Overview
This Privacy Policy explains how Roomservize ("Roomservize", "we", "us" or "our") collects, uses, shares and protects information when you use the Roomservize mobile application for Android (the "App") and the Roomservize guest web page that opens from a QR code in a hotel room (the "Guest Page"). Together we call them the "Service".
The App is used by hotel owners and their staff to run the hotel — rooms, staff, check-in and check-out, guest requests — and to receive voice calls from guests. The Guest Page is used by hotel guests to call reception, request services and see information about their stay.
By creating an account, using the App, or using the Guest Page, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.
Hotels, staff and guests
Three kinds of people use the Service, and their data is handled differently:
- Hotel owners create the hotel in the App and are responsible for it. They sign in with their mobile number.
- Staff — receptionists and housekeeping — are added by the owner, by mobile number, and sign in the same way. Staff accounts belong to the hotel; the owner can deactivate them at any time.
- Guests do not create accounts. Hotel staff record the guest's name, mobile number and, where the hotel requires it, identity documents at check-in. The guest then uses the Guest Page during their stay by entering that mobile number.
The hotel decides what guest information to record and is responsible for having a lawful basis to collect it and for telling guests how it is used. Roomservize processes that information on the hotel's behalf, as described here, and does not use it for its own purposes. If you are a guest with a question about how a hotel handles your details, please ask the hotel first; you can also contact us.
Information we collect
We collect information you provide directly, information generated through use of the Service, and a small amount of information collected automatically by your device.
Account & profile information (owners and staff)
- Mobile number, used to sign in and verified by a one-time code sent over SMS
- Name and role (owner, receptionist or housekeeping)
- Hotel name, address and contact details entered during setup
- Whether a receptionist is on duty, and the time the App last checked in — used to decide whose phone rings
Hotel operations data
- Rooms — number, floor, type, status, and any photos or short video the hotel uploads
- Bookings — check-in and check-out dates, the room, and the guests on the stay
- Guest service catalogue — housekeeping and laundry items, restaurant menu, offers and Wi-Fi details the hotel chooses to publish to guests
Information about guests (recorded by the hotel)
- Guest name and mobile number, recorded at check-in
- Identity documents — photographs of a passport, national ID or similar — if the hotel chooses to capture them at check-in
- Service requests the guest makes from the Guest Page — housekeeping, laundry and restaurant orders — with the items, prices at the time of ordering, and status
- Feedback the guest submits — a rating from 1 to 5 and an optional comment
A guest's mobile number is used as the key to their record in the hotel's guest register, so a returning guest is recognised at their next stay. A guest who gives no mobile number is recorded on the booking only and does not appear in the register.
Call records
- For every call: the hotel, the room, when it was placed, when it was answered and by whom, when it ended, how long it lasted and its outcome (answered, missed, declined, timed out)
- Diagnostic events reported by the two ends of the call — "connecting", "connected" — used to show the right state on screen and to investigate a failed call
The audio of a call is not recorded or stored. See Voice calls.
Guest Page session
- An anonymous, randomly generated identifier issued to the guest's browser so it can be tied to the room and stay. It carries no personal details and expires with the stay.
- The room the QR code was scanned for, kept in the browser's session storage so the page survives a refresh
- A count of requests already seen, kept in the browser's local storage for the unread badge
Automatically collected information
- A push-notification device token for each phone an owner or receptionist signs in on, so an incoming call can ring that phone. It identifies the App installation, not the person.
- Standard server logs — request time, the function called, an approximate IP-based location — kept by our infrastructure provider for security and to diagnose faults
The Service contains no advertising software and no third-party analytics, crash-reporting or behavioural tracking software. We do not build profiles of how you use the Service and we do not track you across other apps or websites.
| Data category | Collected | Shared with third parties |
|---|---|---|
| Name | Yes (owners, staff, guests as recorded by the hotel) | No |
| Mobile number | Yes | Service providers only (authentication, SMS delivery) |
| Identity documents | Only if the hotel captures them at check-in | Service providers only (cloud storage) |
| Photos & videos | Yes (rooms) | Service providers only (cloud storage) |
| Voice audio | Streamed live during a call; never recorded | Service providers only (real-time transport) |
| Call records | Yes (time, duration, room, outcome) | No |
| Service requests & feedback | Yes | No |
| Device push token | Yes (owners and receptionists) | Service providers only (push delivery) |
| Precise location | No — never collected | Not applicable |
| Contacts, SMS, call log | No — never collected | Not applicable |
| Card or bank credentials | No — never collected | Not applicable |
| Advertising or tracking identifiers | No — never collected | Not applicable |
Voice calls
When a guest taps Call Reception, audio travels directly between the guest's browser and the receptionist's phone over Agora's real-time voice network. Roomservize issues a short-lived, single-call access token so that only the two parties to that call can join it.
- Audio is transmitted live and is not recorded, transcribed or stored by Roomservize.
- Agora processes the audio stream in transit as our service provider and does not retain it for us.
- What we keep is the call record described above: who was called, from which room, when, for how long, and what happened.
Owners and staff see the room number of an incoming call on the phone's lock screen. The push notification that wakes the phone carries only an internal call identifier; the room number is fetched by the App after the notification arrives and is never sent through the push network.
How we use information
We use the information we collect to:
- Create and authenticate accounts, including mobile-number sign-in for owners and staff, and tie a guest's browser to their stay
- Operate the Service — set up a hotel, manage rooms and staff, check guests in and out, ring the right phones when a guest calls, connect the call, and deliver and track service requests
- Show hotel staff what they need to act on: which room is calling, what has been ordered, which rooms need cleaning
- Send push notifications to owners and receptionists about incoming calls and, where the hotel enables it, new guest requests
- Diagnose faults with calls and the App, and prevent fraud or misuse
- Communicate with hotels about their account or support requests
- Comply with legal obligations
We do not use guest identity documents, room media or call records for any purpose unrelated to running the hotel that recorded them.
App permissions
The App asks for the following access on Android. Each is used only for the purpose described and can be changed at any time in your device settings.
- Microphone — to carry your voice during a guest call. Requested the first time you accept a call; never used outside a call.
- Notifications — to ring your phone, including from the lock screen, when a guest calls, and to tell you about new requests.
- Bluetooth (nearby devices) — to route a call to a Bluetooth headset or earpiece if you use one.
- Network access — to reach the Service.
The App does not request access to your camera, precise location, contacts, SMS messages, call logs, calendar or files outside the media you choose to attach. Room photos and identity documents are taken with the phone's own camera app or chosen from your gallery, using Android's standard picker; the App holds no camera permission of its own. Sign-in verification codes are typed by you; the App does not read your messages to obtain them.
The Guest Page asks the browser for microphone access only when the guest taps Call Reception, and for nothing else.
How we share information
We do not sell personal information. We share information only in the following circumstances:
- Within the hotel — an owner and the staff they add can see the hotel's rooms, bookings, guests, requests and call records according to their role. Housekeeping staff see rooms and their own requests, not the guest register.
- With the guest — the Guest Page shows a guest their own room, their own requests, and the catalogue, Wi-Fi details and offers the hotel publishes. It never shows one guest another guest's information.
- Service providers — we use trusted third-party providers for cloud hosting and database storage, authentication and SMS delivery, file storage, push-notification delivery and real-time voice transport. They process data on our behalf and are bound by confidentiality and data-protection obligations. See Third-party services.
- Legal requirements — we may disclose information if required by law, regulation, legal process or governmental request, or to protect the rights, property or safety of Roomservize, hotels, guests or the public.
- Business transfers — if Roomservize is involved in a merger, acquisition or sale of assets, information may be transferred as part of that transaction, subject to this policy or a successor policy.
Information is not shared between hotels. One hotel's staff cannot see another hotel's data.
Data security
We use industry-standard measures to protect information: encrypted transmission, access-controlled cloud infrastructure, and rules that limit each account to its own hotel and role. No phone or browser can write to the database directly — every change goes through a server function that checks who is asking. Room photos and identity documents are stored as private files that can only be opened by an authenticated member of the hotel; they are never published at a shareable link. Data is stored in Google Cloud's Mumbai region (asia-south1).
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Data retention
- Owner and staff accounts are retained while the account is active. Deactivating a staff member ends their access immediately; their record is kept so that past actions in the hotel remain attributable.
- Hotel operations data — rooms, bookings, requests, feedback and call records — is retained while the hotel's account is active, as the hotel's own business record.
- Guest register entries and identity documents are retained by the hotel for as long as the hotel keeps them. Hotels may be subject to local requirements to keep guest records for a set period; the hotel is responsible for that retention and for removing documents it no longer needs.
- Guest Page sessions expire automatically and stop working at check-out.
- Push tokens are replaced whenever the App is reinstalled or the phone changes, and are removed when the account is deleted.
- Server logs are kept by our infrastructure provider for a limited period for security and diagnostics.
Your rights & choices
Depending on where you are, you may have the right to:
- Access the personal information held about you
- Request correction of inaccurate information
- Request deletion of your information, subject to legal retention requirements
- Object to or restrict certain processing
- Withdraw permissions such as microphone or notifications in your device settings (calls will not work without them)
Owners and staff can exercise these rights by contacting us. Guests should contact the hotel they stayed at, which holds their record; we will help the hotel respond, and you can also contact us directly.
Account & data deletion
Staff accounts
A receptionist or housekeeping account is created and removed by the hotel owner from Manage → Staff in the App. Ask your hotel owner to remove you. If they are unreachable, email us from a number or address we can match to the account.
Owner accounts and the hotel
To delete an owner account and the hotel with it, email info@roomservize.com from the mobile number on the account (or quote it). We will verify the request and delete the account within 30 days. Deleting the hotel permanently removes its profile, rooms and room media, staff accounts, bookings, guest register and identity documents, requests, feedback, call records and push registrations.
Guests
Guest details are held by the hotel. To have them removed, contact the hotel; a hotel can delete a guest's documents from the booking in the App. If you cannot reach the hotel, contact us with the hotel name and the mobile number you gave at check-in and we will assist.
Children's privacy
The App is intended for hotel owners and staff aged 18 and older and is not directed to children. The Guest Page is intended for the adult who checked in. We do not knowingly collect personal information from anyone under 18 except where a hotel records a minor as a guest on a booking, in which case the hotel is responsible for that record. If we become aware that we hold a child's information without a hotel's lawful basis, we will delete it promptly.
Third-party services
The Service relies on the following providers. Each has its own privacy policy governing how it handles information, and we encourage you to review them.
- Google Firebase (Google LLC) — mobile-number sign-in and SMS verification, database (Cloud Firestore), file storage (Cloud Storage), server functions (Cloud Functions) and push notifications (Firebase Cloud Messaging). The App also uses Google Play services for phone-number verification integrity checks.
- Agora (Agora, Inc.) — real-time transport of call audio between the guest and the receptionist.
We do not use an advertising network, an analytics provider, a crash-reporting service or a payment processor. The Service takes no payments: prices on a request are a record of what the hotel will charge, settled between the hotel and the guest outside the Service.
Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify hotels through the App or by other reasonable means before the changes take effect. The "Effective date" at the top of this page indicates when this policy was last revised.
Contact us
If you have questions, concerns or requests regarding this Privacy Policy or your information, contact us at:
- Roomservize
- Email: info@roomservize.com
- Coimbatore, Tamil Nadu, India