Hoteloil
Hoteloil

Privacy Policy

Our privacy policy and how we use your data

Last updated: July 21, 2026

Introduction

HotelOil ("Hoteloil," "we," "us," or "our") is a hotel digital advertising analytics and marketing platform operated by Reviewstay, LLC. This Privacy Policy explains how we collect, use, disclose, and protect information when you use hoteloil.com, our web application, APIs, Folio public hotel sites, and related services (collectively, the "Service").

By creating an account or using the Service, you acknowledge that you have read this Privacy Policy. If you do not agree, please do not use the Service.

Scope of this policy

This policy applies to HotelOil Pro (analytics dashboard), HotelOil Autopilot (managed advertising services), Folio (hotel website builder and social publishing), team workspaces, and optional integrations you connect, such as advertising platforms, calendar and notification services, and social networks.

ReviewStay and SMS RS are separate products in the Reviewstay family. When you connect ReviewStay to a hotel workspace, we process only the review and reputation data needed to display that integration inside HotelOil and Folio.

Information we collect

Account and profile information

When you register, we collect information such as your name, email address, authentication credentials, and account preferences. If you join a team workspace, we also store your role, permissions, and membership status.

Hotel and analytics data

To provide analytics, reporting, and Autopilot services, we process hotel performance data you upload or connect, including campaign metrics, spend, revenue, pace reports, and custom data sources (for example, Expedia, Booking.com, Koddi, and other channels you configure). This may include property names, campaign identifiers, dates, and financial metrics contained in your files or connected sources.

Billing information

Paid subscriptions are processed by Stripe. We receive billing status, plan identifiers, invoice references, and limited payment metadata from Stripe. We do not store full credit card numbers on our servers.

Folio and public site content

If you use Folio, we store site configuration, page content, media, domain settings, event listings, geo content, and other materials you publish to your hotel's public site.

Usage, device, and log data

We automatically collect technical information when you use the Service, such as IP address, browser type, device identifiers, pages viewed, timestamps, referral URLs, and error logs. We use this data to operate, secure, and improve the Service.

Support and communications

If you contact us, we retain the content of your messages and any information you choose to provide so we can respond and maintain support records.

How we use information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Generate dashboards, reports, heatmaps, leaderboards, and scheduled exports
  • Operate Autopilot enrollment, campaign management, invoicing, and performance reporting when you subscribe to those services
  • Publish Folio sites and social content you authorize
  • Send transactional emails, in-app notifications, and optional external notifications you configure
  • Process payments and manage subscriptions
  • Authenticate users and enforce access controls
  • Detect, prevent, and investigate fraud, abuse, and security incidents
  • Comply with legal obligations and respond to lawful requests
  • Analyze aggregated usage trends to improve product performance (see our Cookie Policy for analytics cookies)

We do not sell your personal information. We do not use hotel analytics data or connected account data for third-party advertising.

Legal bases for processing

Where applicable under data protection laws such as the GDPR, we process personal data based on: (a) performance of our contract with you; (b) your consent (for example, optional analytics cookies or third-party connections you authorize); (c) our legitimate interests in operating and securing the Service; and (d) compliance with legal obligations.

How we share information

We share information only as described below:

  • Service providers: We use trusted vendors for hosting, database, authentication, email delivery, payment processing, error monitoring, and AI-assisted support features. These providers process data on our behalf under contractual safeguards.
  • Team members: Information in a hotel workspace is visible to authorized members of that workspace according to their role and permissions.
  • Third-party platforms you connect: When you link external services (social networks, calendars, advertising platforms), data flows between HotelOil and those services as needed to perform the integration. Each platform's own privacy policy also applies.
  • Legal and safety: We may disclose information when required by valid legal process or when we believe disclosure is necessary to protect rights, safety, or the integrity of the Service.
  • Business transfers: If we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy.

Service providers

Our infrastructure and operations rely on third-party processors, including Supabase (database and authentication), Vercel (application hosting), Stripe (billing), Resend (transactional email), Sentry (error monitoring), and OpenAI (in-app documentation assistant). We configure these services to access only the data necessary for their function.

Google Calendar

When you connect Google Calendar from Notifications settings, HotelOil uses Google's OAuth 2.0 service with the calendar.events scope. We use this access solely to create and update calendar events you configure through notification rules—for example, daily HotelOil metric digests, Autopilot invoice due dates, or Folio event alerts.

We store an encrypted OAuth access token and refresh token, the Google account's selected calendar identifier, and a display name for your connection. During setup we may read your calendar list so you can choose which calendar receives events. We do not read, export, or sell the contents of your existing calendar events for advertising or unrelated purposes.

You can disconnect Google Calendar anytime from Notifications in your account, or revoke access from your Google Account permissions. Disconnecting removes stored tokens and connection metadata from HotelOil.

Microsoft Outlook / Calendar

When you connect Outlook Calendar, HotelOil uses the Microsoft Graph API with delegated permissions to read your profile (User.Read), maintain offline access (offline_access), and create or update events on calendars you can access (Calendars.ReadWrite). We use this access only to add or update calendar events for notification rules you configure in HotelOil.

We store an encrypted OAuth access token and refresh token, the selected Outlook calendar identifier, and a display name for your connection. We do not read your email, contacts, or unrelated Microsoft 365 data, and we do not sell Microsoft account data or use it for advertising.

You can disconnect Outlook anytime from Notifications in your account, or revoke HotelOil's access from your Microsoft account app permissions. Disconnecting removes stored tokens and connection metadata from HotelOil.

Slack

When you connect Slack from Notifications settings, you may authorize HotelOil via Slack OAuth or provide an incoming webhook URL. With OAuth, we request permission to post messages and to list channels you can target (chat:write, channels:read, groups:read). With a webhook, you supply a URL that posts to a workspace channel you configure in Slack.

We store an encrypted OAuth token or webhook URL, your selected Slack workspace and channel identifiers where applicable, and a display name for the connection. We use Slack only to deliver notification messages you enable—for example, HotelOil metric digests, Autopilot billing alerts, or Folio event updates. We do not read your Slack message history, direct messages, or files, and we do not sell Slack data or use it for advertising.

You can disconnect Slack anytime from Notifications in your account, remove the incoming webhook, or revoke the app from your Slack app management settings. Disconnecting removes stored tokens, webhook URLs, and connection metadata from HotelOil.

Meta (Facebook, Instagram, Threads)

When you connect Meta properties for Folio social publishing, HotelOil uses Meta's APIs to publish content you authorize and to store connection metadata (OAuth tokens, page or profile identifiers, and display handles). We do not read your personal feed, direct messages, or unrelated Meta data, and we do not sell Meta account data or use it for advertising.

You can disconnect Meta anytime from Folio social settings or remove HotelOil from your Meta account under Facebook Settings → Apps and Websites. Meta may notify us via our data deletion callback when you remove the app; see Data deletion status for details.

LinkedIn

When you connect a LinkedIn account, HotelOil uses LinkedIn's Marketing and Share on LinkedIn APIs solely to publish content you authorize and to display your account name. We store your OAuth access and refresh tokens, LinkedIn member or organization identifiers, and handles. We do not read your personal feed, connections, or messages, and we never sell LinkedIn data or use it for advertising.

LinkedIn tokens are used only to post on your behalf and are retained until you disconnect. You can revoke HotelOil's access anytime from LinkedIn Settings → Data privacy → Permitted services, or from within HotelOil under Folio → Social → Disconnect.

X (formerly Twitter)

When you connect an X account for social publishing, HotelOil stores encrypted OAuth tokens and account identifiers needed to publish posts you schedule or approve. We do not read your direct messages, timeline, or unrelated X data, and we do not sell X account data or use it for advertising. You can disconnect X anytime from Folio social settings or revoke the app from your X account settings.

Data deletion (Meta / Threads)

You can remove HotelOil from your Meta account in Facebook Settings → Apps and Websites. Meta will notify us via our data deletion callback and we will delete stored OAuth tokens, handles, and external account identifiers for your Meta social connections.

After submitting a deletion request through Meta, you can check status using the confirmation code at /data-deletion.

Hotel team admins can also disconnect social platforms anytime under Folio → Social → Disconnect.

Data retention

We retain information for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. When you delete your account or disconnect an integration, we delete or anonymize associated data within a reasonable period, except where retention is required by law or legitimate business needs (such as billing records).

Security

We implement administrative, technical, and organizational measures designed to protect information, including encryption of OAuth tokens, role-based access controls, and row-level security on workspace data. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

Your rights and choices

Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to or withdraw consent for certain processing. You can update account settings in the Service, disconnect integrations, manage cookie preferences per our Cookie Policy, or contact us to exercise your rights.

If you are in the European Economic Area or United Kingdom, you may lodge a complaint with your local data protection authority.

International transfers

HotelOil is operated from the United States. If you access the Service from other regions, your information may be transferred to, stored in, and processed in the United States and other countries where our service providers operate. We take steps designed to ensure appropriate safeguards for such transfers where required by law.

Children's privacy

The Service is intended for business users and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe we have collected such information, please contact us so we can delete it.

Disclosure required by law

We may disclose account data where required by valid legal process from a public authority, such as a subpoena, court order, or warrant. We review the legality of each request, challenge requests we consider unlawful, disclose only the minimum information necessary, and document each request and our response.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the "Last updated" date. Material changes may also be communicated by email or in-app notice where appropriate.

Contact

For privacy or data deletion questions, contact Reviewstay, LLC at reports@hoteloil.com.

Products
Drive
  • Multi-channel ad intelligence
  • Calendar heatmaps
  • Pace reporting
  • Goals vs performance
  • Data ingest
  • AI Strategist
  • Expedia bid enhancers
  • Custom / connected sources
  • Corporate / Drive reporting
  • Portfolio rollups
ReviewStay
  • Send / activity logs
  • Branded guest / review pages
  • Compset benchmarking
  • Guest outreach Send
  • QR Studio
  • Sentiment dashboards
SMS RS
  • Campaign builder + templates
  • Campaign management
  • Compliance (quiet hours, timezone, STOP/HELP)
  • How SMS RS works
  • Offers + public offer landings
  • Scheduling
  • Split testing
  • Subscriber / segment management
Folio
  • AI design pipeline
  • Custom domain + embed
  • Event intelligence → auto guides
  • Folio analytics / citation rollup
  • Multi-property portfolio pages
  • Portfolio website builder
  • Seat licensing
  • Theme packs + motion
TRVVL
  • AI concierge
  • Hub builder + device preview
  • Offers on the hub
  • Link Hub
  • Local events (PredictHQ)
  • Machine-readable facts / llms.txt
Autopilot
  • Accounts receivable / invoices
  • Autopilot + Drive Pro bundle unlock
  • Enrollment + platform verification
  • Funding schedule
  • Managed growth
  • Performance scoring / recommendations
  • PredictHQ demand opportunities + event ads
  • ROAS-linked commission model
Hoteloil

Hoteloil is the os to keep your hotels digital performance running smooth in the AI age. Built by hoteliers, for hoteliers.

© 2026 Hoteloil | Reviewstay. All rights reserved.

Built in America.Secured in Switzerland.

Company
  • Hoteloil OS
  • Pricing
  • Documentation
  • Blog
  • Changelog
  • FAQ
  • Contact
Contact
  • (623) 254-4370
  • 2390 East Camelback Road Suite #130
    Phoenix, AZ 85016
  • hello@hoteloil.com
Legal
  • Terms of Service
  • Privacy Policy
  • Cookie Policy