PRIVACY

Privacy Policy

MOYU runs a hotel's operation, which means we handle personal data — the hotel's, and its guests'. This explains what we collect, why, and the limits we hold ourselves to. Plain language first; the formal version comes with counsel before public launch.

Draft · last updated July 2026In effect for our pilot
This is a pre-launch draft. MOYU is in private beta. We operate under this policy for our pilot hotels today; the formal version — including our registered legal entity, data-protection contact, and effective date — will be finalised before we take on customers publicly. The operator is referred to below as MOYU (legal entity & registered address — to be confirmed). Questions today go to hello@getmoyu.com.

01Who controls what

There are two relationships to be clear about, because they carry different responsibilities.

Guest data belongs to the hotel. When a hotel uses MOYU, it decides what guest information to collect and why. The hotel is the controller of that data; MOYU is the processor that stores and acts on it under the hotel's instructions. We don't repurpose guest data, and we don't sell it — to anyone, ever.

Account data belongs to us to manage. For the staff and owners who log into MOYU, and for people who contact us or request access, MOYU is the controller. This policy covers both, and says which is which as it goes.

02What we collect

From the people who use MOYU

  • Account details — name, work email, role, and hashed credentials for staff and owners.
  • Contact & enquiry details — what you send us when you request access or email us.
  • Technical & usage data — logs, device and browser information, and error diagnostics that keep the service running and secure.

On behalf of the hotel, about its guests

To run the front desk, MOYU processes the guest information a hotel would normally keep: names and contact details, stay dates and room assignments, folio and payment records, messages exchanged with the property, and any preferences or notes staff record. The hotel decides what of this to collect; we process it to make the operation work.

03How we use it

  • To provide the service — reservations, folios, rates, messaging, the nightly close.
  • To let the MOYU agent act within the policies a hotel configures.
  • To keep the service secure, reliable, and free of fraud and abuse.
  • To support you, respond to enquiries, and send service-related messages.
  • To improve MOYU — using operational and aggregate signals, not by mining guest data for unrelated purposes.

04Our lawful basis

We process personal data to perform our agreement with the hotel, to meet our legitimate interest in running and securing the service, to comply with law, and — where required — on the basis of consent. For guest data, the hotel is responsible for having a lawful basis to collect it; MOYU acts on the hotel's documented instructions. We intend to operate in line with Indonesia's Personal Data Protection Law (UU PDP — specifics to be confirmed with counsel).

05Who we share with

We do not sell personal data. We share it only where it's needed to run the service, with providers bound to protect it:

  • Infrastructure & hosting — the servers and database that run MOYU.
  • Email delivery — to send confirmations and service messages.
  • Error & performance monitoring — to detect and fix problems.
  • Payments & integrations — where a hotel connects them, limited to what each needs to function.

We may also disclose data where the law genuinely requires it. A current list of sub-processors will be published here before public launch.

06How long we keep it

We keep personal data for as long as the hotel's account is active and as long as we need it for the purposes above — including the legitimate need to keep an accurate financial record. Because folios and events are an append-only ledger, corrections are made by new entries rather than by erasing history; where erasure is required by law, we handle it in a way that preserves the integrity of that record. When data is no longer needed, we delete or anonymise it.

07Your rights

Depending on where you are, you may have the right to access, correct, delete, or restrict the use of your personal data, and to object to certain processing. For account holders, contact us directly and we'll act on it. For guests of a hotel, the hotel is the controller — direct requests to the property, and MOYU will support the hotel in fulfilling them.

08Security & location

Data is encrypted in transit, sensitive fields are encrypted at the column, and each hotel's data is isolated from every other's at the database layer. The full picture is on our Security page. MOYU is operated from Indonesia; some providers we rely on may process data elsewhere, and where they do we take the steps required to protect it.

09Children

MOYU is a tool for hotel operators and is not directed to children. We don't knowingly collect data from children through the product. A hotel may hold guest records that concern minors as part of a booking; that data is the hotel's to control, and the hotel is responsible for any additional protections the law requires for minors.

10Changes & contact

We'll update this policy as MOYU grows, and we'll change the date at the top when we do. For anything about privacy or your data, email hello@getmoyu.com. A named data-protection contact will be listed here before public launch.

Draft Privacy Policy for MOYU · private beta · July 2026. To be finalised with counsel before launch.

Read the Terms →