Skip to main content Skip to navigation

    Vendor Privacy Directory v1

    The hotel vendor privacy questions every portfolio should be able to answer.

    A public reference directory for common hotel systems and the privacy documentation checks they usually trigger. Use it to start vendor review, then verify every answer against your actual contract and implementation.
    View Posture Summary

    Reference-grade

    Useful for scoping and review, not a substitute for contract verification.

    DPA-focused

    Flags the privacy terms and vendor documents hotel teams should locate.

    Hotel-specific

    Organized around PMS, CRS, POS, CRM, payment, and operational systems.

    Top 10 Vendor Starters

    Start with the systems most likely to touch guest records.

    Directory entries are intentionally practical: what the system usually touches and what your team should verify.

    Property Management System

    Oracle Hospitality OPERA

    Typical Data

    Guest profiles, reservations, folios, payment references, preferences, stay history

    Review Checks

    Confirm PMS agreement, DPA or data processing terms, subprocessors, retention/export procedures

    Central Reservation System

    Sabre SynXis

    Typical Data

    Reservations, rates, booking channel details, contact data, loyalty references

    Review Checks

    Confirm controller/processor role, booking data flow, DPA status, transfer terms, OTA interfaces

    CRS, Sales, and Distribution

    Amadeus Hospitality

    Typical Data

    Reservations, group sales, event records, guest profiles, distribution data

    Review Checks

    Review DPA coverage, product modules in scope, subprocessors, and international transfer terms

    PMS and Channel Management

    Cloudbeds

    Typical Data

    Guest profiles, reservations, channel data, invoices, communications, payment references

    Review Checks

    Confirm DPA status, processor role, subprocessor list, deletion/export process, and channel data sharing

    Hospitality Cloud / PMS

    Mews

    Typical Data

    Guest profiles, reservations, stay history, payments, housekeeping and operational records

    Review Checks

    Confirm DPA, subprocessors, EU transfer posture, retention controls, and payment processor boundaries

    Payment Processing

    Stripe

    Typical Data

    Payment tokens, billing records, transaction metadata, fraud signals, contact details

    Review Checks

    Document payment role, PCI boundary, DPA or data processing terms, retention and dispute-data handling

    Point of Sale

    Oracle MICROS

    Typical Data

    F&B transactions, room charges, staff activity, guest identifiers tied to folios

    Review Checks

    Confirm POS/PMS data flow, DPA status, processor role, retention, and payment-data boundaries

    CRM and Guest Marketing

    Revinate

    Typical Data

    Guest profiles, stay history, preferences, email engagement, survey and campaign records

    Review Checks

    Review marketing consent, sale/share exposure, DPA status, unsubscribe handling, and audience syncing

    Guest Messaging and Digital Check-In

    Canary Technologies

    Typical Data

    Guest contact data, identification workflow data, messages, upsell activity, check-in records

    Review Checks

    Confirm identity-document handling, DPA status, subprocessors, retention, and messaging consent flows

    Revenue Management

    Duetto

    Typical Data

    Reservation demand, rates, booking patterns, market segments, possible guest-linked reservation signals

    Review Checks

    Confirm whether data is aggregated or guest-identifiable, DPA status, model-training use, and transfer terms

    Vendor Review Checklist

    The five questions that turn a vendor list into a compliance record.

    Is the vendor acting as a service provider, processor, controller, or third party?

    Is a DPA, data processing addendum, or equivalent privacy contract executed?

    Does the vendor publish subprocessors and international transfer terms?

    Does the vendor receive sensitive personal information, payment data, or identity documents?

    Can the hotel export, correct, delete, or suppress relevant guest records when required?

    Need hotel-specific verification?

    Turn your vendor stack into documented evidence.