Last updated 30 September 2026
Hotels and other operators run their properties on Vector Guest, and trust it with their guests' data. This page describes how that data is protected today.
Each operator's data is its own
An operator's data is kept separate from every other operator's. The separation is part of how the system reads and writes data, and automated tests check it on every change.
The operator decides how its guests' data is used. We process it on the operator's behalf under a data processing agreement, as our privacy policy describes.
Encryption
- In transit. Every connection to Vector Guest uses HTTPS, and browsers are told never to connect without it.
- At rest. Sensitive fields, such as integration credentials and message contents, are encrypted in the database.
Access
- Each person signs in with their own account. Roles and permissions decide what they can see and do.
- Two-factor authentication is available for every account.
- Changes to important records are written to an audit log, with who made them and when.
AI agents
Agents work within permissions, like people do. Approval rules decide what an agent may do on its own and what waits for a person's decision, and each proposal is recorded with the facts behind it.
Payments
Card payments are handled by our payment providers. Vector Guest does not store card numbers.
Guest privacy
A guest's personal data can be erased on request, across the records that hold it. Guests ask the property they stayed at, and we carry out the erasure for the operator.
Reporting a problem
If you believe you have found a security problem, write to [email protected].