We believe in data minimalism. We only collect the information absolutely necessary to operate the Brain Cap platform effectively. We do not—and will never—sell personal data. Hotels remain the sole proprietors of their guest data, and all infrastructure is secured with enterprise-grade protocols.
1. Information We Collect
To provide our services, we collect information in the following categories:
- Account Information: When registering a hotel, we collect the company name, primary contact email, phone number, physical address, and administrator login credentials.
- Platform Configuration Data: Information inputted to run your operations, such as service catalogs, departmental routings, staff records, and specific WhatsApp API configurations.
- Operational Guest Data: Data processed on behalf of the hotel, including guest names, room numbers, contact details, stay dates, generated requests, complaints, and direct messaging histories.
- System & Usage Logs: We automatically gather metadata regarding how users interact with the platform. This includes IP addresses, browser types, device information, and time-stamped interaction logs strictly used for diagnostics and security.
2. How We Use Your Information
The information we collect is utilized exclusively to deliver, maintain, and improve our services. Specific uses include:
- Authenticating administrators and granting secure access to specific hotel dashboards.
- Orchestrating automated WhatsApp workflows, digital keys, and room service requests.
- Routing guest requests and complaints to the appropriate internal hotel departments.
- Processing service orders and compiling billing/audit histories for hotel management.
- Monitoring platform health, troubleshooting technical issues, and preventing fraudulent activity.
3. The Role of the Hotel (Data Controller)
In the context of guest data, the Hotel operates as the Data Controller, while Brain Cap acts as the Data Processor. Hotels are fully responsible for the guest information they add, solicit, or receive through our messaging APIs and guest stay links. It is the hotel's responsibility to ensure they have obtained the necessary consent from their guests to communicate via WhatsApp and other digital channels provided by our platform.
4. Data Sharing and Third Parties
We do not sell, rent, or trade personal data to third parties for marketing purposes. Data is only shared under the following circumstances:
- Service Providers: We use trusted third-party infrastructure (such as secure cloud hosting providers like AWS/Google Cloud) and messaging infrastructure (Meta/WhatsApp API) to deliver our services. These providers are bound by strict confidentiality agreements.
- Legal Compliance: We may disclose information if required to do so by law, court order, or governmental request to protect our rights, property, or the safety of our users.
5. Data Retention
We retain hotel account information and associated guest data for as long as your account remains active, or as necessary to provide you with our services. Upon account termination, we will delete or anonymize your data within 30 days, unless a longer retention period is required by law or for legitimate auditing purposes.
6. Cookies and Tracking Technologies
Our platform uses standard "cookies" and similar tracking technologies primarily to keep administrators securely logged in, remember your site preferences, and understand how the dashboard is utilized. We do not use advertising or tracking cookies across third-party websites.
7. Your Privacy Rights
Depending on your location (such as the GDPR in Europe or CCPA in California), you may have specific rights regarding your personal data:
- Right to Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You may request that we correct any inaccurate or incomplete data.
- Right to Erasure (Right to be Forgotten): You may request that we delete your data, subject to certain legal exceptions.
- Right to Restrict Processing: You may request that we limit the way we use your data.
To exercise these rights, please contact our support team. If you are a guest of a hotel using our platform, you must direct your data requests directly to the hotel.
8. Security Measures
We implement industry-standard security protocols to safeguard your data. All data transmitted between your browser and our servers is encrypted using HTTPS/TLS. Passwords are cryptographically hashed using modern algorithms. Access to the production database is strictly restricted to authorized engineering personnel using multi-factor authentication (MFA).
9. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our platform, technology, or legal requirements. If we make material changes, we will notify registered administrators via email or prominently display a notice within the platform dashboard prior to the changes taking effect.
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please reach out to our privacy compliance team via our Contact page.