Policies
Last updated: August 16, 2026
Privacy Policy
This Privacy Policy explains how Anjono ("we", "us") handles information when hotels and their guests use our digital guest directory.
Our role: hotels are the data controllers
Anjono is a tool that hotels use to publish information to their guests and to collect responses through forms they build themselves. For any personal data collected from guests through a hotel's directory (for example, form submissions), the hotel is the data controller and Anjono acts as a data processor on their behalf. Each hotel decides what information to request, how it is used, and how long it should be kept. Anjono is not responsible for a hotel's own use of the data it collects through the service. Guests with questions about a specific hotel's use of their data should contact that hotel directly.
Anjono is the data controller for information we hold about hotel accounts and staff who log in to the portal (see "Hotel account data" below).
Hotel account data (controller: Anjono)
- Hotel name, slug, contact email, and billing details.
- Staff user accounts: username, hashed password, role, last login time, and failed-login counters.
- Portal session records for staff: sign-in and sign-out timestamps, session duration, IP address, and user-agent string. Used for security, abuse detection, and to power the admin activity view.
Directory content (controller: the hotel)
- Pages, text, images, and PDFs uploaded by hotel staff. Uploaded files are stored in Amazon S3 and served through Amazon CloudFront using short-lived signed URLs.
- Verified email addresses the hotel has added to receive form notifications.
- Extracted "facts" and vector embeddings generated from the hotel's directory content and PDFs. These power the in-app AI search and are stored per hotel.
Guest data (controller: the hotel; processor: Anjono)
- Anonymous usage statistics. When a guest views a directory we record a random session identifier, device type (mobile or desktop), language, which pages were viewed, view order, page-view duration, and total session duration. We do not record the guest's IP address, user-agent string, precise location, name, or any account identifier.
- Form submissions. If a hotel publishes a form, we store the answers the guest submits together with the form language and a timestamp. The content of the submission is entirely defined by the hotel; it may or may not include personal data depending on what the hotel asks.
- PIN-protected directory sessions. When a hotel restricts access with a PIN, we store a hashed session token and the IP address of the device that entered the PIN. This is used solely to rate-limit incorrect attempts and to bind the access token to the requesting device.
- Language preference. The guest's chosen display language is stored in the guest's own browser (localStorage) so the directory opens in the right language next time. It is also sent with usage statistics.
How we use information
- To operate, secure, and improve the Anjono service.
- To translate directory content into the languages the hotel has enabled.
- To index directory content so guests can search it inside the app.
- To send form-submission notifications to the email addresses the hotel has verified.
- To produce aggregated usage statistics (traffic, popular pages, active guests) for the hotel and for us.
- To provide support and respond to inquiries.
- To comply with legal obligations.
Subprocessors
We do not sell personal information. We use a small number of subprocessors to run the service:
- Amazon Web Services — hosting, database, S3 and CloudFront (file storage and delivery), and SES (transactional email for form notifications).
- OpenAI — translation of directory content into guest languages and extraction of searchable facts and embeddings from pages and PDFs. Directory content the hotel publishes, and text extracted from uploaded PDFs, is sent to OpenAI for these purposes. Anjono does not send form submissions or guest analytics to OpenAI.
Data retention
- Hotel account data is retained for the lifetime of the subscription and deleted within 30 days of account closure unless retention is required by law.
- Form submissions will be automatically deleted six months after they are received. Hotels that need to keep a submission longer should export it to their own systems before then.
- Directory content, assets, and RAG facts are retained while the hotel keeps them in the portal and are deleted when the hotel deletes them (or when the account is closed).
- Portal session records are retained while the account is active for security and audit purposes.
- Guest usage sessions and page-view records are retained in aggregate for product analytics. Individual session rows are short-lived and are not tied to any identifiable person.
- Internal background job queues (translation, RAG, email) are purged on a rolling basis by our maintenance worker.
Your rights
If Anjono holds personal data about you (for example, because you are a staff user of a hotel that uses Anjono), you may request access, correction, or deletion of that data at any time by contacting us at privacy@anjono.com. If you submitted a form to a hotel through our service, the hotel is the controller of that data — please direct requests about it to the hotel. We will help the hotel action the request where technically necessary.
Terms of Service
These Terms of Service ("Terms") govern access to and use of Anjono by hotels and their staff. By creating an account or using the service, you agree to these Terms.
Accounts
You are responsible for maintaining the confidentiality of your account credentials and for all activity that occurs under your account. Notify us immediately of any unauthorised use.
Your content and your guests' data
You retain ownership of all content you upload. You grant Anjono a limited licence to host, display, translate, and index that content solely to provide the service to you and your guests.
You are the data controller for any personal data you collect through the service (for example, form submissions from your guests). You are solely responsible for: deciding what to ask for, having a lawful basis to collect it, informing your guests about how you will use it, honouring their rights, and complying with all applicable data-protection laws. Anjono stores this data on your behalf and is not responsible for the purposes for which you use it.
Acceptable use
- Do not upload unlawful, infringing, or malicious content.
- Do not use the service to collect personal data you have no lawful basis to collect.
- Do not attempt to disrupt, reverse engineer, or overload the service.
- Do not use the service to send unsolicited messages or spam.
Billing and cancellation
Subscriptions are billed in advance on a monthly or annual basis. You may cancel at any time; cancellation takes effect at the end of the current billing period. Fees already paid are non-refundable except where required by law.
Termination
We may suspend or terminate your access if you breach these Terms. On termination, your right to use the service ends immediately and we will delete your data as described in the Privacy Policy.
Disclaimer and liability
The service is provided "as is" without warranties of any kind. To the maximum extent permitted by law, Anjono's aggregate liability arising from your use of the service is limited to the fees you paid in the twelve months preceding the claim.
Changes
We may update these Terms from time to time. Material changes will be communicated via email or a notice in the portal.