Dashboard Privacy Policy
Version 2026-07-13 · Last updated 13 July 2026
1. Introduction
At myhotail, protecting your privacy and maintaining the security of your information are fundamental principles of how we design and operate our Services.
This Dashboard Privacy Policy (“Privacy Policy”) explains how myhotail GbR (“myhotail”, “we”, “our” or “us”) collects, uses, stores, shares and protects personal data when you access or use the myhotail Dashboard (the “Dashboard”).
The Dashboard is a subscription software platform that enables hotels and accommodation providers to monitor, analyse and improve their visibility across selected artificial intelligence search and conversational platforms.
We are committed to processing personal data fairly, lawfully and transparently in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and all other applicable data protection laws.
Please read this Privacy Policy carefully before using the Dashboard.
2. Data Controller
The controller responsible for the processing of personal data described in this Privacy Policy is:
myhotail GbR
Strelitzer Str. 66
10115 Berlin
Germany
Authorised Representative Partners
Clemens Miller
Mateo Iacovelli
Email: info@myhotail.com
If you have any questions regarding this Privacy Policy or our processing of personal data, you may contact us using the details above.
3. Scope
This Privacy Policy applies exclusively to the myhotail Dashboard.
It applies whenever you:
- create a Dashboard account;
- sign in using email, Google Sign-In or a magic link;
- complete the onboarding process;
- submit a Hotel for monitoring;
- configure competitors, prompts or Dashboard settings;
- initiate or receive AI Visibility Scans;
- receive automated monthly Scans;
- communicate with us regarding your Dashboard account; or
- otherwise use the Dashboard and its related Services.
This Privacy Policy does not apply to the public myhotail website, separate consulting services, website optimisation projects, AI implementation services or other professional services unless expressly stated.
4. Definitions
For the purposes of this Privacy Policy:
Personal Data means any information relating to an identified or identifiable natural person as defined by Article 4 GDPR.
Processing means any operation performed on Personal Data, including collection, storage, organisation, use, disclosure, transmission or deletion.
Customer means the individual or legal entity registered to use the Dashboard.
Hotel Data means business information relating to the Hotel monitored through the Dashboard, including its name, website, location, property characteristics, competitors, prompts and Scan results.
Scan means the automated analytical process carried out by the Dashboard to assess AI visibility and publicly available website signals.
AI Engine means any supported third-party artificial intelligence platform used during a Scan, including OpenAI ChatGPT, Anthropic Claude, Google Gemini, Perplexity and Google AI Overviews.
5. Personal Data We Collect
The categories of Personal Data we process depend upon how you use the Dashboard.
5.1 Account Information
When you register for a Dashboard account, we may collect:
- email address;
- encrypted authentication credentials managed by Supabase;
- Google account information where Google Sign-In is used (including your name, email address, profile picture and account identifier);
- authentication method;
- account creation date; and
- account status.
myhotail does not receive or store your plaintext password.
Passwords are securely managed through Supabase Auth.
5.2 Hotel Profile Information
During onboarding and subsequent use of the Dashboard, we process business information relating to your Hotel, including:
- Hotel name;
- website URL;
- city and location;
- property type;
- star rating;
- neighbourhood;
- nearby landmarks;
- guest types;
- amenities;
- unique selling points;
- supported search languages; and
- Dashboard configuration settings.
Most of this information relates to your business rather than to you as an individual.
5.3 Competitor Information
Where you choose to benchmark your Hotel against competitors, we process:
- competitor Hotel names;
- competitor website URLs; and
- comparative analytical data generated through Dashboard Scans.
Competitor information is used solely for comparative visibility analysis within your Dashboard.
5.4 Search Prompts
The Dashboard stores:
- automatically generated traveller search prompts;
- manually created prompts;
- edited prompts;
- disabled prompts; and
- language preferences associated with those prompts.
These prompts are used exclusively for performing AI Visibility Scans.
5.5 Scan Results
Each Scan may generate and store:
- visibility scores;
- AI mention rates;
- competitor comparisons;
- sentiment classifications;
- AI response excerpts;
- GEO Actions;
- technical website audit findings;
- historical Scan results; and
- trend data over time.
These results are retained to provide historical reporting and longitudinal analysis within the Dashboard.
5.6 Legal Acceptance Records
When you create your Dashboard account or accept updated legal documents, we record:
- accepted document versions;
- date and time of acceptance;
- IP address (where available);
- browser user agent; and
- associated Dashboard account.
These records are maintained for compliance, evidentiary and legal purposes.
5.7 Information We Do Not Collect
The Dashboard is designed to minimise the processing of personal data.
In particular, we do not intentionally collect or process:
- payment card information;
- guest reservation data;
- Property Management System (PMS) data;
- traveller personal information;
- booking records;
- passport or identity information;
- special categories of personal data within the meaning of Article 9 GDPR; or
- advertising or behavioural tracking identifiers.
At the time of publication of this Privacy Policy, the Dashboard does not include an integrated payment processor or advertising or analytics technologies.
6. How We Use Personal Data
We process Personal Data only where necessary to operate, maintain, improve and secure the Dashboard and to fulfil our contractual and legal obligations.
Depending on how you use the Dashboard, we may process Personal Data for one or more of the following purposes:
- creating and managing Dashboard accounts;
- authenticating users and maintaining secure login sessions;
- delivering the Dashboard Services;
- performing automated AI Visibility Scans;
- generating visibility scores, competitor analyses and GEO Actions;
- auditing publicly accessible sections of Hotel websites;
- storing historical Scan results and trend data;
- enabling Dashboard functionality and user preferences;
- preventing fraud, abuse and unauthorised access;
- enforcing scan limits and Subscription features;
- providing customer support;
- communicating important service-related information;
- maintaining the security, stability and availability of the Dashboard;
- complying with applicable legal obligations;
- establishing, exercising or defending legal claims;
- maintaining legal acceptance records;
- improving the quality, reliability and functionality of the Dashboard; and
- protecting the rights, property and security of myhotail, our Customers and third parties.
We do not sell Personal Data.
We do not use Personal Data for advertising purposes.
We do not build advertising profiles or behavioural marketing profiles.
7. Legal Bases for Processing
Under the GDPR, every processing activity must have a lawful basis.
Depending on the processing activity, we rely on one or more of the following legal bases.
7.1 Performance of a Contract (Article 6(1)(b) GDPR)
Most processing carried out by the Dashboard is necessary to provide the Services requested by the Customer.
This includes:
- creating Dashboard accounts;
- authenticating users;
- maintaining Dashboard sessions;
- storing Hotel profiles;
- performing AI Visibility Scans;
- generating reports and recommendations;
- maintaining Dashboard history;
- providing customer support; and
- delivering Subscription functionality.
Without this processing we would be unable to provide the Dashboard.
7.2 Legitimate Interests (Article 6(1)(f) GDPR)
We process certain Personal Data where necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms.
These legitimate interests include:
- operating and improving the Dashboard;
- protecting the Dashboard against misuse;
- preventing fraudulent activity;
- detecting security incidents;
- maintaining system stability;
- monitoring technical performance;
- enforcing these Terms;
- protecting our intellectual property;
- maintaining internal business records;
- improving scan methodologies;
- investigating abuse; and
- defending legal claims where necessary.
Whenever we rely upon legitimate interests, we carefully balance those interests against your privacy rights.
7.3 Consent (Article 6(1)(a) GDPR)
Where required by applicable law, we rely upon your consent.
This may include, for example:
- accepting updated legal documents where required;
- optional communications where consent is required by law; or
- future optional functionality introduced into the Dashboard.
You may withdraw consent at any time where processing is based upon consent.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
7.4 Legal Obligations (Article 6(1)(c) GDPR)
Certain Personal Data must be processed in order to comply with applicable legal obligations.
These obligations may include:
- accounting;
- taxation;
- financial record keeping;
- responding to lawful requests from competent authorities;
- complying with judicial or regulatory proceedings; and
- maintaining legally required business records.
8. AI Visibility Scans
The Dashboard performs automated AI Visibility Scans in order to analyse the visibility of your Hotel across supported AI Engines.
Each Scan may include:
- generating traveller-style search prompts;
- submitting those prompts to supported AI Engines;
- analysing whether your Hotel is mentioned;
- evaluating competitor mentions;
- measuring visibility metrics;
- classifying sentiment;
- generating visibility scores;
- producing GEO Actions; and
- storing historical results.
Scan results are intended solely as analytical business intelligence.
They should not be interpreted as guarantees regarding rankings, discoverability, bookings or commercial performance.
8.1 Search Prompts
The Dashboard automatically generates search prompts using information contained within your Hotel profile.
These prompts are designed to simulate realistic traveller searches.
Customers may edit, delete, disable or create additional prompts where supported.
8.2 AI Providers
During a Scan, search prompts are transmitted to supported third-party AI providers.
Importantly:
The name of your Hotel and the names of your competitors are not transmitted to AI providers.
Instead, the Dashboard generates generic location-based search prompts, such as:
“romantic boutique hotel near Brandenburg Gate Berlin”
or
“best family hotel in Kreuzberg Berlin”
The Dashboard performs Hotel mention detection and competitor matching locally after receiving AI responses.
This approach reduces the amount of business-specific information disclosed to third-party AI providers.
8.3 AI Responses
Responses generated by AI providers may be stored, in whole or in part, in order to:
- calculate visibility metrics;
- identify Hotel mentions;
- determine sentiment;
- compare competitors;
- generate recommendations;
- display historical results; and
- improve continuity between Dashboard Scans.
AI responses are not used to train proprietary myhotail AI models.
9. Website Crawling
As part of each AI Visibility Scan, the Dashboard automatically analyses publicly accessible portions of the Hotel website.
This may include, where publicly available:
- homepage HTML;
- robots.txt;
- sitemap.xml;
- metadata;
- structured data;
- headings;
- publicly accessible images and image attributes;
- technical configuration relevant to discoverability; and
- other publicly available information relevant to AI visibility.
The Dashboard does not intentionally access:
- password-protected pages;
- reservation systems;
- booking engines;
- Property Management Systems (PMS);
- customer databases;
- payment systems;
- email accounts; or
- any restricted systems.
Website crawling is limited to information intentionally made publicly available by the website operator.
By submitting a Hotel to the Dashboard, you confirm that you are authorised to permit this analysis of the publicly accessible portions of the submitted website.
10. Third-Party Service Providers and Sub-processors
To operate the Dashboard, we engage carefully selected third-party service providers (“Sub-processors”).
Each Sub-processor processes Personal Data only to the extent necessary to perform the services requested by myhotail.
At the time of publication of this Privacy Policy, the Dashboard uses the following principal service providers:
| Provider | Purpose | Information Processed |
|---|---|---|
| Supabase | Authentication, database hosting, secure storage and transactional authentication emails | Account information, Hotel profile information, Dashboard data |
| OpenAI | AI Visibility Scans (ChatGPT) | Generic location-based search prompts |
| Anthropic | AI Visibility Scans (Claude) | Generic location-based search prompts |
| Google (Gemini) | AI Visibility Scans | Generic location-based search prompts |
| Perplexity | AI Visibility Scans | Generic location-based search prompts |
| SearchApi.io | Retrieval of Google AI Overview results | Generic location-based search prompts |
| Google OAuth | Optional Google Sign-In | OpenID profile information (name, email address, profile image, account identifier) |
| hCaptcha | Bot protection during authentication | Bot-detection signals and challenge verification |
| Vercel | Cloud hosting and infrastructure | Application hosting, technical logs and infrastructure metadata |
We periodically review our Sub-processors and may replace or introduce additional providers where necessary to improve the Dashboard.
Where new Sub-processors materially affect the processing of Personal Data, this Privacy Policy will be updated accordingly.
11. International Data Transfers
Certain Sub-processors engaged by myhotail may process Personal Data outside the European Economic Area (“EEA”).
Where international transfers occur, myhotail implements appropriate safeguards in accordance with Chapter V GDPR.
Depending upon the provider and destination country, these safeguards may include:
- an adequacy decision adopted by the European Commission;
- certification under the EU–US Data Privacy Framework where applicable;
- the European Commission’s Standard Contractual Clauses (SCCs); or
- another legally recognised transfer mechanism.
We seek to work only with providers that maintain appropriate technical, organisational and contractual safeguards for the protection of Personal Data.
12. Data Retention
We retain Personal Data only for as long as necessary to fulfil the purposes described in this Privacy Policy, provide the Dashboard, comply with legal obligations and protect our legal rights.
Retention periods vary depending upon the category of information.
In general:
Account Information
Retained while your Dashboard account remains active.
Following account deletion, Account Information is deleted unless retention is required by applicable law or necessary for the establishment, exercise or defence of legal claims.
Hotel Profile Information
Retained while your Dashboard account remains active.
Deletion of your account permanently removes associated Hotel profile information except where retention is legally required.
Scan Results
Historical Scan results are retained while your Dashboard account remains active to provide historical reporting and trend analysis.
Deletion of your Dashboard account permanently removes associated Scan data unless legal retention obligations apply.
Legal Acceptance Records
Legal acceptance records may be retained after account deletion where necessary to demonstrate compliance with contractual or legal obligations or to establish, exercise or defend legal claims.
Technical Logs
Security logs and infrastructure logs are retained only for as long as reasonably necessary to ensure the security, integrity and stability of the Dashboard.
Where Personal Data is no longer required, we securely delete or anonymise it unless we are legally required or otherwise permitted to retain it.
13. Security Measures
Protecting Personal Data is a core principle of the Dashboard.
We implement appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
These measures include, where applicable:
- encrypted HTTPS communication;
- Supabase Authentication;
- hashed passwords managed by Supabase;
- Row-Level Security (RLS) within the database;
- secure cloud infrastructure;
- role-based access controls;
- authentication session management;
- bot protection using hCaptcha;
- infrastructure monitoring;
- security logging;
- regular software updates; and
- restricted administrative access based upon business need.
Although we take reasonable steps to protect Personal Data, no electronic transmission or storage system can be guaranteed to be completely secure.
Customers should therefore also take appropriate measures to protect their own devices, passwords and accounts.
14. Cookies and Similar Technologies
The Dashboard uses only cookies and similar technologies that are necessary for its operation and security.
At the time of publication of this Privacy Policy, the Dashboard uses:
Authentication Cookies
Supabase authentication cookies are used to maintain secure login sessions.
These cookies are strictly necessary for the operation of the Dashboard.
Preference Cookie
The Dashboard stores a language preference cookie that remembers your selected interface language.
This cookie does not contain sensitive Personal Data and is used solely to improve your user experience.
hCaptcha
The authentication pages use hCaptcha to protect the Dashboard against automated abuse, fraudulent registrations and credential attacks.
hCaptcha may set its own cookies or similar technologies as part of its security services.
No Advertising or Analytics Cookies
The Dashboard does not currently use:
- advertising cookies;
- behavioural profiling cookies;
- third-party analytics cookies;
- marketing pixels;
- cross-site tracking technologies; or
- similar advertising technologies.
If non-essential cookies are introduced in the future, we will update this Privacy Policy and, where required by law, obtain the necessary consent before placing such cookies.
15. Your Rights under the GDPR
Subject to the conditions and limitations provided by applicable data protection law, you have the following rights regarding your Personal Data.
15.1 Right of Access
You have the right to request confirmation as to whether we process your Personal Data and, where applicable, obtain access to that Personal Data together with additional information regarding the processing activities.
15.2 Right to Rectification
You have the right to request that inaccurate or incomplete Personal Data be corrected without undue delay.
Many items of Dashboard information may also be updated directly through your Dashboard account.
15.3 Right to Erasure
You have the right to request deletion of your Personal Data in accordance with Article 17 GDPR.
The Dashboard provides a self-service account deletion feature within the account settings.
Deleting your account permanently removes your Dashboard account together with associated Hotel profiles, competitor information, prompts, Scan results and related Dashboard data, except where continued retention is required by applicable law or necessary for the establishment, exercise or defence of legal claims.
15.4 Right to Restriction of Processing
Under certain circumstances, you may request that we restrict the processing of your Personal Data while particular issues are investigated or resolved.
15.5 Right to Object
Where processing is based upon our legitimate interests, you have the right to object to such processing where your particular circumstances justify doing so.
15.6 Right to Data Portability
You have the right to receive certain Personal Data that you have provided to us in a structured, commonly used and machine-readable format and, where technically feasible, to request that such information be transmitted directly to another controller.
Where self-service export functionality is not available, such requests may be submitted to us using the contact details provided below.
15.7 Right to Withdraw Consent
Where processing is based upon your consent, you may withdraw that consent at any time.
Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
15.8 Right to Lodge a Complaint
If you believe that your Personal Data has been processed unlawfully, you have the right to lodge a complaint with the competent data protection supervisory authority.
We nevertheless encourage you to contact us first so that we may attempt to resolve your concerns directly.
16. Automated Processing
The Dashboard performs certain automated processing activities in order to provide its Services.
These activities include:
- scheduled monthly AI Visibility Scans;
- automated website analysis;
- generation of search prompts;
- visibility score calculations;
- competitor benchmarking;
- sentiment classification;
- technical website audits; and
- generation of GEO Actions.
These automated processes are designed solely to analyse publicly available business information relating to Hotels.
They are not intended to evaluate individual users or make decisions producing legal or similarly significant effects concerning natural persons within the meaning of Article 22 GDPR.
The Dashboard does not use automated decision-making to determine employment, creditworthiness, insurance eligibility, legal rights or other comparable matters relating to individuals.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time in order to reflect:
- improvements to the Dashboard;
- changes to our processing activities;
- changes to applicable laws or regulations;
- changes to our Sub-processors;
- security improvements;
- new Dashboard functionality; or
- operational changes.
The most recent version will always be made available within the Dashboard and will include its effective date.
Where changes materially affect the processing of Personal Data, we will provide appropriate notice before such changes take effect where required by applicable law.
Where legally required, continued use of the Dashboard following material changes may require acknowledgement or acceptance of the updated Privacy Policy.
18. Contact
If you have any questions regarding this Privacy Policy, your Personal Data or your rights under applicable data protection laws, please contact us.
myhotail GbR
Strelitzer Str. 66
10115 Berlin
Germany
Authorised Representative Partners
Clemens Miller
Mateo Iacovelli
Email: info@myhotail.com
We are committed to handling privacy enquiries transparently, responsibly and in accordance with applicable data protection laws and will make reasonable efforts to respond within the time periods required by law.