Privacy Policy

Last updated: September 27, 2026 · Leer en español

Anfigo is a guest-messaging service for hotels and other lodging businesses: an AI assistant that answers a property's guests on WhatsApp, Facebook Messenger, Instagram and Telegram, connected to the property's reservation system (PMS), with a dashboard for the property's team. This policy explains what personal data is involved, who is responsible for it, and how it is protected. It is provided by anfigo LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA ("Anfigo", "we").

1. Who is responsible for what

  • Guests' data — the hotel decides, we act for it. When a guest writes to a hotel that uses Anfigo, the hotel decides why and how that conversation is used (it is the "controller"), and Anfigo processes it on the hotel's behalf and on its instructions (as "processor"), under our Data Processing Addendum. If you are a guest, the hotel you wrote to is your first point of contact; you can also write to us (§8).
  • Data from a hotel's PMS. Some PMS providers' terms make the software that connects to them responsible for the data it reads (Cloudbeds' API terms, for example). We therefore also meet the PMS provider's own obligations for that data — including its security and deletion rules — and use it only to provide the service to the hotel.
  • Hotels' account data and this website — we decide. For the accounts of the hotels that use Anfigo, their team members, and visitors to anfigo.com, Anfigo is the controller.

2. What we collect

From guests who message a hotel (on the hotel's behalf):

  • Identifiers: WhatsApp phone number; for Messenger and Instagram, the page-scoped or Instagram-scoped user ID and the name and profile picture Meta makes available for messaging; for Telegram, the user ID and display name.
  • Messages and attachments: text, photos, documents (such as payment receipts) and voice notes, with the transcript or description our AI writes of a voice note or image so it can answer.
  • What the guest tells the hotel for a booking: name, e-mail, country, dates, number of guests, room choice, language, and the booking and payment status the hotel's PMS and payment provider report.
  • Notes and labels the hotel's team adds to the chat.

From a hotel's PMS (when the hotel connects it): reservations with guest names, contact details, dates, rooms, amounts and payments.

From hotels and their teams: business and property name, account e-mail, a password (stored only as a one-way hash) or Google sign-in, optional door PINs (hashed), settings, knowledge base content, photos and documents they upload, and the details in an order form or invoice.

Technical data: server logs (including IP address and request details) kept for security and troubleshooting, and, inside the hotel dashboard only, product-usage events measured with Google Analytics for Firebase. The public website anfigo.com uses no analytics or advertising cookies.

3. How we use it

  • To answer guests on the hotel's behalf: understand the message, find the answer in the hotel's knowledge and PMS, send replies, photos and payment links from the hotel's own payment account, and hand the chat to the hotel's team when a person is needed.
  • To give the hotel's team its inbox, guest profiles, bookings and reports.
  • To keep the service working and safe: security, abuse prevention, backups, and finding and fixing mistakes in the assistant's replies (people at Anfigo may review chats and AI replies for that purpose).
  • To run the hotel's account: sign-in, support, invoicing and notices.

We never use hotels' or guests' data to train AI models — ours or anyone else's. We do not sell personal data, do not share it for advertising, and do not use it to profile guests for anyone but the hotel they wrote to.

Legal bases (where the GDPR or similar laws apply): for guest data, the hotel's own legal basis (we act on its instructions); for hotel accounts, the performance of our contract; for security, service improvement and product analytics, our legitimate interests; for records we must keep, legal obligation.

4. The AI assistant

Replies are written by a large language model (today Google's Gemini API, on the paid service, whose terms say that on paid services Google does not use prompts or responses to improve its products). The same service transcribes voice notes and describes images. The assistant says it is the hotel's virtual assistant whenever a guest asks. It takes booking and payment actions only within the rules the hotel switched on, and anything it cannot answer goes to the hotel's team. It does not make decisions that produce legal effects on a guest by itself.

4a. Facebook Messenger, Instagram and WhatsApp

When a hotel connects its Facebook Page and the Instagram professional account linked to it, Meta sends us the messages guests write to that Page or account, with the guest's page-scoped or Instagram-scoped user ID and the name and profile picture Meta makes available for messaging. When a hotel connects WhatsApp, we receive the messages sent to its number and the sender's phone number. We use this data only to answer the guest on the hotel's behalf, to show the conversation to the hotel's team, and to hand the chat to a person when needed. Replies the hotel's staff send from the Facebook, Instagram or WhatsApp Business apps are also delivered to us so that Anfigo pauses its automatic replies on that chat.

We store the access token Meta issues for the hotel's Page only to read and send messages for that Page and account. Disconnecting Messenger in the Anfigo dashboard deletes the token and stops all further data flow. We comply with Meta's Platform Terms and Developer Policies: data from Meta's platforms is never used for advertising, never sold, never used to train models, and never shared except with the sub-processors in §5. Guests and hotels can have it deleted at any time; see our data deletion instructions.

5. Who we share it with

Only with the providers that run the service for us (sub-processors), each under contract and only for that purpose, and with the platforms the hotel itself connects:

  • Google LLC (USA) — cloud hosting, database and file storage (United States), task scheduling, sign-in, the Gemini AI API, and Google Analytics for Firebase in the dashboard.
  • Meta Platforms — WhatsApp, Messenger and Instagram, the channels the hotel connects; messages pass through Meta under Meta's own terms.
  • Dualhook (WADA B.V., Netherlands) and ManyChat, Inc. (USA) — connection providers that link a hotel's WhatsApp number to Anfigo.
  • Telegram — when a hotel connects a Telegram bot.
  • The hotel's PMS (today Cloudbeds) and the hotel's payment provider (today Recurrente) — the hotel's own accounts, which the service reads from and writes to for that hotel.
  • E-mail providers that carry messages to and from our @anfigo.com addresses.

We may also disclose data when the law requires it, to protect rights and safety, or to a company that takes over our business under this policy. The current list is kept in our Data Processing Addendum; hotels are told before a new sub-processor is added.

6. Where it is stored

Anfigo is a US company, and the data is stored in the United States (Google Cloud). Some sub-processors process data in other countries. For data from the European Economic Area, the United Kingdom or Switzerland, transfers rely on the European Commission's standard contractual clauses (and their UK and Swiss equivalents), included in our DPA.

7. How long we keep it

  • Chats, guest profiles and bookings: for as long as the hotel's account is active, unless the hotel or the guest has them deleted sooner.
  • AI processing traces: 30 days. Message delivery receipts: 30 days.
  • When a hotel leaves: data read from its PMS is deleted within 10 days; everything else within 30 days after the 30-day export window (Terms §13).
  • After a deletion request: within 30 days (see data deletion).
  • Backups: copies are never restored into the service and expire on a fixed schedule, at most 12 weeks after they were made. Deleted data therefore disappears from backups within that time.
  • Invoices and records the law requires: for the period the law requires.

8. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict some uses, and to complain to a data-protection authority.

  • Guests: ask the hotel you wrote to, or write to privacy@anfigo.com with the hotel's name, the channel and the number or account you used. We act on the hotel's behalf and, where the law lets us act directly, we do. Step-by-step: data deletion instructions.
  • Hotels and team members: write to privacy@anfigo.com from the account e-mail.

We answer within 30 days and may ask you to confirm the request comes from you. We do not charge for it and do not treat you differently for using these rights. We do not "sell" or "share" personal information as those words are used in California law.

9. Security

Encryption in transit and at rest, hashed passwords and PINs, per-property separation of data, verified webhooks, least-privilege access, monitoring and layered backups. Details on our Security page. If a breach affects a hotel's data we tell the hotel without undue delay and within 72 hours.

10. Children

Anfigo is a business service and is not directed to children. Hotels should not use it to collect information from children beyond what a stay needs.

11. Cookies and similar storage

The hotel dashboard keeps the sign-in session in the browser's local storage and uses Google Analytics for Firebase to understand how the dashboard is used; it uses no advertising cookies. The public site anfigo.com sets no cookies of its own.

12. Changes

We post changes here with a new date. For a change that materially affects hotels, we e-mail each account at least 30 days before it takes effect.

13. Contact

Privacy questions and requests: privacy@anfigo.com · anfigo LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA.