Privacy policy
Innwaya portal and connected services
Last updated: October 4, 2026
This policy explains how Innwaya By BrightPath handles personal information through the Innwaya portal, its workforce and hospitality modules, related forms and staff links, and connected services. Privacy questions and requests may be sent to hp71991@gmail.com.
The information handled depends on your organization's enabled features, your role, and the records you or your organization provide. This policy covers the portal as a whole. Additional details about the Chrome extension are available in the Innwaya — Gmail to Tasks privacy policy.
1. Your organization and Innwaya
Innwaya provides software for authorized businesses and their teams. The hotel, employer, or other organization operating your workspace determines which business records to collect, who may access them, which optional features to enable, and how those records are used in its operations. Innwaya processes workspace information to provide and support those services. We also handle account, support, and technical information needed to operate the platform.
If a hotel or employer entered information about you, its own privacy notices and employment or guest policies may also apply. Contact that organization about its records and decisions, or contact us for assistance identifying the appropriate workspace administrator. This policy does not replace a separate notice or consent required for a particular workplace practice.
2. Information we handle
- Accounts and access: Names, usernames, email addresses, phone numbers, roles, assigned properties, staff identifiers, authentication credentials and session information, access settings, language preferences, and profile photographs.
- Employees and applicants: Contact details, addresses, dates of birth, emergency contacts, applications, resumes, availability, employment history, work eligibility, identification documents, signatures, and acknowledgments. Where onboarding, tax, or payroll features are used, records can include Social Security or other tax identifiers, I-9 and work-authorization information, withholding elections, and bank or direct-deposit details.
- Workforce operations: Schedules, attendance, clock-in and clock-out times, breaks, timecard edits, approvals, pay rates and wage history, payroll calculations and exports, leave or absence records, performance or disciplinary records, employee responses, separation details, and related staff notes.
- Location and verification: When a configured workflow requests location access, it may collect precise coordinates, accuracy, distance from the workplace, timestamps, and the result of a location check. Camera and facial-verification information is described below.
- Guests and hotel operations: Guest names and contact information, room and stay details, confirmation numbers, guest requests, complaints, incident reports, parking or shuttle records, work orders, inspection findings, operational logs, photographs, and supporting documents provided by users.
- Sales, vendors, and financial records: Lead and customer contact information, company names, booking or event requirements, travel dates, sales activity, vendor contacts and tax information, contracts, invoices, payment status, financial account information, bank or card statements, transactions, budgets, revenue reports, and other accounting documents uploaded or entered into the portal.
- Communications and files: Task titles, descriptions, comments, assignments, reminders, team messages, email content captured through the extension, reports, file attachments, recipient details, and delivery or notification records.
- Technical and audit information: Request and session identifiers, browser or device information, IP addresses processed by our services or hosting providers, timestamps, security and access events, workflow activity, errors, service performance, and delivery or processing outcomes. Audit records can identify the acting user, organization, property, and affected record.
We receive information directly from users and administrators, through applications and public or staff forms, from uploaded or imported files, through enabled integrations, and from the technical operation of the service. Notes and attachments may contain additional personal or sensitive information supplied by the organization. Users should provide only information needed for an authorized business purpose.
3. How information is used
We use information to authenticate users and apply access permissions; manage employees, applicants, schedules, timekeeping, and payroll workflows; coordinate hotel operations and guest service; manage sales, vendors, accounting, tasks, and documents; generate reports; and deliver requested messages, reminders, and notifications.
Information also supports document extraction and AI features described below, troubleshooting, support, fraud and misuse prevention, security monitoring, audit trails, and applicable recordkeeping or legal requirements. Workspace administrators control many of these uses through their configuration and access decisions.
4. Camera, location, and facial verification
Some onboarding and staff workflows request a camera image, an uploaded identification document, or a selfie. Where facial verification is enabled, the service can store a reference photograph and a numerical facial template derived from the image to compare against later verification attempts. These templates may constitute biometric information. Verification records can include consent confirmation, match results, confidence or distance measures, timestamps, and diagnostic information.
Location-enabled timekeeping and maintenance workflows may record precise location and whether the device was within the configured workplace area. The organization uses these records to verify the location and identity associated with an activity and to investigate discrepancies.
Your browser or device controls camera and location permissions. Denying or revoking access may prevent the associated feature from completing. Contact your employer or workspace administrator about available alternatives and any required notices or consent before using these features. This policy alone is not consent to biometric processing.
Disabling a feature, archiving an employee, or resetting facial enrollment does not necessarily erase all related records. For example, a reset may remove an enrollment template while a separately stored profile photograph or verification audit record remains. Requests to delete these categories should identify the photograph, biometric template, and audit records concerned.
5. AI and document processing
When you use enabled AI assistance or document-reading features, relevant prompts, conversation content, selected workspace context, and submitted files may be sent to OpenAI for processing. For example, invoice and statement extraction can send the uploaded document's contents, and the assistant may use relevant property or operational information to answer a request. Rate-research features may use an external web-search capability.
AI features can produce suggestions, extracted information, or requested workflow actions. Review results before relying on them for business, financial, or employment decisions. The information sent depends on the feature and request; using an AI feature is different from simply viewing a record in the portal.
External services handle the information they receive under their applicable service terms and privacy practices. We do not represent that every provider retains information for the same period or that disabling response storage removes all provider security or processing logs.
6. Sharing and service providers
Information is made available or transferred as needed for the following purposes:
- Within your organization: Authorized managers, administrators, HR or payroll personnel, and teammates can access records according to workspace permissions and workflows. Assigning a task to one person does not necessarily make it private to that person.
- Hosting and storage: Vercel provides hosting and request processing. Supabase provides authentication, databases, file storage, and backend services used by the portal. These providers process information needed to operate the service.
- AI services: OpenAI processes information submitted through the enabled features described above.
- Email and messaging: Configured mail services, including Google Workspace/Gmail, process recipient addresses, message content, and attachments for reports and notifications. Meta/WhatsApp processes phone numbers and message content when WhatsApp notifications or sharing are enabled. Intended recipients receive the information included in the message.
- Document previews: Some Office or image-document previews use Google Docs Viewer, which receives the selected document URL and can retrieve the document to display it.
- Connected systems: Enabled integrations, such as ClickUp task import or synchronization, handle the records necessary for that connection. Information exchanged depends on the integration and its configuration.
- User-directed sharing: Downloads, exports, emailed reports, and shared links may disclose information to recipients chosen by authorized users. Some staff or public forms use access links or tokens; anyone who obtains a valid link may be able to use the access it grants. Recipients may retain their own copies.
- Support, security, and legal needs: Information may be accessed or disclosed to resolve a support request, investigate misuse, protect the service or people, or meet applicable legal requirements.
The portal's business workflows do not require selling personal information or using workspace content for advertising. Information shared through external services is also subject to those services' applicable terms. Administrators should choose recipients and integrations appropriate for the information involved.
7. Cookies and browser storage
Innwaya uses browser storage and, in some access flows, cookies to maintain sign-in sessions, remember settings, and support its features. Stored information can include authentication or staff-access tokens, selected properties, language preferences, notification state, cached operational records or profile images, and locally held documents or drafts.
Some pages load fonts or software libraries from Google Fonts, jsDelivr, unpkg, Cloudflare CDN, or SheetJS. Those services receive associated technical requests, which can include the device's IP address and browser information. The resources used depend on the page and feature.
Use browser settings to manage cookies and site storage. Clearing storage can sign you out or remove local-only information. Signing out or clearing browser storage does not necessarily delete records already saved in the portal or copies downloaded or sent to recipients. On shared devices, sign out and follow your organization's device-use rules.
8. Retention and deletion
Retention depends on the record type, workspace configuration, operational need, and applicable employment, payroll, tax, accounting, security, or legal requirements. There is no single automatic deletion period covering the entire portal.
Archiving a user or record, rejecting an application, ending employment, or allowing an access link to expire does not by itself delete the associated stored documents and history. Removing an account also does not automatically remove business records created by that account. Backups, audit records, and copies sent to recipients may follow different retention processes.
For information about a workspace's retention practices or to request deletion, contact its administrator or hp71991@gmail.com. We may need to coordinate with the organization responsible for the record and retain information where there is a continuing lawful need. The Chrome extension's local-draft expiration rules apply only to its local drafts and save records, not to the portal's stored records.
9. Security and processing locations
The service uses HTTPS, authentication, role and property permissions, and security and audit controls to support the protection of information. Some workflows use time-limited or revocable links. Access depends on the feature and the organization's configuration. No system can guarantee absolute security, and local caches, exports, and downloaded documents also depend on the security of the user's device and sharing practices.
Service providers may process information in the United States and other locations where they operate. Processing locations and provider retention practices can vary by service and configuration; this policy does not promise that all information remains in one country.
10. Your choices and privacy requests
Depending on your location and relationship with the organization, you may have rights to request access, correction, deletion, or a copy of personal information, or to restrict or object to certain processing. Where processing relies on consent, you may request to withdraw it, subject to applicable requirements and the consequences for the affected feature.
Send requests to hp71991@gmail.com, or to the hotel or employer responsible for the workspace. Include the relevant organization and enough information to locate the record. Do not send passwords, a full Social Security number, bank credentials, or identification documents in an initial email. Identity and authority may need to be verified before records are disclosed or changed. Some requests may be limited by legal obligations, other people's rights, or the organization's responsibility for the records.
You can also manage camera and location permissions through your device, review notification settings where available, and disable connected extensions or integrations. Disabling future access does not automatically delete information previously saved or shared.
11. Chrome extension, children, and policy updates
Chrome extension: The Innwaya — Gmail to Tasks extension has a dedicated privacy policy explaining user-initiated email capture, attachment handling, local drafts, and Chrome Web Store Limited Use commitments. That policy supplements this portal policy for the extension's handling of data.
Children: Innwaya is a business service for authorized organizations, their teams, applicants, and related business workflows. It is not directed to children under 13. Contact us if you believe a child has submitted information through an inappropriate use of the service.
Updates: We may update this policy as features and practices change. The date at the top identifies the latest revision. Additional notice or consent will be provided where required for a particular change.
12. Text messaging (SMS)
BrightPath Hospitality Solution LLC operates a sales enquiry text line at its hotels. It is used only for one-to-one conversations with a person who has contacted a hotel about group rooms, corporate accounts, event space or a similar sales enquiry. It is not used for marketing or promotional messages.
How consent is given: either by sending a text message to the hotel sales number published on our website, in email signatures and on printed sales materials, or by telling a member of hotel staff during a telephone enquiry that you are happy to be texted at your number. Verbal consent is recorded against your enquiry with the name of the member of staff who took it and the date and time.
What to expect: Message frequency varies and depends on your enquiry. Standard message and data rates may apply. Reply STOP at any time to stop receiving messages. Reply HELP for assistance. You may also ask us to stop by telephone, by email or in person, and we will record it.
No mobile information is shared: mobile phone numbers and text message consent obtained for this service are never sold, and are never shared with third parties or affiliates for marketing or promotional purposes. The messaging provider named in section 6 processes message content and phone numbers solely to deliver the messages you have asked for. No mobile opt-in data is shared with anyone else for any other purpose.
The full terms for this service are set out in our text messaging terms and conditions.
Contact: Innwaya By BrightPath · hp71991@gmail.com.
