Legal

Data Policy

Where your data lives, how long we keep it, and how you can take it with you.

Tenant isolation

Every record in RoomTiq carries a hotel ID. Database row-level security and storage prefixes enforce that data from one hotel is never visible to another.

Encryption

Data is encrypted in transit (TLS 1.2+) and at rest. Document storage uses signed, time-limited URLs — no public links to guest IDs.

Retention

  • Hotel & booking records: retained while the account is active.
  • Guest ID images: retained for the duration required by local guest-registration law, then purged on request.
  • Audit logs: retained for 24 months for security and compliance.

Export

You can export bookings, guests and document download links from the Reports module at any time as CSV.

Deletion

You can request full account deletion by writing to privacy@roomtiq.app. We will purge your data within 30 days, except where retention is legally required.

Subprocessors

We use a managed cloud database, object storage and an AI gateway. A current list is available on request.

Last updated: 29 June 2026