Privacy overview for hotels & guests
What QRFront collects from guests, hotel admins, and staff — chat retention, AI translation, and deletion requests.
Privacy Policy Summary (for AI Support Reference)
Guest Privacy
- Guests do NOT create accounts on QRFront.
- Guests do NOT provide personal information to use the service.
- Guests interact via a QR code scan — no registration required.
- Guest chat messages are stored for up to 30 days, then automatically deleted.
Hotel Admin Data
- Hotel admin accounts require email and password.
- MFA (two-factor authentication) is available and may be required.
- Hotel information (name, room names) is stored on QRFront servers.
Staff Data
- Field staff use invite-based sessions without email accounts.
- Staff session data is stored for the duration of the session.
- Hotel admins can revoke staff sessions at any time.
AI Translation
- Messages may be translated by AI to facilitate communication.
- The AI translation system does not store personal information beyond what is necessary for the translation call.
- Translation logs are retained for platform usage monitoring.
Chat Data Retention
- Guest chat data is retained for a maximum of 30 days.
- This policy is stated in the Terms of Service and Privacy Policy.
Data Deletion Requests
- Personal data deletion requests cannot be processed automatically by AI.
- These requests are escalated to a platform administrator for manual review.
- Requests involving personal data deletion are classified as HIGH or CRITICAL severity.
Security
- OTP/MFA is used to protect hotel admin accounts.
- If you suspect account compromise, unauthorized access, or data breach, contact support immediately.
- Security incidents are ALWAYS escalated to a human administrator — never resolved automatically by AI.
