Your information and MyHotels
This policy explains how personal information is collected, used, stored, protected, and disclosed when owners, employees, and guests interact with the MyHotels hotel-management platform.
Hotel owners generally decide which guest and employee information is entered into MyHotels and why it is used. If you are a hotel guest, the relevant hotel is normally your first point of contact for questions about your booking information.
Scope of this policy
This policy applies to the MyHotels website, registration and verification process, authenticated dashboard, hotel records, room and booking features, guest directory, employee assignments, payment records, housekeeping tasks, reports, uploaded room photographs, and related communications.
It does not govern an individual hotel’s independent website, surveillance systems, payment terminals, marketing activities, Wi-Fi service, or other systems that do not operate through MyHotels. Hotels should provide their own privacy information where required.
Privacy roles and responsibilities
For account-registration, authentication, security, and platform administration information, the MyHotels service operator determines how information is processed. For guest, booking, hotel-employee, payment, and operational records entered by a hotel, the hotel owner or operating organization generally determines the purpose and means of processing.
Hotel owners are responsible for ensuring that they have a lawful basis to enter Personal Data, provide required notices, respond to guest and employee requests, configure employee access appropriately, and comply with applicable privacy and data-protection requirements.
Information we may collect
Owner and employee account data
This includes names, email addresses, telephone numbers, password hashes, account roles, hotel assignments, permission levels, verification status, acceptance of legal terms, login timestamps, and account status.
Hotel and operational data
This includes hotel names, addresses, contact information, floor counts, rooms, room types, amenities, photographs, rates, taxes, operating times, availability, maintenance status, housekeeping instructions, and employee assignments.
Guest and booking data
This may include guest names, email addresses, telephone numbers, nationality, address, identification type and number, stay dates, room assignments, companions or occupancy counts, booking source, special requests, notes, and booking status.
Payment and financial records
This includes amounts, payment methods, transaction or receipt references, payment timestamps, rates, taxes, discounts, balances, and the employee who recorded a transaction. MyHotels should not be used to store complete card numbers, card security codes, mobile-money PINs, or online-banking passwords.
Technical and security information
The platform may process IP addresses, session identifiers, browser and device information, timestamps, error logs, audit events, uploaded-file metadata, and security events needed to authenticate users, diagnose failures, and protect the service.
How information is used
Information may be processed to:
- Create, verify, authenticate, and administer owner and employee accounts.
- Separate hotels and enforce property-specific permissions.
- Manage rooms, availability, bookings, guests, check-in, checkout, payments, housekeeping, and operational reports.
- Send verification messages, security alerts, and essential service communications.
- Produce receipts, exports, occupancy information, revenue summaries, and audit records.
- Prevent fraud, unauthorized access, abuse, malicious uploads, and interference with the service.
- Maintain, troubleshoot, support, secure, and improve platform functionality.
- Comply with lawful requests, legal obligations, dispute resolution, and enforcement of the Terms of Service.
Personal information will not be sold. It should not be used for unrelated advertising or profiling without a separate lawful basis and appropriate notice.
Legal grounds for processing
Depending on the circumstances and applicable law, processing may be necessary to perform a service agreement, take steps requested before entering an agreement, pursue legitimate interests in providing and securing hotel-management services, comply with legal obligations, protect vital interests, or act with consent.
Hotels are responsible for identifying the proper legal ground for guest and employee information they control. Consent should only be relied upon where it is freely given, specific, informed, and capable of being withdrawn.
Security safeguards
Measures may include password hashing, authenticated sessions, CSRF protection, prepared database queries, hotel-specific access checks, role restrictions, encrypted transport, email verification, upload restrictions, server logging, and restricted storage of private configuration.
No security measure eliminates all risk. Owners and employees must protect credentials, use trusted devices and networks, restrict exports and printed records, maintain current contact information, and report suspected unauthorized access promptly.
Do not send passwords, database credentials, card security codes, or mobile-money PINs by email or place them in guest notes.
How long information is retained
Information is retained for as long as reasonably necessary to provide the service, maintain hotel records, comply with legal and accounting obligations, resolve disputes, enforce agreements, and preserve security logs. Different categories may have different retention periods.
Hotels determine retention periods for guest, booking, employee, and financial information under their control. When an account or hotel is closed, records may remain temporarily in backups or be retained where law, fraud prevention, dispute resolution, or legitimate operational needs require it.
When retention is no longer necessary, information should be deleted, anonymized, or rendered inaccessible using reasonable procedures.
Privacy rights and choices
Subject to applicable law, an individual may have rights to request access, correction, deletion, restriction, objection, portability, or information about processing. An individual may also have the right to complain to an appropriate data-protection authority.
Hotel guests and hotel employees should normally contact the hotel owner or management first because the hotel controls the relevant operational records. Account owners may contact the service using the address below for account-level requests. Identity and authority may need to be verified before a request is fulfilled.
Some requests may be limited where information must be retained for legal obligations, financial records, security, fraud prevention, legal claims, or the rights of other people.
Hosting and international processing
Hosting, email, backup, or infrastructure providers may process information in countries other than the user’s location. Where cross-border safeguards are legally required, reasonable contractual, organizational, or technical protections should be used.
Users should consider whether their legal or contractual obligations impose data-location requirements before entering regulated or highly sensitive information.
Children’s information
MyHotels accounts are intended for adults authorized to operate or work for hotels. Hotels may accommodate children and may need limited information about them for lawful booking and safety purposes. Hotels should collect only information that is necessary, apply appropriate safeguards, and obtain authorization from a parent or guardian where required.
Changes to this policy
This policy may be updated when services, legal requirements, processing practices, or providers change. The effective date and version at the top identify the current policy. Material changes may be communicated through the platform or account contact details.
Questions, requests, and concerns
For information controlled by a specific hotel, contact that hotel first. For account-level or platform privacy questions, contact no-reply@myhotels.co.tz.
Include your full name, contact information, relevant hotel, your relationship to the hotel, and a clear description of the request. Do not send passwords or sensitive identification documents unless specifically requested through a secure method.