Privacy Policy
Last updated: 21 July 2026 · Version 2.2
This policy explains how the KiBand commercial brand (“KiBand”, “we”) processes personal data through the KiBand platform, its web interfaces and the KiBand Terminal Android application (package name: com.kiband.terminal).
KiBand is a professional solution for hotels, hotel groups and their teams. It identifies guests using an NFC wristband, QR code or room card and manages the entitlements, points, meals, coupons and consumption linked to their stay.
1. Responsibilities
For guest, stay, employee and hotel-operation data, the hotel or hotel group using KiBand is generally the data controller. KiBand acts as a data processor according to the property’s instructions and configuration.
KiBand acts as controller for its own business contacts, customer contracts, service security and requests sent directly to KiBand.
2. Data we process
2.1 Hotel guest data
- first and last name, occupant type and accompanying-guest information;
- booking number, room number and stay dates;
- rate plan, meal plan, extras and folio information;
- credential identifier: NFC wristband, wallet QR or room card;
- allocated points, balance, consumption, meals, coupons, receipts and tickets;
- eligibility-check results, date, time, service point and reason for approval or denial.
2.2 Professional user data
- name, email address, mobile identifier, role and associated hotel;
- authorized service points and access rights;
- operations performed, including scans, lookups and consumption;
- mobile PIN, securely verified and stored server-side only in unreadable form;
- connection logs and security events.
2.3 Terminal and technical data
- terminal model, Android platform and technical identifier;
- selected hotel and service point;
- IP address, user agent, and request date and time;
- session tokens and technical data required for security and synchronization.
2.4 Business contacts and requests sent to KiBand
- name, role, property and country;
- professional email address and telephone number;
- property size, offer of interest and request content;
- contact source, communications, meetings and next steps;
- authorized channel, any consent and opt-out request.
3. Android application permissions
3.1 NFC
NFC access reads the technical identifier of a wristband presented to the terminal. This identifier is sent to KiBand to retrieve the stay and verify guest entitlements. KiBand does not read other phone content or use NFC for advertising.
3.2 Camera
The camera is used only when a user chooses to scan a KiBand QR code. Images are analyzed locally in real time; they are not saved to the gallery, retained by KiBand or sent to our servers. Only the QR code’s technical content is used to identify the relevant wallet.
3.3 Internet
Internet access is required to authenticate the terminal, synchronize stay data, verify credentials and record operations. The application does not request access to location, contacts, microphone, SMS or personal phone files.
4. Local storage and offline operation
The professional terminal may locally retain a session token, selected POS, the last known state of previously checked credentials and operations awaiting synchronization. This enables service continuity during network outages.
Synced operations are progressively removed from the local queue. Other local data is removed when application data is cleared or the app is uninstalled. Android application backup is disabled.
5. Data sources
Data may come from:
- the hotel and its authorized users;
- PMS, POS or other hotel-connected systems, including eZee Absolute, eZee Optimus or ipos247;
- credentials presented to a KiBand terminal;
- operations performed in KiBand applications.
- people who submit a form, request a conversation or contact us directly;
- a professional introduction or, on a limited basis, publicly available professional sources.
6. Purposes
- authenticate users and secure access;
- identify guests and verify eligibility;
- manage wallets, points, meals, coupons and consumption;
- support use within one property or across a hotel group;
- synchronize data with authorized PMS and POS systems;
- produce histories, tickets, reports and audit trails;
- prevent abuse, errors, duplicate consumption and fraud;
- provide support, maintenance and service continuity.
- respond to requests, arrange demonstrations and prepare commercial proposals;
- manage relationships with prospects, customers and partners;
- send commercial communications only where consent or another applicable legal condition permits it.
KiBand does not sell personal data, serve targeted advertising or use hotel guest data to train artificial-intelligence models.
7. Legal bases
Processing follows the hotel’s instructions and may rely, depending on context, on performance of the hotel contract, performance of the KiBand contract, requested pre-contract steps, legitimate interests in service security and operation, a legal obligation, or consent where required. Electronic prospecting addressed to a natural person is carried out only with prior consent or in another case expressly permitted by applicable law.
8. Recipients and service providers
Data is available only to authorized hotel users, authorized entities within its group and KiBand personnel who require access for support or security. KiBand notably relies on:
- Supabase for database and storage services;
- Vercel for web and API hosting;
- Clerk for web-user authentication;
- Resend for transactional emails and responses to requests;
- Cloudflare for DNS and domain protection.
Hotel-connected PMS and POS providers process data under their own contracts and policies. KiBand does not share data with advertising networks or data brokers.
9. International transfers
KiBand prioritizes primary hosting within the European Union. Some authentication, hosting, security or email providers may nevertheless process data in the United States or other countries. KiBand applies the relevant contractual and organizational safeguards and completes the formalities required by applicable regulations.
10. Retention
Data is retained for the time required to operate the service, manage the contractual relationship, meet hotel audit needs and comply with legal obligations. Exact periods may depend on the contract and hotel instructions.
- professional accounts and access are retained while active, then disabled or deleted according to hotel instructions;
- stay and credential data may be deleted or anonymized when no longer needed;
- some tickets, logs and histories may be retained longer where required by law, security or transaction evidence.
- inactive prospect contacts are reviewed no later than twelve months after the last interaction and deleted or anonymized when no longer needed; minimal information may be retained to continue honoring an opt-out request.
11. Security
KiBand uses HTTPS encryption, role-based access controls, property isolation, revocable terminal tokens, operation logging and technical backups. Android access requires a hotel, user identifier and PIN, followed by an authorized POS selection.
Vulnerabilities may be reported to security@kiband.app.
12. Your rights and deletion
Depending on applicable law, individuals may request access, correction, deletion, restriction, objection or portability of their data.
Hotel guests should first contact their hotel, which controls their stay data. Professional users should contact their hotel administrator to disable or delete access. Requests may also be sent to privacy@kiband.app.
The mobile application does not allow self-service account creation; access is created and managed by the hotel. Individuals may also contact the competent data-protection authority, including Morocco’s CNDP or the authority in their country of residence.
13. Cookies and audience measurement
Web interfaces use only cookies and storage required for authentication, security and service operation. KiBand does not include advertising in its Android application or use advertising or behavioral-tracking SDKs.
When a visitor reaches the website with campaign parameters (UTMs), KiBand keeps them in first-party browser session storage until the session ends so that a later contact request can be attributed to its source. This mechanism does not track browsing on other websites, store unrelated URL parameters or create behavioral profiles.
14. Use by minors
The Android application is a professional tool restricted to authorized property employees and contractors. It is not designed for direct use by children.
15. Policy changes
This policy may change to reflect updates to the service, its providers or regulations. The current version and update date are always available on this page.
16. Contact
Privacy: privacy@kiband.app
General: hello@kiband.app
KiBand, Casablanca, Morocco. Full legal details of the contracting entity are stated in the applicable order form.