Security and privacy, no fine print.
You trust ViaHotel with your guests. We treat that as what it is: the most serious part of the product.
LGPD by design
We collect the minimum: the guest page works with no sign-up and no advertising. The only measurement there is anonymous usage analysis, to understand where navigation stalls — with whatever the guest types masked out. Personal data only enters with explicit consent (e.g. WhatsApp opt-in, pre-check-in) and a stated purpose.
Per-tenant isolation (RLS)
Each property lives in its own “vault”: Row-Level Security policies in the database guarantee that one hotel’s data is never visible to another — the rule is enforced in the database, not just in the interface.
End-to-end encrypted traffic
All traffic uses TLS. Sensitive pre-check-in data (documents, signatures) is also encrypted at rest with managed keys — not even our team reads it in plain text.
Minimal retention and automatic purge
Pre-check-in data is deleted automatically after the configured period (default: 30 days after checkout). Guest conversations and sessions store no personal identification without an opt-in.
Role-based access
Every team member sees only what they need: owner, admin, manager, editor and front-desk roles, scoped per property. Invitations expire and every administrative access is logged.
Your data is yours
Export everything (content, analytics, pre-check-ins) at any time, straight from the dashboard. When you cancel, you take your data with you — and you can request permanent deletion whenever you want.
In practice
Concrete commitments you can hold us to.
- ✓ Infrastructure on providers with industry certifications (SOC 2 / ISO 27001), with automatic backups and separate production and test environments.
- ✓ Payments processed by Stripe — card data never touches our servers.
- ✓ The public guest page loads no advertising pixels and no tracking for advertising. The only third-party measurement is anonymous usage analysis (heatmaps and session replay), with typed content masked and the pre-check-in entirely excluded from recording.
- ✓ Marketing pixels on the corporate website only load with your consent (LGPD banner).
- ✓ Data Protection Officer available at info@viahotel.com.br — we answer data subject requests within the deadlines set by the LGPD.
Full details in the Privacy Policy and the Terms of Service.