Introduction
Hernando Ariel Solís (Tax ID / CUIT 20-23816618-8), doing business as "Lodgy", operates Lodgy CRM, a guest relationship management platform designed for the hotel industry. This policy describes how we handle personal data from hotels using our platform and their guests.
- We do not sell personal data to third parties.
- WhatsApp, Facebook, Instagram, and email messages are processed solely to centralize hotel-guest communication.
- Meta Platform data (Facebook, Instagram, WhatsApp) is used only to send and receive messages between the hotel and its customers.
- AI processes messages to generate automatic responses on behalf of the hotel.
Legal Framework
Lodgy complies with applicable legislation in Argentina and with the policies of the third-party platforms we integrate with:
Data Collected
Hotel data (Lodgy customers)
- Establishment name, registered address, tax ID (CUIT/CUIL)
- Business contact email and phone number
- Integration credentials: WhatsApp Business API tokens, Facebook Page Access Tokens, SMTP/IMAP configuration
- Billing and subscription data
Hotel guest data
- First and last name, email, phone number
- Channel identifiers: WhatsApp ID, Facebook ID, Instagram ID
- Message history across all channels
- Travel preferences and booking history (when provided by the hotel)
- Country, city, preferred language
Technical data
- IP address, browser, and device used to access the CRM
- Agent activity logs (messages sent, actions performed)
- Metadata from webhooks received from Meta Platform
Use of Information
- Service provision: centralizing and managing communications between the hotel and its guests.
- Clark AI: processing incoming messages to generate automatic responses on behalf of the hotel.
- Operational notifications: alerts for new messages, token expiration, integration errors.
- Platform improvement: anonymous and aggregated usage analysis to improve features.
- Security: detection of unauthorized access and fraud prevention.
- Billing: subscription management and invoice issuance.
Meta Platform Integration
Lodgy CRM integrates with Meta Platform APIs to allow hotels to manage guest communications from a single omnichannel inbox. This section describes in detail how we use data from Meta.
Permissions used and their purpose
Meta data we store
- Page Access Tokens: stored encrypted in the database. Used exclusively to send messages via Graph API. Valid for 60 days and automatically renewed on reconnection.
- Page ID / WABA ID / Phone Number ID: identifiers of the hotel's page or account on Meta.
- Sender ID (Facebook ID / Instagram ID / WhatsApp ID): guest identifier on the corresponding platform. Used to associate messages with the client profile in the CRM.
- Message content: text of messages exchanged between the hotel and guests. Stored in the CRM database for the active account period.
- User name: guest's public name on the platform, used to identify them in the CRM inbox.
What we do NOT do with Meta data
- We do not sell or transfer Meta message data to unauthorized third parties.
- We do not use Meta data for advertising or commercial profiling outside the hotel's service.
- We do not share access tokens outside Lodgy's infrastructure.
- We do not access Meta data beyond what is necessary to provide the contracted messaging service.
- We do not store Meta data longer than necessary for CRM operation.
Meta Webhooks
Lodgy operates webhooks registered on Meta Platform at the following URLs to receive messages in real time:
https://lodgy.app/crm/webhooks/facebook.php— Messengerhttps://lodgy.app/crm/webhooks/instagram.php— Instagram Directhttps://lodgy.app/crm/webhooks/whatsapp.php— WhatsApp Business
Incoming payloads are processed immediately and only the relevant data is stored (sender, message, timestamp). We do not store the full webhook payload.
Legal basis for processing
- Contract performance: the hotel contracts Lodgy CRM to manage its communications.
- Consent: the guest voluntarily initiates the conversation with the hotel.
- Legitimate interest: improving hotel guest service.
AI Services
Lodgy CRM's advanced plan includes Clark AI, a multilingual virtual assistant that automatically responds to guests on behalf of the hotel.
- Guest messages are sent to the OpenAI API (ChatGPT) to generate contextual responses.
- Context includes: conversation history, hotel information, rates and availability configured by the hotel.
- OpenAI processes the message and returns a response that is sent to the guest through the corresponding channel.
- No message is used to train AI models without explicit consent.
- When an automated conversation begins, the guest receives a notice indicating they are interacting with the hotel's virtual assistant, and may request to speak with a human agent at any point in the conversation.
For more information on OpenAI's data handling, see their policy at openai.com/privacy.
Data Sharing
Lodgy does not sell personal data. We share data only with the following infrastructure providers under confidentiality agreements:
We never share the content of guest messages with third parties beyond what is necessary to operate the service.
Data Security
- Encryption in transit: HTTPS/TLS across all communications.
- Access tokens: stored hashed with restricted application access.
- Access control: independent session authentication per hotel with unique verification tokens.
- Firewalls and WAF: protection via Cloudflare on the main domain.
- Auditing: access logs and agent actions stored for audit purposes.
- Backups: periodic database backups.
Data Retention
When the service is cancelled, data is deleted within a maximum of 30 business days, except where legal retention obligations apply.
User Rights
Under Argentina's Law 25.326 on Personal Data Protection, data subjects have the right to:
- Access: know what data we store, free of charge at intervals no shorter than six months.
- Rectification: correct inaccurate or incomplete data.
- Deletion: request the deletion of data when it is no longer necessary for the purpose it was collected for.
- Objection: object to data processing under certain circumstances.
- Portability: receive data in a structured format.
Any user (hotel or guest) can request the deletion, access, or correction of their personal data —including data obtained through Facebook, Instagram, or WhatsApp— through our dedicated page: lodgy.app/baja.php. There you'll find the request form, processing timelines, and details on what data is deleted.
Cookies
Lodgy uses cookies strictly necessary for CRM operation (session management) and anonymous analytics cookies to improve the service. We do not use advertising or cross-site tracking cookies.
- lodgy_crm_session: CRM session cookie. Expires when the browser is closed.
- crm_dark: dark/light theme preference. Stored in localStorage.
Contact
Privacy questions?
To exercise your rights, request information, or report a security incident, contact us directly.
✉️ info@lodgy.appWe respond within a maximum of 15 business days.