Privacy Policy
Xentry — Contactless Check-in & Check-out Platform
Effective Date: August 20, 2026 | Website: xentryapp.com
This Privacy Policy explains how Xentry ("Xentry", "we", "us", or "our") collects, uses, discloses, and protects personal data through the website xentryapp.com and the Xentry platform (the "Service"). It applies both to our business customers (accommodation providers, "Customers") and to the guests of those Customers who complete a check-in or check-out through the Service ("Guests").
Where a Customer uses Xentry to collect Guest data as part of their own check-in process, Xentry generally acts as a data processor / service provider on the Customer's behalf, and the Customer acts as the data controller responsible for that Guest data. This Policy describes our practices in that role as well as our practices as a data controller for account and website data of our Customers.
1. Information We Collect
1.1 Account & Customer Data
- Business contact details: name, email, phone number, job title, property/company name and address.
- Billing details processed via our payment providers.
- Login credentials and account activity logs.
1.2 Guest Data (collected on behalf of Customers)
- Identity details: full name, date of birth, nationality, and government-issued ID or passport information, where required for legal guest-registration purposes.
- Contact details: email address, phone number, and postal address.
- Stay details: arrival/departure dates, reservation reference, room type, and special requests.
- Uploaded documents and, where enabled by the Customer, identity-verification images used to match a Guest's face to their ID document.
- Digital signatures collected for check-in forms, waivers, or rental agreements.
- Payment information for check-in-related charges, processed by our third-party payment processors; Xentry does not store full card numbers.
1.3 Automatically Collected Data
- Device and log data: IP address, browser type, operating system, and access timestamps.
- Usage data: pages visited, features used, and interaction patterns within the Service.
- Cookies and similar technologies, as described in Section 7 below.
2. How We Use Information
- To provide, operate, and maintain the Service, including facilitating digital check-in/check-out on behalf of Customers.
- To verify Guest identity where the Customer has enabled identity-verification features.
- To generate guest-registration reports Customers may be legally required to submit to local authorities.
- To process payments related to bookings, upsells, or tourist taxes where enabled.
- To communicate with Customers about their account, billing, and Service updates.
- To send Guests check-in instructions, digital keys, and stay-related communications on behalf of the Customer.
- To monitor, secure, and improve the Service, including diagnosing technical issues and preventing fraud or abuse.
- To comply with legal obligations and enforce our Terms & Conditions.
3. Legal Bases for Processing
Where applicable data protection law (such as the GDPR) requires a legal basis, Xentry and/or the relevant Customer relies on one or more of the following: performance of a contract (facilitating a Guest's stay), compliance with a legal obligation (statutory guest registration or tax reporting), legitimate interests (Service security and improvement), and consent (for optional features such as biometric identity verification or marketing communications), which can be withdrawn at any time.
4. Sharing of Information
We do not sell personal data. We may share information with:
- The Customer (accommodation provider) for whom the Guest is completing check-in, since collecting and delivering that data to the Customer is the core purpose of the Service.
- Sub-processors and service providers who support the Service, such as cloud hosting, identity-verification, payment processing, and communications providers, bound by confidentiality and data-protection obligations.
- Local authorities, where a Customer is legally required to submit guest-registration data and uses the Service to do so.
- Professional advisors, or successors in a merger, acquisition, or asset sale, subject to appropriate safeguards.
- Law enforcement or regulators where required by applicable law or a valid legal process.
5. International Data Transfers
Personal data may be processed in countries other than the one in which it was collected, including India and other jurisdictions where our hosting and sub-processors operate. Where required, we rely on appropriate safeguards such as standard contractual clauses to protect data transferred internationally.
6. Data Retention
We retain Guest data for as long as required to fulfil the check-in purpose and any statutory guest-registration or record-keeping obligations applicable to the Customer's jurisdiction, after which it is deleted or anonymised, unless a longer retention period is required by law or agreed with the Customer. Account and billing data for Customers is retained for the duration of the subscription and for a reasonable period afterward to meet accounting and legal requirements.
7. Cookies & Tracking Technologies
Our website and Service use cookies and similar technologies to keep you signed in, remember preferences, and understand usage patterns. You can control cookies through your browser settings and, where offered, our cookie-consent banner. Disabling certain cookies may affect the functionality of the Service.
8. Data Security
We use administrative, technical, and physical safeguards designed to protect personal data, including encryption in transit, access controls, and regular security reviews. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. Guests should generally direct such requests to the Customer (accommodation provider) they stayed or are staying with, as the data controller; Xentry will assist Customers in responding to such requests where we act as processor. Customers and website visitors can contact us directly using the details in Section 12.
10. Children's Privacy
The Service is not directed to children, and we do not knowingly collect personal data from children without appropriate parental or guardian involvement as required for a Guest's stay (for example, minors listed on a booking by an adult Guest).
11. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be notified via the Service or by email at least 15 days before taking effect. The "Effective Date" at the top of this Policy reflects the latest revision.
12. Contact Us
Email: privacy@xentryapp.com
Website: https://www.xentryapp.com
[Company registered name and registered address to be inserted here.]