Legal document

Privacy Policy

How we collect, use, and protect your information on the Lodgy CRM platform.

📅 Last updated: July 7, 2026 🌐 Version 2.1 🇦🇷 Argentine Law 25.326 — AAIP
1

Introduction

Hernando Ariel Solís (Tax ID / CUIT 20-23816618-8), doing business as "Lodgy", operates Lodgy CRM, a guest relationship management platform designed for the hotel industry. This policy describes how we handle personal data from hotels using our platform and their guests.

⚡ Executive Summary
  • We do not sell personal data to third parties.
  • WhatsApp, Facebook, Instagram, and email messages are processed solely to centralize hotel-guest communication.
  • Meta Platform data (Facebook, Instagram, WhatsApp) is used only to send and receive messages between the hotel and its customers.
  • AI processes messages to generate automatic responses on behalf of the hotel.
2

Legal Framework

Lodgy complies with applicable legislation in Argentina and with the policies of the third-party platforms we integrate with:

🇦🇷 ArgentinaLaw 25.326 on Personal Data Protection. AAIP regulations.
🌐 Meta PlatformMeta Platform Policy. WhatsApp Business API Terms. Messenger Platform Policy.
🤖 OpenAIOpenAI Usage Policies for the Clark AI service.
📧 EmailCAN-SPAM regulations. SMTP sending best practices.
3

Data Collected

Hotel data (Lodgy customers)

  • Establishment name, registered address, tax ID (CUIT/CUIL)
  • Business contact email and phone number
  • Integration credentials: WhatsApp Business API tokens, Facebook Page Access Tokens, SMTP/IMAP configuration
  • Billing and subscription data

Hotel guest data

  • First and last name, email, phone number
  • Channel identifiers: WhatsApp ID, Facebook ID, Instagram ID
  • Message history across all channels
  • Travel preferences and booking history (when provided by the hotel)
  • Country, city, preferred language

Technical data

  • IP address, browser, and device used to access the CRM
  • Agent activity logs (messages sent, actions performed)
  • Metadata from webhooks received from Meta Platform
4

Use of Information

  • Service provision: centralizing and managing communications between the hotel and its guests.
  • Clark AI: processing incoming messages to generate automatic responses on behalf of the hotel.
  • Operational notifications: alerts for new messages, token expiration, integration errors.
  • Platform improvement: anonymous and aggregated usage analysis to improve features.
  • Security: detection of unauthorized access and fraud prevention.
  • Billing: subscription management and invoice issuance.
5

Meta Platform Integration

📘 Meta Platform — Facebook, Instagram, WhatsApp

Lodgy CRM integrates with Meta Platform APIs to allow hotels to manage guest communications from a single omnichannel inbox. This section describes in detail how we use data from Meta.

Permissions used and their purpose

pages_messaging
Allows sending and receiving Facebook Messenger messages on behalf of the hotel's page. Messages are stored in the CRM database for management by hotel agents.
pages_read_engagement
Allows reading the status of sent messages (delivered, read) to display confirmations in the CRM.
pages_manage_metadata
Allows subscribing the hotel's page to Lodgy's webhook to receive real-time new message notifications.
instagram_manage_messages
Allows sending and receiving Instagram direct messages on behalf of the hotel's professional account.
instagram_basic
Allows identifying the Instagram Business account associated with the hotel's Facebook page.
whatsapp_business_messaging
Allows sending and receiving WhatsApp Business messages on behalf of the hotel through the WhatsApp Business API.
whatsapp_business_management
Allows managing the hotel's WhatsApp Business account configuration.

Meta data we store

  • Page Access Tokens: stored encrypted in the database. Used exclusively to send messages via Graph API. Valid for 60 days and automatically renewed on reconnection.
  • Page ID / WABA ID / Phone Number ID: identifiers of the hotel's page or account on Meta.
  • Sender ID (Facebook ID / Instagram ID / WhatsApp ID): guest identifier on the corresponding platform. Used to associate messages with the client profile in the CRM.
  • Message content: text of messages exchanged between the hotel and guests. Stored in the CRM database for the active account period.
  • User name: guest's public name on the platform, used to identify them in the CRM inbox.

What we do NOT do with Meta data

⚠️ Usage Commitments
  • We do not sell or transfer Meta message data to unauthorized third parties.
  • We do not use Meta data for advertising or commercial profiling outside the hotel's service.
  • We do not share access tokens outside Lodgy's infrastructure.
  • We do not access Meta data beyond what is necessary to provide the contracted messaging service.
  • We do not store Meta data longer than necessary for CRM operation.

Meta Webhooks

Lodgy operates webhooks registered on Meta Platform at the following URLs to receive messages in real time:

  • https://lodgy.app/crm/webhooks/facebook.php — Messenger
  • https://lodgy.app/crm/webhooks/instagram.php — Instagram Direct
  • https://lodgy.app/crm/webhooks/whatsapp.php — WhatsApp Business

Incoming payloads are processed immediately and only the relevant data is stored (sender, message, timestamp). We do not store the full webhook payload.

Legal basis for processing

  • Contract performance: the hotel contracts Lodgy CRM to manage its communications.
  • Consent: the guest voluntarily initiates the conversation with the hotel.
  • Legitimate interest: improving hotel guest service.
6

AI Services

Lodgy CRM's advanced plan includes Clark AI, a multilingual virtual assistant that automatically responds to guests on behalf of the hotel.

🤖 How Clark AI works
  • Guest messages are sent to the OpenAI API (ChatGPT) to generate contextual responses.
  • Context includes: conversation history, hotel information, rates and availability configured by the hotel.
  • OpenAI processes the message and returns a response that is sent to the guest through the corresponding channel.
  • No message is used to train AI models without explicit consent.
  • When an automated conversation begins, the guest receives a notice indicating they are interacting with the hotel's virtual assistant, and may request to speak with a human agent at any point in the conversation.

For more information on OpenAI's data handling, see their policy at openai.com/privacy.

7

Data Sharing

Lodgy does not sell personal data. We share data only with the following infrastructure providers under confidentiality agreements:

🖥️ HostingHostinger International Ltd. Servers in Europe. ISO 27001.
📘 Meta PlatformFacebook Ireland Ltd. For sending/receiving messages. Under Meta Platform Terms.
🤖 OpenAIOpenAI LLC. For the Clark AI service. API processed without permanent retention.
💳 PaymentsMercadoPago / PayPal. For subscription processing. PCI DSS compliant.

We never share the content of guest messages with third parties beyond what is necessary to operate the service.

8

Data Security

  • Encryption in transit: HTTPS/TLS across all communications.
  • Access tokens: stored hashed with restricted application access.
  • Access control: independent session authentication per hotel with unique verification tokens.
  • Firewalls and WAF: protection via Cloudflare on the main domain.
  • Auditing: access logs and agent actions stored for audit purposes.
  • Backups: periodic database backups.
9

Data Retention

💬 MessagesFor the duration of the subscription + 90 days after cancellation.
👤 Customer dataWhile the subscription is active. Upon deletion request.
🔑 Meta tokensUp to 60 days or until the hotel revokes them.
📊 Logs90 days for operational logs. 1 year for security logs.

When the service is cancelled, data is deleted within a maximum of 30 business days, except where legal retention obligations apply.

10

User Rights

Under Argentina's Law 25.326 on Personal Data Protection, data subjects have the right to:

  • Access: know what data we store, free of charge at intervals no shorter than six months.
  • Rectification: correct inaccurate or incomplete data.
  • Deletion: request the deletion of data when it is no longer necessary for the purpose it was collected for.
  • Objection: object to data processing under certain circumstances.
  • Portability: receive data in a structured format.
🗑️ Data Deletion Instructions

Any user (hotel or guest) can request the deletion, access, or correction of their personal data —including data obtained through Facebook, Instagram, or WhatsApp— through our dedicated page: lodgy.app/baja.php. There you'll find the request form, processing timelines, and details on what data is deleted.

11

Cookies

Lodgy uses cookies strictly necessary for CRM operation (session management) and anonymous analytics cookies to improve the service. We do not use advertising or cross-site tracking cookies.

  • lodgy_crm_session: CRM session cookie. Expires when the browser is closed.
  • crm_dark: dark/light theme preference. Stored in localStorage.
12

Contact

Privacy questions?

To exercise your rights, request information, or report a security incident, contact us directly.

✉️ info@lodgy.app

We respond within a maximum of 15 business days.