Privacy Policy
Last updated: August 10, 2026
1. Introduction & Roles (Controller vs. Processor)
Welcome to Eco-Credit ("we", "our", or "us"). We are dedicated to respecting and protecting the privacy of our partner hoteliers, staff, and hotel guests under the General Data Protection Regulation (GDPR / AVG).
Under EU data protection law, our role depends on whose data is being processed:
- For Partner Hotels & Admin Staff: Eco-Credit acts as the Data Controller for administrator account credentials, contact information, billing records, and configuration parameters.
- For Hotel Guests: The Partner Hotel acts as the Data Controller, while Eco-Credit acts as a Data Processor operating strictly on behalf of the hotel to dispatch WhatsApp messages, record housekeeping skips, and issue room credits.
If you have any questions or wish to exercise your privacy rights, contact us at privacy@eco-credit.nl.
2. Information We Process
To provide our automated reward incentive engine, we process specific categories of data collected directly from partner hotels via Mews API integrations and guest interactions:
- Hotel Admin & Account Data: Hotel name, staff email addresses, time zones, billing preferences, and whitelisted product outlets.
- Housekeeping Status Logs: Room numbers and dates marked as "skipped", "delayed", or "completed" to calculate credit accruals and environmental savings.
- Guest Messaging & Stay Information: Guest mobile phone numbers, reservation checkout dates, stay duration, and opt-in choices for the Eco-Credit program. We minimize direct personally identifiable information (PII) and tokenize reservation references wherever possible.
- Financial & Sustainability Impact Metrics: Calculated water, energy, and laundry savings totals used to post folio rebates and aggregate ESG impact reports.
3. Legal Basis for Processing (GDPR Art. 6)
We process personal data only when a valid legal basis exists under GDPR Article 6:
- Contract Performance (Art. 6(1)(b)): Processing hotel admin accounts, Mews API syncs, and issuing credits necessary to provide the Eco-Credit service agreed with the hotel.
- Legitimate Interest (Art. 6(1)(f)): Processing guest phone numbers and stay dates to deliver automated in-stay messaging and room cleaning skip prompts on behalf of the host hotel, improving operational efficiency and sustainability.
- Legal Obligation (Art. 6(1)(c)): Retaining financial transaction and billing records to satisfy Dutch tax and accounting mandates (Rijksbelastingdienst).
4. Sub-Processors & Data Sharing
We never sell, rent, or trade personal data. We share data only with authorized sub-processors necessary to run the platform:
- Mews PMS Infrastructure: Guest credits, voucher adjustments, and housekeeping room statuses are synced directly with the host hotel's authorized Mews Property Management System.
- Meta Cloud API (WhatsApp Business): We utilize Meta Cloud API endpoints (Meta Platforms Ireland Ltd.) to dispatch automated WhatsApp welcome greetings, daily prompts, and credit confirmations to guest phone numbers. Meta processes this data strictly as a communications service provider on our behalf.
- Cloud Hosting & Database (Supabase / AWS): Database hosting and backend logic run on Supabase (hosted on AWS in EU regions), complying with SOC2 Type II and ISO 27001 standards.
- Legal Mandates: Where required by law to comply with judicial proceedings or enforceable government requests.
5. Data Retention & Storage
All data in transit is encrypted using TLS 1.3, and stationary databases utilize AES-256 transparent encryption with Supabase Row-Level Security (RLS) ensuring total multi-tenant data isolation.
We retain personal data strictly as long as necessary:
- Guest Phone Numbers & Stay Logs: Retained for the duration of the guest's stay plus 30 days post-checkout for rebate audit reconciliation, after which guest interaction logs are permanently deleted or anonymized.
- Hotel Admin Accounts & Financial Records: Retained for the active duration of the hotel subscription plus 7 years to comply with Dutch statutory accounting obligations.
6. Cookies & Trackers
Our platform uses strictly necessary session cookies for administrator authentication and secure API access. We do not use third-party advertising cookies or cross-site tracking technologies. For full details, see our Cookie Policy.
7. Your GDPR Rights
Under GDPR, individuals have rights regarding their personal data, including the right to access, rectify, erase, restrict processing, or port data. To exercise any of these rights, or if a guest wishes to request data deletion, contact our privacy team at privacy@eco-credit.nl.
8. User Data Deletion Instructions
In compliance with Meta Platform Policies and GDPR regulations, users (including guests receiving WhatsApp notifications) may request the deletion of personal data processed by Eco-Credit:
- Send an email to privacy@eco-credit.nl with the subject line "Data Deletion Request".
- Include your name, associated phone number or email address, and hotel name (if applicable).
- We will verify the request, process data deletion within 30 days, and issue a written confirmation.
9. Contact & DPO Information
Eco-Credit Security & Data Privacy TeamEmail: privacy@eco-credit.nl