Legal & Governance

Privacy Policy

Brain Cap provides hotels with tools to manage guest communication, automated workflows, and service operations. This comprehensive policy explains how we collect, process, and safeguard your data.

Effective Date: September 1, 2026
Executive Summary

We believe in data minimalism. We only collect the information absolutely necessary to operate the Brain Cap platform effectively. We do not—and will never—sell personal data. Hotels remain the sole proprietors of their guest data, and all infrastructure is secured with enterprise-grade protocols.

1. Information We Collect

To provide our services, we collect information in the following categories:

2. How We Use Your Information

The information we collect is utilized exclusively to deliver, maintain, and improve our services. Specific uses include:

3. The Role of the Hotel (Data Controller)

In the context of guest data, the Hotel operates as the Data Controller, while Brain Cap acts as the Data Processor. Hotels are fully responsible for the guest information they add, solicit, or receive through our messaging APIs and guest stay links. It is the hotel's responsibility to ensure they have obtained the necessary consent from their guests to communicate via WhatsApp and other digital channels provided by our platform.

4. Data Sharing and Third Parties

We do not sell, rent, or trade personal data to third parties for marketing purposes. Data is only shared under the following circumstances:

5. Data Retention

We retain hotel account information and associated guest data for as long as your account remains active, or as necessary to provide you with our services. Upon account termination, we will delete or anonymize your data within 30 days, unless a longer retention period is required by law or for legitimate auditing purposes.

6. Cookies and Tracking Technologies

Our platform uses standard "cookies" and similar tracking technologies primarily to keep administrators securely logged in, remember your site preferences, and understand how the dashboard is utilized. We do not use advertising or tracking cookies across third-party websites.

7. Your Privacy Rights

Depending on your location (such as the GDPR in Europe or CCPA in California), you may have specific rights regarding your personal data:

To exercise these rights, please contact our support team. If you are a guest of a hotel using our platform, you must direct your data requests directly to the hotel.

8. Security Measures

We implement industry-standard security protocols to safeguard your data. All data transmitted between your browser and our servers is encrypted using HTTPS/TLS. Passwords are cryptographically hashed using modern algorithms. Access to the production database is strictly restricted to authorized engineering personnel using multi-factor authentication (MFA).

9. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our platform, technology, or legal requirements. If we make material changes, we will notify registered administrators via email or prominently display a notice within the platform dashboard prior to the changes taking effect.

10. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please reach out to our privacy compliance team via our Contact page.