viahotel

Security and privacy, no fine print.

You trust ViaHotel with your guests. We treat that as what it is: the most serious part of the product.

LGPD by design

We collect the minimum: the guest page works with no sign-up and no advertising. The only measurement there is anonymous usage analysis, to understand where navigation stalls — with whatever the guest types masked out. Personal data only enters with explicit consent (e.g. WhatsApp opt-in, pre-check-in) and a stated purpose.

Per-tenant isolation (RLS)

Each property lives in its own “vault”: Row-Level Security policies in the database guarantee that one hotel’s data is never visible to another — the rule is enforced in the database, not just in the interface.

End-to-end encrypted traffic

All traffic uses TLS. Sensitive pre-check-in data (documents, signatures) is also encrypted at rest with managed keys — not even our team reads it in plain text.

Minimal retention and automatic purge

Pre-check-in data is deleted automatically after the configured period (default: 30 days after checkout). Guest conversations and sessions store no personal identification without an opt-in.

Role-based access

Every team member sees only what they need: owner, admin, manager, editor and front-desk roles, scoped per property. Invitations expire and every administrative access is logged.

Your data is yours

Export everything (content, analytics, pre-check-ins) at any time, straight from the dashboard. When you cancel, you take your data with you — and you can request permanent deletion whenever you want.

In practice

Concrete commitments you can hold us to.

  • Infrastructure on providers with industry certifications (SOC 2 / ISO 27001), with automatic backups and separate production and test environments.
  • Payments processed by Stripe — card data never touches our servers.
  • The public guest page loads no advertising pixels and no tracking for advertising. The only third-party measurement is anonymous usage analysis (heatmaps and session replay), with typed content masked and the pre-check-in entirely excluded from recording.
  • Marketing pixels on the corporate website only load with your consent (LGPD banner).
  • Data Protection Officer available at info@viahotel.com.br — we answer data subject requests within the deadlines set by the LGPD.

Full details in the Privacy Policy and the Terms of Service.