App Privacy Notice
Last updated: August 2026
Data protection information (GDPR / nDSG) for the MinibarFlow mobile application. For the website and general service, see the MinibarFlow Privacy Policy.
1. Data Controller
The controller responsible for the processing of your personal data within the meaning of the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nDSG) is:
Louis Bienaimé
La Ruai 1
2738 Court, Switzerland
Email: contact@minibarflow.com
2. What Data We Process and Why
2.1 Employee Data
We process the following data about hotel employees who use this application:
- Authentication credentials (email address, hashed password): to provide secure access to the application.
- Display name and optional profile photo: to identify users within the application and facilitate team collaboration.
- Phone number (optional): for account recovery and team communication.
- Role and hotel assignment: to control access permissions and ensure users see only data relevant to their hotel and role.
- Shift activity records (start/end times, rooms checked, stock movements): to track minibar operations and generate operational reports.
2.2 Guest Data
We process minimal guest data strictly necessary for minibar operations:
- Guest name (from expected arrival records): to associate minibar preparation with the correct room assignment. Guest names are only visible to hotel managers and administrators; employees do not see guest names except when registering a check-in.
- Stay duration and optional notes: to plan minibar restocking schedules.
We do not process guest payment information, identity documents, or any special categories of personal data.
2.3 Device Data
When you use the application, we may process the following technical data:
- Push notification token: to deliver operational notifications (e.g., shift reminders, stock alerts). Notification payloads contain no personal data.
- Crash reports and performance metrics (only with your explicit consent): to diagnose application errors and improve reliability.
3. Legal Basis for Processing
We process your personal data on the following legal bases under Art. 6(1) GDPR:
- Art. 6(1)(b), performance of a contract: Processing of employee data is necessary for the performance of the employment contract between you and the hotel operator. This includes authentication, shift management, and operational activity tracking.
- Art. 6(1)(f), legitimate interests: Processing of guest names and stay information is based on the hotel operator's legitimate interest in efficient minibar management. Stock movement logs and operational reports serve the legitimate interest of inventory control and loss prevention.
- Art. 6(1)(a), consent: Crash reporting and analytics data are only collected with your explicit, freely given consent. You may withdraw consent at any time via the Privacy settings in your profile, without affecting the lawfulness of processing performed before withdrawal.
4. Recipients and International Transfers
Your data may be shared with the following categories of recipients:
- Firebase / Google Cloud (europe-west6, Zurich): Authentication, database (Firestore), file storage, and Cloud Functions are hosted in the europe-west6 region (Zurich, Switzerland). Data remains within the EEA/Switzerland adequacy framework.
- Google Crashlytics (United States): Crash reports are transmitted to Google servers in the United States only when you have granted explicit consent. Google LLC participates in the EU-US Data Privacy Framework. You may disable this at any time in your profile settings.
- Expo Push Notification Service (United States): Push notification delivery is routed through Expo's servers in the United States. Notification payloads are generic (no personal data) and contain only operational message text and a device token.
We do not sell, rent, or otherwise share your personal data with third parties for marketing or advertising purposes.
5. How Long We Keep Your Data
We retain personal data only as long as necessary for the purposes described above. Specific retention periods are:
| Data Category | Retention Period |
|---|---|
| Guest names (in room check records) | Automatically anonymized after 30 days |
| Guest names (expected arrivals) | Automatically deleted after 7 days |
| Push notification history | 30 days (read) / 90 days (unread) |
| Room check photos | Automatically deleted after 90 days |
| Employee identifiers in historical records | Automatically anonymized after 12 months |
| Active employee accounts and profile data | Retained until account deletion |
| Crash and analytics data | 90 days (managed by Google) |
After the applicable retention period, personal data is automatically deleted or anonymized. Aggregated, non-identifiable operational statistics may be retained indefinitely.
6. Data Minimization Measures
The application implements the following data minimization measures:
- Guest name visibility: Guest names are restricted to managers and administrators. Employees do not see guest names in room tiles, shift cards, or room detail screens. Employees can only enter a guest name during the check-in process.
- Photo metadata: EXIF metadata (GPS, device info) is automatically stripped from all photos before upload.
- Push notifications: All push notification payloads use generic text (e.g., "A team member started their shift") and do not include personal names.
- Offline cache: Guest names and email addresses are stripped from locally cached data.
- Crash reports: Only a pseudonymized user ID and role are sent to crash reporting services. No email addresses or names are transmitted.
7. Your Rights
Under the GDPR and the nDSG, you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR / Art. 25 nDSG): You may request confirmation of whether we process your personal data and, if so, obtain a copy of that data.
- Right to rectification (Art. 16 GDPR): You may request correction of inaccurate personal data or completion of incomplete data. You can update your display name and phone number directly in the application.
- Right to erasure (Art. 17 GDPR / Art. 32 nDSG): You may request deletion of your personal data, subject to legal retention obligations. When an employee account is deleted, all associated data is either deleted (notifications, profile photos) or anonymized (shift records, room check records, stock movements) so that it can no longer be attributed to a specific individual.
- Right to data portability (Art. 20 GDPR / Art. 28 nDSG): You may request to receive your personal data in a structured, commonly used, machine-readable format (JSON). Contact the data controller to initiate a data export request.
- Right to object (Art. 21 GDPR): You may object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
- Right to withdraw consent: Where processing is based on consent (e.g., crash reporting), you may withdraw your consent at any time via the Privacy settings in your profile. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
- Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority. For Switzerland, the competent authority is the Federal Data Protection and Information Commissioner (FDPIC). For EU/EEA residents, contact your local data protection authority.
8. Request deletion of your data
To request deletion of your MinibarFlow account and the personal data linked to it, send an email to contact@minibarflow.com from the email address linked to your account. Your account is created and managed by your hotel, so requests concerning operational work records (shifts, room checks, stock movements) are handled together with your hotel, which processes them in the context of your employment.
When your account is deleted:
- Deleted: your authentication credentials, display name, profile photo, phone number, push notification token, and notification history.
- Anonymized: shift records, room check records, and stock movements are stripped of your identity so they can no longer be attributed to you. These anonymized operational records are retained for the hotel's inventory and reporting purposes.
- Retained for a limited period: crash and analytics data collected with your consent is kept by Google for up to 90 days before automatic deletion.
9. Contact
If you have questions about this privacy notice or wish to exercise your data protection rights, please contact:
Louis Bienaimé
La Ruai 1
2738 Court, Switzerland
Email: contact@minibarflow.com