Privacy Policy

Last updated: 21 July 2026 · Version 2.2

This policy explains how the KiBand commercial brand (“KiBand”, “we”) processes personal data through the KiBand platform, its web interfaces and the KiBand Terminal Android application (package name: com.kiband.terminal).

KiBand is a professional solution for hotels, hotel groups and their teams. It identifies guests using an NFC wristband, QR code or room card and manages the entitlements, points, meals, coupons and consumption linked to their stay.

1. Responsibilities

For guest, stay, employee and hotel-operation data, the hotel or hotel group using KiBand is generally the data controller. KiBand acts as a data processor according to the property’s instructions and configuration.

KiBand acts as controller for its own business contacts, customer contracts, service security and requests sent directly to KiBand.

2. Data we process

2.1 Hotel guest data

2.2 Professional user data

2.3 Terminal and technical data

2.4 Business contacts and requests sent to KiBand

3. Android application permissions

3.1 NFC

NFC access reads the technical identifier of a wristband presented to the terminal. This identifier is sent to KiBand to retrieve the stay and verify guest entitlements. KiBand does not read other phone content or use NFC for advertising.

3.2 Camera

The camera is used only when a user chooses to scan a KiBand QR code. Images are analyzed locally in real time; they are not saved to the gallery, retained by KiBand or sent to our servers. Only the QR code’s technical content is used to identify the relevant wallet.

3.3 Internet

Internet access is required to authenticate the terminal, synchronize stay data, verify credentials and record operations. The application does not request access to location, contacts, microphone, SMS or personal phone files.

4. Local storage and offline operation

The professional terminal may locally retain a session token, selected POS, the last known state of previously checked credentials and operations awaiting synchronization. This enables service continuity during network outages.

Synced operations are progressively removed from the local queue. Other local data is removed when application data is cleared or the app is uninstalled. Android application backup is disabled.

5. Data sources

Data may come from:

6. Purposes

KiBand does not sell personal data, serve targeted advertising or use hotel guest data to train artificial-intelligence models.

7. Legal bases

Processing follows the hotel’s instructions and may rely, depending on context, on performance of the hotel contract, performance of the KiBand contract, requested pre-contract steps, legitimate interests in service security and operation, a legal obligation, or consent where required. Electronic prospecting addressed to a natural person is carried out only with prior consent or in another case expressly permitted by applicable law.

8. Recipients and service providers

Data is available only to authorized hotel users, authorized entities within its group and KiBand personnel who require access for support or security. KiBand notably relies on:

Hotel-connected PMS and POS providers process data under their own contracts and policies. KiBand does not share data with advertising networks or data brokers.

9. International transfers

KiBand prioritizes primary hosting within the European Union. Some authentication, hosting, security or email providers may nevertheless process data in the United States or other countries. KiBand applies the relevant contractual and organizational safeguards and completes the formalities required by applicable regulations.

10. Retention

Data is retained for the time required to operate the service, manage the contractual relationship, meet hotel audit needs and comply with legal obligations. Exact periods may depend on the contract and hotel instructions.

11. Security

KiBand uses HTTPS encryption, role-based access controls, property isolation, revocable terminal tokens, operation logging and technical backups. Android access requires a hotel, user identifier and PIN, followed by an authorized POS selection.

Vulnerabilities may be reported to security@kiband.app.

12. Your rights and deletion

Depending on applicable law, individuals may request access, correction, deletion, restriction, objection or portability of their data.

Hotel guests should first contact their hotel, which controls their stay data. Professional users should contact their hotel administrator to disable or delete access. Requests may also be sent to privacy@kiband.app.

The mobile application does not allow self-service account creation; access is created and managed by the hotel. Individuals may also contact the competent data-protection authority, including Morocco’s CNDP or the authority in their country of residence.

13. Cookies and audience measurement

Web interfaces use only cookies and storage required for authentication, security and service operation. KiBand does not include advertising in its Android application or use advertising or behavioral-tracking SDKs.

When a visitor reaches the website with campaign parameters (UTMs), KiBand keeps them in first-party browser session storage until the session ends so that a later contact request can be attributed to its source. This mechanism does not track browsing on other websites, store unrelated URL parameters or create behavioral profiles.

14. Use by minors

The Android application is a professional tool restricted to authorized property employees and contractors. It is not designed for direct use by children.

15. Policy changes

This policy may change to reflect updates to the service, its providers or regulations. The current version and update date are always available on this page.

16. Contact

Privacy: privacy@kiband.app
General: hello@kiband.app
KiBand, Casablanca, Morocco. Full legal details of the contracting entity are stated in the applicable order form.