edge CDN, and WAF security | Global Edge |
| Amazon Web Services / Supabase | Encrypted database storage & cloud hosting | United States (East) |
| Groq, Inc. | Ultra-low latency Whisper speech transcription inference | United States |
| Google Cloud Enterprise | Multimodal vision processing & OCR infrastructure | United States |
09. Zero Data Sale or Rental Pledge
Under the California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), and Delaware Online Privacy Protection Act:
10. International Transfers & Standard Contractual Clauses
ChatBeds operates primary servers located in the United States. If you access ChatBeds from the European Economic Area (EEA), United Kingdom, Switzerland, or other regions with laws governing data collection and use that may differ from United States law:
We ensure an adequate level of data protection by entering into European Commission-approved Standard Contractual Clauses (SCCs) and implementing supplementary technical safeguards (such as cryptographic pseudonymization and end-to-end transport encryption).
11. Enterprise Data Security & Storage
Bang Tech Inc. enforces technical and administrative controls designed in alignment with SOC 2 Type II and ISO 27001 standards:
- Encryption in Transit: All HTTP and WebSocket communications enforce TLS 1.3 encryption with strict HSTS headers.
- Encryption at Rest: All database volumes, backups, and media artifacts are encrypted using AES-256 standards.
- Least-Privilege RBAC: Production databases are segregated; only authenticated engineers with dual-factor hardware security keys have temporary just-in-time access for maintenance.
- Immutable Ledger Audits: Financial and operational state transitions are cryptographically hashed to prevent undetected manipulation.
12. Retention & Deletion Schedule
We retain personal information only for the duration necessary to deliver the ChatBeds service, satisfy legal, tax, and accounting reporting requirements, and resolve contractual disputes:
- Active Subscriptions: Hotel operational data is maintained for the duration of the subscription agreement.
- Accounting & Tax Records: Folio transaction ledgers and invoices are retained for up to 7 years in accordance with statutory accounting and tax regulations.
- Ephemeral Voice Audio: Audio clips sent via messaging for command execution are discarded immediately following text transcription.
- Account Termination: Upon termination of a customer agreement, hotel proprietary data is exported to the hotelier and irreversibly expunged from primary production datastores within 60 calendar days.
13. Your Privacy Rights (GDPR, CCPA & Global)
Depending on your jurisdiction, you have specific statutory privacy rights regarding your personal information:
To exercise your rights, please submit a written request to contact@chatbeds.app. We respond to all verified requests within thirty (30) days.
14. Cookies & Web Telemetry
The ChatBeds website and web portals utilize strictly necessary and performance cookies. We do not employ third-party advertising tracking cookies or invasive cross-site behavioral beacons.
- Session & Security Cookies: Essential for authenticating staff, maintaining CSRF protection, and preserving administrative dashboard sessions.
- Preference Cookies: Retain interface display choices, such as currency, language, and dark mode theme.
15. Contact Privacy Office & Notice Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact our Data Protection Officer: