Mizumi is an AI-powered guest communication and property management platform that enables hotels and other hospitality operators to manage omnichannel guest interactions, automate routine inquiries, take payments, and integrate with their existing Property Management Systems (PMS).
This Policy explains how Mizumi collects, uses, and protects information across our hotel staff portal, embedded guest widget, integrations, and APIs.
Mizumi acts in two distinct capacities depending on the data:
By using the Services, you agree to the practices described in this Privacy Policy. Hotel guests should also refer to the privacy notice provided by the hotel they are staying with, who is the data controller for their information.
| Party | Role | Description |
|---|---|---|
| Hotel | Data Controller | Determines the purposes and means of processing guest and staff data |
| Mizumi | Data Processor | Processes personal data on the hotel's documented instructions |
| Sub-processors | Sub-processors | Third-party services engaged by Mizumi to deliver the platform |
Hotels retain full control over guest data and are responsible for ensuring lawful bases exist for processing (e.g., legitimate interest, contract performance, consent).
| Category | Data Elements | Purpose |
|---|---|---|
| Identity | First name, last name, title, date of birth, nationality, preferred language | Guest profile management, personalisation |
| Contact | Email address, mobile phone number (used for SMS and messaging-app delivery), additional phone numbers, postal address (street, city, state, postal code) | Guest communications, booking confirmations, SMS notifications |
| Booking | Check-in/check-out dates, room type, rate, number of guests (including children and ages), source channel, special requests | Reservation management, PMS synchronisation |
| Communication | Full message history across all channels (WhatsApp, web chat, email, SMS, Facebook, Instagram, Zalo, WeChat), conversation metadata | Omnichannel guest support, AI response generation |
| Payment | Payment amount, currency, payment method type, payment status, tokenised payment reference | Payment facilitation (raw card data is never stored by Mizumi) |
| Profile metadata | Guest classification (VIP, repeat, first-time, corporate), total stays, lifetime value, marketing consent flag, guest tags and notes | Segmentation, personalised service |
| Device & network | IP address, derived geolocation (country, region), browser fingerprint | Fraud prevention, analytics, channel detection |
| Documents | Uploaded files (e.g., ID documents, booking confirmations) | Identity verification at the hotel's request |
| Category | Data Elements | Purpose |
|---|---|---|
| Identity | Name, email address | Account management, authentication |
| Access | Role, permissions, property assignments | Access control |
| Activity | Conversation assignments, action logs, anonymisation audit records | Operational accountability |
We use collected information to:
When a hotel uses the Services to send SMS, MMS, or messaging-app texts to a guest, Mizumi processes the guest's mobile phone number to deliver those messages. SMS and MMS messages are dispatched through Twilio (see Section 8.5); WhatsApp Business messages are dispatched through Twilio and/or Meta. Categories of messages may include: reservation confirmations and reminders, pre-arrival and in-stay service messages, guest support replies, payment links and receipts, post-stay follow-ups, and — where the hotel has obtained the required prior consent — marketing or promotional messages.
Message frequency varies based on the hotel's communications and the guest's interactions. Standard message and data rates may apply from the recipient's mobile carrier; Mizumi and the hotel are not responsible for carrier charges. Recipients may opt out of further non-transactional SMS at any time by replying STOP to a message from the hotel's sending number, and may request help by replying HELP. Opt-out requests are honoured at the sending-number / short-code level by the underlying carrier. Mobile phone numbers are retained as part of the guest profile for the period described in Section 9 (Data Retention) and are never sold or shared with third parties for their own marketing purposes.
We do not sell your personal information.
We share information only as described below:
Trusted vendors who assist with hosting, infrastructure, AI processing, payment, messaging, analytics, security, and communication. The complete list is provided in Section 8 (Sub-processors).
When you (or the hotel you are interacting with) authorise Mizumi to connect with systems such as a PMS, channel manager, CRM, or payment gateway, we share only the data required for that integration to operate.
We may disclose information if required by law, court order, subpoena, or governmental request, or when we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Mizumi, our customers, or the public.
In connection with a merger, acquisition, financing, reorganisation, bankruptcy, or sale of all or a portion of Mizumi's assets, information may be transferred as part of the transaction, subject to confidentiality protections and to this Privacy Policy.
All Mizumi production infrastructure is hosted on Amazon Web Services (AWS) in the USA.
| Component | Technology | Region |
|---|---|---|
| Primary database | AWS RDS | USA |
| File and asset storage | AWS S3 | USA |
| Content delivery | AWS CloudFront CDN | Global edge network |
| Message queuing | AWS SQS | USA |
| Email delivery | AWS SES and SendGrid (Twilio Inc.) | USA |
| Authentication | AWS Cognito | USA |
| Secrets management | AWS SSM Parameter Store / Secrets Manager | USA |
| Static site hosting (this site) | Cloudflare Pages | Global edge network |
Mizumi operates a multi-tenant, property-scoped architecture. Data belonging to one hotel cannot be accessed by another hotel's users.
| Layer | Implementation |
|---|---|
| Encryption at rest | AWS KMS field-level encryption applied to sensitive columns in PostgreSQL; separate KMS keys per environment |
| Encryption in transit | TLS 1.2 or higher enforced for all API, WebSocket, and CDN connections |
| Credential storage | All third-party integration credentials (PMS tokens, payment keys, messaging tokens) are encrypted with KMS before database storage |
| Authentication tokens | JSON Web Tokens (JWT) signed and validated via JWKS; short-lived access tokens |
Mizumi uses Datatrans SecureFields (and equivalent tokenisation provided by other configured processors) for PCI-compliant payment form handling. Card data is tokenised client-side and transmitted directly to the payment processor; raw card numbers never pass through Mizumi servers. Mizumi stores only a tokenised payment reference returned by the processor.
Mizumi engages the following third-party sub-processors to deliver the Services. Each sub-processor is bound by contractual obligations requiring them to apply equivalent data protection standards. Only sub-processors corresponding to features your hotel has configured will receive data; for example, a hotel that has not enabled WeChat does not transmit data to Tencent.
| Sub-processor | Service | Data Processed | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure (compute, database, storage, queuing, email, identity, CDN, key management, monitoring) | All platform data | USA |
| Cloudflare, Inc. | DNS, edge network, and static site hosting (legal.mizumi.ai, chat.mizumi.ai) | Public website request metadata | USA / Global edge |
| SendGrid (Twilio Inc.) | Transactional email delivery for guest notifications and administrative communications | Recipient email address, message content | USA |
| Sub-processor | Service | Data Processed | Location |
|---|---|---|---|
| OpenAI, L.L.C. | Large language model (GPT-4.1 series) for AI-powered guest responses, query classification, and knowledge retrieval | Guest messages, conversation context | USA |
| Google LLC (Gemini API) | Alternative/backup LLM provider | Guest messages, conversation context | USA |
| LangSmith (LangChain, Inc.) | LLM observability and tracing | LLM inputs/outputs for debugging | USA |
| Sub-processor | Service | Data Processed | Location |
|---|---|---|---|
| Mews Systems | PMS integration — guest profiles, bookings, rates, room inventory synchronisation | Guest PII, booking data | Czech Republic / USA |
| Cloudbeds | PMS integration — guest profiles, bookings | Guest PII, booking data | USA |
| Smile PMS | PMS integration | Guest PII, booking data | Vietnam |
PMS integrations are hotel-configured. A hotel only shares data with PMS providers it has actively connected. Mizumi acts as an intermediary, not an independent data source.
Mizumi supports multiple payment gateways depending on the hotel's region and configuration. Only the payment processors activated by the hotel will process guest payment data.
| Sub-processor | Service | Data Processed | Location |
|---|---|---|---|
| Datatrans AG | PCI-compliant payment tokenisation (SecureFields) | Payment card data (tokenised) | Switzerland |
| Stripe, Inc. | Credit/debit card processing | Payment data | USA |
| VNPay | Vietnamese payment gateway | Payment data | Vietnam |
| OnePay | Payment processing | Payment data | Vietnam |
| MoMo (M_Service) | Vietnamese mobile wallet | Payment data | Vietnam |
| ZaloPay (VNG Corporation) | Vietnamese digital payment | Payment data | Vietnam |
| PayPal Holdings, Inc. | Global payment processing | Payment data | USA |
| Square (Block, Inc.) | Point-of-sale / payment processing | Payment data | USA |
Mizumi routes guest messages through third-party channel providers. Only channels that the hotel has activated are used.
| Sub-processor | Service | Data Processed | Location |
|---|---|---|---|
| Meta Platforms, Inc. (WhatsApp / Facebook / Instagram) | Messaging channel delivery and receipt | Guest messages, metadata | USA |
| Twilio Inc. | SMS and WhatsApp Business API delivery | Guest phone numbers, message content | USA |
| Zalo (VNG Corporation) | Vietnamese messaging channel | Guest messages, metadata | Vietnam |
| WeChat (Tencent Holdings Ltd.) | Chinese messaging channel | Guest messages, metadata | China |
| Sub-processor | Service | Data Processed | Location |
|---|---|---|---|
| Google Maps (Google LLC) | Property location display in guest-facing widget | Hotel address data | USA |
| Baidu Maps (Baidu, Inc.) | Property location display (China-region widget) | Hotel address data | China |
| Sub-processor | Service | Data Processed | Location |
|---|---|---|---|
| PostHog, Inc. | Product analytics, session replay (hotel staff portal only) | Staff usage patterns, anonymised interaction events | USA |
| FingerprintJS, Inc. | Browser fingerprinting for session identification and fraud signals | Browser fingerprint hash (guest widget) | USA |
PostHog is used in the hotel staff portal only. Session replay is configured with privacy controls: all text inputs are masked, DoNotTrack settings are respected, and network payloads are masked for sensitive headers.
Guest and booking data is retained for the duration of the hotel's active subscription with Mizumi, plus a reasonable post-termination period sufficient to complete any outstanding legal or financial obligations, unless otherwise agreed in writing. Data may be anonymised and aggregated for analytics or product improvement.
Depending on your jurisdiction, you may have the right to:
Hotel guests should generally direct these requests to the hotel they interacted with, since the hotel is the data controller. Mizumi will assist hotels in fulfilling such requests.
Mizumi includes a built-in guest anonymisation workflow:
Mizumi provides a dedicated DSAR workflow:
To exercise rights directly with Mizumi (for example, where Mizumi is the controller of your data as a hotel customer or website visitor), contact [email protected].
Mizumi's production infrastructure is located in the United States.
Mizumi relies on the following transfer mechanisms:
Hotels in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data transfer restrictions should ensure their Data Processing Agreement with Mizumi includes appropriate transfer documentation.
Vietnam-specific: For Vietnamese hotels, Mizumi uses Vietnam-based sub-processors (VNPay, MoMo, ZaloPay, Zalo) where applicable to minimise cross-border data transfers for payment and messaging.
We use cookies and similar technologies to:
You may adjust your browser settings to block or delete cookies, though some features may not function properly without them. The Mizumi guest widget honours DoNotTrack signals for analytics.
Mizumi is not intended for individuals under the age of 16, and we do not knowingly collect personal information directly from children. Hotels may, in the ordinary course of operating their property, record the ages of children associated with a booking (e.g., for room capacity purposes). Such information is processed on the hotel's instruction.
As the data controller, the hotel is responsible for:
Hotels using Mizumi in a capacity that involves processing personal data of EU/EEA residents (or residents of other jurisdictions with similar requirements) should execute a Data Processing Agreement with Mizumi.
The DPA governs:
To request a DPA, contact your Mizumi account representative or email [email protected].
Mizumi will provide 30 days' advance notice of any material changes to the sub-processor list (additions or replacements that may affect the protection of personal data). Hotels that have signed a DPA may object to new sub-processors during this notice period.
We may update this Privacy Policy from time to time. We will notify hotel customers of material changes through the platform or via email and will update the "Last Updated" date at the top of this page.
| Purpose | Contact |
|---|---|
| Data processing and privacy inquiries | [email protected] |
| Security incidents | [email protected] |
| DPA requests | [email protected] |
| General support | [email protected] |
Mizumi AI Inc.
8 The Green, Suite B
Dover, Delaware 19901, USA