1Who This Policy Applies To
This policy applies to three categories of individuals:
- Hotel Clients (Businesses): Companies and individuals who subscribe to Shadowbook to manage guest communications and reservations.
- Hotel Guests (End Users): Guests who interact with a hotel's Shadowbook-powered AI concierge via WhatsApp, Instagram, Facebook Messenger, or other channels.
- Website Visitors: Anyone who visits app.shadowbook.online or related Shadowbook web properties.
2Data We Collect
We collect data in the following categories depending on how our platform is used:
2.1 Account & Business Data (from Hotel Clients)
- Business name, contact email, and profile information
- Property details (hotel name, property IDs, room configurations)
- API credentials for connected services (stored encrypted)
- Billing information (processed by our payment provider; we do not store full card details)
- Subscription plan and usage data
2.2 Guest Communication Data
- Guest names and contact information (phone number, email) as provided during booking or messaging
- Message content exchanged via WhatsApp Business API, Facebook Messenger, Instagram DMs, or Telegram
- Reservation details synced from connected PMS (check-in/out dates, room type, booking reference)
- Guest preferences and service requests derived from conversations
- Voice recordings (if voice AI feature is enabled) — processed for transcription and then deleted within 30 days
2.3 Meta Platform Data (WhatsApp, Instagram, Messenger)
When a hotel client connects their Meta assets to Shadowbook, we access and store:
- whatsapp_business_management: WhatsApp Business Account (WABA) ID, Phone Number ID, and account configuration — used to manage and monitor the connected WABA
- whatsapp_business_messaging: Message content sent and received through the connected WhatsApp Business number — used to deliver AI concierge responses to hotel guests
- instagram_basic / instagram_business_basic: Instagram Business account handle, account ID, and profile information — used to identify and display the connected account
- instagram_manage_messages / instagram_business_manage_messages: Instagram Direct Messages sent to the hotel's account — used to route guest DMs into the Shadowbook unified inbox for AI-powered responses
- pages_messaging: Facebook Messenger messages sent to the hotel's Facebook Page — used to receive and respond to guest inquiries via Messenger
- pages_manage_metadata: Facebook Page webhook subscriptions — used to receive real-time notifications of Page events (new messages, comments) so Shadowbook can respond promptly
- pages_show_list / pages_read_engagement: List of Pages the hotel admin manages — used to display available Pages for connection during the OAuth setup flow
- business_management: Meta Business Portfolio information — used to display business details and manage app permissions via the Embedded Signup flow
⚠️ Meta platform data is used exclusively to deliver the Shadowbook service to the hotel client. We do not use this data for advertising, profiling, or any purpose beyond the service described.
2.4 PMS Integration Data (Apaleo, Mews)
- OAuth tokens for connected PMS accounts (stored encrypted, never logged in plaintext)
- Reservation records, guest profiles, and booking data synced from the PMS
- Property IDs, room types, and rate plans used to personalize AI concierge responses
- Webhook event payloads from the PMS (new reservations, check-in/out events, cancellations)
2.5 Technical & Usage Data
- IP addresses and browser/device information for security and fraud prevention
- Log data (API request logs, error logs) retained for up to 90 days
- Analytics on feature usage to improve the platform (aggregated, not linked to individual guests)
3How We Use Your Data
We use the data we collect exclusively for the following purposes:
- Delivering the Shadowbook AI concierge service — routing, reading, and responding to guest messages across all connected channels
- Syncing reservation data from connected PMS to personalise AI responses and anticipate guest needs
- Providing the Shadowbook dashboard — displaying KPIs, conversation history, reservation timelines, and channel statuses to hotel staff
- Sending automated check-in reminders, upsell suggestions, and service updates to guests via the hotel's connected channels
- Configuring and maintaining webhook subscriptions to receive real-time events from Meta platforms and PMS providers
- Authenticating hotel clients via OAuth and maintaining secure API token refresh cycles
- Improving our AI model responses and platform reliability using aggregated, anonymised usage data
- Complying with legal obligations and enforcing our Terms of Service
We do not use any data for advertising, data brokering, profiling for third parties, or any purpose not described above.
4Data Sharing & Third-Party Service Providers
We do not sell your data. We share data only with the service providers necessary to operate Shadowbook:
| Provider | Purpose |
|---|---|
| Meta (WhatsApp, Instagram, Messenger) | Transmitting messages via official Meta APIs under hotel client authorisation |
| Apaleo / Mews | Syncing reservation data under hotel client OAuth authorisation |
| Google Cloud Platform | Backend hosting, Cloud Storage for session data, and Cloud Run services |
| Firebase (Google) | Frontend hosting and real-time database services |
| Supabase | Primary relational database (PostgreSQL) for storing account, reservation, and conversation data |
| Google AI (Gemini) | AI language model for generating concierge responses and parsing guest intent |
| Groq / OpenAI | Secondary AI inference and voice transcription services |
| Twilio | Voice AI call handling and telephony (if Voice AI feature is enabled) |
All third-party providers are contractually bound to process data only as instructed and in compliance with applicable data protection laws.
5Meta Platform Data — Specific Restrictions
Shadowbook's use of data obtained via Meta's APIs (WhatsApp Business API, Instagram Graph API, Facebook Graph API) is strictly governed by Meta's Platform Terms and Developer Policies. In particular:
- We access Meta platform data only on behalf of the hotel client who granted explicit permission via Meta's OAuth or Embedded Signup flow
- Meta platform data is not used to build audience profiles, serve advertisements, or shared with any ad networks
- Message content obtained through Meta APIs is stored only as long as necessary to deliver the service and is not used to train AI models without explicit consent
- Hotel clients may revoke Shadowbook's access to their Meta assets at any time through their Meta Business Settings or via the Shadowbook Settings panel, which will trigger immediate token revocation and data deletion
- We comply with all applicable Meta Platform Terms including restrictions on data portability and data retention
6Data Retention
- Active account data: Retained for the duration of the subscription and up to 90 days after account termination
- Guest conversation data: Retained for up to 12 months after the last interaction, then anonymised or deleted
- PMS reservation data: Retained for up to 12 months after check-out date
- Voice recordings: Deleted within 30 days of processing
- Technical logs: Retained for 90 days for security and debugging purposes
- Deleted account data: Permanently purged within 30 days of account deletion request
7Data Security
We implement industry-standard and enterprise-grade security measures to protect your data:
- All data in transit is encrypted using TLS 1.2 or higher (HTTPS)
- All data at rest is encrypted using AES-256 encryption via our cloud providers
- OAuth tokens and API credentials are stored encrypted and never logged in plaintext
- Access to production databases is restricted to authorised personnel via role-based access control
- Webhook endpoints are secured with signature verification to prevent spoofed events
- Regular security reviews and dependency audits are conducted
In the event of a data breach that affects your personal data, we will notify affected parties in accordance with applicable law, and no later than 72 hours after becoming aware of the breach where required by GDPR.
8Your Rights (GDPR & Data Subject Rights)
If you are in the European Economic Area (EEA), United Kingdom, or other jurisdictions with similar data protection laws, you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your personal data (subject to legal retention requirements)
- Right to Restrict Processing: Request that we limit how we use your data
- Right to Data Portability: Request your data in a machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, contact us at support@shadowbook.online. We will respond within 30 days.
Hotel guests should contact the hotel directly for requests related to reservation data, as the hotel is the data controller for guest information.
9Cookies & Tracking
Shadowbook uses essential cookies only — strictly necessary for authentication sessions and security. We do not use tracking cookies, advertising pixels, or third-party analytics that track individuals across websites.
- Session cookies: Required to maintain your logged-in state on the dashboard
- Security cookies: Used for CSRF protection
10Children's Privacy
Shadowbook is a B2B platform designed for hotel and hospitality businesses. We do not knowingly collect data from children under the age of 13. If you believe a child has provided personal data to us, please contact us and we will promptly delete it.
11International Data Transfers
Shadowbook operates globally and your data may be processed and stored in servers located outside your country of residence, including within the European Economic Area, United States, and other countries where our cloud providers operate. We ensure appropriate safeguards are in place for international transfers, including Standard Contractual Clauses (SCCs) where applicable.
12Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and notify active hotel clients via email or in-app notification. Continued use of Shadowbook after the effective date constitutes acceptance of the updated policy.
13Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy:
Shadowbook
Email: support@shadowbook.online
Privacy requests: privacy@shadowbook.online
Website: https://app.shadowbook.online