Transparency & Data Protection

Privacy Policy

Last Updated: August 25, 2026·Version 1.2

1. Introduction

Grove ("we," "our," or "the Platform") provides a multi-tenant cloud-based Property Management System (PMS) designed for hotels, boutique properties, resorts, and hospitality operators ("Hotels" or "Customers").

This Privacy Policy explains how we collect, process, store, and safeguard data when hotels use Grove to manage front desk operations, reservations, billing, housekeeping, inventory, and staff permissions.

2. Data Controller vs. Data Processor Distinction

Important Clarification:

The Hotel operates as the Data Controller for all guest details, reservation records, stay histories, and guest folio billing data inputted into Grove. Grove operates strictly as the Data Processor providing the technical infrastructure to store and process this operational information on behalf of the Hotel.

3. Information We Collect

We collect information in three primary operational categories:

  • Hotel Account Data: Hotel name, business address, contact person, billing email, tax/GST identifiers, and room category configurations.
  • Staff User Data: Operational staff names, professional email addresses, assigned operational roles (Owner, Manager, Reception, Housekeeping), and system activity timestamps.
  • Guest & Stay Data (Processed on behalf of Hotels): Guest full names, phone numbers, email addresses, check-in/check-out dates, room assignments, identity verification document references, folio transactions, and payment mode metadata.

4. How We Use Your Information

We utilize the collected information strictly for operational and technical service fulfillment:

  • Authenticating authorized hotel owners and staff members into their property workspace.
  • Enforcing multi-tenant database isolation so that each hotel only accesses its own property data.
  • Generating compliant hotel folios, GST invoices, and financial reports requested by hotel staff.
  • Maintaining operational audit trails for check-ins, check-outs, room status shifts, and billing adjustments.
  • Providing technical support, service uptime monitoring, and critical platform security notices.

5. Data Storage & Tenant Isolation Architecture

Grove is engineered on PostgreSQL with Row-Level Security (RLS). All hotel operational data — including rooms, reservations, folios, KOT orders, and staff records — is strictly scoped by a unique hotel_id.

Database-level policies ensure that staff from Hotel Alpha can never view, query, or mutate records belonging to Hotel Beta.

6. Data Sharing & Third-Party Processors

We do not sell, rent, or trade hotel, staff, or guest personal data to data brokers, advertisers, or third parties.

We engage selected technical infrastructure providers solely to deliver platform functionality:

  • Supabase (Authentication & Database): Used for secure token-based user authentication, session management, and encrypted database hosting.
  • Hosting Infrastructure: Used to serve the web application over HTTPS with standard TLS encryption.

7. Data Retention & Deletion

Operational hotel data is retained for the duration of the Hotel's active account with Grove. Upon account termination or written request by an authorized Hotel Owner, we provide data export options and initiate secure deletion procedures in accordance with applicable statutory record-keeping periods.

8. Hotel / Customer Responsibilities

Hotels using Grove are responsible for:

  • Obtaining any necessary consent from guests before inputting personal data into the PMS.
  • Ensuring that staff credentials are safeguarded and not shared among multiple employees.
  • Complying with local hospitality laws regarding guest register maintenance and tax filing.

9. User Rights

Staff and account owners have the right to inspect, update, or correct their account profile information. Guests seeking to exercise data subject rights regarding stay histories or personal details should contact the specific Hotel where they stayed, as the Hotel is the designated Data Controller.

10. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect architectural updates or regulatory adjustments. Any revisions will be published on this page with an updated "Last Updated" date.

11. Contact Us

If you have questions about this Privacy Policy or Grove's data handling practices, please contact our privacy team:

Grove Privacy & Data Governance

Email: privacy@grovepms.com

Website: https://grovepms.com/privacy-policy