Privacy overview for hotels & guests

What QRFront collects from guests, hotel admins, and staff — chat retention, AI translation, and deletion requests.

Privacy Policy Summary (for AI Support Reference)

Guest Privacy

  • Guests do NOT create accounts on QRFront.
  • Guests do NOT provide personal information to use the service.
  • Guests interact via a QR code scan — no registration required.
  • Guest chat messages are stored for up to 30 days, then automatically deleted.

Hotel Admin Data

  • Hotel admin accounts require email and password.
  • MFA (two-factor authentication) is available and may be required.
  • Hotel information (name, room names) is stored on QRFront servers.

Staff Data

  • Field staff use invite-based sessions without email accounts.
  • Staff session data is stored for the duration of the session.
  • Hotel admins can revoke staff sessions at any time.

AI Translation

  • Messages may be translated by AI to facilitate communication.
  • The AI translation system does not store personal information beyond what is necessary for the translation call.
  • Translation logs are retained for platform usage monitoring.

Chat Data Retention

  • Guest chat data is retained for a maximum of 30 days.
  • This policy is stated in the Terms of Service and Privacy Policy.

Data Deletion Requests

  • Personal data deletion requests cannot be processed automatically by AI.
  • These requests are escalated to a platform administrator for manual review.
  • Requests involving personal data deletion are classified as HIGH or CRITICAL severity.

Security

  • OTP/MFA is used to protect hotel admin accounts.
  • If you suspect account compromise, unauthorized access, or data breach, contact support immediately.
  • Security incidents are ALWAYS escalated to a human administrator — never resolved automatically by AI.