Legal
Privacy policy
BreakInn runs breakfast service for hotels, which means guest data from your property management system passes through our systems every day. This statement sets out exactly which fields we hold, why we hold them, how long they survive and who else ever sees them.
Last updated: 29 July 2026
Your guest data stays yours
Guest records arrive from your PMS and remain your property. We process them only to run the breakfast service you have configured, never for our own purposes.
No tracking, no advertising
We run no analytics, advertising or third-party tracking of any kind. The only cookies we set keep you signed in and remember your display settings.
Never sold or repurposed
We do not sell personal data, do not build profiles from guest records, and do not use them to train machine-learning models.
Who is responsible for what
Under the GDPR, BreakInn wears two hats at the same time. Which one applies depends on whose data it is, and it decides who you go to in order to exercise your rights.
Controller — your account with us
For the accounts your staff sign in with, and the billing details behind your subscription, BreakInn is the data controller. We decide what is collected and why, and this statement is our notice to you about it.
Processor — your guests' data
For everything that arrives from your property management system, your hotel is the controller and BreakInn is the processor. We act only on your documented instructions, under a data processing agreement, and we never decide on our own what happens to a guest record.
What we hold
This is the full inventory, grouped the way it is actually stored. The field names follow what your Opera export calls them, so you can match this against your own records.
Hotel staff accounts
The people at your property who sign in to BreakInn. These records are created when you invite a colleague; we collect them from nowhere else.
- Name, email address, and the team and role assigned to the account, together with the email address an invitation was sent to.
- A hashed password (never the password itself), two-factor authentication secrets and recovery codes, and any registered passkeys.
- Interface language, light or dark appearance, and the last release notes shown to the account.
- The date our terms were accepted and which edition was accepted, so a stored agreement records what was actually agreed to.
Subscription and billing
Held per hotel rather than per person, and used only to invoice your subscription.
- Company name, billing email address and phone number, VAT number and billing address.
- The card type and its last four digits, plus the identifiers that link your records to our payment provider. Full card numbers never reach BreakInn.
- Your plan, room count, trial and renewal dates, and subscription status.
Guest and reservation data from your PMS
Read from the scheduled reports your property management system sends us. We take only the fields the breakfast workflow needs, and we never ask your PMS for anything beyond them.
- Guest name and first name as printed by your PMS, together with the reservation, confirmation and guest profile references that identify the booking.
- Room number and room category, arrival and departure dates, number of nights, and the number of adults and children on the booking.
- Rate code, package and product codes, market segment, booking source, company or travel agent name, and any external reference. These are the fields that decide whether breakfast is included.
- VIP or loyalty status, membership number, and the reservation preferences and free-text comments your own staff typed into the PMS, where your report includes them.
- What your team records in BreakInn itself: breakfast check-ins and the time they happened, ad-hoc walk-in entries, breakfast charges, notes added to a booking, and the history of who changed what.
Guest feedback
Collected from the tablet in your breakfast room, if you switch the feedback kiosk on. It is deliberately anonymous.
- A star rating and, optionally, a room number the guest chooses to type in.
- A free-text comment. We ask for no name and no email address, and we record no device or network identifier behind a response.
Technical records
Created automatically by the act of running the service.
- Sign-in sessions, including the IP address and browser user agent of the device an account signed in from.
- The report files your PMS sends us, stored in their original form while they are processed and for a short window afterwards so a failed import can be replayed.
- Application and delivery logs, which record the addresses report messages were sent from and to, and any errors the service ran into.
How guest data reaches us
BreakInn does not connect to your PMS directly and holds no credentials for it. Guest data arrives one way only:
- 1
Your property management system sends its scheduled breakfast and guest reports to a unique inbound address issued for your hotel. Nothing arrives that you have not scheduled yourself.
- 2
The message is taken in by our email intake and stored, encrypted, in our object storage. The address it was sent to is what tells us which hotel it belongs to.
- 3
We read the report attachment, take the fields listed above and write them to your hotel's own isolated records. Every other field in the report is ignored.
- 4
The original message is deleted as soon as it has been read. The extracted report file is kept briefly so a failed import can be replayed, then deleted automatically.
Why we are allowed to hold it
For the data we control — your staff accounts and your billing details — these are our legal bases under Article 6 of the GDPR. For guest data we are the processor, so your hotel determines the legal basis and we act on your instructions.
- Performance of a contract
- Running your subscription, giving your staff access to the service, and invoicing you for it.
- Legitimate interests
- Keeping the service secure and available, preventing abuse, and contacting you about the service you use. We do not rely on legitimate interests for anything a hotel would not reasonably expect.
- Legal obligation
- Retaining invoices and the billing records behind them for as long as tax law requires.
How long we keep it
Different data has a different life span. Where no period is fixed by law, the rule is that we keep data for as long as your hotel uses BreakInn, and delete it when you leave.
- Report files from your PMS
- The original message is deleted as soon as it has been read. The extracted report file is deleted automatically 14 days after it arrives.
- Guest and reservation records
- Kept for as long as your account is open, because the breakfast history, forecasts and reports your team relies on are built from them. When a hotel's account is deleted, its guest records, feedback and reservation history are deleted with it. You can ask us to remove specific records, or an earlier period, at any time.
- Staff accounts
- Kept while the account exists. Deleting an account, or removing someone from your team, removes their access and their account data.
- Invoices and billing records
- Kept for seven years from the invoice date, as Dutch tax law requires, even after your subscription ends.
- Sign-in sessions
- Expire automatically after a period of inactivity, and are cleared when you sign out.
Who else touches the data
We use a small number of processors to run the service. Each is bound by a processing agreement, and none of them may use your data for their own purposes.
Cloudflare
Receives the report messages from your PMS, stores those messages and the extracted report files, and delivers our outbound email such as team invitations and service alerts. This is the only sub-processor that ever sees guest data.
Our hosting provider
Runs the application and the database in which your hotel's records are stored.
Stripe
Processes subscription payments and holds your billing details and card data. Stripe receives no guest data of any kind.
We will tell you before adding or replacing a sub-processor that handles guest data, so you have the chance to object. The list published here is always the current one.
How we protect it
The measures below are in place today. They are our technical and organisational measures within the meaning of Article 32 of the GDPR.
- All traffic to and from BreakInn is encrypted in transit, and the report files we store are encrypted at rest.
- Passwords are stored only as salted hashes, and are not readable by anyone at BreakInn.
- Two-factor authentication and passkeys are available on every account, and your hotel can make two-factor mandatory for its whole team.
- Every hotel's data is scoped to its own team. Queries are constrained to the signed-in team, and an automated check in our build blocks code that tries to sidestep that.
- Access within your hotel is governed by the roles you assign, so staff see only what their job needs.
- Guest names can be masked on check-in screens, so full names stay off a tablet standing in a public dining room.
Cookies
BreakInn sets no analytics, advertising or third-party cookies, neither on this website nor inside the application. There is no cookie banner because there is nothing to consent to. The only cookies we set are strictly necessary, or remember a display choice you made yourself:
- A session cookie and a security token that keep you signed in and protect forms against cross-site request forgery. If you choose to stay signed in, a long-lived sign-in cookie is added.
- Your light or dark theme choice.
- Whether you left the sidebar open or collapsed.
Your rights
You have the following rights over your personal data. Write to us and we will respond within one month.
- Ask for a copy of the personal data we hold about you.
- Have inaccurate data corrected.
- Ask for your data to be deleted, where we have no obligation to keep it.
- Ask us to pause processing while a dispute is being resolved.
- Receive your data in a structured, machine-readable format.
- Object to processing that we base on our legitimate interests.
If you are a hotel guest
Your data reached BreakInn from the hotel you stayed at, and that hotel decides what happens to it. Please contact the hotel directly to exercise your rights. If you write to us instead, we will pass your request on without delay and help the hotel answer it.
Contact us
For any question about this statement, or to exercise one of the rights above, write to our privacy contact. BreakInn is based in Amsterdam, the Netherlands.
[email protected]Data processing agreement
Hotels using BreakInn process guest data through us, so a data processing agreement forms part of our contract. It names the sub-processors listed above, the security measures we commit to, and what happens to your data when the contract ends. Ask us and we will send you the current version.
If you believe we have handled your data wrongly, we would like the chance to put it right first. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), or with the supervisory authority in your own country.
This statement sits alongside our Terms, which govern the agreement between BreakInn and your hotel.