Back to FrontDeskIQ
Designed with GDPR & CCPA Principles
Enterprise Data Privacy Standard

Privacy Policy & Data Protection

Effective Date: August 23, 2026 | Version 2.4 (Enterprise Multi-Tenant Standard)

Zero Guest PII

FrontDeskIQ never stores guest credit card numbers, CVVs, or passport data.

Voice AI Privacy

Microphone audio is processed transiently in memory. No biometric voiceprints are retained.

Row-Level Security

Multi-tenant PostgreSQL Row-Level Security data isolation per property and hotel organization.

1. Roles Under GDPR & CCPA (Data Processor vs. Controller)

FrontDeskIQ ("we", "our", "us") operates as a Data Processoron behalf of hotel property owners, management companies, and franchised properties ("Customer" or "Data Controller").

Hotel properties collect operational shift data and employee sales metrics. FrontDeskIQ processes this information solely to deliver revenue intelligence, gamified commission tracking, and AI-driven coaching simulation.

2. Categories of Information Processed

  • User Account Data: Name, work email address, hotel role (Agent, Property Manager, Super Admin), and encrypted authentication credentials.
  • Operational Shift & Upsell Metrics: Aggregated shift revenue, room upgrade counts, incentive commission totals, and date timestamps ingested via PMS CSV exports.
  • Training & Roleplay Simulation Transcripts: Text messages exchanged during AI roleplay simulator sessions and calculated 5-axis competency scores.
  • Technical Log Data: Anonymized telemetry, IP addresses for API rate-limiting, and error diagnostics.

3. PCI-DSS Principles & Guest Data Minimization

FrontDeskIQ is strictly engineered as a revenue intelligence and coaching platform. We do not process, store, or transmit Payment Card Industry (PCI) cardholder data.

When hotel properties upload PMS shift CSV files (from Opera, Cloudbeds, Mews, or custom PMS systems), our ingestion pipeline automatically strips unmapped columns and omits Primary Account Numbers (PAN), CVVs, passport numbers, and guest personal contact data.

4. Voice AI & Audio Stream Processing

When hotel staff practice with the AI Roleplay Simulator:

  • Microphone audio converted to text via browser Web Speech Recognition is executed locally on client hardware or transiently streamed for text transcription.
  • Synthesized guest speech audio (via ElevenLabs or local Web Speech API) is cached ephemerally in memory and never linked to personal biometric profiles.
  • Commercial API interactions with generative AI models operate on zero-retention enterprise terms and are not used to train public foundation models.

5. Enterprise Sub-Processors & Infrastructure

Sub-ProcessorPurposeData LocationProvider Security Certifications
Supabase Inc.Database, Row-Level Security, AuthUS / EUSOC 2 Type II, ISO 27001 (Provider Certified)
Google Cloud (Gemini)AI Roleplay & NLQ Coaching IntelligenceUS / GlobalSOC 2, ISO 27017/27018 (Provider Certified)
ElevenLabs Inc.Neural Voice SynthesisUS / EUSOC 2 (Provider Certified)
Vercel Inc.Application Hosting & Edge DeliveryGlobal EdgeSOC 2 Type II (Provider Certified)

6. Data Subject Rights & Management

Authorized hotel staff and enterprise customers have full data management capabilities:

Right of Access & ExportExport your shift logs, revenue metrics, and training mastery history in standard CSV/JSON formats.
Right to Erasure ("Be Forgotten")Request complete database deletion of user accounts and associated simulator transcripts.
Right to RectificationCorrect any inaccurate agent profiles, assigned properties, or shift records.
Right to Restrict ProcessingOpt out of non-essential AI coaching telemetry and cookie preferences at any time.

Contact Our Data Protection Team

For privacy inquiries, Data Processing Agreements (DPA), or data subject access requests (DSAR):

Email: privacy@frontdeskiq.ai

Security Inquiries: security@frontdeskiq.ai

Response Time SLA: Within 48 business hours

© 2026 FrontDeskIQ. All rights reserved.