Privacy Policy

Last Updated: February 26, 2026

1. Introduction

KillCommissions ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Direct Deal Widget service (the "Service").

This policy applies to two categories of users:

  • Hotel Customers: Hotels and accommodation providers who subscribe to our Service
  • Guests: End users who make bookings through the widget installed on hotel websites

2. Data Controller vs. Data Processor

For Hotel Customer Data: We act as the data controller for information we collect directly from hotel customers about their business and account.

For Guest Data: We act as a data processor on behalf of our hotel customers. Hotels are the data controllers for guest information collected through bookings. See our Data Processing Agreement for details.

3. Information We Collect

3.1 Hotel Customer Information

When hotels register for our Service, we collect:

  • Account Information: Business name, contact name, email address, phone number, billing address
  • Hotel Data: Property details, room types, pricing, availability, images, amenities
  • Payment Information: Stripe Connect account details, billing information (processed securely by Stripe)
  • Configuration Data: Widget settings, branding preferences, custom messages, AI context
  • Usage Data: Dashboard access logs, API usage, feature usage analytics

3.2 Guest Information

When guests make bookings through the widget, we collect:

  • Personal Information: Full name, email address, phone number
  • Booking Details: Check-in/out dates, number of guests, room preferences, special requests
  • Payment Information: Payment method details (tokenized by Stripe, we never store full card numbers)
  • Conversation Data: Messages exchanged with the AI-powered booking assistant
  • Device Information: Browser type, device type, IP address, approximate location

3.3 Automatically Collected Information

  • Technical Data: IP addresses, browser type and version, time zone, operating system
  • Usage Data: Page views, widget interactions, booking funnel analytics, session duration
  • Cookies: See Section 10 for cookie usage details

4. How We Use Your Information

4.1 Hotel Customer Data

We use hotel customer information to:

  • Provide and maintain the Service
  • Process subscription payments and billing
  • Customize the widget appearance and functionality
  • Provide customer support and respond to inquiries
  • Send service updates, security alerts, and administrative messages
  • Analyze usage patterns and improve the Service
  • Detect and prevent fraud and security issues
  • Comply with legal obligations

4.2 Guest Data

We process guest information on behalf of hotels to:

  • Process and confirm bookings
  • Send booking confirmations and reminders via email
  • Enable AI-powered conversation assistance
  • Process payments securely through Stripe
  • Provide booking management for hotels
  • Handle booking modifications and cancellations

5. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), UK, and Switzerland, we process personal data based on the following legal grounds:

  • Contract Performance: Processing necessary to provide the Service you requested
  • Legitimate Interests: Improving our Service, fraud prevention, security
  • Legal Obligation: Compliance with laws, regulations, and legal processes
  • Consent: For marketing communications and optional features (you may withdraw consent at any time)

6. Data Sharing and Third-Party Services

We share data with the following third-party service providers who help us operate the Service:

6.1 Third-Party Service Providers

6.2 Other Disclosures

We may disclose information when:

  • Required by law, regulation, or legal process
  • Necessary to protect our rights, property, or safety
  • In connection with a merger, acquisition, or sale of assets (with notice to affected users)
  • With your explicit consent

6.3 No Selling of Personal Data

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

7. Data Retention

We retain personal information for as long as necessary to provide the Service and fulfill the purposes outlined in this policy:

  • Active Hotel Accounts: Data retained while account is active
  • Closed Accounts: 90 days after account closure (to allow reactivation)
  • Booking Records: 7 years for tax and accounting purposes
  • Payment Data: Retained by Stripe per their policies, not stored on our servers
  • Conversation Logs: 2 years for quality assurance and improvement
  • Analytics Data: Aggregated and anonymized data may be retained indefinitely
  • Backups: Up to 30 days in backup systems after deletion from production

8. Data Security

We implement industry-standard security measures to protect your information:

  • Encryption: All data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256.
  • Access Controls: Role-based access controls and multi-factor authentication for staff
  • Regular Audits: Security audits and vulnerability assessments
  • Payment Security: PCI-DSS compliant payment processing through Stripe
  • Monitoring: 24/7 security monitoring and intrusion detection
  • Data Minimization: We collect only the data necessary to provide the Service

However, no method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

9. Your Privacy Rights

9.1 Rights for All Users

You have the right to:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information (subject to legal obligations)
  • Export: Receive your data in a portable, machine-readable format
  • Opt-Out: Unsubscribe from marketing communications

9.2 GDPR Rights (EEA, UK, Switzerland)

If you are located in the EEA, UK, or Switzerland, you have additional rights:

  • Right to Restriction: Request restriction of processing in certain circumstances
  • Right to Object: Object to processing based on legitimate interests
  • Right to Data Portability: Receive data in a structured, commonly used format
  • Right to Withdraw Consent: Withdraw consent for processing based on consent
  • Right to Lodge a Complaint: File a complaint with your local data protection authority

9.3 CCPA Rights (California Residents)

California residents have the right to:

  • Know: What personal information we collect, use, and disclose
  • Delete: Request deletion of personal information (subject to exceptions)
  • Opt-Out: Opt out of the sale of personal information (we do not sell personal information)
  • Non-Discrimination: Not be discriminated against for exercising your rights

9.4 How to Exercise Your Rights

To exercise any of these rights, please:

  • Email us at: privacy@killcommissions.com
  • Use the data request form in your account dashboard
  • Contact our Data Protection Officer (see Section 16)

We will respond to verified requests within 30 days (GDPR) or 45 days (CCPA). We may request additional information to verify your identity.

9.5 Guest Data Rights

If you are a guest who made a booking through the widget, your data is controlled by the hotel. Please contact the hotel directly to exercise your privacy rights. We will assist hotels in responding to guest data requests as their data processor.

10. Cookies and Tracking Technologies

10.1 Types of Cookies We Use

  • Essential Cookies: Required for the Service to function (authentication, security, load balancing)
  • Functional Cookies: Remember your preferences and settings
  • Analytics Cookies: Help us understand how users interact with the Service
  • Performance Cookies: Measure Service performance and optimize user experience

10.2 Managing Cookies

You can control cookies through:

  • Our cookie consent banner (for non-essential cookies)
  • Your browser settings (may affect Service functionality)
  • Cookie preferences in your account dashboard

10.3 Do Not Track

Some browsers support "Do Not Track" signals. Our Service does not currently respond to Do Not Track signals, but you can control cookies through our cookie consent banner.

11. International Data Transfers

Our Service is operated in the United States. If you are located outside the United States, please be aware that information we collect will be transferred to and processed in the United States.

For users in the EEA, UK, and Switzerland, we rely on:

  • Standard Contractual Clauses approved by the European Commission
  • Data Processing Agreements with third-party processors
  • Adequacy decisions where applicable

We ensure that appropriate safeguards are in place to protect your data in accordance with this Privacy Policy.

12. Children's Privacy

Our Service is not directed to children under 16 years of age. We do not knowingly collect personal information from children under 16. If we learn that we have collected personal information from a child under 16, we will delete it promptly. If you believe we have collected information from a child, please contact us at privacy@killcommissions.com.

13. Data Breach Notification

In the event of a data breach that affects your personal information:

  • We will notify affected users within 72 hours of discovery
  • We will provide details about the breach and steps we are taking
  • We will notify relevant data protection authorities as required by law
  • For guest data breaches, we will notify the affected hotel who will notify their guests

14. California Privacy Rights

California residents have specific rights under the California Consumer Privacy Act (CCPA):

Categories of Personal Information Collected

  • Identifiers (name, email, phone, IP address)
  • Commercial information (booking history, purchase records)
  • Internet activity (browsing history, widget interactions)
  • Financial information (payment details, processed by Stripe)
  • Professional information (for business accounts)

Business Purpose for Collection

See Section 4 for detailed information on how we use personal information.

Sale of Personal Information

We do not sell personal information as defined by CCPA. We share information with service providers as described in Section 6.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes:

  • We will update the "Last Updated" date at the top of this policy
  • We will notify you via email at least 30 days before changes take effect
  • We may display a prominent notice on our website or Service
  • For material changes affecting guest data, we will notify hotel customers to inform their guests

Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.

16. Contact Information

For questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:

Email: privacy@killcommissions.com

Data Protection Officer: dpo@killcommissions.com

Support: support@killcommissions.com

Mailing Address:
KillCommissions
Attn: Privacy Department
[Business Address - To Be Added]

EU Representative

If you are located in the EEA or UK, you may also contact our EU representative at: [To Be Designated]

By using the KillCommissions Direct Deal Widget service, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described herein.