Privacy Policy
How ResortConcierge AI collects, uses, shares, and protects personal data for hotels, resorts, their staff, and their guests.
This Privacy Policy (the "Policy") explains how Anchor Point Agency, LLC, a limited liability company organized under the laws of the State of South Carolina, United States, doing business as ResortConcierge AI ("ResortConcierge," "we," "us," or "our"), collects, uses, discloses, retains, and protects personal data in connection with the ResortConcierge AI websites, web and mobile applications, dashboards, APIs, integrations, documentation, and related services (collectively, the "Service"). It applies to personal data we handle as a controller — primarily about hotel and resort staff who administer the Service, prospects, and website visitors — and explains our role as a processor for the guest personal data our customers entrust to us. This Policy should be read together with our Terms of Service, Cookie Policy, Acceptable Use Policy, and, where applicable, our Data Processing Agreement (DPA). Where you and ResortConcierge have entered into a signed agreement that addresses privacy or data protection, that agreement controls to the extent it conflicts with this Policy for the subject it covers.
1. Scope & our role (controller vs. processor)
This Policy covers personal data processed through the Service. Our role depends on the data in question, and that role determines who is responsible for responding to individuals' requests.
- Controller — for account, billing, support, marketing, and website data about our customers' staff, prospects, and visitors, we determine the purposes and means of processing and act as the controller.
- Processor — for guest personal data that a hotel or resort loads into or generates through the Service, the customer is the controller and we act as a processor, handling that data on the customer's documented instructions.
- Where we act as a processor, the customer's own privacy notice governs how guest data is collected and used, and guests should direct their requests to that customer; we assist our customers in responding as described in our DPA.
- This Policy does not apply to third-party websites, products, or services that we do not control, even where they link to or integrate with the Service.
2. Personal data we collect
We collect personal data that you provide to us, that is generated as you use the Service, and that we receive from third parties. The categories below describe what we typically process.
- Account & profile data — names, business email addresses, phone numbers, job titles, roles and permissions, and property associations for the staff who administer or use the Service.
- Authentication & security data — credentials, multi-factor authentication details, session and login records, and security event logs.
- Billing & transaction data — billing contacts, plan and subscription details, Credit usage, and payment-method information processed by our payment processors (we do not store full card numbers).
- Customer & guest data (as processor) — guest profiles, messages and conversation history, service requests, preferences, and other content that customers choose to load into or generate through the Service.
- Usage, device & log data — IP address, device and browser type, pages and features used, timestamps, referring URLs, diagnostic data, and similar technical information collected automatically.
- Cookies & similar technologies — identifiers and preferences collected through cookies and comparable technologies, as described in our Cookie Policy.
- Communications & support data — the content of messages, support tickets, survey responses, and feedback you send us.
- Marketing data — contact details, interactions with our emails and campaigns, and preferences, where you engage with our marketing.
3. How we collect personal data
- Directly from you — when you create or configure an account, contact us, request a demo, subscribe, or otherwise communicate with us.
- Automatically — through cookies, server logs, and similar technologies as you interact with the Service and our website.
- From our customers — when a hotel or resort provisions Authorized Users or loads guest and property data into the Service.
- From third parties & integrations — such as identity providers, property management systems (PMS), payment processors, analytics providers, and AI model providers, where you connect them or where they lawfully share data with us.
4. How we use personal data
We use personal data to operate and improve the Service, support our customers, secure the platform, and meet our legal and contractual obligations. For guest data we hold as a processor, we use it only to provide the Service and on the customer's documented instructions.
- Provide, maintain, configure, and deliver the Service and its features.
- Authenticate users, manage accounts, and administer roles and permissions.
- Process subscriptions, Credits, billing, and payments, and prevent and detect fraud.
- Provide customer support and respond to requests, questions, and feedback.
- Monitor, secure, troubleshoot, and improve the performance and reliability of the Service.
- Generate aggregated and de-identified analytics that do not identify any individual.
- Send service, administrative, and security communications, and — where permitted — relevant marketing you can opt out of.
- Comply with applicable law, enforce our agreements, and establish, exercise, or defend legal claims.
5. Legal bases for processing (GDPR/UK GDPR)
Where the GDPR or UK GDPR applies and we act as a controller, we rely on one or more of the following legal bases for each processing activity.
- Performance of a contract — to provide the Service to you and administer your account, subscription, and billing.
- Legitimate interests — to secure, operate, and improve the Service, prevent fraud and abuse, and conduct measured marketing, balanced against your rights and interests.
- Consent — where required, for example for certain cookies and electronic marketing; you may withdraw consent at any time without affecting prior processing.
- Legal obligation — to comply with applicable laws, tax and accounting requirements, and lawful requests from authorities.
- Where we act as a processor for guest data, the customer (controller) is responsible for establishing the legal basis for that processing.
6. AI features & personal data
The Service uses artificial intelligence to generate AI Output such as concierge responses, summaries, and translations. Personal data may be processed by the AI features and by our AI model providers solely to provide the Service.
- We do not sell personal data, and we do not use guest personal data to train general-purpose foundation models for our own unrelated purposes.
- AI model providers act as our subprocessors and are contractually restricted in how they may use the data we send them.
- Customers are responsible for the knowledge-base content and configurations they provide and for maintaining appropriate human oversight of AI Output before it is relied on or sent to guests.
- We do not use the Service to make decisions that produce legal or similarly significant effects about individuals without human involvement; see Section 13.
7. How we share & disclose personal data
We share personal data only as described in this Policy. We do not sell personal data, and we do not share it for cross-context behavioral advertising as those terms are defined under applicable U.S. state privacy laws.
- Service providers & subprocessors — vetted vendors (such as hosting, infrastructure, analytics, communications, payment, and AI providers) who process data on our behalf under contractual safeguards.
- Our customers — where we act as a processor, we make guest data available to the customer that controls it and acts on their instructions.
- Integrations you enable — when you connect a PMS, messaging channel, payment processor, or other third-party service, we exchange data with it as needed to provide the integration.
- Legal & safety — where required by law, legal process, or to protect the rights, property, or safety of ResortConcierge, our users, or the public.
- Business transfers — in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate confidentiality protections.
- With your direction or consent — where you ask us to share data or otherwise consent to its disclosure.
8. Subprocessors & service providers
We use third-party subprocessors to help deliver the Service, including cloud infrastructure, hosting, communications, analytics, payment, and AI model providers. We require each subprocessor to commit to data protection obligations no less protective than those in our agreements and applicable law, and we remain responsible for their performance of the obligations they undertake on our behalf. A current list of subprocessors, and a mechanism for notice of changes, is available to customers under the DPA on request.
9. International data transfers
We are based in the United States and may process and store personal data in the United States and other countries where we or our subprocessors operate. Where we transfer personal data from the European Economic Area, the United Kingdom, Switzerland, or other regions with cross-border transfer restrictions, we put in place recognized transfer mechanisms — such as the European Commission's Standard Contractual Clauses and the UK Addendum — together with supplementary measures where appropriate. You may contact us through our contact page to request more information about the safeguards we use.
10. Data retention
We retain personal data only for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law.
- Account, billing, and transaction records are retained for the duration of the relationship and for the periods required by tax, accounting, and other legal obligations.
- Guest data we process as a processor is retained according to the customer's instructions and the configuration and retention controls the Service makes available, and is deleted or returned at the end of the engagement as set out in the DPA.
- Logs, security records, and backups are retained for limited periods consistent with security and operational needs.
- When personal data is no longer needed, we delete, anonymize, or securely isolate it from further processing.
11. How we protect personal data
We maintain administrative, technical, and physical safeguards designed to protect personal data appropriate to its nature and the risks involved, including encryption in transit and at rest where appropriate, role-based access controls, approval workflows for sensitive actions, IP masking, network protections, monitoring, and audit logging. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; you are responsible for safeguarding your credentials and for the security configuration choices available to you in the Service.
12. Your privacy rights (GDPR/UK GDPR & global)
Depending on where you are located and our role, you may have the following rights regarding your personal data. To exercise a right where we are the controller, contact us through our contact page; where we are a processor, please contact the hotel or resort that controls the data.
- Access — obtain confirmation of whether we process your personal data and a copy of it.
- Rectification — have inaccurate or incomplete personal data corrected.
- Erasure — request deletion of personal data in certain circumstances.
- Restriction & objection — restrict or object to certain processing, including processing based on legitimate interests and direct marketing.
- Portability — receive certain personal data in a structured, commonly used, machine-readable format.
- Withdraw consent — withdraw consent at any time where processing is based on consent.
- Complaint — lodge a complaint with your local supervisory or data protection authority.
- We will respond within the timeframes required by applicable law and may need to verify your identity before acting on a request.
13. U.S. state privacy rights (CCPA/CPRA & similar)
If you are a resident of California or another U.S. state with a comprehensive privacy law, you may have additional rights, subject to applicable exceptions. We do not sell personal information or share it for cross-context behavioral advertising.
- Right to know — the categories and specific pieces of personal information we collect, use, and disclose, and the purposes for doing so.
- Right to delete — request deletion of personal information we collected from you.
- Right to correct — request correction of inaccurate personal information.
- Right to opt out — of any sale or sharing of personal information (we do not engage in these) and of certain targeted advertising or profiling.
- Right to limit — the use of sensitive personal information to what is necessary to provide the Service.
- Right to non-discrimination — you will not receive discriminatory treatment for exercising your rights.
- Authorized agents may submit requests on your behalf with proper authorization, and we will verify requests as permitted by law.
14. Cookies & similar technologies
We and our service providers use cookies and similar technologies to operate the Service, remember preferences, secure access, and understand usage. You can manage non-essential cookies where a consent mechanism is shown and through your browser settings. Our Cookie Policy explains the categories of cookies we use, the purposes, and how to control them in detail.
15. Children's privacy
The Service is intended for business use by hospitality operators and their authorized staff and is not directed to children. We do not knowingly collect personal data directly from children under the age required by applicable law. Where guests' data is processed through the Service, our customers are responsible for ensuring an appropriate legal basis and any required parental consent. If you believe a child has provided personal data to us as a controller, contact us through our contact page and we will take appropriate steps to delete it.
16. Guest data & the customer relationship
For personal data about hotel and resort guests, the customer is the controller and we are the processor. The customer decides what guest data to collect and load into the Service, the purposes for which it is used, and the privacy notices and consents provided to guests. We process guest data only to provide the Service and on the customer's documented instructions, as further described in our DPA. Guests who wish to exercise privacy rights, or who have questions about how their data is used, should contact the hotel or resort that serves them; we will support our customers in responding to those requests.
17. Automated decision-making
The Service uses AI to generate suggestions, summaries, classifications, and responses to assist hotel staff and guests. These features are designed to support human decision-making, not to replace it. We do not use the Service to make decisions producing legal or similarly significant effects about individuals based solely on automated processing without meaningful human involvement, and we require our customers to maintain appropriate human oversight of guest-facing AI Output.
18. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last updated" date below and, where required by law, provide additional notice through the Service, by email, or in your account. Changes take effect when posted unless stated otherwise, and your continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.
19. Contact & effective date
This Policy is provided by Anchor Point Agency, LLC, a South Carolina limited liability company doing business as ResortConcierge AI, which is responsible for personal data processed as a controller as described above. Questions about this Policy, requests to exercise your rights, or other privacy inquiries can be sent to Anchor Point Agency, LLC through our contact page. Last updated: June 14, 2026.
Frequently Asked Questions
Questions about privacy?
Contact our team and we'll point you to the right resources or help you exercise your rights.