Privacy Policy
Last updated: July 2026 · Version 1.0
This policy explains how ViaHotel ("we") handles personal data under Brazil's General Data Protection Law — LGPD (Law No. 13.709/2018). It covers the entire ViaHotel service: the website, the customer dashboard and the guest pages.
1. Roles: when we are controller and when we are processor
For your account data (name, e-mail, billing details), ViaHotel is the controller. For the data of your property's guests (messages, pre-check-in), ViaHotel acts as processor — the property decides the purposes, and we process the data on its instructions.
2. What data we collect
- Account: name, e-mail, optional phone number, password when set (stored only as a hash by the authentication provider) and billing data (processed by Stripe).
- Sign in with Google: when you choose this method, Google sends us your account identifier, name, verified e-mail and profile picture. We use this data only to create, connect and authenticate your ViaHotel account; we do not request access to Gmail, Drive, Calendar or any other Google product.
- Marketing attribution: if you arrive from an ad or a referral, we store URL parameters (utm, ref, coupon) in our own first-party cookie (
vh_attr, 90 days) — without identifying you personally. - Guests: the guest page works without any sign-up. Personal data is only collected through an explicit guest action: a WhatsApp opt-in or filling in the pre-check-in (encrypted and automatically deleted after the retention period set by the property).
- Product usage: technical events and aggregate metrics (scans, questions answered) to operate and improve the service.
3. Legal bases
We process data on the following bases: performance of a contract (account, billing, support), legitimate interest (security, aggregate metrics, fraud prevention), consent (marketing cookies, promotional communications, WhatsApp opt-in) and compliance with legal obligations (invoices, FNRH guest registration where applicable).
4. Cookies
We use essential cookies (session, preferences, first-party attribution) and — only with your consent in the banner — campaign measurement and usage analysis cookies, including heatmaps and anonymous session replay (Microsoft Clarity), which record clicks, scrolling and mouse movement, without identifying you and without capturing what you type. The public guest page uses the same anonymous analysis, in a separate project and for the sole purpose of improving navigation: no advertising pixel, typed content (chat, concierge, orders) masked, and the pre-check-in entirely excluded from recording. You can change your choice by clearing the site data in your browser.
5. Sharing
We do not sell data. We share it only with the sub-processors the service requires: cloud and database infrastructure, authentication (Supabase and Google, when that method is chosen), payment processing (Stripe), transactional e-mail delivery, WhatsApp Business (Meta) when you enable notifications, and AI providers that generate Concierge answers (they receive only the published property content and the question, never account data).
Ad measurement. When you arrive through one of our ads and create an account, we send Meta (Facebook/Instagram) and Google the milestones of that journey — visited the page, submitted the sign-up, confirmed the e-mail, published the property, went to payment and subscribed. This is how we learn which ad brings actual customers. What goes with it: your e-mail turned into an irreversible code (never in readable text), the campaign cookie identifiers and the value of the plan subscribed. Part is sent from your browser and part from our server, carrying the same identifier so nothing is counted twice.
Ad audiences. We also send Meta lists of hospitality business contacts — obtained from public company registries, always with the e-mail turned into that same irreversible code — so the platform can find people with a similar profile to show ads to. People on the list do not become targets by being on it.
Both depend on your consent in the banner: choosing “Essential only” stops the sending immediately. Meta and Google process this data in the United States — that is an international transfer, carried out under each provider’s standard contractual clauses. You may request deletion at any time at the e-mail below.
6. Data subject rights
You (and the guests of each property) may request: confirmation of processing, access, correction, anonymisation, portability, deletion and information about data sharing. Account owners can export and delete data directly in the dashboard; any data subject may write to info@viahotel.com.br. We reply within the deadlines set by the LGPD.
7. Retention and security
We keep data only as long as the purposes require: pre-check-in data is purged automatically (default 30 days after checkout, configurable); account data is deleted within 30 days of closure, except what the law requires us to keep. Our security measures are described in Security & data protection.
8. Data Protection Officer and contact
Data Protection Officer: the ViaHotel team — info@viahotel.com.br. ViaHotel is a product of the Slideworks group, developed and operated by Slideworks Tecnologia LTDA, registered under Brazilian company number (CNPJ) 50.511.436/0001-13. More information at slideworks.cc.
9. Changes to this policy
If something relevant changes, we notify you by e-mail and in the dashboard in advance. The version in force is always the one on this page.