Privacy Policy
Last updated: 2026-10-10
1. Who we are
Inn-ovative is a management system for hotel apartments, run by [registered business name], commercial registration [CR number], [address]. For privacy matters, contact [email address].
This policy covers the hotel system (inn-ovative.com) and the guest app (guest.inn-ovative.com). It is written for Saudi Arabia's Personal Data Protection Law (PDPL).
2. Our role
- We are responsible for the data in hotel owner and staff accounts, and in guest app accounts.
- For guest records that a hotel enters (stays, payments, bookings), the hotel is responsible. We process that data on the hotel's behalf and only as it instructs.
3. What we collect
- Owner and staff accounts: name, email, mobile number, role, preferred language. Passwords are stored in a scrambled form that cannot be read back.
- Guest records entered by a hotel: name, email, mobile number, nationality, stay dates, rent, payments and deposits, service requests.
- Guest app accounts: name, email, mobile number, nationality, preferred language, and when the terms were accepted.
- Technical data: system logs (record numbers, page addresses, results and times), and the IP address of failed sign-ins, for security and support.
- Uploads by a hotel: property and room photos, and expense invoices.
We do not collect national ID or Iqama numbers, or copies of identity documents.
4. Why we use it
- To provide the service: rooms, stays, bookings, payments and guest requests.
- To keep accounts and the system secure and prevent misuse.
- To meet legal obligations, such as tax invoices.
- To send messages the service needs, such as password resets and email confirmation.
We do not sell personal data, and we do not use it for advertising or tracking.
5. Who sees it
- Each hotel sees only its own guests and staff.
- Service providers we need to run the system: hosting (DigitalOcean), and an email-sending provider once enabled. They process data only on our behalf.
- Authorities, when the law requires us to share.
6. Where it is stored
Our servers are currently in the Netherlands (European Union). Data goes there under the PDPL and its rules on transfers outside the Kingdom. We are working on moving hosting into Saudi Arabia.
7. How long we keep it
- Accounts: while the account exists.
- Hotel records: while the hotel's account exists, or as long as the law requires (for example, tax records).
- Backups: 14 days, then deleted.
- System logs: overwritten within weeks.
8. How we protect it
Every page is encrypted (HTTPS). Passwords are scrambled, access depends on each person's role, and the server sits behind a firewall. Sign-in attempts are limited, and backups run daily. System logs never contain guests' names or phone numbers.
If a data breach happens, we notify the competent authority and the people affected, as the law requires.
9. Your rights
Under the PDPL you have the right to:
- be told how your data is processed;
- see your data and get a copy of it;
- have it corrected or deleted;
- withdraw your consent.
Write to [email address]. If a hotel holds your record, we may pass your request to that hotel. You can also complain to the Saudi Data & AI Authority (SDAIA).
10. Cookies
We use only the cookies the site needs to work, which don't require separate consent:
- the sign-in session, which ends after 8 hours;
- a security token for forms;
- the language you chose.
The browser also keeps small preferences, such as whether the notification sound is on. We use no advertising, analytics or third-party tracking, and fonts are served from our own servers.
11. Children
The service is not meant for anyone under 18, and guest app accounts are for people aged 18 and over.
12. Changes
We may update this policy; the date at the top shows the latest version. We announce significant changes in the system.