Scan & Sleep
  • FAQ
  • Setup Guide
  • Pricing
  • Login
  • Start Free Trial
Select Page

Legal

Privacy Policy

This Privacy Policy explains how Scan & Sleep collects, uses, stores and protects personal data when people visit our website, create an account or use the Scan & Sleep Service.

Last updated: 3 August 2026

Privacy at a glance

  • Guests do not need to create an account, provide their name, provide an email address or install an application.
  • The standard Scan & Sleep Service does not currently collect free-text messages from guests.
  • Do Not Disturb activity is deleted according to the applicable 7, 30, 90 or 365-day History period.
  • We do not sell personal data.
  • We do not currently use advertising, behavioural tracking or optional website analytics cookies.

Contents

Who we are and scope Data protection roles Data we collect Purposes and legal bases Service providers and transfers Data retention Security Your rights Cookies Contact

1. Who We Are

Scan & Sleep is an online hospitality service operated from Crete, Greece.

In this Privacy Policy, “Scan & Sleep”, “we”, “us” and “our” refer to the provider of the Scan & Sleep website and application.

For privacy-related questions or requests, contact:

Scan & Sleep
Crete, Greece
Email: [email protected]

2. Scope of This Privacy Policy

This Privacy Policy applies when someone:

  • visits the Scan & Sleep website;
  • submits the website Contact Form;
  • creates or uses a Scan & Sleep business account;
  • creates or manages a hospitality Property through the application;
  • accesses a Staff Dashboard or read-only Staff History page;
  • scans a room QR code and activates or cancels Do Not Disturb;
  • receives an Email Alert relating to Do Not Disturb activity;
  • purchases a plan or add-on;
  • communicates with Scan & Sleep for sales, billing, support or another business purpose.

Scan & Sleep is designed primarily for hospitality businesses and professional users.

3. Our Data Protection Roles

3.1 Scan & Sleep as Data Controller

Scan & Sleep acts as a data controller when we determine why and how personal data is processed, including in relation to:

  • business account registration;
  • contact and support communications;
  • sales, billing and payment administration;
  • service security and abuse prevention;
  • website and application administration;
  • legal, tax and accounting obligations.

3.2 The Hospitality Property as Data Controller

A hotel, villa, apartment property or other hospitality business normally determines how Scan & Sleep is used within its own operation.

Where Do Not Disturb activity can be connected by the Property to a particular guest, employee or room occupant, the relevant Property normally acts as the data controller for that operational data.

3.3 Scan & Sleep as Data Processor

Where Scan & Sleep stores, displays or otherwise processes operational data on behalf of a Property, Scan & Sleep acts as a data processor to the extent required by applicable data-protection law.

The Data Processing Terms included in our Terms of Use apply to this processing.

4. Personal Data We Collect

4.1 Website Contact Form

When someone submits the Contact Form, we may collect:

  • name;
  • business or Property name;
  • email address;
  • telephone number, where provided;
  • the content of the enquiry;
  • any other information voluntarily included in the message;
  • limited technical information associated with the submission, such as its date and time.

Please do not submit sensitive personal data through the Contact Form unless it is strictly necessary.

4.2 Business Account Data

When a user creates or manages a Scan & Sleep account, we may process:

  • account email address;
  • authentication and account identifiers;
  • authentication session information;
  • account creation and login records;
  • Property name;
  • country and time zone;
  • room names or room numbers;
  • Property Settings;
  • trial and access status;
  • selected plan, limits and add-ons;
  • support and account communications.

Customers should use room numbers or non-personal room descriptions and should not use guest names as room labels.

4.3 Guest Do Not Disturb Activity

When a guest scans a permanent room QR code, the Service may process:

  • the permanent room identifier;
  • the Property identifier;
  • the selected Do Not Disturb end time;
  • activation time;
  • cancellation time, where applicable;
  • automatic expiry information;
  • the source of the status action;
  • related operational and security records.
Guests do not need to create an account, provide a name, provide an email address or install an application.

The standard Scan & Sleep Service does not currently provide a free-text guest-message field. Free-text guest messages are not collected as part of the standard Service.

If an additional guest-input feature is introduced or activated in the future, the relevant Privacy Policy, customer terms and operational information will be reviewed and updated before it is offered for standard use.

4.4 Staff Dashboard and Staff History

The live Staff Dashboard and read-only Staff History may be accessed through confidential Property-specific links containing permanent access tokens.

These pages may display:

  • Property name;
  • room names or room numbers;
  • active or inactive Do Not Disturb status;
  • activation and expiry times;
  • recent Activity History;
  • operational status information.

Staff members are not normally required to create individual Scan & Sleep accounts.

The Property is responsible for sharing Staff Dashboard and Staff History links only with authorised team members.

4.5 Email Alert Data

When Email Alerts are enabled, we may process:

  • recipient email addresses configured by the Property;
  • Property name;
  • room name or room number;
  • Do Not Disturb activation and expiry information;
  • email delivery status;
  • delivery time;
  • provider message identifier;
  • failure or skip reason;
  • recipient count.

Email Alerts are an additional notification method and are not the sole operational source for Do Not Disturb information.

4.6 Billing and Payment Data

When a Customer purchases a paid plan, add-on or support service, we may process:

  • business or contact name;
  • billing address;
  • billing email address;
  • tax or VAT information, where required;
  • selected plan and room limit;
  • selected add-ons;
  • payment amount;
  • payment date and status;
  • invoice or transaction reference.

Payments may be completed through:

  • a personal SureCart and Stripe payment link;
  • bank transfer or IBAN;
  • another payment method agreed directly with the Customer.

Where a payment provider processes a card payment, full card details are handled by that provider and are not intended to be stored directly by Scan & Sleep.

4.7 Technical and Security Data

We and our infrastructure providers may process limited technical and security information, including:

  • IP address;
  • browser and device type;
  • operating system;
  • access date and time;
  • requested page or application route;
  • authentication and session events;
  • error and diagnostic records;
  • failed login attempts;
  • rate-limit or abuse-protection events;
  • room activation limits and temporary room locks.

This information is used to operate, secure, troubleshoot and protect the Service.

5. Why We Use Personal Data

We may process personal data for the following purposes:

  • creating and administering business accounts;
  • providing and managing the 30-day free trial;
  • providing and activating paid plans and add-ons;
  • operating permanent room QR codes;
  • recording and displaying Do Not Disturb status;
  • providing Staff Dashboard and Staff History access;
  • sending Email Alerts where enabled;
  • managing rooms, plan limits, retention options and access;
  • responding to enquiries and providing customer support;
  • processing payments and maintaining billing records;
  • preventing misuse, fraud and unauthorised access;
  • investigating technical and security problems;
  • improving the reliability and usability of the Service;
  • complying with legal, tax and accounting obligations;
  • establishing, exercising or defending legal claims.

6. Legal Bases for Processing

6.1 Contract

Processing may be necessary to create an account, provide a free trial, deliver the Service, activate a paid plan, administer an add-on or fulfil another agreement with the Customer.

6.2 Legitimate Interests

Processing may be necessary for our legitimate business interests, including:

  • securing and maintaining the Service;
  • preventing fraud, abuse and unauthorised access;
  • responding to business enquiries;
  • providing customer support;
  • maintaining appropriate operational records;
  • improving performance and reliability;
  • protecting our legal rights.

We consider these interests against the rights and freedoms of affected individuals.

6.3 Legal Obligation

Certain billing, payment, tax, accounting or compliance data may be processed and retained because applicable law requires us to do so.

6.4 Consent

Where consent is legally required, such as for future optional analytics, advertising or marketing cookies, we will request consent before using the relevant technology.

Consent may be withdrawn at any time without affecting processing that occurred before withdrawal.

6.5 Processing on Behalf of a Property

Where Scan & Sleep processes operational data on behalf of a hospitality Property, the Property is responsible for determining the appropriate legal basis and providing required information to guests or staff.

7. How We Share Personal Data

We do not sell personal data.

We may share personal data only where reasonably necessary with service providers and professional advisers that support Scan & Sleep, including:

  • Supabase, for authentication, database and application infrastructure;
  • Vercel, for application hosting and technical delivery;
  • Resend, for transactional Email Alerts;
  • SureCart, for payment-link and order administration;
  • Stripe, for card-payment processing;
  • WordPress website, hosting, Contact Form and email providers;
  • banks and financial institutions where payment is made by bank transfer;
  • accountants, legal advisers, auditors and other professional advisers;
  • public authorities where disclosure is required by law.

Providers process data under applicable contracts, data processing terms and privacy notices.

8. International Data Transfers

Some service providers or their subprocessors may process personal data outside Greece or outside the European Economic Area.

Where an international transfer requires additional safeguards, we will use an appropriate legal mechanism, which may include:

  • an adequacy decision;
  • the European Commission’s Standard Contractual Clauses;
  • an applicable data privacy framework;
  • another transfer mechanism permitted by applicable law.

Information about applicable safeguards may be requested by contacting us.

9. Data Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, subject to legal, security and operational requirements.

9.1 Do Not Disturb Activity History

Do Not Disturb activity is automatically deleted according to the applicable History option:

History option Retention period
Standard Activity History 7 days
Extended History option 30 days
Extended History option 90 days
Extended History option 365 days

After the applicable retention period, the relevant activity records are deleted from the active Service.

Where secure backups exist, residual copies may remain temporarily until those backups are overwritten or removed through the normal backup-rotation process.

9.2 Account and Property Data

Account and Property data is normally retained while the account is active and for a limited period after closure where reasonably necessary for:

  • support and account closure;
  • security and abuse investigations;
  • dispute resolution;
  • legal or regulatory obligations.

9.3 Billing and Payment Records

Invoices, transaction records and tax-related information may be retained for the period required by applicable tax, accounting and legal obligations.

9.4 Contact Form and Support Communications

Contact Form submissions and support communications are retained for as long as reasonably necessary to answer the enquiry, manage related follow-up and maintain appropriate business records.

9.5 Technical and Security Records

Technical, diagnostic and security records are retained only for the period reasonably necessary to detect abuse, investigate incidents, maintain security and resolve technical problems.

10. Security

We use reasonable technical and organisational measures designed to protect personal data, which may include:

  • encrypted HTTPS connections;
  • authentication and session controls;
  • Property ownership checks;
  • restricted Internal Admin access;
  • server-side authorisation;
  • protected service credentials;
  • rate limiting and abuse protection;
  • Property and room-specific access tokens;
  • logging of relevant security and email-delivery events;
  • access restrictions based on operational need.

No online service can guarantee absolute security or uninterrupted availability.

Customers are responsible for protecting:

  • their account password;
  • their registered email account;
  • Staff Dashboard links;
  • Staff History links;
  • owner and Property management links;
  • any other confidential access link or token.

11. Automated Security Controls

Scan & Sleep may use automated technical controls to detect abnormal activity, apply rate limits or temporarily lock a room QR code where repeated activations indicate possible misuse.

These controls are used for security and Service protection. We do not use personal data to make automated decisions that produce legal or similarly significant effects on individuals.

12. Your Data Protection Rights

Subject to applicable law, individuals may have the right to:

  • request access to their personal data;
  • request correction of inaccurate data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • request data portability where applicable;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with a competent supervisory authority.

Requests may be submitted to:

[email protected]

We may need to verify the identity and authority of the person making the request.

Where Scan & Sleep processes data on behalf of a hospitality Property, a guest or staff member may be directed to the relevant Property as the data controller. We will provide reasonable assistance to the Property where required.

13. Cookies and Similar Technologies

The website and application may use cookies or similar technologies that are technically necessary for:

  • account authentication;
  • maintaining secure sessions;
  • email confirmation and password-reset flows;
  • maintaining user preferences;
  • protecting the application;
  • providing requested website or application functions.

We do not currently use advertising or behavioural-tracking technologies.

We do not currently use optional website analytics cookies.

If optional analytics, advertising or marketing technologies are introduced in the future, this Privacy Policy will be updated and consent will be requested where required.

14. Children

Scan & Sleep is a business service intended for hospitality Properties and professional users.

The guest QR page does not require a guest to provide their name, age, email address or account information.

The Service is not designed to intentionally collect personal data from children.

15. Third-Party Links

The website or application may contain links to third-party websites or services.

We are not responsible for the privacy practices, security or content of independent third-party services. Users should review the privacy information provided by those third parties.

16. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

  • changes to the Service;
  • new or discontinued features;
  • legal or regulatory requirements;
  • security improvements;
  • changes to service providers;
  • changes to our business operations.

The updated version will display a new “Last updated” date.

Where a change materially affects registered Customers, we may also provide notice by email, through the Service or through the website.

17. Contact and Complaints

For questions, privacy requests or complaints relating to this Privacy Policy, contact:

Scan & Sleep
Crete, Greece
Email: [email protected]

Individuals may also lodge a complaint with the Hellenic Data Protection Authority or another competent data-protection supervisory authority.

Questions about your privacy?

Contact Scan & Sleep at [email protected] .

Scan & Sleep

Smart Do Not Disturb for hotels, villas and apartments.

Guests choose when privacy ends. Staff see the status live.

Explore

How it works Pricing FAQ Security & Trust

Access

Contact Login Create account Setup Guide
READY TO START?

Clearer privacy for guests and staff.

Start 30-Day Free Trial No credit card required.

© 2026 Scan & Sleep. All rights reserved.

Privacy Policy • Terms of Use