Skip to content
Privacy Policy by Hyatus

Legal

Privacy Policy

Hyatus privacy practices across the website, iOS and Android app, and Guest Portal for accounts, bookings, payments, identity checks, stay management, support, notifications, analytics, and data rights.

Direct answer

How Hyatus handles your information.

Hyatus uses one canonical customer identity and shared booking and stay systems across its website, mobile app, and Guest Portal. This policy explains the information those products process, why it is needed, the service providers involved, and the choices available to guests.

Website, iOS, Android, and Guest Portal

Booking and stay-management data

Payment, identity, and support providers

Privacy choices and account deletion

Privacy Policy image 1
Privacy Policy image 2
Privacy Policy image 3

Key details

What Hyatus offers.

Hyatus privacy practices across the website, iOS and Android app, and Guest Portal for accounts, bookings, payments, identity checks, stay management, support, notifications, analytics, and data rights.

01

Scope and effective date

Effective and last updated August 3, 2026. This policy applies when you use hyatus.com, the Hyatus app for iOS or Android, the Hyatus Guest Portal, booking and checkout, virtual check-in, stay-management tools, support, rewards, or related Hyatus services.

  • The website, app, and Guest Portal use the same canonical Hyatus account, reservation, pricing, payment, permission, and workflow systems.
  • The Cookie Policy explains browser cookies and similar website technology.
  • The SMS Privacy Policy and SMS Terms explain the optional Hyatus text-messaging program.

02

Information you provide

Hyatus processes information you submit to create or use an account, search for and book a stay, complete payment or check-in, manage a current stay, request help, or participate in rewards. The information depends on the feature and the requirements of the reservation.

  • Account and contact details such as name, email address, phone number, account identifier, and sign-in provider.
  • Booking and stay details such as property, dates, guest count, price, reservation and payment status, trip history, rewards, arrival timing, and customer notes.
  • Check-in details such as date of birth, address when required, additional guest details, vehicle information, license plate, and signed agreements.
  • Support and stay content such as chat messages, cases, claims, maintenance requests, checkout feedback, reviews, and any files or photos you choose to provide.

03

Payments, identity verification, and screening

Some booking and check-in steps use specialized providers. Stripe processes payment details and returns transaction status and limited payment-method information to Hyatus. When a reservation requires identity verification or screening, the selected provider may process a government-issued identification document, selfie, date of birth, address, verification result, or risk and eligibility signals.

  • Stripe Identity or Checkr may provide identity-verification services, depending on the active reservation workflow.
  • AutoHost may support reservation screening or review when that requirement is active.
  • SignatureAPI may process rental agreements and electronic signatures when a signed agreement is required.
  • Hyatus does not receive or store a complete card number from the Stripe mobile payment interface.

04

App, device, notification, and diagnostic information

The Hyatus app may process an app installation identifier, push token, platform, app version, device model, and operating-system version so it can route reservation and stay notifications and revoke a token after logout or opt-out. It also processes bounded technical information needed to keep the app reliable and secure.

  • Optional product analytics, including app interactions and in-app searches, is sent only after the guest enables analytics consent.
  • Sentry may process crash logs, diagnostics, and sampled performance information. Hyatus configures the app to remove account, request, and extra event fields before diagnostic delivery.
  • Expo, Apple Push Notification service, and Firebase Cloud Messaging may process push tokens and notification delivery data after notification permission is granted.
  • The current app requests camera access only for a guest-initiated identity-verification step and does not request precise or approximate location permission.

05

How Hyatus uses information

Hyatus uses personal and technical information to provide the product or service requested, operate a safe hospitality business, communicate with guests, meet contractual and legal duties, and improve reliability.

  • Authenticate the canonical Hyatus account and recover secure, interrupted flows.
  • Show availability and pricing, create and manage reservations, process payments, prevent duplicate bookings or charges, and maintain trip and rewards history.
  • Complete check-in, confirm eligibility for access controls, deliver arrival and stay workflows, and support checkout or overdue billing.
  • Investigate fraud, payment disputes, claims, maintenance, security incidents, or policy violations.
  • Provide Zendesk support, human handoff, service notices, and requested marketing communications.

06

Service providers and other disclosures

Hyatus discloses information to service providers only as needed for them to provide contracted services, secure the platform, or support a guest-requested transaction. The provider used can vary by platform, reservation, location, and production configuration.

  • Payment, identity, screening, and agreement providers include Stripe, Stripe Identity, Checkr, AutoHost, and SignatureAPI where their workflow is active.
  • Support, notification, and diagnostic providers include Zendesk, Expo, Apple, Google/Firebase, and Sentry where configured.
  • Cloud hosting, authentication, communications, analytics, security, and professional advisers may process the minimum information needed for their role.
  • Hyatus may disclose information when required by law, to protect guests or the business, to investigate abuse or fraud, or as part of a merger, financing, acquisition, or asset transfer with appropriate safeguards.
  • Hyatus does not rent guest data or sell it for money.

07

Your choices and controls

You can control optional mobile permissions and communications without creating a separate mobile identity. Some booking or check-in features cannot work when information required for payment, identity, screening, or access eligibility is not provided.

  • Enable or disable optional product analytics from the app privacy controls.
  • Allow or deny notifications in the app and device settings; Hyatus revokes the registered push token after logout or opt-out when the backend is reachable.
  • Allow camera access only when starting an eligible identity-verification step, or deny it and use an available provider handoff or support path.
  • Unsubscribe from optional marketing messages while continuing to receive transactional booking, payment, safety, and stay communications.
  • Request access, correction, or account deletion through the Hyatus account-deletion page or contact path.

08

Security and retention

Hyatus uses encrypted network connections, access controls, credential storage appropriate to each platform, monitoring, and operational safeguards. No system can guarantee absolute security, so guests should protect account credentials and contact Hyatus if they suspect unauthorized access.

  • Hyatus keeps information for as long as reasonably needed to provide bookings and stays, maintain contracts and transaction records, resolve support or disputes, prevent fraud, and meet tax, accounting, safety, and legal obligations.
  • Retention periods vary by data category, reservation state, provider, and applicable law.
  • After a valid deletion request, Hyatus deletes or de-identifies eligible information and retains only information that is required or permitted for legal, security, fraud-prevention, accounting, or dispute purposes.

09

Privacy requests and contact

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of personal information, or to appeal a privacy-request decision. Hyatus may need to verify the request before acting so another person cannot obtain or delete your data.

  • Use the account-deletion page for an account deletion request.
  • Use the Hyatus contact page for access, correction, portability, consent, or other privacy questions.
  • If you provide information about another guest or occupant, you are responsible for having authority to provide it and for sharing this policy with that person.