Legal
Privacy Policy
Effective date: 11 September 2026
This Privacy Policy describes how WOLODGE Global Holdings LLC (“WOLODGE”, “we”, “us”, or “our”) collects, uses, and shares information when you use the ASPIXR platform, including our websites, web applications, mobile applications (including the ASPIXR Operations and ASPIXR Owner apps on Google Play), and related services (collectively, the “Services”).
ASPIXR provides business software to hotels and hospitality operators. Most Services are offered to authorised staff and business users on behalf of a hotel or organisation (“Customer”). Where we process personal data on a Customer’s instructions, the Customer is typically the data controller and WOLODGE acts as a data processor.
1. Who this policy applies to
- Business users — hotel owners, managers, front desk, housekeeping, maintenance, finance, and other staff who sign in to ASPIXR portals or mobile apps.
- Property owners — people who own rooms, units or whole properties that a hotel operates for them, and who sign in to ASPIXR Owner (the app on Google Play) or owner.aspixr.com. An owner is not staff at the hotel: they are the other party to an agreement with it, and the app holds different information about them. Section 2.4 lists it.
- Website visitors — people who browse aspixr.com or submit a contact or demo request.
- Guests and travellers — where a Customer uses ASPIXR guest-facing features (for example registration links, direct booking, or messaging), we process guest data on the Customer’s behalf as described in their policies and our agreements with them.
2. Information we collect
2.1 Information you provide
- Account details such as name, work email, phone number, role, and property assignments.
- Login credentials (passwords are stored in hashed form; we do not store plain-text passwords).
- Business and operational data you enter into the Services (reservations, room status, tasks, maintenance reports, notes, and similar hotel operations data).
- Contact form submissions on aspixr.com (name, email, company, message, and interest type).
- Support requests and communications with us.
2.2 Information collected automatically
- Device and usage data such as IP address, browser type, operating system, app version, pages or screens viewed, and timestamps.
- Mobile app data such as push notification tokens (when you enable notifications), crash diagnostics, and performance logs.
- Cookies and similar technologies on our websites (see Section 8). We use essential cookies for security and session management; analytics cookies only where enabled.
2.3 Information from third parties
- Your employer or hotel administrator when they create or manage your staff account.
- Payment processors when you make a subscription or payment (we receive limited billing metadata, not full card numbers).
- Integration partners (for example channel managers or payment gateways) where your Customer has enabled an integration.
2.4 If you are a property owner (ASPIXR Owner)
The Owner app holds things no staff app does, because it is where an owner is paid and where their agreement with the hotel is recorded. In full:
- Your identity and contact details — name, email address, phone number and postal address.
- Bank details, if you give them — bank name, account number and beneficiary name, or a DuitNow ID. A DuitNow ID may itself be an identification number: an NRIC, a passport number, a mobile number or a business registration number. We hold it so your hotel can pay you; we do not initiate the payment.
- Your financial records — the month reports, payout statements, ledger entries, deductions and contracts for the property you own. This is the substance of the app rather than a by-product of it.
- Your conversations — messages with staff at your hotel, and with Aspi. When you send Aspi a file, it reads the file in order to answer about it. What Aspi remembers between conversations is limited on purpose, and the same limit applies to what it reads out of a file: it will not store an identification number, a bank account, a phone number, an email address, an address or a date of birth, even if one appears in a message or in a document you sent.
- Photographs and documents you send — a photo of a repair you arranged yourself, or a photo, PDF or scan you send to your hotel in a conversation. What happens to those afterwards depends on what you do with them: a file you simply send is deleted 30 days after you close your account, along with the conversation; a file you deliberately file to your documents is kept for as long as your contract runs and then for seven years, because by then it is part of the record.
- The devices you have confirmed, and how you confirm it is you.Before we show or change your bank details, close your account or give you a copy of your data, we ask you to confirm it is you — normally with a code sent to your email address. If you set up an authenticator app instead, we hold the secret that app needs and the recovery codes that go with it, all of them stored so that nobody here can read them back. When you tell us not to ask again on a device, we keep a random identifier that browser gave itself and a description of it such as “Chrome on Android”. You can see that list and remove anything on it in the app, under Account settings.
- A push notification token, only if you turn notifications on, and only to tell you that a statement was published or that something is waiting on your decision.
- Which statements and approvals you opened, and when. A decision about money has to be attributable afterwards, to you as much as to us.
We do not sell any of it, and none of it is used for advertising.
3. How we use information
We use information to:
- Provide, operate, maintain, and improve the Services.
- Authenticate users and enforce access controls and security.
- Send service-related notices, including push alerts configured by your hotel (for example operational reminders).
- Respond to demo requests, sales enquiries, and support tickets.
- Process subscriptions and billing where applicable.
- Monitor performance, prevent fraud and abuse, and comply with legal obligations.
- Develop new features in accordance with our agreements with Customers.
We do not sell your personal information. We do not use staff operational data for unrelated third-party advertising.
4. Legal bases (where applicable)
Depending on your location and the type of processing, we rely on:
- Performance of a contract (providing the Services to you or your Customer).
- Legitimate interests (security, product improvement, B2B communications) balanced against your rights.
- Consent (for example optional marketing emails or non-essential cookies where required).
- Legal obligation (tax, accounting, regulatory requests).
5. How we share information
We may share information with:
- Service providers who help us run the Services, such as cloud hosting, object storage, email delivery, error monitoring, analytics, and payment processing. These providers are bound by confidentiality and data processing terms.
- The AI provider behind Aspi.To answer a question, Aspi sends the conversation and the figures it is answering about to Google’s Generative Language API, under a data processing agreement. Aspi is given only what the person asking is already entitled to see.
- Your organisation — data you enter as a staff user is visible to authorised users within your hotel or operator account according to role permissions.
- The hotel that operates your property, if you are an owner. They publish your statements, hold the agreement and make the payment, so they see your records and the bank details you give. They are the people to ask about anything in a statement.
- Professional advisers (lawyers, accountants) under confidentiality.
- Authorities when required by law or to protect rights, safety, and security.
- Business transfers in connection with a merger, acquisition, or asset sale, subject to continued protection of personal data.
6. International transfers
We and our service providers may process data in countries other than your own. Where required, we use appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) for cross-border transfers.
7. Data retention
We retain information for as long as needed to provide the Services, fulfil our contracts with Customers, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods may vary by data type and Customer configuration. Customers may request deletion or export subject to their agreement with us and applicable law.
Property owners: two clocks, not one. When an owner closes their ASPIXR Owner account, their personal details — name, email address, phone number, identification and bank details, address, and their conversations with Aspi — are deleted after 30 days. The 30 days are a grace period, not a delay: signing in again within them cancels the closure, so a closure made by mistake, or by somebody who should not have been in the account, can be undone. The owner’s financial records — payout statements, ledger entries, invoices and contracts — are kept for 7 years, because the hotel is required to keep them for tax and audit. Once the personal details are deleted, those records no longer name the owner. An account cannot be closed while a payment is outstanding in either direction; closing an account still owed a payout would leave that payment with nowhere to go.
8. Cookies and similar technologies
Our websites use cookies and local storage for authentication sessions, preferences, and security. You can control cookies through your browser settings. Disabling essential cookies may prevent sign-in or certain features from working.
9. Security
We implement administrative, technical, and organisational measures designed to protect information, including encryption in transit (HTTPS/TLS), access controls, and audit logging. No method of transmission or storage is completely secure; please use strong passwords and protect your credentials.
10. Your rights and choices
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to or withdraw consent for certain processing.
- Staff users: contact your hotel administrator or employer first, as they control your account and much of the data in the system.
- Property owners: you do not have to ask anyone. Sign in to ASPIXR Owner, open Account settings and use Close your account — your password and a typed confirmation phrase, no email and no waiting for a reply. The account deletion page sets out exactly what is deleted and when. Questions about a figure in a statement go to your hotel: they calculated it and they hold the agreement.
- Website enquiries: contact us using the details below.
- Push notifications: you can disable notifications in your device settings or within the app where offered.
We will respond to verified requests within the timeframes required by applicable law. You may also lodge a complaint with your local data protection authority.
11. Children’s privacy
The Services are intended for business use and are not directed to children under 16 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.
12. Third-party links and services
The Services may link to third-party websites or integrate with third-party services chosen by a Customer. This policy does not apply to those third parties. Review their privacy policies before providing information to them.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the effective date. Material changes may be communicated through the Services or by email where appropriate.
14. Contact us
WOLODGE Global Holdings LLC (ASPIXR)
Privacy enquiries: privacy@aspixr.com
General contact: aspixr.com/contact
For Google Play and app-store listings, this policy applies to ASPIXR mobile applications published by WOLODGE Global Holdings LLC, including ASPIXR Operations (com.aspixr.frontoffice).