Your privacy matters
How we collect, use, and protect your data — with full transparency.
Last updated: February 20261. Introduction
TIOO ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at tioo.com and associated services.
TIOO operates as a data processor on behalf of our customers (property managers, hosts, and hotel operators) who are the data controllers for their guest data. Our Data Processing Agreement (DPA) governs this relationship and is incorporated into the Terms of Service. A countersigned PDF copy is available on request from [email protected].
This policy should be read alongside our Terms of Service and Cookie Policy.
2. Information We Collect
2.1 Account Information
When you create an account, we collect your name, email address, phone number, and business details including property name, country, and timezone.
2.2 Guest Data (Processed on Behalf of Our Customers)
When guests use the check-in system, property managers may collect guest names, email addresses, phone numbers, ID documents, car registration details, and arrival times. This data is controlled by the property manager and processed by TIOO as a data processor.
ID Documents: Where a property manager has enabled ID verification, guest identity documents are stored securely in encrypted object storage. ID documents are subject to automatic retention limits (see Section 7) and are accessible only to authorised property staff.
2.3 Usage and Security Data
We automatically collect information about how you use our platform, including pages visited, features used, and device information. For security purposes, we also log IP addresses and browser information when users perform significant account actions such as logging in, changing settings, or accessing sensitive data.
2.4 Payment Information
Payment processing is handled by Stripe. We do not store full credit card numbers on our servers. We retain only the information necessary to manage your subscription.
2.5 Communications
When property managers communicate with guests through the platform (via email, SMS, or messaging services), message content, sender details, and delivery status are stored to provide a communication history and ensure message delivery.
3. How We Use Your Information
- To provide and maintain the TIOO platform
- To process subscriptions and payments
- To send transactional communications (booking confirmations, check-in instructions) via email, SMS, or messaging services
- To manage property access on behalf of property managers (e.g. generating temporary access codes)
- To verify guest identity when ID verification is enabled by the property manager
- To provide customer support
- To detect and prevent fraud, abuse, and security incidents
- To improve our platform and develop new features
- To comply with legal obligations
4. Legal Basis for Processing (GDPR)
We process personal data under the following legal bases:
- Contract performance: Processing necessary to provide the service you signed up for (account management, subscriptions, platform features)
- Legitimate interests: Security logging, fraud prevention, platform improvement, and customer support
- Legal obligation: Where we are required to retain data by law (e.g. financial records, tax obligations)
- Consent: Marketing communications (you may withdraw consent at any time)
5. Automated Processing
When enabled by the property manager, our platform may use automated processes to assist with ID document verification. These automated checks produce a confidence score to help the property manager verify guest identity. No decisions are made solely on the basis of automated processing — a property manager can always review and override the result manually.
6. Data Sharing and Sub-Processors
We do not sell your personal data. We share data with the following categories of service providers (sub-processors) as necessary to operate the platform. The full authoritative list, including data location and international-transfer mechanism per sub-processor, is set out in the Data Processing Agreement Section 7.1:
- Cloud hosting: DigitalOcean (compute + managed PostgreSQL, LON1 UK region)
- Object storage: DigitalOcean Spaces (guest ID documents, invoices, gallery images, message attachments — LON1 UK region, private bucket with signed URLs)
- Edge network and bot protection: Cloudflare (CDN, DDoS protection, Turnstile bot verification, custom-domain hostname API)
- Payment processing: Stripe (subscription billing + Stripe Connect for tenant payment collection); PayPal and Paystack (alternative gateways where enabled by the property manager, with Paystack serving African markets)
- Email delivery: Mailgun (transactional and tenant email delivery + inbound email webhooks)
- SMS delivery: Twilio (SMS messaging, phone-number verification)
- Messaging: Meta / WhatsApp Business API (guest messaging where enabled by the property manager)
- Automated ID verification: AWS Rekognition (Ireland region; face-match confidence scoring for ID documents — only when the property manager enables ID verification)
- Smart lock providers: TTLock / Sciener (guest name and PIN provisioning where the property manager enables smart-lock integration — data transferred to China; see DPA Section 10)
- Error monitoring: Sentry (application error tracking, request metadata; personal-data scrubbing enabled at the SDK layer)
- Event data: Ticketmaster Discovery API, TheSportsDB, AIMS marathon feed, Wikidata (Smart Pricing feature — publicly available event data only, no personal or guest data)
- Geocoding: Nominatim / OpenStreetMap Foundation (address lookup for property addresses and Smart Pricing venue coordinates — only address strings)
- Google Places API: Google Reviews sync for the website builder (public review data only, where the property manager enables this integration)
- Stock photography: Unsplash and Pexels (search queries only — no personal or guest data)
- Legal requirements: When required by law or to protect our rights
The authoritative sub-processor list is maintained in the DPA. We notify customers at least 30 days in advance of any material change to the list, giving them the opportunity to object.
7. Data Retention
- Active accounts: Data retained while the account is active
- Deleted accounts: Data deleted within 30 days of account deletion request. A data export is available during this period
- Guest ID documents: Retained for a period configured by the property manager, within the legal bounds for their country. Default and minimum are set per jurisdiction to match local hospitality regulations (for example, the UK Immigration (Hotel Records) Order 1972 requires a minimum of 12 months for premises operating in the United Kingdom). The maximum permitted by TIOO is 7 years. The exact retention period applied to a guest's ID is shown to the guest at the moment of upload as part of the consent flow. On expiry, both the database record and the stored file are deleted
- ID disclosure audit log: When a property manager downloads a guest's ID for disclosure (e.g. to police, courts, or insurers), the disclosure event is recorded with full context (recipient, reason, lawful basis, downloaded-by, audit reference). These audit entries are retained for 6 years to align with the UK Limitation Act 1980 civil-claims window
- Security logs: Retained for 12 months, then automatically purged
- Communication records: Retained while the account is active and deleted with the account
- Financial and billing records: Retained for 7 years after the end of the relevant financial period, as required by UK tax law (HMRC)
- Inactive free accounts: Free plan accounts inactive for 12 months may be automatically deleted after a 30-day notice period. The free plan is available indefinitely, but we reserve the right to modify its terms (see our Terms of Service, Section 4.1)
8. Your Rights
Your rights depend on where you live. TIOO honours all applicable data protection rights and applies the strictest applicable standard where the rules overlap. To exercise any right below, contact us at [email protected]. We respond within the timeframe required by your local law (typically 30 days).
For guests: If you are a guest whose data has been processed through a property manager's account, please contact the property manager directly in the first instance — they are the data controller. You may also contact TIOO and we will assist where possible.
8.1 United Kingdom and European Economic Area (UK GDPR / EU GDPR)
- Access your personal data
- Rectify inaccurate data
- Request deletion ("right to be forgotten")
- Export your data in a portable format
- Restrict or object to processing
- Withdraw consent at any time
- Not be subject to decisions based solely on automated processing
- Lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office at ico.org.uk; in EU member states, your national data protection authority — the full list is at edpb.europa.eu)
8.2 California, United States (CCPA / CPRA)
- Right to Know what personal information we collect, use, disclose, and (if applicable) sell or share
- Right to Delete personal information we hold about you, subject to statutory exceptions
- Right to Correct inaccurate personal information
- Right to Opt-Out of Sale or Sharing — we do not sell or share personal information as those terms are defined under CCPA/CPRA §1798.140, so there is nothing to opt out of, but you may still submit a request and we will confirm this in writing
- Right to Limit Use of Sensitive Personal Information — TIOO uses sensitive PI (e.g. guest ID documents) only for the purposes for which the property manager collected it, in line with CCPA/CPRA §1798.121
- Right to Non-Discrimination for exercising any of the above rights
- Right to Portability — receive your data in a portable, machine-readable format
- You may also file a complaint with the California Privacy Protection Agency at cppa.ca.gov
8.3 Brazil (LGPD)
- Confirmation of the existence of processing
- Access to your data
- Correction of incomplete, inaccurate, or out-of-date data
- Anonymisation, blocking, or deletion of unnecessary or excessive data or data processed in non-compliance with LGPD
- Portability to another service or product provider
- Deletion of personal data processed with your consent
- Information about public and private entities with which we shared your data
- Revocation of consent
- File a complaint with the Autoridade Nacional de Proteção de Dados ("ANPD") at gov.br/anpd
8.4 Canada (PIPEDA / Quebec Law 25)
- Access to your personal information
- Correction of inaccurate personal information
- Withdrawal of consent
- Right to know how your information is being used and disclosed
- Right to portability and deletion under Quebec Law 25 (for residents of Quebec)
- File a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca (or the Commission d'accès à l'information du Québec for Quebec residents)
8.5 Australia and New Zealand (APA / Privacy Act 2020)
- Access your personal information
- Correct inaccurate personal information
- Request deletion where legally required
- Be notified of eligible data breaches affecting you
- File a complaint with the Office of the Australian Information Commissioner at oaic.gov.au or the Office of the Privacy Commissioner (NZ) at privacy.org.nz
8.6 Other Jurisdictions
If you reside outside the regions listed above, you may have rights under your local data protection law (e.g. POPIA in South Africa, PDPA in Singapore, the Nigerian Data Protection Act 2023, the UAE PDPL, India's Digital Personal Data Protection Act 2023, and others). Contact [email protected] — we comply with all applicable local law and will respond in accordance with your jurisdiction's requirements. You may also complain to your local data protection authority.
9. Data Security
Our technical and organisational measures, aligned with UK GDPR / EU GDPR Article 32 and equivalent security requirements under CCPA/CPRA, LGPD, PIPEDA, and other applicable data protection laws, include:
- Encryption in transit: TLS 1.2+ enforced across all HTTP endpoints, SMTP submission, database connections, and object storage.
- Encryption at rest: sensitive fields (integration credentials, TOTP secrets, payment gateway keys) encrypted at the application layer using Fernet (AES-128-CBC + HMAC-SHA256). Database and object-storage volumes encrypted at rest by our infrastructure provider.
- Private object storage: guest ID documents and invoices held in a private cloud bucket with time-limited signed URLs (1-hour TTL).
- Access controls: role-based permissions with per-property scoping. Two-factor authentication (TOTP) available to all users on all plans. Sudo-mode re-authentication required for high-privilege actions (ID document disclosure, account deletion).
- Multi-tenant isolation: tenant data strictly scoped by organisation; sweep tests prevent cross-tenant leakage. Staff investigative access writes to a separate internal audit log that is walled off from tenant-facing surfaces.
- Rate limiting: applied to login, signup, password reset, ID download, and all authentication and enumeration-prone endpoints. Client IP normalised through Cloudflare's verified visitor IP header to prevent spoofing bypass.
- Automated account protection: five failed login attempts in five minutes triggers a fifteen-minute lockout; subdomain-probe auto-blocking after twenty unknown-subdomain hits in five minutes.
- Audit logging: every mutating action recorded with actor, timestamp, IP, and structured details. Sensitive disclosures (ID document downloads) retained for six years to align with statutory civil-claims limitation periods in most common-law jurisdictions (e.g. the UK Limitation Act 1980); other entries retained for twelve months.
- Dependency management: automated vulnerability scanning (Dependabot) and security advisories from the django-security mailing list.
- Backups: PostgreSQL point-in-time recovery via managed database provider. Object storage backed up daily. Backups encrypted at rest.
- Written incident response plan: personal data breaches notified to affected customers within 72 hours of the Processor becoming aware, in line with UK GDPR / EU GDPR Article 33, LGPD Article 48, and equivalent breach-notification duties in other jurisdictions we serve.
Our external audit programme, including planned penetration testing and — where triggered by a customer requirement — SOC 2 Type I preparation, is documented internally and available on request to enterprise prospects under NDA.
10. International Transfers
Personal data is primarily processed in the United Kingdom (DigitalOcean LON1 region for compute, database, and object storage). TIOO serves customers worldwide; where a sub-processor operates outside the customer's home jurisdiction, we rely on the strictest applicable mechanism, chosen from:
- Adequacy decisions issued by the UK Secretary of State, the European Commission, or the equivalent authority in the customer's jurisdiction (e.g. transfers within the EEA, to Switzerland, Canada for commercial organisations, Japan, South Korea);
- the UK International Data Transfer Addendum to the EU SCCs ("UK IDTA"), the EU Standard Contractual Clauses ("EU SCCs"), the Swiss revised SCCs, or equivalent standard contract mechanisms recognised under other applicable laws — each accompanied by a transfer-impact assessment where required;
- the EU-US Data Privacy Framework, the UK Extension to the EU-US DPF, and the Swiss-US DPF where the receiving sub-processor is DPF-certified;
- derogations for specific situations under UK GDPR / EU GDPR Article 49 (or equivalent under other laws). The primary case is the TTLock smart-lock integration (China): the transfer is authorised by the property manager when they enable the integration and is necessary for the performance of their contract with the guest.
For customers subject to CCPA/CPRA, LGPD, PIPEDA, APA, POPIA, PDPA, and other data protection laws, TIOO applies the strictest of the safeguards required by any applicable law. The per-sub-processor transfer mechanism is set out in the DPA Section 7.1.
11. Children's Privacy
TIOO is not intended for use by children under 16. We do not knowingly collect data from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through the platform at least 30 days before the changes take effect.
13. Contact Us
For privacy-related enquiries:
- Email: [email protected]
- General: [email protected]
Questions?
If you have any questions about your privacy or data, we're here to help.
[email protected]