Data Handling

We collect data to run your hostel, not to profit from it.

This page explains what data Dormaflow collects, how it's stored, who can access it, and your rights to that data.

Guest Data

Names, contact details, and booking history—stored to run your operations.

When a guest checks in, Dormaflow stores:

  • Full name and contact details (email, phone)
  • Check-in and check-out dates
  • Bed assignment and room details
  • Payment information (amount paid, date, method)
  • Any special requests or notes you add

What we don't do: We do not share guest data with marketing companies, airlines, or OTAs (except when you manually sync to Booking.com or Hostelworld). We do not use guest data to build profiles or send unsolicited marketing. We do not sell guest contact information. If a guest requests deletion of their data, you can remove them from Dormaflow and their data is permanently deleted from our systems.

Payment Data

Card details are never stored by Dormaflow. Stripe handles all payment data.

When a guest books through your Dormaflow booking page and pays by card, their payment goes directly to Stripe's secure servers. Dormaflow never sees the card number, expiration date, or CVV. Dormaflow only records that a payment was received, the amount, and the date. Stripe stores the encrypted card token and handles PCI compliance. This is the safest way to handle payments online.

Tenant Data Separation

Your hostel data is isolated from all other hostels.

If you manage multiple hostels, each one has its own separate workspace. A staff member at one hostel cannot see bookings, guest lists, or operational data from your other hostels. This isolation is enforced at the database level, not just the user interface, so no bug or misconfiguration can accidentally leak data between properties.

Analytics & Product Improvement

We track usage to improve the platform, not to track individuals.

Dormaflow tracks:

  • Which pages are viewed and how long users spend on them
  • Which features are used most (e.g., check-in flow, housekeeping queue)
  • When errors occur and what type they are
  • General metadata like browser type and operating system

What we don't track: We do not track individual keystrokes, form field values, passwords, or guest names. Analytics are aggregated and non-blocking—if tracking fails, your app continues working normally.

Why we do this: Understanding which features solve real problems helps us prioritize development. If check-in fails frequently, we fix it. If the housekeeping queue is slow, we optimize it. Your operational success is our success.

Data Access & Retention

You own your data. We keep it safe. You can export or delete it anytime.

Who can access your data?

Only your staff members with appropriate roles. Support staff can access your data only with your explicit permission and only to resolve technical issues. We never sell or share your data with third parties.

How long do we keep data?

As long as your Dormaflow account is active. Once you cancel, we retain data for 30 days to allow account recovery. After 30 days, all guest and operational data is permanently deleted. Audit logs are retained for 90 days for compliance purposes.

Can you export your data?

Yes. You can export all your guest data, bookings, and operational logs as CSV or JSON at any time. No lock-in.

Third-Party Services

Dormaflow uses trusted partners for specific services.

Stripe
Payment processing
Data: Payment card tokens, amounts, dates
Privacy policy →
Google Cloud
Infrastructure & data hosting
Data: All application and customer data
Privacy policy →
SendGrid
Transactional email (receipts, confirmations)
Data: Guest email addresses, booking details
Privacy policy →

Your Data Rights

You have control over your data and your guests' data.

  • Access: You can view, export, or download all your data from the platform dashboard anytime.
  • Correction: You can edit guest details, booking information, or any operational record.
  • Deletion: You can delete individual guest records or request full account deletion. All data is permanently removed within 30 days.
  • Portability: You can export your data in standard formats (CSV, JSON) to move to another platform.
  • Questions: Contact [email protected] with any privacy questions or concerns.

Other Trust Topics

Security

Role-based access and operational control

Reliability

How Dormaflow works during degraded connectivity

Privacy | Dormaflow