Legal

SabeeApp GO Privacy Policy

Privacy policy for the SabeeApp GO mobile front-desk application.

Last updated[DATE]

Applies toHotel staff using SabeeApp GO and guests whose data is processed through the App by a Property.
ReplacesFront Office Manager (FOM) Mobile Application Privacy Policy
Owned bythePass Kft — SabeeApp is the brand name of its software.

1. Introduction

thePass Kft. ("SabeeApp," "we," "us," or "our") develops and operates SabeeApp GO (the "App"), a mobile front-desk application for hotels, apartments, and hostels ("Properties") that use the SabeeApp Hotel Management Software ("SabeeApp PMS"). This Privacy Policy explains what personal data the App processes, why, on what legal basis, and what rights are available to the people concerned.

SabeeApp GO replaces the previous Front Office Manager ("FOM") application. GO processes meaningfully more personal data than FOM did — most importantly, it scans and transfers identity documents (passports, national ID cards, driving licences, and address/registration cards) and displays and lets staff edit guest contact details. This Policy reflects that.

If you are a guest whose data was processed through SabeeApp GO by a Property, please also see Section 4 ("Who is responsible for my data?") — in most cases your data protection rights must be exercised against the Property (the hotel, apartment, or hostel), not against SabeeApp directly, because the Property is the data controller for guest data.

If you are a staff member / user of a Property using the App to log in and operate it, Section 4 explains that SabeeApp is the controller for your own account and usage data.

2. Scope

This Policy applies to:

  • The SabeeApp GO mobile application (iOS and Android);
  • Data processed when a Property's staff member scans a guest's identity document, views/edits guest contact details, places a call or sends an email from within the App, or otherwise uses the App's features;
  • Data about the staff member's own use of the App (account, device, diagnostics).

This policy does not cover

  • The SabeeApp PMS web platform or website (see the general SabeeApp Privacy Policy);
  • GuestAdvisor, the Housekeeping App, or other SabeeApp modules, each of which has its own privacy documentation;
  • Any Property's own privacy notice to its guests, which the Property is separately responsible for maintaining (see Section 4).

3. What data we collect

3.1 Data about App users (Property staff)

To use SabeeApp GO, a staff member must have a valid SabeeApp PMS user account with at least operator-level access. We (or the App, on our behalf) process:

  • Account data: username, hashed login credentials, assigned Property/Properties, user role/permissions;
  • Device and technical data: device type, operating system and version, App version, device identifiers, IP address, language/locale settings;
  • Usage data: features used, screens viewed, session length, timestamps of actions performed in the App (e.g., check-in completed, call initiated), crash and diagnostic logs;
  • Location data: only if the operating system-level location permission is granted by the staff member; used solely for [diagnostic / fraud-prevention / analytics — CONFIRM PURPOSE] purposes; the App will request this permission explicitly and it can be declined without losing core functionality;
  • Feature requests: any text, screenshots, or other content submitted through the in-app "send feedback / feature request" tool, together with the account and device data needed to route and respond to the request.

3.2 Data about guests (processed on behalf of the Property)

When a staff member uses the App to check in a guest, SabeeApp GO processes the following categories of guest personal data, strictly as instructed by, and on behalf of, the Property:

  • Identity document data, captured via the App's camera-based scanning feature, from any of: passports, national ID cards, driving licences, and address/residence registration cards. Depending on the document type and country, this can include: full name, date and place of birth, nationality, sex, document number, issuing authority, issue and expiry dates, residential address, a photograph of the holder, and a digital image/scan of the document itself;
  • Contact details: phone number and email address, whether synced from an existing PMS reservation or added/edited by staff directly in the App;
  • Reservation data: booking reference, room assignment, arrival/departure dates, folio/payment status shown for context (e.g., "Payment received"), and any notes staff add;
  • Communication metadata: a record that a call or email was initiated from the App to a guest (we do not record call audio or store the content of emails sent through the guest's own phone/email apps — see Section 6);
  • Documents synced from GuestAdvisor: where a guest has pre-scanned their document via GuestAdvisor before arrival, that previously-collected data is synced into the Property's record and is visible in GO at check-in.

We do not intentionally collect special categories of data beyond what is inherently printed on an identity document (e.g., some national ID/driving licence formats disclose organ donor status or similar). We do not use this incidental data for any purpose and instruct staff not to record it separately.

3.3 Data we do not collect

SabeeApp GO does not collect payment card numbers (payments are handled via SabeePay or the Property's own payment terminal, outside the App), and does not access a guest's device, contacts, or personal accounts.

4. Who is responsible for my data?

Data protection law (GDPR Art. 4(7)–(8) and equivalent laws) distinguishes between a data controller (who decides why and how data is processed) and a data processor (who processes data on the controller's instructions).

DataControllerProcessor
Staff account, device, usage, and feedback data (Section 3.1) SabeeApp (thePass Kft.)
Guest identity, contact, and reservation data (Section 3.2) The Property (the hotel, apartment, or hostel where the guest is staying) SabeeApp (thePass Kft.), acting under the Property's instructions and the Data Processing Agreement in place between SabeeApp and the Property

Practical consequence: If you are a guest and want to know what data a specific Property holds about you, correct it, or request erasure, you should contact that Property first — they are legally responsible for your data and for providing you with their own guest-facing privacy notice. SabeeApp processes the data only as instructed by the Property, under a Data Processing Agreement, and cannot act on a guest's request without the Property's involvement except where required by law.

If you are unable to reach the Property, or believe SabeeApp itself has acted outside the Property's instructions, you may contact us at the details in Section 13 and we will assist or escalate appropriately.

6. Device permissions the App may request

SabeeApp GO will ask the device's operating system to grant the following permissions. Each is requested only when needed and can be reviewed or revoked in your device settings (revoking a permission may disable the related feature):

  • Camera — required to scan identity documents.
  • Phone — to initiate a call to a guest's number using the device's native dialer. SabeeApp does not record, monitor, or store the content of these calls.
  • Email client access / mailto link — to open the device's default email app pre-addressed to the guest. SabeeApp does not read or store the content of emails sent this way.
  • Photo library / storage (if applicable) — only if a staff member chooses to attach an existing image (e.g., to a feature request) rather than use the live scanner.
  • Push notifications — for alerts such as new bookings, housekeeping updates, or payment confirmations shown in the App.
  • Location (optional) — see Section 3.1.

7. Who we share data with

We share personal data only as necessary to operate the App and never sell personal data. Recipients include:

  • The Property itself, via automatic sync with the Property's SabeeApp PMS account — this is the core function of the App;
  • Cloud hosting and infrastructure providers that store SabeeApp PMS and GO data ([NAME PROVIDER(S), E.G., AWS/GCP/AZURE, AND REGION]);
  • Document scanning / OCR technology providers, if a third-party engine is used to read identity documents rather than an in-house one ([CONFIRM: IN-HOUSE OR THIRD-PARTY OCR VENDOR — NAME IT]);
  • Analytics and crash-reporting providers used to monitor App stability and usage ([E.G., GOOGLE ANALYTICS / FIREBASE / SENTRY — CONFIRM]), on an aggregated or pseudonymised basis;
  • Other SabeeApp modules the Property has enabled (e.g., GuestAdvisor, Housekeeping App, SabeePay), where data needs to flow between modules to avoid duplicate entry;
  • Public authorities, where required by law (e.g., statutory guest registration, law enforcement requests);
  • Professional advisers (auditors, lawyers) under confidentiality obligations, where necessary.

All third-party processors are bound by data processing agreements requiring GDPR-equivalent safeguards.

8. International data transfers

[CONFIRM AND COMPLETE] SabeeApp primarily stores and processes data within the European Economic Area (EEA). Where data is transferred outside the EEA (for example, to a sub-processor located in a third country), we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, an adequacy decision, or another lawful transfer mechanism, and can provide details on request.

9. Data retention

[CONFIRM ALL PERIODS — PLACEHOLDERS BELOW]

Data categoryRetention period
Staff account and login data For the duration of the Property's SabeeApp subscription, plus [X] after termination
Usage/diagnostic/crash logs [12 months] from collection
Scanned identity documents and guest contact data For the period instructed by the Property, in line with the Property's own legal retention obligations (e.g., local hotel-registration laws), and in any event no longer than necessary for that purpose; SabeeApp deletes or anonymises this data upon the Property's instruction or contract termination, subject to any independent legal retention duty
In-app feature requests [24 months], or until resolved plus a reasonable follow-up period

Where a specific local law (e.g., a national tourism or police registration law) requires a Property to retain guest registration data for a defined period, that period governs, and the Property is responsible for configuring or instructing retention accordingly.

10. Data security

We apply technical and organisational measures appropriate to the sensitivity of the data processed, including: encryption of data in transit (TLS) and at rest, role-based access controls limiting staff visibility to their assigned Properties, secure storage of scanned identity documents, regular security testing, and access logging. No system is completely secure, and we encourage staff to protect their own login credentials and report any suspected compromise immediately (see Section 13).

11. Your rights

11.1 If you are a guest

Contact the Property directly to exercise your rights under applicable data protection law, which may include the right to access, correct, erase, restrict, or object to processing of your data, and the right to data portability. The Property, as controller, is responsible for responding. SabeeApp will support the Property in fulfilling such requests where our involvement is required.

11.2 If you are a staff member / App user

Contact SabeeApp directly (Section 13) to exercise the same categories of rights over your own account and usage data. You may also lodge a complaint with your local data protection authority — in Hungary, the National Authority for Data Protection and Freedom of Information (NAIH) — or the authority in your own country of residence.

12. Children

SabeeApp GO is intended for use by adult hotel staff and is not directed at children. Where a guest document belongs to a minor travelling with a parent/guardian, the same processing rules in Section 3.2 and Section 4 apply, with the Property responsible for any additional safeguards required by local law.

13. Contact us

thePass Kft.

[REGISTERED ADDRESS]

Email: [PRIVACY CONTACT EMAIL, E.G., privacy@sabeeapp.com]

Data Protection Officer (if appointed): [NAME / CONTACT, OR STATE "NOT REQUIRED UNDER GDPR ART. 37 — CONTACT POINT ABOVE APPLIES"]

14. Changes to this policy

We may update this Policy as the App evolves. Material changes will be notified via the App or by other reasonable means, and the "Last updated" date above will be revised. Continued use of the App after changes take effect constitutes acceptance of the updated Policy.

15. Relationship to the SabeeApp PMS Data Processing Agreement

Processing of guest data by SabeeApp GO on behalf of a Property is additionally governed by the Data Processing Agreement between SabeeApp and the Property (typically part of the SabeeApp Terms and Conditions). In the event of any conflict between this Policy and that Agreement regarding the allocation of controller/processor responsibilities, the Data Processing Agreement prevails.

Still have questions?

Questions about SabeeApp GO?

Visit our knowledge base, or contact your Account Manager inside SabeeApp via your support drawer.