Back to home

Privacy Policy

How Hotel Lobby AI collects, uses, shares, and protects your personal data.

Last updated: 2026-10-05

This Privacy Policy explains how Hotel Lobby AI ("we", "us") collects, uses, and protects personal data when you use Hotel Lobby AI (the "Service"). Version 1.0 — Last updated October 5, 2026. It is referenced by our Terms of Service.

1. Data Controller

  • Controller: Hotel Lobby AI
  • Registered address: China
  • Privacy contact: support@hotellobbygen.com
  • Data Protection Officer: Not appointed (not required at our current scale).

2. Personal Data We Collect

You provide directly:

  • Account data — your email address when you register or sign in (including optional sign-in with Google, which shares only your email and display name). Passwords are stored only as hashes.
  • Content data — the photos you upload, your chosen style and generation settings, and the videos generated for you.
  • Payment data — your order history (pack, amount, date, status). Card numbers and payment credentials never reach our servers; they are entered on the payment processor's hosted checkout (see Section 5).

Collected automatically:

  • First-party analytics — an anonymous cookie ID and page events (e.g. "viewed pricing", "started generation") to measure conversion. We store no IP addresses and no browser fingerprints for analytics, and the cookie contains a random ID only.
  • Technical logs — server logs with timestamps and error codes for security and debugging.

We do not collect biometric templates, precise location, or special-category data, and we do not use third-party advertising trackers.

3. How We Use Your Data

  • Generate your videos and operate your account — performance of a contract.
  • Process credit purchases and prevent fraud — contract / legal obligation.
  • Transactional email (receipts, security notices, support) — contract / legitimate interests.
  • First-party, aggregate analytics to improve the product — legitimate interests.
  • Keep records required by tax and accounting law — legal obligation.
  • Respond to your requests (refunds, deletions, questions) — legitimate interests / legal obligation.
  • Investigate abuse reports and enforce our Acceptable Use Policy (content moderation) — legitimate interests / legal obligation.

4. Cookies and Tracking

  • Strictly necessary — session and authentication cookies; the Service cannot work without them.
  • Functional — a locale-preference cookie remembering your language choice.
  • First-party analytics — the anonymous cookie described in Section 2.

We set no marketing or advertising cookies. You can clear or block cookies in your browser at any time; strictly necessary cookies are exempt from consent requirements.

5. Sharing and Disclosure

We do not sell your personal information. We share data only with:

  • Waffo Pancake (payment processor) — processes your payment exclusively under PCI-DSS; we receive only the order outcome and support-relevant references, never your card data.
  • AI providers (fal.ai and upstream model vendors such as the providers of Kling or Seedance models) — receive the photos you upload and your generation parameters solely to produce your video. Their handling is governed by their own privacy policies.
  • Cloudflare — hosts our application, database, and file storage infrastructure.
  • Legal obligations — where required by law or to protect our rights, or with your explicit consent.

6. Data Security

We use TLS for all transport, encrypt sensitive configuration at rest, hash passwords, apply least-privilege access, and monitor for abuse. No transmission over the Internet is completely secure, but we work to protect your data continuously. In the event of a personal-data breach affecting you, we will notify you and the competent authorities without undue delay and within 72 hours of confirming it.

7. Data Retention

  • Account data (email, auth) — kept until account deletion; erased within 30 days after (backup expiry).
  • Uploaded photos & generation records — kept until you delete them or your account is deleted; erased within 30 days after.
  • Order and payment records — 5 years (tax/accounting requirement), then deleted.
  • First-party analytics events — 24 months, then raw events are deleted and only aggregates kept.
  • Technical logs — 90 days, then deleted.

Note on generated videos: files hosted by the AI provider expire on the provider's schedule (typically about 60 days). Download videos you want to keep.

8. Your Rights

Where GDPR, UK GDPR, CCPA, or similar laws apply, you have the right to: be informed; access your data; correct it; delete it; restrict processing; port it to another service; object to processing based on legitimate interests; and withdraw consent at any time where processing is based on consent. To exercise any right, email support@hotellobbygen.com from your registered address — we respond within 30 calendar days. You may also lodge a complaint with your local data-protection supervisory authority.

9. Marketing and Opt-Out

We currently send transactional messages only (receipts, security and account notices, support replies) — these are necessary for the service and are not marketing. If we ever send product news, every email will carry a one-click unsubscribe link, and account notices will still reach you where legally required.

10. International Transfers

Our infrastructure (Cloudflare) operates globally, and our AI providers are located primarily in the United States. When your data is transferred outside your jurisdiction, we rely on the providers' certification and contractual safeguards (such as Standard Contractual Clauses where applicable) to protect it.

11. Minors

The Service is directed at adults and is not intended for anyone under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided data, contact us and we will delete it promptly.

12. Third-Party Links

The Service may link to third-party sites (e.g. payment or model-provider pages). We are not responsible for their privacy practices; please read their policies.

13. Changes to This Policy

We may update this Privacy Policy. For material changes we will notify account holders at least 15 days before the effective date by email or in-Service notice, and always update the "Last updated" date above. Prior versions are retained with their effective dates.

14. Contact Us

  • Privacy / support email: support@hotellobbygen.com — monitored during business hours
  • Operator: Hotel Lobby AI, China