Legal
Privacy Policy
Rendezvo (City Insider)
Effective date: July 23, 2026 (provisional - updated once reviewed and approved)
1. Who we are
Rendezvo, [LEGAL ENTITY NAME] ("Rendezvo," "we," "us") is a hotel's City Insider delivered to guests over WhatsApp and SMS. A guest messages in and gets a real, sequenced, timed night-out plan, branded as the hotel's own. Contact: privacy@rendezvo.app | hello@rendezvo.app | [MAILING ADDRESS]
2. Two kinds of data, two roles
We handle personal information in two distinct capacities:
(a) Data we collect directly (we act as the "business"/controller). Information from visitors to our marketing site and from hotel staff who administer Rendezvo on behalf of their property.
(b) Guest data we process for our hotel customers (we act as a "service provider"/processor). The hotel is the business/controller of its guests' data. We process guest data only on the hotel's documented instructions, to deliver the City Insider service to that hotel's guests. If you're a hotel guest, the hotel controls your data, not Rendezvo. Direct any privacy request to the hotel; we'll assist them in fulfilling it.
3. Information we collect directly
- Contact and account data: name, business email, hotel name, role, login credentials, when hotel staff set up or manage Rendezvo, or when a visitor fills out a form on our site.
- Usage data: pages visited on our site, device and browser type, IP address, collected via cookies and similar technologies (see our Cookie Policy).
- Communications: emails, support requests, call notes.
4. Guest data we process for hotels
When a guest opts in, by messaging in or at check-in, we process: the guest's phone number; the messages exchanged with the City Insider; stated preferences (mood, party size, budget, timing, cuisine); the generated night-out plan; and any hotel- or stay-context the hotel chooses to share with us (such as dates of stay or room type). This is a minimal, opt-in set of data collected to build and deliver the plan.
5. How we use information
Data we collect directly: to provide and improve our site and the service, respond to inquiries, send service and (with opt-out) marketing communications, secure our systems, and comply with law.
Guest data processed for hotels: only to deliver the contracted City Insider service, including generating the night-out plan as described in our AI & Automated Processing Disclosure. Guest data is never used for our own marketing or advertising, never sold, and never used to train AI models without the hotel's written consent.
6. How we share information
We share personal information only with: subprocessors that help us run the service (cloud hosting, our LLM inference provider, our SMS/WhatsApp messaging provider, database hosting, our email/form provider) under contracts restricting their use of the data; professional advisers; authorities when legally required; and a successor entity in a merger or acquisition.
We do not sell personal information and we do not share it for cross-context behavioral advertising. As a service provider, we are contractually prohibited from selling, retaining, or using guest data outside the contracted service.
7. Retention
Direct data: kept as long as the account or relationship is active, then deleted or de-identified within [12] months unless the law requires longer. Guest data: retained only as long as needed to deliver the plan and support the stay, then deleted per the hotel agreement; a guest, or the hotel on the guest's behalf, can request erasure at any time (see Section 9).
8. Security
Encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access controls with MFA, minimal data retention, logging, and vendor due diligence. SOC 2 Type II is on our roadmap; we are not yet certified. No system is perfectly secure; we will notify affected parties of breaches as required by applicable law.
9. Your privacy rights
EU and UK guests. If you are located in the EEA or UK, GDPR gives you rights to access, correct, delete, restrict, or port your personal information, and to object to certain processing. We process your data based on your consent, given by opting in via WhatsApp/SMS or at check-in.
US guests. Depending on your state (including California, Colorado, Connecticut, Texas, Utah, Virginia, and others with comprehensive privacy laws), you may have the right to know/access, correct, delete, and obtain a portable copy of your personal information, and to opt out of sale, sharing, or targeted advertising (we do none of these). We honor Global Privacy Control signals.
To exercise rights: email privacy@rendezvo.app. We locate and erase guest data by phone number across our datastore. We verify requests, respond within the statutory window (generally 30 days for GDPR, 45 days for US state laws), and will not discriminate against you for exercising rights. Hotel guests may also submit requests to their hotel; we assist the hotel as its service provider.
10. Children
The service is not directed to anyone under 16. We do not knowingly collect children's data on our own behalf, and we ask hotels not to route guests under 16 to the service without a parent or guardian's involvement.
11. Changes
We will post updates here with a new effective date; material changes will be flagged on the site or by email.
12. Contact
privacy@rendezvo.app | hello@rendezvo.app | [MAILING ADDRESS]