Misfora is a guest registration and check-in platform built for hotels. This Privacy Policy explains what information Misfora processes, why, how it is protected, and what rights you have — whether you are a hotel using Misfora, a member of a hotel's staff, or a guest completing a registration link.
We have tried to write this policy in plain English rather than dense legal language, because we think a privacy policy should actually be readable by the people it affects. Where we've made specific technical or operational choices — how data is stored, who can delete it, which infrastructure providers we use — we describe them directly, rather than in vague generalities.
If anything here is unclear, you can reach us at partners@misfora.com.
Who We Are
Misfora is currently operated by PE Andrii Kashkin, a private entrepreneur registered in Ukraine (registration number 3216106672). We refer to this entity as "Misfora," "we," "us," or "our" throughout this policy.
As Misfora grows, we expect to incorporate a dedicated legal entity to operate the service. When that happens, this policy will be updated to reflect the new operator, and hotels will be notified in advance. The nature of the service, the way data is handled, and the commitments in this policy will not change as a result of that transition — only the legal entity behind them.
Scope of This Privacy Policy
This policy applies to:
- Hotels and their staff who use the Misfora admin dashboard to manage bookings, guest registrations, and check-ins.
- Guests who receive a registration link and use it to submit their identity document and personal details ahead of, or during, check-in.
- Visitors to misfora.com, our marketing website.
It does not apply to the hotel's own systems (its PMS, its website, its booking engine), which are governed by that hotel's own privacy practices. It also does not apply to government systems that a hotel's registration data may ultimately be submitted to, which are governed by the relevant government's own rules — more on this in "Government Registration Services" below.
Roles and Responsibilities: Hotel as Controller, Misfora as Processor
This is one of the most important sections of this policy, because it defines who is responsible for what.
The hotel is the data controller for its guests' personal data. The hotel decides to use Misfora, invites its own staff, and is responsible for having a lawful basis to collect and process its guests' information (typically the booking contract itself, and legal obligations to register foreign guests with the relevant authorities).
Misfora is a data processor. We process guest data on the hotel's behalf and according to the hotel's instructions — principally, to help the hotel register guests, sync data to its property management system (PMS), and, where applicable, submit registration data to government systems on the hotel's behalf. We do not sell guest data, use it for our own marketing, or share it with anyone other than the hotel and the specific systems the hotel has connected (its PMS, and government registration systems where configured).
This mirrors the roles described under regulations like the GDPR and Turkey's KVKK, where the entity that decides why data is collected (the hotel) is the controller, and the service provider that processes data on that entity's behalf (Misfora) is the processor.
Information We Process
Depending on how a hotel uses Misfora, we may process:
- Guest identity information: full name, date of birth, gender, citizenship/nationality, document type and number, document expiry date, and a scanned image of the guest's passport or national ID card.
- Booking information: room number, arrival and departure dates, number of guests, booking source, and related fields synced from the hotel's PMS.
- Contact information: the guest's email address or phone number, used to send the registration link and any related reminders.
- Staff account information: name, email address, and a securely hashed password for hotel employees who use the Misfora dashboard.
- Technical and usage information: IP address, browser type, device type, and general usage patterns, collected automatically when anyone uses our website or product (see "Cookies and Analytics" below).
We do not intentionally collect payment card details, health information, or any other special category of data. Passport and ID document images may incidentally reveal some of this (for example, if a document lists nationality that correlates with ethnicity) — we treat all document data with the same strict access controls regardless.
How Information Is Collected
Guest information reaches Misfora in three ways:
- The guest submits it directly. When a hotel sends a registration link, the guest opens it in their own browser, photographs their document, and Misfora's optical character recognition (OCR) extracts the relevant fields automatically. No app download is required.
- A hotel staff member enters it manually, for guests who register in person at the front desk rather than using a link.
- It is synced from the hotel's PMS, for booking-level information (room, dates, guest count) that the hotel's PMS already holds and that does not need to be re-entered.
How We Use Information
We use the information described above to:
- Generate and send registration links to guests.
- Recognize and extract data from photographed identity documents.
- Flag mismatches or low-confidence results for a hotel staff member to review, so that incorrect data is not silently accepted.
- Sync recognized guest and booking data back to the hotel's PMS.
- Submit registration data to government systems, where a hotel has that integration enabled (see below).
- Provide the hotel's staff with a dashboard to track registration status, export data, and manage their account.
- Maintain the security of our service — for example, keeping an internal log of which staff member accessed sensitive guest data and when.
- Understand how our website and product are used, so we can improve them (see "Cookies and Analytics").
We do not use guest document images or personal data to train machine learning models, and we do not share guest data with any third party for their own marketing purposes.
Government Registration Services
Many countries require hotels to register foreign guests with a government authority. Where Misfora has a working integration with a country's system — currently, Turkey's KBS (Kimlik Bildirme Sistemi) — and a hotel has that integration enabled, Misfora submits the relevant guest registration data to that government system automatically on the hotel's behalf, once required fields have been collected and verified.
It's important to understand that once this data is submitted, it is retained by the government system under that government's own retention rules, not Misfora's. We do not control, and cannot delete, records held by KBS or any other government system after submission. Our responsibility ends at accurate, timely submission.
We plan to support additional countries' government registration systems over time. Where a country is not yet supported, hotels remain responsible for completing that registration through their own existing process.
Data Storage and Security
We've made a number of concrete architectural choices specifically to limit who can see what:
- Document images are stored separately from the rest of the database. Scanned passports and ID cards live in a private object storage bucket (Cloudflare R2), physically and logically separate from the database that holds booking and guest records. Access to a document image requires a short-lived, expiring link generated on demand — images are never served from a permanent public URL.
- Staff passwords are never stored in plain text. They are hashed using Argon2, a modern, deliberately slow hashing algorithm designed to resist brute-force attacks. No one — including Misfora staff — can view a hotel employee's actual password.
- PMS integration credentials are encrypted at rest, separately for each hotel property. A compromise of one property's stored credentials does not expose another's.
- Access is role-based. Each hotel employee has their own individual login. A hotel's staff can only see data belonging to their own company — there is no cross-hotel visibility.
- We keep an internal audit log of which staff member accessed sensitive guest data and when. This log records the fact of access, not the document numbers themselves.
No system is perfectly secure, and we don't claim otherwise. What we can say honestly is that these are deliberate, specific design decisions — not a generic assurance.
Data Retention and Deletion
We do not promise that all guest data is automatically deleted once processing is complete, because that would not be accurate. Here is what actually happens:
Misfora stores guest data only for as long as required for the hotel to complete the registration process and operate the service. Beyond that, retention is largely in the hotel's control:
- Each hotel has full control over its own data and can permanently delete guest records and uploaded document images directly from the Misfora application, at any time, without needing to contact Misfora support.
- Data synced to the hotel's PMS remains in the PMS under that system's own retention rules — deleting a record in Misfora does not delete it from the hotel's PMS, and vice versa.
- Data submitted to a government registration system remains there, governed by that government's retention requirements, as described above.
If a hotel's account with Misfora is closed, we delete the hotel's stored guest data and document images from our systems within a reasonable period, except where we are legally required to retain limited records for longer (for example, for security or fraud-investigation purposes).
International Data Transfers
Misfora's infrastructure runs on Railway (application hosting and database) and Cloudflare R2 (document image storage). Depending on the hotel's location and our infrastructure configuration, data may be processed in a different country from the one the hotel or guest is physically in — for instance, our primary application infrastructure currently runs in the EU (Ireland).
Where data is transferred internationally, we rely on the safeguards our infrastructure providers make available (such as their own compliance with recognized data transfer frameworks) and take reasonable steps to ensure data is handled consistently with this policy, regardless of where it is processed.
Third-Party Service Providers
Misfora uses a small number of trusted infrastructure and analytics providers to operate the service:
- Railway — application hosting and database infrastructure.
- Cloudflare R2 — secure object storage for uploaded document images.
- Resend — transactional email delivery (for example, guest registration links and staff account invitations).
- Google Analytics — anonymized website usage analytics.
- Microsoft Clarity — website usage analytics and session recordings, used to understand how visitors use misfora.com.
These providers process data only as necessary to provide their respective services, and only under our instructions or their own applicable terms. We do not use any provider to sell or repurpose guest data for unrelated purposes.
Cookies and Analytics
Our marketing website (misfora.com) uses Google Analytics and Microsoft Clarity to help us understand how visitors find and use the site — for example, which pages are read, and where visitors drop off before signing up. These tools may use cookies or similar technology and may record aggregated or anonymized usage patterns, and in the case of Microsoft Clarity, session recordings of on-site behavior (mouse movement and clicks, not keystrokes in sensitive fields).
The Misfora product application (the guest registration camera page and the hotel admin dashboard) does not use these analytics tools — they apply to the public marketing website only.
Your Rights
Depending on your location, you may have rights under data protection laws such as the GDPR (EU/EEA) or KVKK (Turkey), including the right to access, correct, or request deletion of your personal data, and the right to object to certain processing.
Misfora is designed to support hotels in meeting these obligations — for example, by giving hotels direct, immediate control to delete guest records and document images. However, because the hotel is the data controller, requests regarding a specific guest's data should generally be directed to the hotel that collected it, as they are best positioned to fulfill them in the context of the booking. If you contact us directly, we will help route your request to the relevant hotel, or handle it ourselves where we are able to.
We want to be direct about something: we have not undergone a formal GDPR or KVKK compliance audit or certification. This policy, and the architecture it describes, is designed with these frameworks' requirements in mind, and we believe it reflects good-faith, substantive privacy practices — but we do not claim formal certified compliance, and we won't claim it until it has actually been independently verified.
Children's Privacy
Misfora is not directed at children, and we do not knowingly collect data from children as our primary users. That said, hotel guests occasionally travel with minors, and a minor's identity document may be processed as part of a family booking's registration, under the authority of the accompanying parent or guardian and the hotel's own legal obligations to register all guests, including minors, with the relevant authorities. We do not treat this data any differently in terms of security, but we do not independently seek consent from a minor, as the booking and registration is made by the accompanying adult.
Changes to This Policy
We may update this policy as Misfora's product, infrastructure, or operating entity changes — for example, when we incorporate a dedicated legal entity, add support for a new country's government registration system, or change infrastructure providers. We will update the "Last updated" date at the top of this page when we do, and for material changes, we will make reasonable efforts to notify hotels directly rather than relying on a silent update to this page.
Contact Information
If you have questions about this policy or how Misfora handles data, contact us at: