Skip to main content

Privacy Policy

InnSyst

Effective Date: March 2026 Last Updated: April 17, 2026

1. Introduction

This Privacy Policy ("Policy") explains how InnSyst ("we," "our," "us," or "Company") collects, uses, discloses, and otherwise processes personal information from hotel operators, staff members, and guests through our website (innsyst.com), our cloud-based hotel management platform (hotel.presidiumservices.com), and related services (collectively, the "Platform").

This Policy also applies to any white-label or partner domains that are powered by the InnSyst platform. These domains operate on the same underlying technology and are subject to the same privacy practices described herein. For a current list of white-label domains covered by this Policy, please contact us at [email protected].

We are committed to protecting your privacy and ensuring you have a transparent understanding of our data practices. This Policy applies to all users of the Platform, including hotels and their staff, and describes your rights regarding your personal information.

Last Updated: March 2026

2. Information We Collect

2.1 Information Provided Directly

Hotel Admin and Staff Information:

Name, email address, phone number, job title, and role

Login credentials and authentication information

Communication preferences and account settings

Guest Information:

Name, email address, phone number, and address

Reservation details (check-in/check-out dates, room preferences)

Payment information (limited to first 6 digits and last 4 digits of credit/debit cards, card type, and expiration month/year) — see Section 4 for payment data handling

Special requests, preferences, and stay history

Guest feedback and reviews

Business Information:

Hotel name, address, and property details

Tax ID or business identification information

Billing and invoice information

2.2 Information Collected Automatically

IP address, browser type, and device type

Pages visited within the Platform and time spent on each page

Referring/exit pages and clickstream data

Platform usage patterns and feature adoption

Cookies and similar tracking technologies (see Section 9)

2.3 Information from Third Parties

Payment processors and financial institutions (transaction status and authorization codes)

Cloud service providers who host our Platform

Integrations with booking systems, communication platforms, or reporting tools

3. Legal Basis for Processing (GDPR Compliance)

We process personal information based on one or more of the following legal grounds:

Contractual Necessity: Processing required to provide the Platform and fulfill our contractual obligations

Legitimate Business Interests: Data processing necessary for security, fraud prevention, analytics, and service improvement

Compliance with Law: Processing required to meet legal or regulatory obligations (e.g., tax, booking regulations)

Consent: Where required by law (e.g., marketing communications), we obtain explicit consent before processing

Performance of Official Tasks: Processing on behalf of hotel customers to facilitate their operations

4. How We Use Information

4.1 Core Platform Operations

Providing, maintaining, and improving the InnSyst

Processing reservations, check-ins, and payments

Managing user accounts and authentication

Providing customer support and responding to inquiries

Sending transactional communications (confirmation emails, receipts, payment notifications)

4.2 Business and Legal Purposes

Detecting and preventing fraud, security incidents, and abuse

Complying with legal obligations and regulations (PCI DSS, GDPR, CCPA, tax requirements)

Enforcing our Terms of Service and other agreements

Responding to legal requests or government inquiries

Protecting the rights, property, and safety of our Company, users, and the public

4.3 Service Improvement and Analytics

Analyzing Platform usage to improve features and user experience

Generating anonymized, aggregated reports and insights (not tied to individuals)

Conducting performance monitoring and technical improvements

Training and optimizing our services

We use the following analytics tools on our website (innsyst.com):

Google Analytics (GA4) — provided by Google LLC. Collects anonymized data about traffic sources, user flow, page views, and demographics to help us understand how visitors use our website.

Microsoft Clarity — provided by Microsoft Corporation. Collects behavioral analytics including heatmaps, scroll tracking, and session recordings to help us understand how visitors interact with our website. Session recordings capture mouse movements, clicks, and scrolls. Sensitive content such as passwords, credit card numbers, and form inputs are automatically masked and never recorded.

Umami Analytics — provided by Umami Software, Inc. A privacy-focused analytics service that collects anonymized traffic statistics including page views, referrers, browser type, and country. Umami does not use cookies and does not collect personally identifiable information.

4.4 Marketing and Communications (with Consent)

Sending product updates and feature announcements

Sending promotional offers and newsletters (only with user consent or opt-in)

Conducting surveys and feedback requests

We do not send marketing communications to guest email addresses without explicit consent from the hotel.

4.5 Payment Data Use

First 6 and last 4 digits of payment cards are used solely for:

Transaction identification and reconciliation

Fraud detection and prevention

Guest convenience (displaying masked card details for recurring charges)

Fulfilling payment processor requirements

Complete payment card numbers are never stored, processed, or retained by our Platform (see Section 4 of our PCI Compliance Statement)

5. Who We Share Information With

5.1 Hotel Staff and Authorized Users

Information is shared with authorized hotel staff members based on their user role and permissions within the Platform. Hotels are responsible for controlling staff access through role-based permissions.

5.2 Payment Processors and Service Providers

We share data with:

PCI DSS-compliant payment processors (for payment authorization and processing)

Cloud infrastructure providers (for hosting and data storage)

Communication service providers (for email delivery, SMS notifications)

Analytics services: Google Analytics (Google LLC), Microsoft Clarity (Microsoft Corporation), and Umami Analytics (Umami Software, Inc.) — anonymized data only

Customer support tools

All service providers are contractually obligated to maintain confidentiality and comply with data protection laws.

5.3 Legal and Regulatory Authorities

We may disclose information when:

Required by law, regulation, or legal process (e.g., court order, subpoena, government request)

Necessary to enforce our Terms of Service and other agreements

Necessary to protect our rights, privacy, safety, and property

Responding to claims of illegal activity or negligence

5.4 Data Sharing with Hotels and Hotel Owners

Hotels are responsible for managing guest data according to applicable privacy laws. Guest information may be shared with:

Hotel management companies and franchise operators (as specified in hotel management agreements)

Hotel ownership and corporate entities

Third parties authorized by the hotel (e.g., marketing vendors, loyalty programs)

Hotels are responsible for obtaining any necessary guest consent before sharing data with third parties.

5.5 Business Transfers

If our Company is acquired, merges with another entity, or undergoes bankruptcy, personal information may be transferred as part of that transaction. Users will be notified of any material change in how their information is handled.

5.6 Anonymized and Aggregated Data

We may share anonymized, aggregated data that cannot identify individuals (e.g., industry benchmarks, usage statistics) with third parties for analytics, research, and business intelligence purposes.

6. Data Retention

6.1 Active User Data

Hotel Staff and Admin Information: Retained during active use of the Platform. Deleted within 30 days of account termination or cancellation of service.

Guest Reservation and Stay Data: Retained for the duration of the hotel's subscription to the Platform. Specific retention periods can be configured by hotels based on their business needs.

6.2 Cardholder Data

Limited Cardholder Data (First 6 and Last 4 Digits): Retained as long as the hotel subscription is active, or per hotel preference. Deleted upon account closure or guest request.

Complete Cardholder Data: Never stored by our Platform. Handled and retained only by PCI DSS-compliant payment processors.

6.3 Transactional and Payment Records

Retained in compliance with tax, accounting, and regulatory requirements (typically 7 years for financial records).

Retained for fraud investigation, chargeback resolution, and legal disputes as necessary.

6.4 Backup Data

Data may be retained in backup systems for up to 30-90 days to ensure business continuity and disaster recovery.

Backup data is subject to the same security and confidentiality protections as active data.

6.5 Legal Hold

If we receive a legal request or become aware of potential litigation, we may retain data beyond normal retention periods as required by law.

7. User Rights and Choices

7.1 GDPR Rights (European Users)

If you are located in the European Union or United Kingdom, you have the following rights:

Right to Access: Request access to your personal information and receive a copy

Right to Rectification: Request correction of inaccurate or incomplete information

Right to Erasure ("Right to be Forgotten"): Request deletion of your personal information, subject to legal exceptions

Right to Restrict Processing: Request limitation on how we use your information

Right to Data Portability: Request your data in a portable format

Right to Object: Object to certain types of data processing

Right to Withdraw Consent: Withdraw consent at any time (doesn't affect prior processing)

Right to Lodge a Complaint: File a complaint with your local data protection authority

Response Timeline: We will respond to data subject requests within 30 days (extendable to 60-90 days for complex requests).

7.2 CCPA Rights (California Residents)

If you are a California resident, you have the following rights:

Right to Know: Request to know what personal information is collected, used, and shared

Right to Delete: Request deletion of personal information (subject to exceptions)

Right to Correct: Request correction of inaccurate personal information

Right to Opt-Out: Opt out of the sale or sharing of personal information

Right to Limit: Limit use and disclosure of sensitive personal information

Right to Non-Discrimination: We do not discriminate for exercising your privacy rights

Response Timeline: We will respond to requests within 45 days. Requests may be extended by an additional 45 days if necessary.

7.3 Other State Privacy Rights

Many other U.S. states (Colorado, Connecticut, Delaware, Indiana, Iowa, Mississippi, Montana, New Hampshire, Tennessee, Utah, Virginia) have enacted privacy laws. If applicable to your state, similar rights to those listed above apply. Contact us for specific information about your state's requirements.

7.4 Marketing Communications

You can opt out of promotional emails and marketing communications by clicking the "Unsubscribe" link in any email or by contacting us.

You can manage communication preferences in your Platform account settings.

We will honor opt-out requests within 10 business days.

7.5 Cookies and Tracking

You can disable cookies in your browser settings, though some Platform features may not function properly.

See Section 9 (Cookies) for additional information and opt-out options.

7.6 Exercising Your Rights

To exercise any of the rights described above, submit a request to:

Email: [email protected] Mail: InnSyst (Presidium Services LLC), 8996 Little Bluestem Dr, Land O Lakes, FL 34637 Web Form: https://innsyst.com/contact

We will verify your identity before processing your request. If you are requesting on behalf of a hotel or business, we may require proof of authorization.

8. Data Security

8.1 Security Measures

We implement industry-standard security controls to protect personal information:

Encryption in Transit: All data transmitted to and from the Platform uses TLS 1.2+ encryption (HTTPS)

Encryption at Rest: Databases and storage systems containing personal information are encrypted using AES-256 or equivalent

Access Controls: Role-based access controls restrict data access to authorized personnel only

Multi-Factor Authentication: MFA required for administrator access to sensitive systems

Firewalls and Network Security: Industry-standard firewalls and intrusion detection systems protect our infrastructure

Vulnerability Management: Regular security assessments, penetration testing, and vulnerability scanning

Patch Management: Timely application of security updates and patches to all systems

Secure Development: Security best practices followed during development, including code reviews and testing

8.2 Incident Response and Breach Notification

In the event of a data breach:

Investigation: We will investigate the breach to determine scope and impact

Notification: We will notify affected users, hotels, and regulators as required by law within the required timeframes:

GDPR: 72 hours to relevant data protection authorities

CCPA/CPRA: Prompt notification to affected individuals

Other States: Per applicable state breach notification laws

Cooperation: We will cooperate with law enforcement and regulatory authorities as required

9. Cookies and Tracking Technologies

9.1 Cookies

We use cookies to:

Maintain your login session and remember preferences

Analyze Platform usage and improve functionality

Prevent fraud and enhance security

Provide a personalized user experience

9.2 Types of Cookies

Essential Cookies: Required for Platform functionality (cannot be disabled)

Performance Cookies: Track usage analytics and performance metrics

Preference Cookies: Remember your settings and choices

Marketing Cookies: Used to deliver personalized content (with consent where required)

9.3 Your Cookie Choices

Most browsers allow you to refuse cookies or alert you when cookies are set

Disabling essential cookies may impair Platform functionality

You can manage cookie preferences through your browser or our cookie management tools

9.4 Do Not Track Signals

Some browsers include a "Do Not Track" feature. Our Platform does not currently respond to "Do Not Track" signals, but you can disable tracking through browser settings and our cookie controls.

10. Data Protection for Hotel Staff and Guests

10.1 Hotel Responsibilities

Hotels using the Platform are responsible for:

Obtaining guest consent where required by law before collecting and processing guest information

Maintaining their own privacy notices and policies for guests

Securing and controlling access to guest information within the Platform

Ensuring compliance with privacy laws applicable to their jurisdiction

Notifying guests of any data breaches affecting guest information

10.2 Platform's Role

We act as a data processor on behalf of hotels. We:

Process data according to hotels' instructions and contracts

Implement appropriate security measures to protect data

Do not use hotel data or guest data for our own marketing or business purposes (except with explicit permission)

Will notify hotels of any data requests or legal orders we receive

Support hotels' compliance with applicable privacy laws

10.3 Data Processing Agreement

Hotels and our Company execute a Data Processing Agreement (DPA) that defines roles, responsibilities, and security obligations for handling guest and hotel data. The DPA incorporates Standard Contractual Clauses for international data transfers where required by GDPR.

11. Children's Privacy

Our Platform is not intended for children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will delete it immediately.

12. International Data Transfers

12.1 Global Platform

Our Platform operates globally and data may be transferred, stored, or processed in countries other than where you reside. Some countries may not provide the same level of data protection as your home country.

12.2 Data Transfer Mechanisms

For international transfers, we use:

Standard Contractual Clauses (SCCs): For transfers to countries not deemed to have adequate data protection

Privacy Shield or Adequacy Decisions: Where applicable and recognized

Hotel Consent: When required by applicable law

12.3 GDPR Compliance

Data transfers to countries outside the EU/EEA comply with GDPR Chapter V requirements. We execute Standard Contractual Clauses with service providers and sub-processors to ensure adequate safeguards.

13. Third-Party Links and Services

Our Platform may contain links to third-party websites, applications, and services that are not operated by us. We are not responsible for the privacy practices of third-party services. When using third-party integrations or visiting external sites, please review their privacy policies independently.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

Posting the updated Policy on our website with the "Last Updated" date

Sending you a notification email if the change significantly affects how we handle your data

Requiring your explicit consent if required by law

Your continued use of the Platform following posted updates constitutes your acceptance of the revised Policy. For significant changes, we will provide you with a 30-day notice period.

15. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact:

Data Protection Officer / Privacy Team

Email: [email protected] Phone: (520) 815-7571 Mailing Address: InnSyst (Presidium Services LLC) 8996 Little Bluestem Dr Land O Lakes, FL 34637 United States

EU Data Protection Authority (for GDPR complaints): Contact your local Data Protection Authority

California Attorney General (for CCPA complaints): California Attorney General 300 South Spring Street Los Angeles, CA 90013 Website: oag.ca.gov

16. Additional Information

16.1 Data Retention Schedule

16.2 Legal Basis Reference (GDPR Article 6)

Our processing is justified under:

Article 6(1)(a): Consent (marketing communications, non-essential cookies)

Article 6(1)(b): Contract performance (providing Platform services)

Article 6(1)(c): Legal obligation (tax records, payment processing compliance)

Article 6(1)(f): Legitimate interests (security, fraud prevention, service improvement)

16.3 Acknowledgments

This Privacy Policy complies with GDPR, CCPA/CPRA, and applicable state privacy laws as of April 2026

Policies and practices are reviewed annually and updated to reflect regulatory changes

Professional legal review is recommended before implementing this policy in your jurisdiction

Document prepared: March 2026 Effective Date: March 2026 Last Updated: April 2026 Next Review Date: March 2027

This Privacy Policy is provided for informational purposes and should be reviewed by legal counsel before implementation to ensure compliance with applicable laws in your specific jurisdiction.