Privacy Policy
Innhapp Platform · Version 1 · June 2026
1. Data Controller
The controller of the processing of personal data is:
Innviteme Solutions, SL, the company that operates the technological platform marketed under the Innhapp brand (hereinafter, interchangeably, the "Platform" or "Innhapp").
Tax ID (CIF): B22958961
Registered address: C/ Gregorio Benítez 10, 1C, Madrid (28043), Spain
Email address: hello@innhapp.com
Hereinafter, the "Controller".
2. Scope of Application
This Privacy Policy governs the processing of personal data of users (hereinafter, the "User") who register and use the Innhapp technological platform.
Use of Innhapp is voluntary and is exclusively limited to people staying at a hotel establishment that has joined the Platform (hereinafter, the "Hotel"). The service is initially provided in Spain, without prejudice to its possible future extension to other territories.
Innhapp offers two main features: (i) the ability for Users staying at the same Hotel to create profiles, connect with each other, and exchange messages during their stay; and (ii) the ability to create and join plans called "Happenings", as described in this Policy and in the Terms and Conditions of use.
3. Relationship with Hotels
3.1 General rule. Hotel staff expressly authorised to use the Innhapp management panel have access to the profiles of Users staying at their establishment and to the public content of Happenings published on the Platform (organiser, description, and participants), regardless of who created them.
The Hotel never has access to messages or private conversations between Users.
Beyond the above, the Hotel:
- is not responsible for the processing of data arising from the general technical operation of the Platform (infrastructure, storage, security);
- does not intervene in the management, moderation, or storage of such data.
For these purposes, the Hotel acts solely as a facilitator of access to the service.
3.2 Hotel commitments regarding the use of such access. In relation to the access described in section 3.1, the Hotel acts as an independent data controller, and contractually undertakes to the Controller to:
- limit such access to strictly necessary and duly authorised staff;
- use the information exclusively for guest service and supervision of the use of the service by Users staying at the Hotel, including, where applicable, the management of Happenings created by the Hotel itself;
- not use it for commercial, promotional, or any other purposes unrelated to such management;
- not transfer it to third parties; and
- apply appropriate confidentiality and security measures.
The Hotel shall be liable to Users and to the competent authorities for any use of such information contrary to the above.
4. Personal Data Collected
4.1 Data Provided by the User
- Profile information (language, interests, place of origin, or other voluntary information).
- Profile photographs voluntarily provided by the User.
- Check-out date.
- Profile content and exchanged messages.
- Happenings created by the User (title, description, date, time, location, and capacity) and Happenings they have registered for.
- Connection status with other Users (accepted connections, pending invitations) and, where applicable, blocks or reports made.
Profile photographs will be visible to other Users staying at the same establishment during the period of stay, as well as to authorised Hotel staff, as described in section 3.
Photographs and the rest of the profile data will be automatically deleted together with the profile at the end of the stay or when the User deletes their account.
The Controller does not verify the identity of Users or the authenticity of the published photographs.
4.2 Data obtained through third parties
When the User registers through third-party authentication services (Google or Apple), the Controller receives only the full name and the validated email address associated with that account, in accordance with the configuration chosen by the User in those services.
Likewise, to verify the reservation indicated by the User at registration, the Controller queries the selected Hotel's property management system (PMS), obtaining exclusively the validity of the reservation and the check-in and check-out dates associated with it. The Controller does not obtain any other data from the PMS (such as the name of the reservation holder) and does not verify that the registered person is that holder.
4.3 Technical Data
- IP address.
- Basic device information and usage logs.
- Technical identifiers generated by the infrastructure, analytics, and messaging tools used by the Controller (Google Firebase), including the token required to send push notifications.
- Email address and technical delivery metadata (sending status, delivery errors) needed to send transactional emails through Mailgun (a service operated by Sinch).
4.4 Location data associated with Happenings
When a User or a Hotel creates a Happening, they must indicate a meeting point, which may consist of (i) a predefined point within the Hotel itself (for example, lobby or hall), or (ii) an external location selected through the Google Places search tool. In this second case, the search terms entered and the selected location are shared with Google in accordance with its own privacy policy.
4.5 Security Data
- Reports submitted by Users.
- Information associated with blocks, exclusions from Happenings, or account moderation.
5. Purposes of Processing
Personal data are processed for the following purposes:
- To allow registration and use of the Platform.
- To verify that the User is an active guest of the Hotel, by validating their reservation against the selected Hotel's property management system (PMS).
- To display profiles of other guests of the same establishment.
- To manage invitations, connections, and chats.
- To allow the creation of Happenings and the voluntary registration of Users, as well as to display the list of organiser and participants, including, where applicable, the indication that one of the participants corresponds to a User blocked by the User.
- To allow authorised Hotel staff to access their guests' profiles and the public content of Happenings, for guest service and supervision of the use of the service, as described in section 3.
- To send operational notifications related to Happenings (new registrations, changes, cancellations, or exclusions).
- To facilitate the search for external locations through Google Places.
- To ensure the security of the Platform and prevent misuse.
- To automatically delete the profile and chats at the end of the stay.
Electronic Communications
The Controller will not send commercial or promotional communications to Users.
The provided email address, as well as push notifications, will be used exclusively for:
- the technical management of the account and of Happenings, and
- exceptional and necessary communications related to security, service operation, or compliance with legal obligations.
These email communications are sent through Mailgun, a specialised provider of transactional email delivery (a service operated by Sinch), which acts as a data processor on behalf of the Controller.
6. Legal Basis for Processing
The processing of data is based on:
- Performance of a contract, upon the User's acceptance of the Terms and Conditions.
- The User's consent, by voluntarily registering and, where applicable, creating or joining a Happening.
- The Controller's legitimate interest, to ensure the security and proper functioning of the Platform, including the blocking, reporting, and Happening-exclusion mechanisms.
- The legitimate interest of the Hotel and the Controller in guest service and supervision of the use of the service, which underpins the Hotel's access described in section 3.
7. Duration of Processing and Data Retention
7.1 Limited Profile Duration
Profile data, messages, and Happenings created or registered for:
- are retained only during the User's stay;
- are automatically deleted once the check-out date obtained through the reservation validation is reached.
If the User who organised a Happening ends their stay before the date scheduled for it, the Happening will be automatically cancelled and the registered Users will be notified, without this giving rise to any liability for the Controller.
7.2 Limited Retention for Legal Reasons
Certain technical or security data (reports, blocks, incidents) may be retained for an additional period of up to twelve (12) months from their generation, or the longer period required by law, in order to:
- comply with legal obligations;
- handle claims;
- prevent fraudulent or improper use.
Under no circumstances will active profiles be retained after check-out.
8. Data Recipients
Personal data may be disclosed to:
- technology providers that provide services to the Controller, including infrastructure, storage, analytics, and messaging services (among others, Google Firebase / Google Cloud);
- Mailgun (a service operated by Sinch), as the provider of transactional email delivery to Users;
- Google, as the provider of the location search service (Google Places), when the User selects an external location for a Happening;
- the Hotel, in relation to its guests' profiles and the public content of Happenings, on the terms described in section 3, without ever including messages between Users;
- public authorities, when there is a legal obligation.
Messages and private conversations between Users are not shared with the Hotel under any circumstances.
9. International Data Transfers
The Google Firebase / Google Cloud services used by the Controller are hosted in the europe-west1 region (Belgium), within the European Economic Area. The sending of transactional emails through Mailgun (operated by Sinch) also takes place in the European Union region.
However, given that both Google LLC and the companies of the Sinch group have support, billing, or maintenance functions located outside the European Economic Area (including the United States), incidental access to the data from such locations for exclusively technical or administrative purposes cannot be ruled out. Such access, where applicable, is covered by the standard contractual clauses approved by the European Commission and other safeguards included in the data processing agreements signed with these providers.
10. User Rights
The User may exercise the following rights:
- Access.
- Rectification.
- Erasure.
- Objection.
- Restriction of processing.
- Data portability.
Requests may be sent to: hello@innhapp.com. Documentation may be requested to verify the identity of the applicant.
The User also has the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) if they consider that the processing of their personal data does not comply with current regulations.
11. Security Measures
The Controller applies reasonable technical and organisational measures to protect personal data and prevent unauthorised access, loss, or misuse.
However, the User acknowledges that no system is completely secure.
12. User Responsibility
The User is responsible for the use they make of the Platform, for the information they choose to share with other Users, and for their decision to create or participate in Happenings, whatever their location or format, as well as for the personal decisions they make in that context, including, where applicable, the consumption of alcohol.
The Controller does not actively control or supervise interactions between Users or the execution of Happenings, and is not responsible for the consequences arising from such interactions or activities.
13. Exclusion of Hotel Liability
The User expressly acknowledges that, as a general rule:
- the Hotel is not responsible for the processing of data arising from the general technical operation of the Platform;
- the Hotel has access to Users' profiles and to the public content of Happenings, on the terms described in section 3, but never to messages or private conversations between Users;
- the Hotel is not responsible for interactions, meetings, or behaviour of Users.
When the Hotel creates a Happening, it will act as the organiser of that specific activity on the terms described in the Terms and Conditions of use, without this altering its exemption regarding the general technical operation of the Platform.
Any claim related to the processing of data on the Platform must be addressed exclusively to the Controller, never to the Hotel.
14. Amendments to the Privacy Policy
The Controller may modify this Privacy Policy at any time.
The version in force will always be the one published on the Platform. Continued use of the service implies acceptance of such modifications.
15. Applicable Law
This Privacy Policy is governed by Spanish regulations and the General Data Protection Regulation (GDPR).