Back to home

Privacy Policy

Last updated: July 2026

1. Introduction

Doraki (“we”, “our”, “us”) operates a guest platform for luxury hotels and resorts: spa, dining and sports bookings, a take-home storefront, gift vouchers, and concierge services — all in the hotel’s own brand. This Privacy Policy explains how personal data is collected, used, and protected when you interact with our website and with hotel services powered by Doraki.

For guest-facing services, the hotel you are staying with (or buying from) is the data controller and merchant; Doraki processes personal data on the hotel’s behalf to provide the service. For this website and partner enquiries, Doraki is the controller.

2. Data We Collect

  • Enquiry data — name, property name, email address, provided when you request a demo or contact us.
  • Booking data — name, contact details, party size, preferences and special requests, provided when a guest books a table, treatment, court or experience.
  • Order data — product selections, delivery preferences and order history from the guest storefront.
  • Voucher data — buyer and recipient name and email (where provided), voucher value, balance and redemption history. Vouchers can be added to Apple Wallet or Google Wallet; the device registration needed to keep a pass up to date is processed by Apple or Google under their own terms.
  • Payment data — card payments are processed by the hotel’s payment provider (e.g. Stripe or JCC). Doraki never stores card numbers; we receive only transaction references and status.
  • Concierge chat — messages sent to the AI concierge, processed to generate a reply. Do not include sensitive personal information in chat.
  • Usage data — pages visited, device and browser information, collected via privacy-friendly analytics.

3. How We Use Data

  • Operate bookings, orders, vouchers and concierge services on behalf of partner hotels
  • Post charges and reservations to the hotel’s property management system where the hotel has enabled it (e.g. charge-to-room)
  • Send transactional messages (booking confirmations, voucher delivery, reminders)
  • Respond to partner enquiries and demo requests
  • Improve the platform, and comply with legal obligations

We do not sell personal data, and we do not use guest data for third-party advertising.

4. Data Sharing

Data is shared only as needed to run the service: with the relevant partner hotel (which remains responsible for its guests), with the hotel’s payment provider to complete transactions, with its property management system for reservations and folio postings, and with our service providers — hosting and database (EU, Frankfurt), content delivery, email delivery, wallet-pass services (Apple, Google) and AI processing for the concierge chat — under appropriate data processing agreements.

5. Data Retention

We retain personal data only as long as needed for the purposes above or as required by law (for example, transaction records the hotel must keep for tax purposes). Voucher records are kept for the life of the voucher plus any legally required period. You may request deletion at any time; requests concerning a hotel stay may be fulfilled together with the hotel.

6. Your Rights

Under the GDPR and applicable law you may access, correct, delete or port your personal data, and withdraw consent or object to processing. Write to us and we will respond, or coordinate with the relevant hotel where it is the controller.

7. Security

We use appropriate technical and organisational measures: encrypted connections, encrypted storage of credentials, EU-based hosting, tenant-scoped access controls and signed sessions. No system is perfectly secure; we review and improve these measures continuously.

8. Contact

For any questions or requests regarding personal data, contact us at partners@doraki.co.