Skip to content

Security and data

How Hemmz looks after guest data

A hotel system holds names, stays and payments. Here is what we do to protect them, written so you can check it, and a plain list of what we have not done yet.

01

Each hotel business's data is kept apart

Every record belongs to one hotel business, and the database itself enforces that separation on every query, not only the application in front of it. Within a business, staff are given access property by property.

02

Staff see what their job needs

Each person signs in with their own account and a role: owner, revenue manager, front desk, housekeeping, driver, kitchen and so on. A housekeeper sees rooms, not bills. Owners and revenue managers sign in with a one-time code as well as a password.

03

Card numbers never reach our servers

When a guest pays online, the card details go from their browser straight to the payment provider. Hemmz stores the result of the payment, not the card.

04

Hosted where you choose

Hemmz runs on Amazon Web Services, in the AWS region agreed with each customer from the regions AWS offers. Data is encrypted in transit and the database is encrypted at rest. Some supporting services, such as payments and email delivery, are provided by companies that may process data elsewhere; we share the list with each customer.

05

A record of who did what

Changes that matter are written to an audit log with the person and the time. Closed accounting days cannot be edited afterwards; a correction is a new entry.

06

Your data stays yours

The property controls its guest and business data. A guest's data can be exported or erased on request, and we agree in writing how you retrieve your data if you leave.

What we have not done yet

Hemmz does not hold a third-party security certification such as ISO 27001 or SOC 2, and we do not publish an uptime figure, because we do not yet have a long enough record to stand behind one.

Before a property goes live we agree the support arrangements with it in writing, as part of the contract. If your own security review needs more detail, ask and we will share what we can.

Send us your security questionnaire

Send it over. We answer them ourselves, and we will say so where the answer is not yet.

Request a demo