Privacy Policy

Guest privacy is fundamental to true hospitality.

Last updated: September 30, 2026.

At Bienvue, we believe that hospitality begins with respect and trust. This Privacy Policy describes how Bienvue (“we”, “us”, or “our”) collects, uses, and protects personal data across our websites at bienvue.com and bienvue.app (with their subdomains, including guest guide pages), our cloud services, administrative dashboard, and television applications. We apply General Data Protection Regulation (GDPR) standards as our global baseline for all users and guests, regardless of where they are located.

Who we are

Bienvue is provided by Bienvue Ltd., a Colorado limited liability company, of 1500 N Grant St Ste N, Denver, CO 80203, United States. Reach us about privacy at [email protected] or at that address.

We have not appointed a representative in the European Union or the United Kingdom under Article 27 of the GDPR or the UK GDPR. People and supervisory authorities in the EU, the EEA and the UK can contact us directly, at the email or postal address above.

Roles: Data Controller and Data Processor

Under data protection laws including the GDPR:

Zero guest tracking

We do not track, profile, or collect personal data from guests viewing guide cards on in-room televisions. Guests do not create accounts with Bienvue. Scanning a Wi-Fi code connects guests directly. Scanning a recommendation’s code opens a page on Bienvue, which counts the scan and any link chosen for that card. We record no guest identity, device, phone number or address when it does.

Information we collect

Self-hosted servers

If you run bienvue-local, it sends us its name, its address on your home network, its version and an identifier (a one-way hash of the machine's name and its data folder, which stays the same across restarts) when it starts, every 12 hours, and when any of these changes. We see the internet address it connects from and keep only a keyed one-way hash of it, never the address itself. We use this only to help televisions on the same network find your server and to count active installations. Each record expires 36 hours after the server last checked in and is deleted in the next daily cleanup. Start bienvue-local with --no-announce and nothing is sent.

Legal bases for processing (GDPR Article 6)

We process personal data only when we have a valid legal basis:

Data retention and deletion

We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy:

Marketing site analytics

With your permission, we use Google Analytics on bienvue.com and on our sign-up and sign-in pages to learn which pages help people find Bienvue. Nothing loads until you choose Allow, and No thanks is just as easy. It never runs on guest guides, televisions, or your dashboard. Google processes this data only as our service provider, under its data processing terms: Google signals, ad personalization, ads links and Google’s own data sharing settings are all off, so Google does not use it for advertising or its own products. The cookie lasts at most 13 months, and Google keeps the data for 14 months. Change your mind any time with Cookie settings at the bottom of any page.

Waitlist and contact messages

When you join the waitlist or write to us, we keep what you sent (your email, and the property details or message you chose to share) so we can send your invite or reply. We don't store your IP address, and we use it for nothing else. It's deleted after 12 months, or when you delete your Bienvue account. Ask us at [email protected] to delete it sooner.

Newsletter

Only if you check the box and then confirm by email. We keep a record of when and how you agreed, for 3 years, as proof. Our email provider, Mailjet, holds the list. Every newsletter has an unsubscribe link, which removes you immediately. Deleting your Bienvue account also deletes your address from Mailjet.

Your rights under GDPR (Worldwide)

Regardless of your citizenship or physical location, Bienvue extends the full set of GDPR data rights to all users:

To exercise any of these rights, contact us at [email protected]. Requests are answered without charge within 30 days.

California residents

The California Privacy Rights Act (CPRA) gives California residents additional rights over their personal information. We do not meet a CPRA threshold as a business today, but we describe our practices in its terms anyway:

Each category above lists the subprocessors that actually received it in the past 12 months, for the business purposes described under Subprocessors below. We have not sold or shared personal information in the past 12 months, including that of consumers under 16. Every recipient above, Google Analytics included, processes it only as our service provider or contractor, for our purposes and not its own.

Our only sensitive personal information is account login credentials, and we use it only to sign you in and keep your account secure — nothing else, so there is nothing to limit.

Your CPRA rights

Alongside the GDPR rights above, which we already extend to everyone regardless of location, California residents have:

Verification and authorized agents

We verify a request by checking that you are signed in to your account, or by asking you to confirm from the email address on your account. An authorized agent may make a request on your behalf with your signed, written permission; we may still ask you to confirm the request directly before we act on it.

Global Privacy Control

We honor the Global Privacy Control signal as an opt out of sale and sharing. In practice, that means no analytics loads on any page that has analytics when your browser sends the signal — no banner and no Google — and our sign-up analytics event sends nothing when the request carries Sec-GPC: 1.

Children’s privacy

Bienvue is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child’s personal information has reached us, write to [email protected] and we will delete it.

Subprocessors and international data transfers

We do not sell or share personal data, as the CCPA defines those terms, and we do not sell it to advertisers or anyone else. We disclose it only to the subprocessors below, each processing it on our behalf to operate the service:

We rely on each subprocessor’s data processing terms to meet GDPR Article 28, and on the standard contractual clauses (SCCs) approved by the European Commission, or an adequacy decision, when data crosses borders. Sentry requires its customers to opt in to its data processing terms, and we have.

If you choose to sign in with Google or Apple, that company signs you in and shares your name and email address with us. Each does this as an independent controller under its own privacy policy, not as our subprocessor.

Supervisory authority complaint rights

If you believe our processing of your personal data infringes data protection laws, you have the right to lodge a complaint with an EU data protection supervisory authority, including the Commission Nationale de l'Informatique et des Libertés (CNIL) in France (cnil.fr), or your local national data protection regulator.

Contact

If you have questions, concerns, or requests regarding data protection or our Data Processing Agreement, contact our privacy team at [email protected].