Kinora

Privacy Policy

Effective date: July 23, 2026 Last updated: July 23, 2026

Kinora ("Kinora," "we," "us," or "our") operates the website at kinorahq.com and provides a software-as-a-service platform that enables independent and boutique hotels ("Hotels") to create branded guest-facing pages, including an AI-powered concierge feature called Clef. This Privacy Policy explains what information we collect, how we use it, and the choices available to you.

This Privacy Policy applies to:

  • Hotels and their authorized users who subscribe to Kinora
  • Guests of subscribing Hotels who interact with a Kinora-hosted page or with Clef
  • Visitors to kinorahq.com

Jurisdictional note. Kinora is currently offered to Hotels located in the United States (including California), Canada excluding the Province of Quebec, and Mexico. It is not currently offered to Hotels located in the European Union, the European Economic Area, the United Kingdom, or Quebec. If you are an EU, EEA, or UK resident, or a business located in those jurisdictions, Kinora is not currently available to you, and we ask that you do not submit personal information through our service. We will expand availability to those jurisdictions in the future with additional privacy notices specific to them.

California residents: Kinora became available to California Hotels on July 23, 2026. See Section 10 — California privacy rights for the disclosures and rights that apply to you.


1. Information we collect

1.1 Information Hotels provide to us

When a Hotel subscribes to Kinora, we collect:

  • Hotel name, location, website URL, and contact email
  • Name and email of the Hotel's authorized user(s)
  • Payment information (processed by Stripe — we do not store full payment card numbers)
  • Content the Hotel adds to its Kinora page: links, images, taglines, and configuration
  • Hotel website content automatically retrieved by our crawler approximately every 24 hours
  • Hotel-configured preferences for Clef (tone, forwarding email, etc.)

1.2 Information we collect from Guests who use a Kinora page

When a guest visits a Hotel's Kinora page or interacts with Clef, we may collect:

  • IP address, browser type, device type, and general location (country/region)
  • Pages viewed, links clicked, and time spent
  • UTM parameters and referral source
  • If the guest chats with Clef: the conversation content
  • If the guest asks Clef to forward a request to the Hotel: name and one contact method (email or phone number) that the guest voluntarily provides

Clef is instructed not to collect, and we do not knowingly store: payment card details, passport or government ID numbers, health or medical information, date of birth, or Social Security numbers. If a guest volunteers any of these, Clef is instructed not to acknowledge or repeat them and we will remove such content from logs upon discovery or request.

1.3 Information we collect automatically from website visitors

When you visit kinorahq.com, we automatically collect standard server logs (IP address, user agent, referring URL, pages accessed) and analytics data via standard cookies.


2. How we use information

We use the information we collect to:

(a) Provide, maintain, and improve the Kinora service, including generating Clef responses using the content of the Hotel's website (b) Process payments and manage subscriptions (c) Send service-related communications (account notifications, service updates, security alerts) (d) Forward guest requests from Clef conversations to the relevant Hotel (e) Monitor, analyze, and troubleshoot the service, including reviewing flagged Clef conversations to improve guardrails (f) Comply with legal obligations and enforce our Terms of Service (g) Prevent fraud, abuse, and security incidents

We do not use guest personal data or Hotel content to train AI models, sell to data brokers, or send marketing messages to guests.


3. How information is shared

3.1 Service providers (sub-processors)

We share information with trusted third-party service providers who process data on our behalf under contractual confidentiality obligations. Our current sub-processors are:

ProviderPurposeData processed
Anthropic, PBCAI inference for ClefConversation content + crawled website content
Supabase Inc.Database hostingAll stored data
Vercel Inc.Web hosting and cronServer logs, request data
Stripe Inc.Payment processingHotel billing information
Resend Inc.Email deliveryEmail addresses for magic links and notifications
Google LLCPlaces API (Google reviews)Hotel identifier, retrieved reviews
Cloudflare Inc.CDN / edge hosting for landing pageVisitor IP, request metadata

This list may be updated as our infrastructure evolves. The table above is the current list; we update it here and change the "Last updated" date at the top of this policy when a sub-processor changes.

3.2 Between Hotel and Kinora

The Hotel has access to guest conversation logs, analytics, and any contact details a guest voluntarily shared through Clef. Hotels are responsible for handling this data in accordance with their own privacy practices and applicable law.

3.3 Legal requirements

We may disclose information if required by law, court order, or valid legal process, or to protect the rights, property, or safety of Kinora, our users, or others.

3.4 Business transfers

If Kinora is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction. We will provide notice before any such transfer.

We do not sell personal information to third parties.


4. Your choices and rights

4.1 Hotels

Hotels can update account information, modify their Kinora page, change Clef configuration, and request deletion of their account at any time via the dashboard or by emailing partner@kinorahq.com.

4.2 Guests

Guests who have interacted with a Hotel's Kinora page or Clef can:

  • Request a copy of their conversation history
  • Request correction of inaccurate data
  • Request deletion of their data

To exercise any of these rights, contact the Hotel directly or email partner@kinorahq.com with the request, the Hotel name, and your email address or name as it appeared in the conversation. We will respond within 30 days.

4.3 California residents

If you are a California resident, Section 10 (California privacy rights) sets out additional rights — including the rights to know, delete, and correct — and explains exactly how to exercise them.

4.4 Do Not Track

Kinora does not respond to Do Not Track signals, as there is no common industry standard for how to interpret them.


5. Data retention

We retain personal information only as long as we have a clear business reason to do so, then delete it automatically. Our retention windows:

  • Hotel account data: retained while the account is active, plus 90 days after cancellation for billing reconciliation
  • Guest conversation logs (Clef chat): retained for 30 days from the date of the last message, then automatically deleted nightly
  • Flagged conversations (those involving safety concerns, abuse, or complaints requiring investigation): retained for 12 months
  • Analytics events (page views, link clicks, UTM data): retained for 90 days
  • Server logs (IP addresses, request metadata): retained for 30 days

Hotels or guests may request earlier deletion at any time (see Section 4). All retention windows are enforced by automated nightly deletion jobs.


6. Security

We implement industry-standard security measures to protect information, including encryption of data in transit (TLS), encryption at rest for sensitive fields, access controls, and regular security reviews of our sub-processors. No system is perfectly secure, however, and we cannot guarantee absolute security. If we become aware of a security incident affecting your data, we will notify you in accordance with applicable law.


7. Cookies and similar technologies

Kinora uses cookies and similar technologies on kinorahq.com and on Hotel Kinora pages for:

  • Authentication (to keep you signed in)
  • Session management
  • Basic analytics (which pages are viewed)
  • If the Hotel has enabled them: Meta Pixel, Google Analytics, or TikTok Pixel (UTM tracking)

You can control cookies through your browser settings. Disabling cookies may affect the functionality of the service.


8. Children's privacy

Kinora is not directed to children under 16. We do not knowingly collect personal information from children under 16. Clef is instructed to refuse substantive engagement with anyone who identifies as under 16 and to route them to ask a parent or guardian. If we learn that we have collected information from a child under 16, we will delete it promptly. If you believe a child has provided information to us, contact partner@kinorahq.com.


9. International data transfers

Kinora is currently operated from the United States and data is primarily processed in the United States. Because Kinora is not currently offered to Hotels located in the European Union, the European Economic Area, or the United Kingdom, we do not currently rely on Standard Contractual Clauses or equivalent cross-border transfer mechanisms. If you access Kinora from a jurisdiction with different data protection laws, by using the service you consent to the transfer and processing of information in the United States.


10. California privacy rights

This section applies to California residents and supplements the rest of this Privacy Policy. It is provided under the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the "CCPA"). We extend the rights described here to California residents whether or not Kinora currently meets the CCPA's business-size thresholds.

10.1 Our two roles

  • As a business. For personal information about a Hotel's own account and its authorized users, Kinora decides how and why that information is processed.
  • As a service provider. For personal information about Guests that we process on a Hotel's behalf — Clef conversation content, requests a Guest asks Clef to forward, and page analytics — Kinora acts as a service provider to that Hotel under a written contract, and we process that information only to provide the service. We do not retain, use, or disclose it for any other purpose, and we do not combine it with information from other sources. A Guest who wants to exercise rights over that information should contact the Hotel; if a Guest contacts us instead, we will help the Hotel respond.

10.2 What we collect, and why

In the preceding 12 months we have collected the following categories of personal information. Sources, purposes, and recipients are described in full in Sections 1, 2 and 3.

CCPA categoryWhat this means for KinoraCollected fromDisclosed for a business purpose to
IdentifiersHotel name and contact email; authorized user name and email; a Guest's name and one contact method voluntarily given to Clef; IP addressHotels, Guests, automaticallySub-processors in Section 3.1; the Hotel (Section 3.2)
Customer records (Cal. Civ. Code §1798.80)Billing contact details. Card numbers are handled by Stripe and are never stored by KinoraHotelsStripe
Commercial informationSubscription plan, billing historyHotels, automaticallyStripe
Internet or other network activityPages viewed, links clicked, referral and UTM data, Clef conversation contentAutomatically, GuestsSub-processors in Section 3.1; the Hotel
Geolocation dataGeneral location (country or region) inferred from IP address. Not precise geolocationAutomaticallySub-processors in Section 3.1
InferencesNone. We do not build profiles or draw inferences about Guests——

We do not collect Social Security numbers, driver's license or passport numbers, payment card numbers, precise geolocation, biometric information, account credentials, or health information.

10.3 Sensitive personal information

We do not collect sensitive personal information as the CCPA defines it, and we do not use or disclose any for purposes that would give rise to the right to limit. Clef is instructed not to collect it (Section 1.2); if a Guest volunteers such information anyway, Clef is instructed not to acknowledge or repeat it, and we remove it from logs on discovery or on request.

10.4 We do not sell or share personal information

Kinora has not sold personal information, and has not shared personal information for cross-context behavioural advertising, in the preceding 12 months — or at any time. We also do not use Guest personal information or Hotel content to train AI models, and we do not disclose personal information to third parties for their own direct marketing. Because we do not sell or share, there is no "Do Not Sell or Share My Personal Information" opt-out to offer; if that ever changes we will add one and update this policy first.

We have not sold or shared the personal information of consumers we know to be under 16.

10.5 How long we keep it

Each category is retained only for the period stated in Section 5 (Data retention) and is then deleted by an automated nightly job.

10.6 Your rights

As a California resident you have the right to:

  • Know and access — the categories and specific pieces of personal information we have collected about you, the sources, the business purposes, and the categories of parties we disclosed it to
  • Delete — request deletion of personal information we collected from you, subject to the exceptions the CCPA allows (for example, completing a transaction, security, or complying with a legal obligation)
  • Correct — request correction of inaccurate personal information
  • Opt out of sale or sharing — not applicable: we do neither (Section 10.4)
  • Limit the use of sensitive personal information — not applicable: we collect none (Section 10.3)
  • Non-discrimination — we will not deny you service, charge you a different price, or give you a lower quality of service because you exercised any of these rights. We do not offer financial incentives in exchange for personal information

10.7 How to make a request

Use the data request page at kinorahq.com/data-request, or email partner@kinorahq.com with the subject line "California privacy request". Tell us which right you are exercising and give us enough to find your records — for a Hotel, the account email address; for a Guest, the Hotel's name and the email address or name you used in the conversation.

Verification. We verify a request by matching the details you give us against what we hold, and by confirming the request from the email address on the account or used in the conversation. If we cannot verify you from that alone we may ask for one additional piece of information, used only for verification and then deleted. You do not need an account to make a request.

Timing. We acknowledge requests within 10 business days and respond within 45 calendar days. If we need longer we will tell you within that period, and may take up to a further 45 days.

Authorized agents. You may use an authorized agent. We will ask the agent for written permission signed by you, and we may ask you to confirm your identity with us directly.

10.8 Shine the Light

California Civil Code §1798.83 lets California residents ask a business about personal information it disclosed to third parties for those third parties' direct marketing. Kinora does not disclose personal information for third-party direct marketing, so there is nothing to report. You may still ask at partner@kinorahq.com.


11. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top will reflect the most recent revision. For material changes, we will notify active Hotels by email. Continued use of the service after a change constitutes acceptance of the revised Privacy Policy.


12. Contact

Questions about this Privacy Policy or your data:

Kinora Email: partner@kinorahq.com Support: partner@kinorahq.com Website: kinorahq.com


This Privacy Policy is written for clarity and reflects our actual practices. It is not a substitute for legal advice. We recommend reviewing this policy periodically and reaching out with questions.