How guest data is protected
Tento obsah zatím není dostupný ve vašem jazyce.
| Why | Answer guests who ask “what happens to my passport details” — and know yourself where the data lives, who sees it, and what the protection rests on. |
| Who | Administrators and front desk staff who collect guest details and field their questions about data safety. |
| What you’ll get | A clear picture: what data the guest leaves, how it is protected, who has access to it, and where it is stored. |
| Limitations | This is an overview: no infrastructure details or provider names here. There is no self-service delete button in the portal — deletion requests go through us. |
A passport is the most personal thing a guest leaves with a hotel. In HotelsCalendar this data enters the system through the online check-in form and the guest profile, is encrypted, and is stored in the EU.
This article covers what exactly is collected, how it is protected, who sees it, and what to do when a guest asks to have it deleted.
What data is collected
Section titled “What data is collected”The main path is the online form before check-in: the guest enters their own details and those of their travel companions, and uploads documents. Every guest on the booking has their own separate set of details.
Three kinds of guest data live in the system:
- Contacts — phone and email, the channels the hotel uses to reach the guest before and after the stay.
- Passport details — identity and document fields: what registering a guest requires.
- Document files — scans and photos the guest uploads themselves.
Staff work with the same set of fields: on the guest profile these are “Last name”, “First name”, “Phone”, “Email”, “Country”, and the passport fields below it. Which fields appear and which are required is up to the hotel, so the form differs from property to property.
On the booking card, guest data shows up on the “Rooms and guests” and “Documents” tabs — the same place the team works with the booker and their companions.
How the data is protected
Section titled “How the data is protected”- Encryption at the application level. Passport fields are encrypted with AES-256: in storage they are not plain text but encrypted values, decrypted when a staff member works with that guest — within their role.
- Hash comparison when finding duplicates. The system finds duplicate guests by passport, email, and phone. Passports are compared by hash: to spot a repeat, the system never needs to read the number in plain text.
- The sign-in link carries no password and is stored as a hash. A guest’s personal portal link contains no password and is kept in the database only as a hash. Reissue the link, and the old one — together with any active sessions on it — stops working immediately: see The guest’s personal link: preview and reissue.
Add the basic discipline on top: the guest shares no password with the hotel, and staff have no reason to keep passport scans in loose files and emails — documents are attached to the guest profile.
The infrastructure details behind all this are deliberately out of scope: you don’t need them to reassure a guest calmly and to the point.
Who sees guest data
Section titled “Who sees guest data”Two sides have access, and both are limited.
- Hotel staff see the guest profile and its documents — but not everyone and not everything: access is role-based, and a person’s role in the system decides what they can see. Guest document files are visible to the hotel team — at check-in and while working with the booking, that is exactly what the front desk needs.
- The guest sees their own data in the Guest Portal — what they entered themselves: the passport fields of the form and the documents they uploaded.
There is a third boundary — exports: booking exports to CSV leave personal data out by default. Columns with it are added separately and deliberately, not swept into the file on their own.
Where the data lives
Section titled “Where the data lives”HotelsCalendar is a web system: guest profiles live in the system’s storage, not in files on an office computer and not in the front desk inbox.
The servers are in the EU, and guest data is stored in the EU. EU storage is part of the system itself — there is nothing to switch on when the property signs up.
If a guest asks to delete their data
Section titled “If a guest asks to delete their data”There is no “delete my data” button in the portal — guests do not manage deletion themselves. But they can ask for it: in a reply to an email or in person at the front desk.
When such a request reaches the hotel, write to us — it will reach the HotelsCalendar team, and we will help you through the standard deletion procedure.
Until the request is resolved, the guest’s data lives under the same rules as before: encryption, role-based access, EU storage.
What the guest sees in the portal
Section titled “What the guest sees in the portal”Sign-in is by the personal link from the email plus a one-time code: 6 digits, valid for 60 minutes with 5 attempts; after signing in, the session stays alive for up to 30 days. There is no password at all — nothing to forget and nothing to reuse.
Inside the portal is the guest’s own booking in full: rooms, guests, prices by day, ordered services, taxes, and the balance due. Their own data is here too: the passport fields from the form and the uploaded documents — exactly what the guest entered themselves.
Team notes are internal: the guest does not see them in the portal.
There are no payments in the portal: the guest sees the balance due, but the payment itself follows the rate’s rules — on the booking site or at the front desk.
If a guest asks where to find their booking, point them to the Guests & Guest Portal article; the check-in form and documents are covered in the article on preparing for arrival.
See also
Section titled “See also”- Prepare guests for arrival: companions and documents — where guests enter their details and upload documents before check-in.
- Guest profiles: history, notes, files, duplicates — where guest data lives in the system and how duplicates are found.
- Guest Portal: frequently asked questions — short answers on sign-in, payments, and data safety.