Effective and updated: 1 October 2026
Privacy notice
How CheckinPort processes personal data on its website, in its applications and in services for guests, accommodation providers and municipalities.
Globalio LLC16192 Coastal Hwy · Lewes, Delaware 19958-3608 · United Statesinfo@checkinport.com1. Operator and privacy roles
CheckinPort is operated by Globalio LLC, 16192 Coastal Hwy, Lewes, Delaware 19958-3608, United States. Contact: info@checkinport.com. This notice applies to website visitors, account holders, guests, organization representatives and people who contact us.
Globalio LLC is the controller for its own accounts, sales, billing, support, security and marketing. An accommodation provider is the controller for guest records, its bookings, statutory reporting and its own campaigns; Globalio acts as its processor when handling that data on its instructions. Municipalities determine their own legal purposes for tax administration and official records. An organization’s own privacy notice also applies. Providing software does not make Globalio the controller of every record.
2. Data and sources
We receive data from you, your organization and its authorized users, accommodation providers, booking forms, connected calendars, payment and communication providers, and your browser or device. This includes names, email and phone, account identifiers, roles, organization and property details, billing details, reservations, dates, occupancy, prices, payment status, preferences, messages, reviews, support requests and voluntary survey answers.
Guest registration can include name, date of birth, nationality, address and identity-document fields necessary for the relevant record. The document-scan workflow extracts text for review; it does not create a permanent document-photo archive in CheckinPort. Document identifiers in statutory guest records use a hash and masked suffix. Do not send identity documents, passwords, payment-card details or sensitive health information in ordinary messages or AI support.
Technical data includes IP address, browser and device information, language, access and security events, session identifiers, push tokens and, with the relevant consent, advertising identifiers and conversion events. A hash or pseudonymous identifier can still be personal data.
3. Purposes and legal bases
Under GDPR Article 6(1)(b), we process necessary data to create and operate your account, deliver services you request, process orders and provide support. Where you act for an organization rather than personally contracting, business-contact administration relies on our legitimate interest in managing that relationship, Article 6(1)(f).
Billing and legally required records rely on applicable legal obligations, Article 6(1)(c). Security, abuse prevention, service reliability and establishing or defending claims rely on legitimate interests, balanced against your rights. Optional analytics, advertising measurement and marketing that requires consent rely on Article 6(1)(a); you may withdraw consent at any time. We do not treat acceptance of the terms as marketing consent.
The accommodation provider or municipality determines the lawful basis for its own guest and tax records, including legal obligations or public tasks where applicable. Required fields are needed to deliver the requested service or comply with those duties; without them we may be unable to create an account, booking or record. Optional permissions and marketing consent are not a condition of purchase.
4. Who receives data
Access is limited by role and purpose to authorized staff, organization members and service providers. The infrastructure and integrations include Vercel for hosting, Supabase for database and authentication, Stripe for payments and connected-account verification, Resend for email, BulkGate for SMS and Firebase and platform push services for device notifications. Only data needed for the enabled function is shared. Stripe receives card and verification data through its own flows; CheckinPort does not store full card numbers or card security codes.
Accommodation providers receive booking and guest information needed for the stay. Municipal interfaces provide authorized operational and tax information, not unrestricted access to guest documents or guest contact lists. Reviews and listing content submitted for publication are visible publicly; private messages are available to the intended conversation participants and authorized service operations.
Data may also be disclosed to professional advisers, competent authorities when legally required, or a successor in a business transfer subject to continuing data protection obligations. Payment, advertising and other providers may also act as independent controllers for their own purposes described in their notices. We do not provide guest records to advertisers as part of the advertising integrations described below.
5. International processing
Globalio LLC is established in the United States, and service providers may process data in the United States or other countries outside the EEA. Where GDPR applies, restricted transfers require an applicable adequacy decision or appropriate safeguards, such as the European Commission’s standard contractual clauses with necessary supplementary measures. An adequacy framework is relied on only where the actual recipient and transfer qualify. Contact info@checkinport.com for information about applicable safeguards or a copy, subject to necessary redactions. This notice is not consent to unrestricted international transfers.
6. Essential storage and optional analytics
Authentication, security, language preferences, reservation and payment flows use necessary cookies, tokens or browser storage. Blocking necessary storage can prevent those functions from working. Embedded VEED videos receive technical browser data when their player loads and operate under the provider’s privacy terms.
On the host offer, optional analytics records visits, referral source and form steps using a random sessionStorage identifier after consent. The host_analytics_consent cookie retains your choice for up to 180 days. Order and payment records are created to fulfil your order independently of analytics consent.
7. Meta advertising measurement
Where you separately consent on the host offer, Meta Pixel and server-side Conversions API measure page and offer views, checkout initiation and confirmed purchases, including value and currency. Meta may receive IP address, browser information, page URL, event identifiers, _fbp and _fbc advertising identifiers, and a SHA-256 email hash for checkout and purchase matching. Hashing does not anonymize your email. Billing address fields are not automatically sent.
The host_meta_consent_v1 and host_meta_browser cookies last up to 180 days. Pending delivery data is retained for at most 7 days and its payload is deleted after successful delivery. Meta may combine events with information it holds for measurement and advertising under https://www.facebook.com/privacy/policy/.
8. OpenAI advertising measurement
This is a separate optional consent from Meta and from AI support. After consent, host_openai_oppref and host_openai_clicked_at store the advertising click reference and time for up to 30 days; host_openai_consent_v1 and host_openai_browser retain the choice and random identifier for up to 180 days.
For an attributed host registration, our server sends OpenAI an event identifier, click identifier, registration time and page address; an internal one-way account hash prevents duplicates. For a verified attributed purchase, it sends the order and click identifiers, time, amount, currency and offer address. This integration sends no name, email, phone or billing address and loads no OpenAI Pixel. Failed delivery is retried for up to 6 days; the queued click identifier is removed after delivery, consent withdrawal or expiry. Incomplete registration or order attribution is retained for up to 30 days.
Use the measurement and cookie settings at the bottom of the host offer to refuse or withdraw optional consents. Purchase remains available without them. Withdrawal stops future consent-based sending but does not undo prior lawful processing or automatically delete events already received by a provider. Provider information: https://openai.com/policies/privacy-policy/.
9. AI support, communications and device permissions
When you submit a question to AI support, your text, up to four recent conversation messages and the interface language are sent to OpenAI. Guest records, property records and authentication tokens are not automatically added. The assistant cannot inspect your account or execute changes. CheckinPort keeps at most 12 messages in device memory and clears them when the AI view closes; chat text is not saved to its database or application logs. Requests use store:false, but OpenAI may retain abuse-monitoring logs, generally for up to 30 days, subject to its applicable terms and legal exceptions. Input filtering is not complete anonymization.
Transactional email, SMS and push notifications support bookings and account operations. Marketing campaigns require the sender’s appropriate legal basis and applicable opt-out options. Optional push, camera and photo permissions can be changed in device settings. Disabling them affects the associated feature, not unrelated account functions.
10. Retention and deletion
Account data is retained while the account is active and subsequently only as needed for legal obligations, unresolved transactions, security investigations or claims. Billing and tax records follow applicable statutory retention periods; dispute records follow the applicable limitation period and duration of proceedings. Guest and municipal records follow the relevant controller’s legal duties and documented instructions, rather than a single worldwide retention period. Support records are retained as necessary to resolve the request and related disputes; technical logs only for the operational or security purpose concerned. Consent evidence is retained as needed to demonstrate compliance. Specific advertising and AI periods are stated above.
You can delete your account in the app or request deletion at info@checkinport.com; instructions are at /account-deletion. Deleting a login does not automatically erase shared organization records, statutory guest records or invoices, cancel a reservation, or release outstanding obligations. Data retained under an exception is restricted to that purpose. Deleted data in backups is removed through the backup lifecycle and is not used for routine operations. We delete or anonymize data when its retention purpose ends.
11. Your rights and requests
Where GDPR applies, you may request access and a copy, correction, erasure, restriction and, for qualifying automated processing based on consent or contract, portability. You may object to legitimate-interest processing on grounds relating to your situation, and object to direct marketing at any time. You may withdraw consent without affecting the lawfulness of earlier processing. These rights are subject to applicable conditions and necessary legal retention.
Send requests to info@checkinport.com. We may request proportionate verification, not unnecessary document copies. We normally respond within one month; a permitted extension of up to two further months for complex or numerous requests is explained within the first month. Requests are normally free. For data controlled by an accommodation provider or municipality, contact that organization; we assist it and route requests appropriately.
You may complain to the supervisory authority in your habitual residence, workplace or place of the alleged infringement, including the Slovak authority at https://dataprotection.gov.sk/. You need not contact us first. Other applicable local privacy rights remain available.
12. Security, children and automated processing
We use encrypted transport, access controls, organization isolation and security records. No system or transmission is completely risk-free. Protect your credentials and private reservation links and report suspected incidents to info@checkinport.com. We handle personal-data breaches and notifications according to applicable law and processor obligations.
Accounts and purchasing are intended for adults with legal capacity. Data about children in a family stay may be provided by an authorized adult where necessary for booking, registration or age-based tax treatment; the service does not solicit children’s independent marketing consent. We do not use the described processing to make solely automated decisions producing legal or similarly significant effects. OCR, tax calculations, recommendations and AI responses remain subject to human verification and correction.
13. Changes and contact
We publish the effective date above and give appropriate notice of material changes. A new purpose requires an appropriate legal basis and information; new consent is obtained where required. Contact Globalio LLC at the postal address above or info@checkinport.com for privacy, safeguards and rights requests.
Contact
Globalio LLC
16192 Coastal Hwy
Lewes, Delaware 19958-3608
United States