Privacy Policy
FrontDesk24, Inc. ("we", "us", "our") operates the autonomous front desk agent at frontdesk24.us and the connected kiosk software, voice agent, admin dashboard, audit record services, and the Front Desk Line AI phone service with its customer console (collectively, "the Service"). This policy explains what data we collect, how we use it, and what rights you, your hotel guests, and callers to a Front Desk Line number have.
1. What We Collect
Operator Account Data
- Email address — used for authentication, billing, and service communication.
- Password hash — stored securely by our identity provider (we never see or store plaintext passwords).
- Billing data — subscription tier, Stripe customer ID, payment status. Credit card details are stored by Stripe, never by us.
- Property configuration — property name(s), room counts, integrations enabled, kiosk identifiers, agent prompts and policies, voice/LLM provider selection, supervisor PINs (hashed).
Operational Data (Audit Records)
For every guest interaction, we record operational audit events:
- Session ID and timestamp
- Channel used (kiosk, voice, SMS, phone)
- Agent decision steps and tool calls
- Gate evaluations (pre-auth, ID verification, payment, key dispensing)
- Outcome (check-in completed, escalated to staff, abandoned, etc.)
- Cryptographic SHA-256 hashes for trace integrity; kiosk behavior traces are chained per session
For on-property deployments, operational audit records are stored on the property system by default. Operators may opt in to a cloud archive; see "Data Retention" below.
Guest Data
When a guest interacts with the agent, the Service may handle the following — strictly to fulfill the check-in, check-out, or service request:
- Reservation identifiers retrieved from the operator's PMS
- Guest name (from the PMS reservation)
- Last 4 digits of the phone number on file (used for verification)
- If
REQUIRE_ID_SCANis enabled by the operator: an image of the guest's ID document and the extracted name (used to fuzzy-match against the reservation, then discarded unless the operator's retention policy keeps it) - Voice audio during a session — streamed to the configured voice/LLM provider and processed in real time. We do not record calls or kiosk sessions and we write no audio files.
- The text of the session conversation — what the guest types, or says and the system transcribes, and what the agent replies — stored in the session record so staff can read and continue the conversation in the admin dashboard. For on-property deployments that record stays on the property system.
- Card-present payment authorization data (handled and stored by Stripe Terminal, our PCI-compliant payment processor — we never touch the PAN)
- Key card encoding events (room number, encoding timestamp)
Front Desk Line Call Data
Front Desk Line is a hosted phone service, and it handles data differently from an on-property kiosk. Calls run on FrontDesk24's servers, and we keep a written record of each call so the subscribing business can see its own calls and so we can operate, troubleshoot, and support the line. For every call to a Front Desk Line number we collect:
- Call metadata — the caller's number as delivered by the carrier, the number called, start and end times, duration, the minutes counted against the plan, and the outcome (message taken, request captured, transferred to a human)
- A written transcript of the call — the speech-recognition text of what the caller says, together with the text the AI agent speaks. It is stored in the subscribing business's own session record on our servers, separated per business.
- Messages and booking or appointment requests the agent captures — caller name, callback number, and what was asked for — delivered to the business by text and email, with an append-only entry in that business's own capture log
- SMS sent to a caller at their request, and STOP/HELP opt-out records for that number
Before a transcript line is written, email addresses and phone- or card-length digit sequences (seven or more digits, or nine or more when spoken in groups) are replaced with placeholders. Shorter digit runs are kept on purpose: room numbers, dollar amounts, and last-4 verification answers are exactly what the business reads a transcript for.
The subscribing business sees live calls as they happen, and can open any call from the last 90 days, in its own console at its fd24.us subdomain, which is reachable only by signing in with the email address on the account. A business sees only its own calls. FrontDesk24 staff can also access this data — see "How We Use Your Data" for why, and "Data Retention" for how long it is kept.
What We Do Not Collect
- Full payment card numbers (PCI-handled by the terminal hardware)
- Continuous location data, biometric identifiers beyond what is required for ID verification, or any data unrelated to the check-in flow
- Marketing, advertising, or behavioral profiling data of any kind
- Audio recordings — no channel is recorded and no audio file is written or stored. The written conversation record described above is kept; audio is not.
2. How Data Is Processed
FrontDesk24 supports on-property, SaaS, and dedicated-cloud deployments. In on-property deployments, guest data, audit records, and session state stay on the property system and the operator's PMS unless cloud archive is enabled. SaaS or dedicated-cloud storage and retention are documented in the operator agreement.
- Voice audio is streamed in real time to the configured LLM/voice provider (e.g. xAI Grok), processed for the active session, and discarded. Only the resulting text is written to disk.
- Front Desk Line is hosted by us, not on-property: each subscribing business's transcripts, call records, captures, opt-out ledger, and settings are stored on FrontDesk24's servers in that business's own directory, kept separate from every other business's.
- LLM prompts include only the data necessary for the task (e.g. reservation candidates for fuzzy matching) — never bulk guest exports.
- Kiosk behavior trace entries are chained with SHA-256 hashes per session; PMS folio and night-audit records use append-only controls where supported, and report artifacts include SHA-256 hashes.
- If the operator enables the cloud archive, audit records are mirrored to our cloud storage with a default 90-day retention.
3. Data Retention
- Operator account data — retained for the lifetime of the account.
- On-property audit records — retained per the operator's local policy (we do not access or rotate these unless the deployment agreement includes management services).
- Cloud-archived audit records (opt-in only) — default 90-day rolling window, configurable up to 7 years for regulated operators.
- Voice audio — transient on every channel; processed during the call or session and discarded. We keep no audio recordings.
- Front Desk Line transcripts, call records, and captures — retained for at least 90 days, and for as long as the account is active. Spoken transcripts are not aged out while a business is using the service. The subscribing business can read them in its console (live calls, and any call from the last 90 days). When a subscription is cancelled the line stops and the business's data is taken out of service immediately; we then retain it for 90 days, after which it is purged.
- SMS opt-out (STOP) records — kept for at least five years as messaging law requires, and preserved separately so they survive the purge of the rest of a cancelled account's data.
- ID-scan images — transient by default; discarded after fuzzy match completes.
- Guest reservation data — owned by the operator's PMS; FrontDesk24 holds no independent copy.
4. How We Use Your Data
- Operate the agent — fulfill check-ins, check-outs, voice calls, and service requests.
- Show a business its own calls — Front Desk Line transcripts and call records are what the subscribing business reads in its console, and captured messages and booking requests are sent on to it by text and email. Keeping this record is the product working as intended.
- Diagnostics, troubleshooting, and service quality — FrontDesk24 reviews call transcripts, logs, and audit records to investigate reported problems, diagnose failures, and check that the agent is answering correctly and reliably. We retain this data deliberately for that purpose.
- Audit and review — power the behavior trace, dashboard, and incident review tools.
- Billing — manage your subscription via Stripe.
- Service communication — notify operators of account or service issues. We do not send marketing email.
We do not sell, share, or provide your data — operator or guest — to third parties for advertising, profiling, or any purpose unrelated to operating the Service.
5. Third-Party Services
FrontDesk24 integrates with the following providers. Where data flows through them, their privacy policies apply in addition to ours:
- xAI Grok (default LLM and realtime voice) — receives the voice stream and prompt context for the active session. xAI Privacy Policy
- Anthropic, OpenAI, Google — alternative LLM/voice providers, used only when the operator selects them. Their respective privacy policies apply.
- Telnyx (telephony) — bridges inbound calls, and provides the phone numbers and SMS delivery for Front Desk Line.
- Stripe (billing + card-present payments via Stripe Terminal) — processes operator subscription payments and, where enabled, guest card-present payment authorization. Stripe Privacy
- Supabase (admin dashboard auth and metadata) — stores operator account data. Supabase Privacy
- PMS providers (when a property connects one) — guest reservation data flows directly between the operator's PMS and the kiosk; we do not relay or store it.
- Lock manufacturers (when a property's key-card encoder is connected) — receive room/encoding requests during key dispensing.
- Let's Encrypt — provides TLS certificates for our domains.
No analytics trackers, advertising pixels, or social media widgets are loaded on frontdesk24.us or the admin dashboard.
6. Data Security
- All web and admin traffic encrypted via HTTPS (TLS 1.2+)
- Kiosk behavior trace integrity protected by a per-session SHA-256 hash chain; PMS report artifacts protected by SHA-256 hashes
- Locally-encrypted kiosk storage
- Supervisor PIN required for sensitive overrides (refunds, key re-dispense, payment voids)
- Pre-auth gating for key dispensing and payment capture — no key issued without a verified guest and authorized capability
- Passwords hashed by the identity provider (bcrypt)
- Database access governed by row-level security policies
- Stripe webhook signatures verified cryptographically
- Capability lookups fail closed — if the system can't confirm a permission, the operation is denied
7. Operator Rights
As an operator, you have the right to:
- Access your data — view it in the admin dashboard.
- Export your data — audit records, configuration, and account data via the dashboard's export tool.
- Delete your account — permanent and irreversible deletion via the dashboard or by contacting [email protected].
- Correct your data — edit property configuration, integrations, and policies at any time through the dashboard.
8. Guest Rights
For data about hotel guests, the operator (the hotel) is the data controller; FrontDesk24 acts as the data processor. Guests should direct privacy requests to the property where they stayed. We will assist the operator in fulfilling guest requests on request, including data deletion and export.
The same split applies to Front Desk Line: the subscribing business is the controller for data about the people who call it, and FrontDesk24 is the processor. Callers should direct privacy requests to the business they called.
9. GDPR Compliance (EU Operators and Guests)
- Legal basis — contract performance (operators), legitimate interest in fulfilling the booking (guests).
- Data minimization — we collect only what the check-in flow requires.
- Data portability — full export available via the dashboard.
- Right to erasure — operator account deletion is self-service; guest data deletion is coordinated with the operating property.
- Retention limits — voice audio and ID images are transient by default; cloud-archived audit records default to 90 days; Front Desk Line call data is retained as described in "Data Retention" above.
- DPA — a Data Processing Agreement is available on request for EU operators.
10. CCPA Compliance (California Operators and Guests)
- We do not sell personal information.
- We do not share personal information for cross-context behavioral advertising.
- You may request deletion of your data at any time.
11. Recording and Notice
Operators are responsible for posting clear, conspicuous notice at the kiosk and in the voice/phone channel that interactions involve an AI agent and may be recorded for audit purposes. We provide template notices; deploying them in compliance with local two-party consent and disclosure laws is the operator's responsibility.
Front Desk Line calls are not audio-recorded, but they are transcribed and the transcript is kept, as described above. A business subscribing to Front Desk Line is responsible for any AI-disclosure or call-monitoring notice its jurisdiction requires of it.
12. Children's Privacy
FrontDesk24 is not directed at children under 13 and is intended for adult guests checking in to a hotel. We do not knowingly collect data from children. Operators should escalate any minor-only check-in attempt to staff per their property policy.
13. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated by updating the "Last updated" date at the top of this page and, where appropriate, by emailing operators directly.
14. Contact
For privacy questions, data requests, or DPA inquiries: [email protected].