Legal
Privacy Policy
Last updated: July 29, 2026
Notice at Collection. The categories of personal information we collect, the purposes we use them for, and the categories of third parties we share them with are summarised in each section below and detailed in Section 13 (California / CCPA). We do not sell personal information, and we do not share it for cross-context behavioural advertising.
Recama Inc. ("Recama", "we", "us", or "our") operates a booking engine and property-management platform for hospitality businesses. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit www.recama.com or use the Recama platform (collectively, the "Service"). By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.
1. Our Role in Data Processing
Recama enables hospitality businesses ('Clients') to take and manage bookings from their guests ('Guests'). Understanding our role matters:
When we act as a data controller. We are the controller for information we collect directly from you when you create a workspace, visit our website, or contact us — account registration data, billing information, and support communications.
When we act as a data processor. When a Client uses Recama to run their property, we process Guest data on that Client's behalf. The Client is the controller; we process according to their instructions. If you are a Guest whose data is processed through Recama, contact the property you booked with directly regarding your privacy rights — they decide what happens to their guest records, and we assist them.
2. Information We Collect
2.1 Information you provide directly. Account information — name, email address, business name, role, language preference, and password. Passwords are handled by our authentication provider and stored only as cryptographic hashes; we never see them. Billing information — the payment details necessary to process your subscription, handled by our payment processor. Support communications — the content of messages you send us. Workspace configuration — property details, rooms and units, rates, availability, policies, branding assets, integration credentials, and where a country requires it for receipts, tax registration details such as an RTN for Honduran fiscal documents.
2.2 Guest information entered or collected by a Client. Full name, email address, phone number, country, nationality, identity-document type and number, reservation dates and items, the amounts paid and outstanding, and the content of guest conversations where the Client uses the guest inbox — across WhatsApp, Instagram, Messenger, email, live chat, and the website contact form.
2.3 Payment information. Full card numbers never reach our servers. Card details are entered directly into the payment processor's own hosted fields. We store the amount, currency, status, the processor's reference identifiers, and where the processor returns them, the card brand and last four digits.
2.4 Information collected automatically. Usage data — features accessed, actions taken, timestamps, session duration. Device and connection information — browser type, operating system, device identifiers, IP address, and general location derived from IP.
2.5 Information from third-party sources. When you connect Recama to a third-party service — a payment provider, a messaging channel, a mailbox, or a calendar feed — we receive the data necessary to provide the integration functionality you enabled.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Providing the Service — showing availability and prices, taking and managing bookings, processing payments, issuing receipts and any legally required fiscal documents, delivering confirmations and other transactional messages, and providing the reports and tools you subscribe to.
- Account management — creating and managing your workspace, authenticating you, and communicating with you about your account.
- Billing — processing payments, managing subscriptions, and calculating your per-unit price from the inventory active in your workspace.
- Service improvement — analysing usage patterns in aggregate, diagnosing technical issues, and developing new features.
- Security — detecting, preventing, and responding to fraud, abuse, and security incidents.
- Legal compliance — meeting our legal, tax, and accounting obligations and responding to lawful requests.
4. How We Share Your Information
We do not sell personal information. We share it only in the following circumstances, and only over encrypted connections:
- With the property a Guest booked with — Guest information is visible to the staff of that property, and to no other customer of Recama.
- With service providers — the sub-processors listed below, each acting on our instructions for the specific purpose named.
- With payment processors — to take a payment, issue a refund, or respond to a dispute.
- With tax authorities — where a country's law requires reporting of issued receipts, for example the Honduran SAR regime.
- For legal requirements — where we believe disclosure is necessary to comply with applicable law, respond to legal process, or protect the rights and safety of any person.
- Business transfers — if Recama is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.
- With your consent — at your explicit direction.
5. Data Retention
We retain your personal information for as long as your workspace is active or as needed to provide the Service. When you close your workspace we delete or anonymise your information within 90 days, except where retention is required for legal, accounting, or security purposes.
For data we process on behalf of a Client, retention is determined by that Client. On termination of a Client's subscription we retain their data for 30 days — so it can be exported or the account reactivated — before permanent deletion.
As a rule of thumb: workspace-tied information for the life of the account; billing records for 7 years for tax purposes; server logs and analytics for 13 months; reservation and fiscal records for the period required by the tax law of the country the property operates in. Identity-document images are not retained at all — see Section 15.
6. Data Security
We implement technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, or destruction:
- Tenant isolation enforced at the database layer using row-level security, so a query made under one workspace's credentials cannot read or write another's. This is enforced by the database itself, not by application code alone.
- Encryption of data in transit using TLS.
- Encryption of data at rest by our database and storage provider.
- Card details never touch our servers — they go directly to the payment processor's hosted fields.
- Payment credentials and other secrets held in a dedicated secret store, never sent to the browser and never written to application logs.
- Role-based access control within a workspace, and an audit log of administrative actions.
- Secure infrastructure hosted on enterprise-grade cloud platforms.
7. Cookies and Tracking Technologies
We use cookies and similar technologies to operate and improve the Service. Essential cookies are required for it to function, including authentication and security. Functional cookies remember your preferences, such as your chosen language. Analytics cookies help us understand how the Service is used so we can improve it.
Most browsers let you control cookies through their settings. Blocking certain cookies may affect functionality — you will not be able to stay signed in without essential cookies.
8. Your Privacy Rights
Depending on where you live, you may have the right to access the personal information we hold about you, to have it corrected or deleted, to receive a copy in a portable format, to object to or restrict certain processing, and to withdraw consent where processing is based on it.
To exercise these rights, contact privacy@recama.com. We will respond within the timeframe required by applicable law.
If you are a Guest whose data is processed through the Service on behalf of a property, direct your request to that property. We assist our Clients in responding to such requests as required by our agreements and applicable law.
9. International Data Transfers
Recama is operated from the United States, and our service providers process data in the United States and other countries. If you access the Service from elsewhere — including Honduras and the rest of Central America — your information may be transferred to, stored, and processed in those countries.
We implement appropriate safeguards for international transfers, including standard contractual clauses where required by applicable law.
10. Children's Privacy
The Service is a business tool and is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children directly. A property may record a minor as an occupant of a booking made by an adult; that information is handled like any other Guest information and remains under the property's control.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will post the updated policy with a new effective date and notify subscribing Clients by email. Continuing to use the Service after changes become effective means you accept the updated policy.
12. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact Recama Inc. at privacy@recama.com. Address: Wilmington, Delaware, United States.
13. Additional Disclosures for California Residents
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act ('CCPA') gives you additional rights. This section applies in addition to the rest of this Policy.
13.1 Categories of personal information collected. In the preceding twelve months we have collected:
| CCPA category | Examples | Collected? |
|---|---|---|
| Identifiers | Name, email, account ID, IP address | Yes |
| Customer records | Billing address, payment method (token only) | Yes |
| Commercial information | Subscription status, billing history, support tickets | Yes |
| Internet / network activity | Pages viewed, feature usage, device metadata | Yes |
| Geolocation (general) | Country/region inferred from IP | Yes |
| Professional information | Business name, job title (only if provided) | Sometimes |
| Inferences | Workspace size, feature affinity for product improvement | Yes |
| Sensitive personal information | Account credentials; guest identity-document numbers held on a Client's behalf | Yes — limited use |
| Biometric / health / genetic | — | No |
- 13.2 Sources. Directly from you; automatically from your device; from third-party services you authorise; and from service providers acting on our behalf.
- 13.3 Business purposes. Providing, maintaining, securing, and improving the Service; authenticating you; billing; support; fraud and abuse prevention; and legal compliance.
- 13.4 Third parties. Service providers (hosting, database, storage, payment processing, email and SMS delivery, messaging channels); integration partners you authorise; government bodies or courts when legally required; and acquirers in a merger or sale, with notice.
- 13.5 Sale or sharing. Recama does not sell personal information as defined under CCPA, and does not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months, and we do not knowingly sell or share the personal information of consumers under 16. Because we do not sell or share, there is no opt-out to exercise. If our practices ever change we will update this section and provide a working opt-out before any sale or sharing begins.
- 13.6 Your CCPA rights. The right to know, to delete, to correct, to opt out of sale or sharing, to limit the use of sensitive personal information, and to non-discrimination — we will not deny service, charge different prices, or provide a lower quality of service because you exercised a right.
- 13.7 How to exercise. Email the privacy address in Section 12 with the subject line 'California Privacy Request'. Before acting we must verify your identity: for account holders this usually means confirming from your registered email; otherwise we may ask you to confirm two or three identifiers we already hold. We will not ask for information we do not already have.
- 13.8 Timing. We confirm receipt within ten business days and respond substantively within forty-five calendar days. We may extend by a further forty-five days where reasonably necessary, and will tell you why before the original deadline expires.
- 13.9 Authorised agents. You may designate an agent to submit a request. We require signed written permission or a valid power of attorney, plus direct verification of your identity and confirmation that you authorised the agent.
- 13.10 Shine the Light. We do not disclose personal information to third parties for their own direct marketing purposes.
14. Additional Disclosures for EEA, UK and Switzerland Residents
If you are located in the EEA, UK, or Switzerland, the GDPR or equivalent local law gives you additional rights.
Legal bases. We process personal information on the basis of performance of a contract with you, our legitimate business interests, your consent, and compliance with legal obligations.
Data controller. For personal information we collect as a controller, Recama Inc. is the data controller; our contact details are in Section 12. Where we process Guest data on behalf of a property, that property is the controller.
Supervisory authority. You have the right to lodge a complaint with your local data protection authority if you believe we have not complied with applicable data protection law.
15. Identity-Document Scanning and AI Features
This section describes how Recama handles identity documents, because it is the most sensitive processing the Service performs. It applies to Clients who use the check-in ID-scanning feature, which is optional — a property can always enter guest details manually instead.
15.1 What happens. A staff member captures or uploads an image of a guest's identity document or passport. The image is transmitted over an encrypted connection to our AI provider, which reads it and returns the fields it contains — typically name, document number, nationality, date of birth, sex, and expiry date. Those extracted fields are saved to the guest record so the property can meet its guest-registration obligations.
15.2 The image is not stored. Recama's scanning service is stateless: it holds no database and no file storage. The document image is processed in transit and is not written to our systems. Only the extracted text fields are retained, on the guest record, under the property's control and retention settings.
15.3 Limited use by the AI provider. Our AI provider processes the image solely to return the extracted fields. Your data, your guests' data, and the content of guest conversations are not used to train AI models shared with other customers or third parties.
15.4 Accuracy. Automated document reading can misread a field. It is an aid to your front desk, not an authority on identity. The property remains responsible for verifying a guest's identity and for the accuracy of the details recorded.
15.5 Other AI features. Where the Service offers assistance drafting guest replies, the same limits apply: output should be reviewed before it is sent, and conversation content is not used to train shared models.
Service providers (sub-processors)
We engage the following providers to operate the Service. Each is contractually obliged to use your information only to provide services to us, must maintain appropriate security measures, and cannot sub-contract processing without our approval.
- Supabase — Database, authentication and file storage — the primary system of record.
- Cloudflare — Application hosting and content delivery.
- Stripe — Subscription billing for properties, and card processing for guest bookings.
- PayPal — Card and PayPal processing for guest bookings, where the property enables it.
- Pagadito — Card processing for guest bookings in Central America, where enabled.
- Postmark — Transactional email (confirmations, receipts, staff notifications).
- Twilio — Transactional SMS, where enabled.
- Zernio — WhatsApp, Instagram and Messenger messaging for the guest inbox.
- Nylas — Email synchronisation for the guest inbox, where a property connects its mailbox.
- Anthropic — Reads an ID or passport image to extract its fields. The image is processed and not stored by Recama.