InnwayaPrivacy & your data

Privacy policy

Innwaya portal and connected services

Last updated: October 4, 2026

This policy explains how Innwaya By BrightPath handles personal information through the Innwaya portal, its workforce and hospitality modules, related forms and staff links, and connected services. Privacy questions and requests may be sent to hp71991@gmail.com.

The information handled depends on your organization's enabled features, your role, and the records you or your organization provide. This policy covers the portal as a whole. Additional details about the Chrome extension are available in the Innwaya — Gmail to Tasks privacy policy.

1. Your organization and Innwaya

Innwaya provides software for authorized businesses and their teams. The hotel, employer, or other organization operating your workspace determines which business records to collect, who may access them, which optional features to enable, and how those records are used in its operations. Innwaya processes workspace information to provide and support those services. We also handle account, support, and technical information needed to operate the platform.

If a hotel or employer entered information about you, its own privacy notices and employment or guest policies may also apply. Contact that organization about its records and decisions, or contact us for assistance identifying the appropriate workspace administrator. This policy does not replace a separate notice or consent required for a particular workplace practice.

2. Information we handle

We receive information directly from users and administrators, through applications and public or staff forms, from uploaded or imported files, through enabled integrations, and from the technical operation of the service. Notes and attachments may contain additional personal or sensitive information supplied by the organization. Users should provide only information needed for an authorized business purpose.

3. How information is used

We use information to authenticate users and apply access permissions; manage employees, applicants, schedules, timekeeping, and payroll workflows; coordinate hotel operations and guest service; manage sales, vendors, accounting, tasks, and documents; generate reports; and deliver requested messages, reminders, and notifications.

Information also supports document extraction and AI features described below, troubleshooting, support, fraud and misuse prevention, security monitoring, audit trails, and applicable recordkeeping or legal requirements. Workspace administrators control many of these uses through their configuration and access decisions.

4. Camera, location, and facial verification

Some onboarding and staff workflows request a camera image, an uploaded identification document, or a selfie. Where facial verification is enabled, the service can store a reference photograph and a numerical facial template derived from the image to compare against later verification attempts. These templates may constitute biometric information. Verification records can include consent confirmation, match results, confidence or distance measures, timestamps, and diagnostic information.

Location-enabled timekeeping and maintenance workflows may record precise location and whether the device was within the configured workplace area. The organization uses these records to verify the location and identity associated with an activity and to investigate discrepancies.

Your browser or device controls camera and location permissions. Denying or revoking access may prevent the associated feature from completing. Contact your employer or workspace administrator about available alternatives and any required notices or consent before using these features. This policy alone is not consent to biometric processing.

Disabling a feature, archiving an employee, or resetting facial enrollment does not necessarily erase all related records. For example, a reset may remove an enrollment template while a separately stored profile photograph or verification audit record remains. Requests to delete these categories should identify the photograph, biometric template, and audit records concerned.

5. AI and document processing

When you use enabled AI assistance or document-reading features, relevant prompts, conversation content, selected workspace context, and submitted files may be sent to OpenAI for processing. For example, invoice and statement extraction can send the uploaded document's contents, and the assistant may use relevant property or operational information to answer a request. Rate-research features may use an external web-search capability.

AI features can produce suggestions, extracted information, or requested workflow actions. Review results before relying on them for business, financial, or employment decisions. The information sent depends on the feature and request; using an AI feature is different from simply viewing a record in the portal.

External services handle the information they receive under their applicable service terms and privacy practices. We do not represent that every provider retains information for the same period or that disabling response storage removes all provider security or processing logs.

6. Sharing and service providers

Information is made available or transferred as needed for the following purposes:

The portal's business workflows do not require selling personal information or using workspace content for advertising. Information shared through external services is also subject to those services' applicable terms. Administrators should choose recipients and integrations appropriate for the information involved.

7. Cookies and browser storage

Innwaya uses browser storage and, in some access flows, cookies to maintain sign-in sessions, remember settings, and support its features. Stored information can include authentication or staff-access tokens, selected properties, language preferences, notification state, cached operational records or profile images, and locally held documents or drafts.

Some pages load fonts or software libraries from Google Fonts, jsDelivr, unpkg, Cloudflare CDN, or SheetJS. Those services receive associated technical requests, which can include the device's IP address and browser information. The resources used depend on the page and feature.

Use browser settings to manage cookies and site storage. Clearing storage can sign you out or remove local-only information. Signing out or clearing browser storage does not necessarily delete records already saved in the portal or copies downloaded or sent to recipients. On shared devices, sign out and follow your organization's device-use rules.

8. Retention and deletion

Retention depends on the record type, workspace configuration, operational need, and applicable employment, payroll, tax, accounting, security, or legal requirements. There is no single automatic deletion period covering the entire portal.

Archiving a user or record, rejecting an application, ending employment, or allowing an access link to expire does not by itself delete the associated stored documents and history. Removing an account also does not automatically remove business records created by that account. Backups, audit records, and copies sent to recipients may follow different retention processes.

For information about a workspace's retention practices or to request deletion, contact its administrator or hp71991@gmail.com. We may need to coordinate with the organization responsible for the record and retain information where there is a continuing lawful need. The Chrome extension's local-draft expiration rules apply only to its local drafts and save records, not to the portal's stored records.

9. Security and processing locations

The service uses HTTPS, authentication, role and property permissions, and security and audit controls to support the protection of information. Some workflows use time-limited or revocable links. Access depends on the feature and the organization's configuration. No system can guarantee absolute security, and local caches, exports, and downloaded documents also depend on the security of the user's device and sharing practices.

Service providers may process information in the United States and other locations where they operate. Processing locations and provider retention practices can vary by service and configuration; this policy does not promise that all information remains in one country.

10. Your choices and privacy requests

Depending on your location and relationship with the organization, you may have rights to request access, correction, deletion, or a copy of personal information, or to restrict or object to certain processing. Where processing relies on consent, you may request to withdraw it, subject to applicable requirements and the consequences for the affected feature.

Send requests to hp71991@gmail.com, or to the hotel or employer responsible for the workspace. Include the relevant organization and enough information to locate the record. Do not send passwords, a full Social Security number, bank credentials, or identification documents in an initial email. Identity and authority may need to be verified before records are disclosed or changed. Some requests may be limited by legal obligations, other people's rights, or the organization's responsibility for the records.

You can also manage camera and location permissions through your device, review notification settings where available, and disable connected extensions or integrations. Disabling future access does not automatically delete information previously saved or shared.

11. Chrome extension, children, and policy updates

Chrome extension: The Innwaya — Gmail to Tasks extension has a dedicated privacy policy explaining user-initiated email capture, attachment handling, local drafts, and Chrome Web Store Limited Use commitments. That policy supplements this portal policy for the extension's handling of data.

Children: Innwaya is a business service for authorized organizations, their teams, applicants, and related business workflows. It is not directed to children under 13. Contact us if you believe a child has submitted information through an inappropriate use of the service.

Updates: We may update this policy as features and practices change. The date at the top identifies the latest revision. Additional notice or consent will be provided where required for a particular change.

12. Text messaging (SMS)

BrightPath Hospitality Solution LLC operates a sales enquiry text line at its hotels. It is used only for one-to-one conversations with a person who has contacted a hotel about group rooms, corporate accounts, event space or a similar sales enquiry. It is not used for marketing or promotional messages.

How consent is given: either by sending a text message to the hotel sales number published on our website, in email signatures and on printed sales materials, or by telling a member of hotel staff during a telephone enquiry that you are happy to be texted at your number. Verbal consent is recorded against your enquiry with the name of the member of staff who took it and the date and time.

What to expect: Message frequency varies and depends on your enquiry. Standard message and data rates may apply. Reply STOP at any time to stop receiving messages. Reply HELP for assistance. You may also ask us to stop by telephone, by email or in person, and we will record it.

No mobile information is shared: mobile phone numbers and text message consent obtained for this service are never sold, and are never shared with third parties or affiliates for marketing or promotional purposes. The messaging provider named in section 6 processes message content and phone numbers solely to deliver the messages you have asked for. No mobile opt-in data is shared with anyone else for any other purpose.

The full terms for this service are set out in our text messaging terms and conditions.

Contact: Innwaya By BrightPath · hp71991@gmail.com.

BrightPath Hospitality Solution LLC
Hotel management and operations · New York
support@brightpath-mgt.com