Legal

Misfora Privacy Policy

Last updated: July 24, 2026

Misfora is a guest registration and check-in platform built for hotels. This Privacy Policy explains what information Misfora processes, why, how it is protected, and what rights you have — whether you are a hotel using Misfora, a member of a hotel's staff, or a guest completing a registration link.

We have tried to write this policy in plain English rather than dense legal language, because we think a privacy policy should actually be readable by the people it affects. Where we've made specific technical or operational choices — how data is stored, who can delete it, which infrastructure providers we use — we describe them directly, rather than in vague generalities.

If anything here is unclear, you can reach us at partners@misfora.com.

Who We Are

Misfora is currently operated by PE Andrii Kashkin, a private entrepreneur registered in Ukraine (registration number 3216106672). We refer to this entity as "Misfora," "we," "us," or "our" throughout this policy.

As Misfora grows, we expect to incorporate a dedicated legal entity to operate the service. When that happens, this policy will be updated to reflect the new operator, and hotels will be notified in advance. The nature of the service, the way data is handled, and the commitments in this policy will not change as a result of that transition — only the legal entity behind them.

Scope of This Privacy Policy

This policy applies to:

It does not apply to the hotel's own systems (its PMS, its website, its booking engine), which are governed by that hotel's own privacy practices. It also does not apply to government systems that a hotel's registration data may ultimately be submitted to, which are governed by the relevant government's own rules — more on this in "Government Registration Services" below.

Roles and Responsibilities: Hotel as Controller, Misfora as Processor

This is one of the most important sections of this policy, because it defines who is responsible for what.

The hotel is the data controller for its guests' personal data. The hotel decides to use Misfora, invites its own staff, and is responsible for having a lawful basis to collect and process its guests' information (typically the booking contract itself, and legal obligations to register foreign guests with the relevant authorities).

Misfora is a data processor. We process guest data on the hotel's behalf and according to the hotel's instructions — principally, to help the hotel register guests, sync data to its property management system (PMS), and, where applicable, submit registration data to government systems on the hotel's behalf. We do not sell guest data, use it for our own marketing, or share it with anyone other than the hotel and the specific systems the hotel has connected (its PMS, and government registration systems where configured).

This mirrors the roles described under regulations like the GDPR and Turkey's KVKK, where the entity that decides why data is collected (the hotel) is the controller, and the service provider that processes data on that entity's behalf (Misfora) is the processor.

Information We Process

Depending on how a hotel uses Misfora, we may process:

We do not intentionally collect payment card details, health information, or any other special category of data. Passport and ID document images may incidentally reveal some of this (for example, if a document lists nationality that correlates with ethnicity) — we treat all document data with the same strict access controls regardless.

How Information Is Collected

Guest information reaches Misfora in three ways:

How We Use Information

We use the information described above to:

We do not use guest document images or personal data to train machine learning models, and we do not share guest data with any third party for their own marketing purposes.

Government Registration Services

Many countries require hotels to register foreign guests with a government authority. Where Misfora has a working integration with a country's system — currently, Turkey's KBS (Kimlik Bildirme Sistemi) — and a hotel has that integration enabled, Misfora submits the relevant guest registration data to that government system automatically on the hotel's behalf, once required fields have been collected and verified.

It's important to understand that once this data is submitted, it is retained by the government system under that government's own retention rules, not Misfora's. We do not control, and cannot delete, records held by KBS or any other government system after submission. Our responsibility ends at accurate, timely submission.

We plan to support additional countries' government registration systems over time. Where a country is not yet supported, hotels remain responsible for completing that registration through their own existing process.

Data Storage and Security

We've made a number of concrete architectural choices specifically to limit who can see what:

No system is perfectly secure, and we don't claim otherwise. What we can say honestly is that these are deliberate, specific design decisions — not a generic assurance.

Data Retention and Deletion

We do not promise that all guest data is automatically deleted once processing is complete, because that would not be accurate. Here is what actually happens:

Misfora stores guest data only for as long as required for the hotel to complete the registration process and operate the service. Beyond that, retention is largely in the hotel's control:

If a hotel's account with Misfora is closed, we delete the hotel's stored guest data and document images from our systems within a reasonable period, except where we are legally required to retain limited records for longer (for example, for security or fraud-investigation purposes).

International Data Transfers

Misfora's infrastructure runs on Railway (application hosting and database) and Cloudflare R2 (document image storage). Depending on the hotel's location and our infrastructure configuration, data may be processed in a different country from the one the hotel or guest is physically in — for instance, our primary application infrastructure currently runs in the EU (Ireland).

Where data is transferred internationally, we rely on the safeguards our infrastructure providers make available (such as their own compliance with recognized data transfer frameworks) and take reasonable steps to ensure data is handled consistently with this policy, regardless of where it is processed.

Third-Party Service Providers

Misfora uses a small number of trusted infrastructure and analytics providers to operate the service:

These providers process data only as necessary to provide their respective services, and only under our instructions or their own applicable terms. We do not use any provider to sell or repurpose guest data for unrelated purposes.

Cookies and Analytics

Our marketing website (misfora.com) uses Google Analytics and Microsoft Clarity to help us understand how visitors find and use the site — for example, which pages are read, and where visitors drop off before signing up. These tools may use cookies or similar technology and may record aggregated or anonymized usage patterns, and in the case of Microsoft Clarity, session recordings of on-site behavior (mouse movement and clicks, not keystrokes in sensitive fields).

The Misfora product application (the guest registration camera page and the hotel admin dashboard) does not use these analytics tools — they apply to the public marketing website only.

Your Rights

Depending on your location, you may have rights under data protection laws such as the GDPR (EU/EEA) or KVKK (Turkey), including the right to access, correct, or request deletion of your personal data, and the right to object to certain processing.

Misfora is designed to support hotels in meeting these obligations — for example, by giving hotels direct, immediate control to delete guest records and document images. However, because the hotel is the data controller, requests regarding a specific guest's data should generally be directed to the hotel that collected it, as they are best positioned to fulfill them in the context of the booking. If you contact us directly, we will help route your request to the relevant hotel, or handle it ourselves where we are able to.

We want to be direct about something: we have not undergone a formal GDPR or KVKK compliance audit or certification. This policy, and the architecture it describes, is designed with these frameworks' requirements in mind, and we believe it reflects good-faith, substantive privacy practices — but we do not claim formal certified compliance, and we won't claim it until it has actually been independently verified.

Children's Privacy

Misfora is not directed at children, and we do not knowingly collect data from children as our primary users. That said, hotel guests occasionally travel with minors, and a minor's identity document may be processed as part of a family booking's registration, under the authority of the accompanying parent or guardian and the hotel's own legal obligations to register all guests, including minors, with the relevant authorities. We do not treat this data any differently in terms of security, but we do not independently seek consent from a minor, as the booking and registration is made by the accompanying adult.

Changes to This Policy

We may update this policy as Misfora's product, infrastructure, or operating entity changes — for example, when we incorporate a dedicated legal entity, add support for a new country's government registration system, or change infrastructure providers. We will update the "Last updated" date at the top of this page when we do, and for material changes, we will make reasonable efforts to notify hotels directly rather than relying on a silent update to this page.

Contact Information

If you have questions about this policy or how Misfora handles data, contact us at:

Email
partners@misfora.com
Operator
PE Andrii Kashkin, Ukraine (registration number 3216106672)