Privacy policy
Data controller
CheckinSecure's controller/operator is the one identified in the Legal notice. Data protection contact: privacy@checkinsecure.com.
Depending on the processing: for owner/manager account data and CheckinSecure's own processing (security, future billing, consented marketing), CheckinSecure acts as controller. For legal guest data that it collects and submits to SES Hospedajes on the owner/manager's behalf, the owner/manager acts as controller of that data (as holder/manager of the hospitality activity under RD 933/2021, where applicable) and CheckinSecure acts as processor, formalized in the Data Processing Agreement (DPA).
A. Processing necessary to provide CheckinSecure
To provide the service we process: owner/manager account data (email, encrypted password); guest data submitted through the check-in link, necessary for the legal communication to SES Hospedajes; and the SES Hospedajes Web Service credentials the owner provides us, stored encrypted. Legal basis: performance of the service contract and compliance with the owner/manager's legal obligations regarding traveller documentary registration. Data collected for the legal SES Hospedajes communication is NEVER automatically reused for commercial purposes.
B. Optional commercial communications
If you explicitly check the relevant box when creating your account (never pre-checked, and always separate from accepting the Terms and from this Policy), we may send you commercial communications about other services for owners/managers from the same company. This processing is based on your express consent, is entirely independent from section A, and never conditions your access to using CheckinSecure for SES Hospedajes for free.
C. Future possibility of informing you about other products/brands of the same controller
If you granted the consent in section B, we may use it in the future to tell you about other products or brands (for example OwnGuests, or a future direct-booking product) as long as they remain under the same data controller. We never share your contact details with a different entity without your separate consent for that.
D. Withdrawal and objection
You can withdraw consent to commercial communications at any time (for example, via the unsubscribe link in each email, or from your account once that option is available). Withdrawing it doesn't erase the record that you once granted it and later withdrew it -- we keep that minimal evidence to be able to demonstrate compliance. Withdrawing marketing consent never affects your access to the free SES service.
E. The free SES service never depends on accepting marketing
You can use CheckinSecure for SES Hospedajes fully and for free without ever checking the commercial communications box in section B.
Retention
Guest data processed for the legal communication to SES Hospedajes is kept for 3 years from the end of the stay/contract, under article 5.3 of RD 933/2021. This retention obligation falls on the obligated party (the Owner/Agency, where applicable); CheckinSecure, as data processor, retains and processes that data according to the Owner/Agency's documented instructions, including this period. Owner/manager account data is kept while the account remains active and, after closure, for as long as needed to meet legal obligations or defend claims.
Recipients and subprocessors
Guest data is communicated to SES Hospedajes (Ministry of the Interior) solely to comply with the corresponding legal obligation. We do not sell personal data to third parties. We use the following technology providers as subprocessors, under a general-authorization model: the Owner/Agency will be notified of any addition or replacement of a subprocessor with reasonable notice, and will have a reasonable window to object on justified grounds. All subprocessors are bound by data-protection obligations equivalent to those in this document.
| Subprocessor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Application and database infrastructure (Workers, D1, queues) | EE. UU. / UE (según configuración de Cloudflare) |
| Resend | Transactional and operational email delivery (never to guests) | EE. UU. |
Security
We apply reasonable technical and organizational measures: credential encryption, per-account data isolation, and a secure (HTTPS) connection across the whole service.
Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to privacy@checkinsecure.com. We will respond within the period set by the GDPR (generally one month from receipt of the request, extendable in complex cases as provided by the Regulation itself). You also have the right to lodge a complaint with the Spanish Data Protection Agency (aepd.es) if you believe the processing of your data does not comply with applicable law.
Data processing agreement with the Owner/Agency
When CheckinSecure processes guest data on behalf of the Owner/Agency, that relationship is governed by the Data Processing Agreement (DPA), current version 2026-09-12-r2.