Privacy Policy
Guest privacy is fundamental to true hospitality.
Last updated: September 30, 2026.
At Bienvue, we believe that hospitality begins with respect and trust. This Privacy Policy describes how Bienvue (“we”, “us”, or “our”) collects, uses, and protects personal data across our websites at bienvue.com and bienvue.app (with their subdomains, including guest guide pages), our cloud services, administrative dashboard, and television applications. We apply General Data Protection Regulation (GDPR) standards as our global baseline for all users and guests, regardless of where they are located.
Who we are
Bienvue is provided by Bienvue Ltd., a Colorado limited liability company, of 1500 N Grant St Ste N, Denver, CO 80203, United States. Reach us about privacy at [email protected] or at that address.
We have not appointed a representative in the European Union or the United Kingdom under Article 27 of the GDPR or the UK GDPR. People and supervisory authorities in the EU, the EEA and the UK can contact us directly, at the email or postal address above.
Roles: Data Controller and Data Processor
Under data protection laws including the GDPR:
- Bienvue as Data Controller: We act as the data controller for personal data collected directly from hosts, organization members, and website visitors (such as account credentials, contact information, billing records, and operational logs).
- Bienvue as Data Processor: For information that hosts configure and present to guests on in-room televisions (such as property manuals, Wi-Fi credentials, and guide cards), the host or hospitality business is the data controller, and Bienvue acts as a data processor. Our processing of such data is governed by our Data Processing Agreement (DPA).
Zero guest tracking
We do not track, profile, or collect personal data from guests viewing guide cards on in-room televisions. Guests do not create accounts with Bienvue. Scanning a Wi-Fi code connects guests directly. Scanning a recommendation’s code opens a page on Bienvue, which counts the scan and any link chosen for that card. We record no guest identity, device, phone number or address when it does.
Information we collect
- Host and account information: When you register as a host or join an organization, we collect your name, email address, and authentication credentials (including two-factor authentication factors) to secure and manage your account.
- Property and guide content: Content you enter into Bienvue—property names, Wi-Fi details, house manuals, recommendations, and theme preferences—is compiled into guide documents delivered to your paired screens.
- Place photos: A photo a host uploads to a place card near their property is shared with other hosts who have a card for the same place, as our Terms of Service (section 4) describe, credited by the name the host gives. That name and the photo are shown to those hosts and to anyone who views their guides.
- Device diagnostics and telemetry: Televisions and client apps communicate with our API using cryptographic device tokens. We record operational telemetry (such as connection timestamps, IP addresses, schema versions, and device hardware models) solely to deliver updates, ensure screen compatibility, and maintain platform security.
- Billing information: Subscription and payment transactions are processed securely through payment processors (such as Stripe). Bienvue does not store raw credit card numbers on its servers.
Self-hosted servers
If you run bienvue-local, it sends us its name, its address on your home network, its version and an identifier (a one-way hash of the machine's name and its data folder, which stays the same across restarts) when it starts, every 12 hours, and when any of these changes. We see the internet address it connects from and keep only a keyed one-way hash of it, never the address itself. We use this only to help televisions on the same network find your server and to count active installations. Each record expires 36 hours after the server last checked in and is deleted in the next daily cleanup. Start bienvue-local with --no-announce and nothing is sent.
Legal bases for processing (GDPR Article 6)
We process personal data only when we have a valid legal basis:
- Performance of a contract (Art. 6(1)(b)): To provide the Bienvue service, authenticate accounts, distribute guide content to screens, and provide technical support.
- Legitimate interests (Art. 6(1)(f)): To secure our network, prevent unauthorized access or abuse, diagnose technical faults, and improve the reliability of our software.
- Compliance with legal obligations (Art. 6(1)(c)): To comply with tax, financial, and statutory recordkeeping requirements.
Data retention and deletion
We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy:
- Account data: Retained for the active duration of your account. Upon account deletion or termination, account data and associated property guides are permanently removed 30 days after deletion. If you sign in with Apple, deleting your Apple Account, or stopping Bienvue's access when Apple is your only way to sign in, deletes your Bienvue account the same way.
- Operational logs and telemetry: Server logs are kept no longer than 90 days. Diagnostic device connection records, kept for reliability and incident investigation, lose their IP address after 90 days and are deleted after 12 months. A record of who changed a guide’s cards, and which fields, without their contents, is deleted after 12 months. Anonymous counts of which guide cards and links are used are kept so hosts can see what guests find useful.
- Place photos: A place photo, with its credit name, stays in the guides that already use it after the host who uploaded it removes it or deletes their account, and no one else can choose it from then on. Ask us to replace your name in its credit with “a Bienvue host”. If you appear in a place photo and didn’t agree to it, tell us and we remove it from every guide.
- Invitations: When a host invites you to Bienvue, we keep your email address with the invitation. If you don't accept it, the address is deleted 30 days after the invitation expires.
- Support records: When our support team acts on your account or organization, such as restoring it or removing a photo, we record what was done, by whom and why. That record, and a note that the deletion happened (with counts, not names), is deleted 12 months after the account or organization is.
- Device tokens: Expired pairing codes expire automatically; device tokens can be revoked at any time by the host from the dashboard.
- Billing and newsletter records: Deleting an organization deletes its Stripe customer record (Stripe keeps invoices and charges for tax records). Deleting your Bienvue account deletes your address from Mailjet. If either service can't be reached we try again the next day, and if the second try fails we finish the deletion and a person completes that step by hand.
Marketing site analytics
With your permission, we use Google Analytics on bienvue.com and on our sign-up and sign-in pages to learn which pages help people find Bienvue. Nothing loads until you choose Allow, and No thanks is just as easy. It never runs on guest guides, televisions, or your dashboard. Google processes this data only as our service provider, under its data processing terms: Google signals, ad personalization, ads links and Google’s own data sharing settings are all off, so Google does not use it for advertising or its own products. The cookie lasts at most 13 months, and Google keeps the data for 14 months. Change your mind any time with Cookie settings at the bottom of any page.
Waitlist and contact messages
When you join the waitlist or write to us, we keep what you sent (your email, and the property details or message you chose to share) so we can send your invite or reply. We don't store your IP address, and we use it for nothing else. It's deleted after 12 months, or when you delete your Bienvue account. Ask us at [email protected] to delete it sooner.
Newsletter
Only if you check the box and then confirm by email. We keep a record of when and how you agreed, for 3 years, as proof. Our email provider, Mailjet, holds the list. Every newsletter has an unsubscribe link, which removes you immediately. Deleting your Bienvue account also deletes your address from Mailjet.
Your rights under GDPR (Worldwide)
Regardless of your citizenship or physical location, Bienvue extends the full set of GDPR data rights to all users:
- Right of access (Art. 15): You can request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): You may update or correct inaccurate or incomplete information directly within your profile settings or by contacting us.
- Right to erasure (Art. 17): You can request deletion of your account and associated personal data (“right to be forgotten”).
- Right to restriction of processing (Art. 18): You can request that we restrict the processing of your data under specific conditions.
- Right to data portability (Art. 20): You can receive your account and property data in a structured, commonly used, and machine-readable format.
- Right to object (Art. 21): You may object to data processing based on legitimate interests.
- Post-mortem directives: In accordance with applicable French and European privacy law, you have the right to set directives regarding the retention, erasure, and communication of your personal data after your death.
To exercise any of these rights, contact us at [email protected]. Requests are answered without charge within 30 days.
California residents
The California Privacy Rights Act (CPRA) gives California residents additional rights over their personal information. We do not meet a CPRA threshold as a business today, but we describe our practices in its terms anyway:
- Identifiers: host name, email, IP address and user agent on sessions, waitlist, contact, and newsletter email addresses, from you, and the email address a host sent you an invitation at, from that host. Disclosed to Cloudflare (hosting), Mailjet (email delivery), Stripe (billing), and Sentry (error reports), each for that business purpose. Not sold or shared.
- Sensitive personal information (account login): your email with a password hash, two-factor secrets, and a Google or Apple sign-in link, from you, used only to sign you in and keep your account secure. Disclosed only to Cloudflare, for hosting. Not sold or shared.
- Commercial information: your plan, subscription status, Stripe customer id, and trial card fingerprint, from you and Stripe. Disclosed to Cloudflare (hosting) and Stripe (billing). Not sold or shared.
- Internet activity: Google Analytics on our marketing site and sign-up and sign-in pages, only after you choose Allow; device events carrying the property network’s IP address, the address cleared at 90 days and the event deleted at 12 months, from your browser and your televisions. Disclosed to Cloudflare (hosting) and, for the analytics portion and only with your consent, Google. Not sold or shared; see Marketing site analytics above.
- Customer records: property content you write, which can include a host’s phone number, address, or photos of people, from you. Disclosed to Cloudflare (hosting) and, when you use the Nearby feature, Google Places, Geoapify and Gemini (your property’s address only, to find and describe nearby places). Not sold or shared.
- We do not collect inferences, biometric information, or precise geolocation.
Each category above lists the subprocessors that actually received it in the past 12 months, for the business purposes described under Subprocessors below. We have not sold or shared personal information in the past 12 months, including that of consumers under 16. Every recipient above, Google Analytics included, processes it only as our service provider or contractor, for our purposes and not its own.
Our only sensitive personal information is account login credentials, and we use it only to sign you in and keep your account secure — nothing else, so there is nothing to limit.
Your CPRA rights
Alongside the GDPR rights above, which we already extend to everyone regardless of location, California residents have:
- Right to know what personal information we collect, use, and disclose, as described in this policy.
- Right to delete your personal information, the same as the right to erasure above.
- Right to correct inaccurate personal information, the same as the right to rectification above.
- Right to opt out of the sale or sharing of personal information. We have nothing to opt out of: we do not sell or share personal information.
- Right to limit the use of sensitive personal information. Our only sensitive personal information is account login credentials, used only to sign you in, so there is nothing to limit.
- Right of non-discrimination for exercising any of these rights. We will not deny you service, charge you a different price, or provide a different level of service because you exercised a privacy right.
Verification and authorized agents
We verify a request by checking that you are signed in to your account, or by asking you to confirm from the email address on your account. An authorized agent may make a request on your behalf with your signed, written permission; we may still ask you to confirm the request directly before we act on it.
Global Privacy Control
We honor the Global Privacy Control signal as an opt out of sale and sharing. In practice, that means no analytics loads on any page that has analytics when your browser sends the signal — no banner and no Google — and our sign-up analytics event sends nothing when the request carries Sec-GPC: 1.
Children’s privacy
Bienvue is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child’s personal information has reached us, write to [email protected] and we will delete it.
Subprocessors and international data transfers
We do not sell or share personal data, as the CCPA defines those terms, and we do not sell it to advertisers or anyone else. We disclose it only to the subprocessors below, each processing it on our behalf to operate the service:
- Cloudflare (edge hosting, compute, and encrypted storage)
- Mailjet (account confirmations, security notices, and the newsletter for people who confirm they want it)
- Google (Analytics on our marketing and sign-up pages, only with your consent; Places and Gemini, which receive your property’s address and location and the name, category, and address of nearby places to build your Nearby suggestions, and Maps, which shows hosts a place’s card in the dashboard and, when a host turns on Google’s photos with their own Google key, receives that place’s ID from our servers; screens load those photos through us, so Google never sees a guest — never guest data)
- Geoapify (KEPTAGO LTD, Cyprus; EU hosting), which receives the names and locations of nearby places, and your property’s address when it finds places for you, to look up their details in OpenStreetMap — never guest data
- Wikimedia and Openverse, public collections of openly licensed photos, which receive the name of a nearby place (and your search town, for Openverse) when you look for photos of it, and your browser’s address when the dashboard shows their thumbnails — never guest data
- Apple (Maps, which finds a place’s Apple Maps link when a host adds it in the dashboard; receives the place’s name and location and the host’s browser address — never guest data)
- Stripe (billing and payment processing)
- Sentry (error reports from our API, dashboard, and admin tool; session cookies, request bodies and tokens in URLs are excluded before a report is sent)
We rely on each subprocessor’s data processing terms to meet GDPR Article 28, and on the standard contractual clauses (SCCs) approved by the European Commission, or an adequacy decision, when data crosses borders. Sentry requires its customers to opt in to its data processing terms, and we have.
If you choose to sign in with Google or Apple, that company signs you in and shares your name and email address with us. Each does this as an independent controller under its own privacy policy, not as our subprocessor.
Supervisory authority complaint rights
If you believe our processing of your personal data infringes data protection laws, you have the right to lodge a complaint with an EU data protection supervisory authority, including the Commission Nationale de l'Informatique et des Libertés (CNIL) in France (cnil.fr), or your local national data protection regulator.
Contact
If you have questions, concerns, or requests regarding data protection or our Data Processing Agreement, contact our privacy team at [email protected].