ARMS Legal

Privacy Policy and Cookie Notice

Effective date: April 14, 2026 · Last updated: April 14, 2026

This Privacy Policy and Cookie Notice explains how ARMS (the "App", "ARMS", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you use ARMS web applications, APIs, and related services.

This document applies to the full ARMS platform, including but not limited to reservations, front desk, guest portal, housekeeping, maintenance, stores/procurement, food and beverages (F&B), accounting, billing, OTA, communications, notifications, and superadmin tools.

1. Who We Are

ARMS is a hospitality and property operations platform.

Data Controller / Service Provider details:

  • Legal entity: ARMS
  • Contact email: support@staywyze.com
  • Privacy contact: support@staywyze.com

If you are a hotel or property using ARMS, your organization may be the data controller for guest and staff data you manage in ARMS. In that case, ARMS acts as a processor/service provider for that customer data.

2. Scope

This policy covers:

  • ARMS web app and dashboards
  • ARMS backend APIs and integrations
  • Authentication, session, and security mechanisms (including cookies)
  • Communications and support interactions related to ARMS

This policy does not cover third-party services that are independently operated and linked from ARMS.

3. Data We Collect

Depending on your role and usage, we may process:

  • Account and identity data: name, email, username, phone, role, permissions, login metadata.
  • Property and operational data: property profiles, rooms/units, reservations, check-in/out, housekeeping and maintenance records.
  • Guest and contact data: guest names, contact details, booking details, service requests, tags/preferences, message history.
  • Commercial and financial data: invoices, folios, payments status, taxes, billing contacts, accounting records.
  • Procurement and vendor data: supplier names, contact details, quotations, purchase orders, receiving records.
  • System and security data: IP address, user agent, device/browser metadata, audit logs, API activity, error logs.
  • Support data: tickets, emails, and other support communications.

Sensitive categories: ARMS is not intended for storing special-category sensitive personal data unless explicitly required and contractually agreed.

4. How We Use Data

We process personal data to:

  • Provide and operate ARMS features.
  • Authenticate users and manage secure sessions.
  • Deliver transactions, workflows, notifications, and reports.
  • Maintain audit trails, enforce access controls, and prevent abuse/fraud.
  • Provide customer support and service communications.
  • Comply with legal, accounting, tax, and regulatory obligations.
  • Improve service quality, reliability, and performance.

5. Legal Bases (where applicable)

Depending on jurisdiction, we rely on one or more of:

  • Contract performance (providing ARMS services).
  • Legitimate interests (security, operations, product improvement).
  • Legal obligation (tax, accounting, compliance, law enforcement requests).
  • Consent (where required, especially for non-essential cookies/tracking).

6. Cookie Notice

ARMS uses cookies and similar technologies primarily for authentication, security, and session continuity.

6.1 Cookies ARMS Uses

Typical cookies used by ARMS include:

  • access_token: Authentication token cookie used to keep users signed in.
  • refresh_token: Token cookie used to renew sessions securely.
  • csrftoken (or equivalent): Helps prevent cross-site request forgery attacks.
  • sessionid (where enabled): Session state and security middleware support.

6.2 Cookie Categories

  • Strictly necessary cookies: required for login, security, API access, and core application behavior. Without these cookies, ARMS cannot function correctly.
  • Functional cookies: may be used to improve user experience and preferences.
  • Analytics/performance cookies: may be used to understand performance and usage patterns. If enabled in your deployment, follow your local consent requirements.

ARMS does not intentionally use advertising cookies in core authenticated workflows.

6.3 Cookie Security Attributes

ARMS is designed to use secure cookie controls, including:

  • HttpOnly for auth tokens where applicable.
  • Secure in production HTTPS environments.
  • SameSite controls based on deployment (for example Lax or None for cross-site setups).
  • Configurable cookie domain and age by environment.

6.4 Managing Cookies

You can control cookies via browser settings. Blocking necessary cookies may prevent login and core ARMS functionality.

For customer-managed ARMS environments, administrators are responsible for implementing any required cookie consent banner and regional cookie compliance settings.

7. Sharing and Disclosure

We may share data:

  • With authorized users under your organization account.
  • With subprocessors and infrastructure providers needed to run ARMS (hosting, storage, communications, monitoring).
  • With payment, tax, and integration providers as configured.
  • With regulators or law enforcement where legally required.
  • During corporate transactions (merger, acquisition, restructuring), subject to safeguards.

We do not sell personal data.

8. International Transfers

Data may be processed in countries outside your own. Where required, we apply contractual and operational safeguards for cross-border transfers.

9. Data Retention

We retain data only as long as necessary for:

  • Service delivery and account operations.
  • Legal, tax, accounting, audit, and dispute requirements.
  • Security investigations and fraud prevention.

Retention periods may vary by module and customer configuration. Customer instructions and applicable law take precedence.

10. Security Measures

We use reasonable technical and organizational safeguards, including:

  • Role-based access controls and permission boundaries.
  • Encrypted transport (TLS/HTTPS) in production.
  • Audit logs and operational monitoring.
  • Authentication/session controls.
  • Routine maintenance and security hardening practices.

No method of transmission or storage is 100% secure, but we continuously improve controls.

11. Your Privacy Rights

Depending on jurisdiction, data subjects may have rights to:

  • Access personal data.
  • Correct inaccurate data.
  • Delete data.
  • Restrict or object to processing.
  • Data portability.
  • Withdraw consent (where consent is the legal basis).

To exercise rights, contact: support@staywyze.com

If ARMS processes data on behalf of a property/customer, requests may need to be directed to that customer first.

12. Children

ARMS is a business platform and is not directed to children. Do not use ARMS to intentionally collect children's data except where operationally required by hospitality services and permitted by law.

13. Changes to This Policy

We may update this policy from time to time. Material updates will be posted with a revised "Last updated" date.

14. Contact

For privacy questions, complaints, or requests:

  • Email: support@staywyze.com
  • Subject line recommendation: "ARMS Privacy Request"