GDGrand Diyafa

Legal

Privacy Policy

Last updated: September 3, 2026

Grand Diyafa (“Grand Diyafa,” “we,” “us,” or “our”) provides property management software for independent hotels, including reservations, front desk, billing, housekeeping, and channel management. This Privacy Policy explains what information we collect, how we use it, and the choices available to hotels and their staff (“Customers”) and the guests whose data Customers process through the platform.

1. Information we collect

  • Account and staff information: name, email address, role, and hotel affiliation for each person a Customer invites to use Grand Diyafa.
  • Guest and reservation data: guest names, contact details, identity/nationality fields, stay dates, room assignments, folio charges, and payment records that a Customer enters or that arrive automatically through a connected booking channel.
  • Connected mailbox data (Channel Manager): when a Customer connects a Gmail inbox to automatically ingest OTA (online travel agency) booking notifications, we access only the messages needed to detect and parse reservation emails from that inbox. We do not read, store, or use the content of unrelated emails, and we never use this data for advertising.
  • Usage data: basic product-analytics events (e.g. pages viewed, actions taken) used to keep the product reliable and to understand feature usage.

2. How we use information

  • To operate the reservation, front-desk, billing, and reporting features Customers rely on.
  • To automatically create and update reservations from connected OTA channels on a Customer’s behalf.
  • To send account, security, and transactional notifications (e.g. password resets, booking confirmations).
  • To maintain, secure, and improve the platform, including diagnosing and fixing issues.
  • To comply with legal obligations, such as hotel guest-registration and tax record-keeping requirements.

3. Google user data & the Gmail integration

Grand Diyafa’s Channel Manager can request read-only access to a Customer-connected Gmail inbox solely to identify and parse OTA reservation emails and turn them into reservations in the PMS. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data for advertising, do not sell it, and do not allow humans to read it except as strictly necessary for security, legal compliance, or with the Customer’s explicit consent for support purposes. A Customer can disconnect Gmail access at any time from Settings → Channels, which revokes our access immediately.

4. Sharing of information

We do not sell personal data. We share information only with subprocessors that help us run the platform (e.g. hosting, database, and email-delivery providers), each bound by contractual confidentiality and data-protection obligations, and when required by law.

5. Data retention

We retain reservation, folio, and guest data for as long as a Customer’s account is active and as needed to meet legal retention obligations (e.g. tax and hospitality record-keeping). Customers can request deletion of their hotel’s data, subject to any records we are legally required to keep.

6. Security

We use industry-standard technical and organizational measures — encryption in transit, access controls, and audit logging of sensitive actions — to protect the data in our systems.

7. Your rights

Depending on your location, you may have the right to access, correct, or delete your personal data, or to object to or restrict certain processing. To exercise these rights, contact us using the details below.

8. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above.

9. Contact us

Questions about this Privacy Policy or how your data is handled can be sent to thesound4life@gmail.com.