Vendor Privacy Directory v1
The hotel vendor privacy questions every portfolio should be able to answer.
Reference-grade
DPA-focused
Hotel-specific
Top 10 Vendor Starters
Start with the systems most likely to touch guest records.
Directory entries are intentionally practical: what the system usually touches and what your team should verify.
Oracle Hospitality OPERA
Typical Data
Guest profiles, reservations, folios, payment references, preferences, stay history
Review Checks
Confirm PMS agreement, DPA or data processing terms, subprocessors, retention/export procedures
Sabre SynXis
Typical Data
Reservations, rates, booking channel details, contact data, loyalty references
Review Checks
Confirm controller/processor role, booking data flow, DPA status, transfer terms, OTA interfaces
Amadeus Hospitality
Typical Data
Reservations, group sales, event records, guest profiles, distribution data
Review Checks
Review DPA coverage, product modules in scope, subprocessors, and international transfer terms
Cloudbeds
Typical Data
Guest profiles, reservations, channel data, invoices, communications, payment references
Review Checks
Confirm DPA status, processor role, subprocessor list, deletion/export process, and channel data sharing
Mews
Typical Data
Guest profiles, reservations, stay history, payments, housekeeping and operational records
Review Checks
Confirm DPA, subprocessors, EU transfer posture, retention controls, and payment processor boundaries
Stripe
Typical Data
Payment tokens, billing records, transaction metadata, fraud signals, contact details
Review Checks
Document payment role, PCI boundary, DPA or data processing terms, retention and dispute-data handling
Oracle MICROS
Typical Data
F&B transactions, room charges, staff activity, guest identifiers tied to folios
Review Checks
Confirm POS/PMS data flow, DPA status, processor role, retention, and payment-data boundaries
Revinate
Typical Data
Guest profiles, stay history, preferences, email engagement, survey and campaign records
Review Checks
Review marketing consent, sale/share exposure, DPA status, unsubscribe handling, and audience syncing
Canary Technologies
Typical Data
Guest contact data, identification workflow data, messages, upsell activity, check-in records
Review Checks
Confirm identity-document handling, DPA status, subprocessors, retention, and messaging consent flows
Duetto
Typical Data
Reservation demand, rates, booking patterns, market segments, possible guest-linked reservation signals
Review Checks
Confirm whether data is aggregated or guest-identifiable, DPA status, model-training use, and transfer terms
Vendor Review Checklist
The five questions that turn a vendor list into a compliance record.
Is the vendor acting as a service provider, processor, controller, or third party?
Is a DPA, data processing addendum, or equivalent privacy contract executed?
Does the vendor publish subprocessors and international transfer terms?
Does the vendor receive sensitive personal information, payment data, or identity documents?
Can the hotel export, correct, delete, or suppress relevant guest records when required?