What we collect, why we collect it, and what you can do about it.
This policy explains what personal information IQRev LLC (“IQRev,” “we,” “us”) collects, why, and what you can do about it. It covers iqrev.com and the IQRev application at ai.iqrev.com.
IQRev is a revenue management tool for hotels. It is deliberately built so that it does not receive hotel guest identity.
Our customers send us commercial reservation attributes — stay dates, room type, rate code and amount, market segment, distribution channel, booking date and similar fields — together with a confirmation or folio number used only so their own staff can find the matching record in their property management system. Our customers are contractually required not to send us guest names, guest email addresses, telephone numbers, postal addresses, free-text reservation notes, payment card data, government ID numbers, or health information.
We hold no key that would let us connect a confirmation number to a person. That link exists only in the hotel’s own system, and we undertake not to try to obtain it.
If you are a hotel guest and want to know what a hotel holds about you, contact that hotel directly. We would not be able to find your record even if you asked us to, because we do not hold your name or contact details. See Section 8.
The personal information we actually hold is about the people who use or evaluate our product — hotel staff, revenue managers, and prospective customers. That is what the rest of this policy is about.
| What | Why | How long |
|---|---|---|
| Analytics data — pages viewed, approximate location derived from IP, device and browser type, referring site | Understanding which pages are useful and how people find us | Up to 14 months |
| Cookies set by Google Analytics 4 | As above | See Section 5 |
We do not run advertising or advertising cookies on iqrev.com.
Our contact form collects your name, email address, hotel name, room count, and PMS, plus anything you write in the message field. We use it to reply to you and to prepare a demo. It reaches us through a third-party form service and is stored in our email. We keep demo enquiries for up to 24 months, then delete them, unless you become a customer.
| What | Why |
|---|---|
| Account data — name, business email, business phone, job role, hashed password, multi-factor authentication state | Creating and securing your account |
| Usage and security data — IP address, timestamps, pages and records viewed, actions taken, and your accept / modify / decline decisions on rate recommendations together with any written rationale | Operating and securing the service, supporting you, and improving our models |
| Billing data — billing contact, billing address, payment method reference | Taking payment. We never see or store full card numbers — our payment processor handles those directly. |
The reservation, rate, occupancy and pace data a hotel sends us is that hotel’s data, and we handle it on their instructions under the Data Protection and Security Addendum published at iqrev.com/terms. We are the service provider; they decide what to send and why. This policy does not change that relationship.
We do not use personal information to make automated decisions producing legal or similarly significant effects about an individual. Our rate recommendations are about rooms, not people, and a human at the hotel decides whether to act on them.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have never done so.
We share it only with:
| Category | Purpose |
|---|---|
| Cloud infrastructure provider | Hosting, storage, encrypted backups |
| AI model provider(s) | Generating recommendations and narratives. Prompts contain aggregated pricing and occupancy context — no guest data, and no confirmation numbers |
| Property management system and market data providers | Integrations our customers direct us to connect to |
| Form and email providers | Handling demo enquiries and service notifications |
| Payment processor | Subscription billing |
| Analytics provider | Website measurement |
| Professional advisors, and authorities where the law requires it | Legal, accounting, compliance |
Each is bound by a contract requiring them to protect the information and to use it only for the purpose we engaged them for. A list naming each provider is available on request — email legal@iqrev.com. We keep the named list confidential.
We may also transfer information as part of a merger, financing, or sale of the business. If that happens, this policy continues to apply until you are told otherwise.
iqrev.com uses Google Analytics 4 to count visits and see which pages get read. It sets cookies that record a randomly generated identifier, not your name.
You can opt out by using Google’s browser opt-out add-on, by blocking cookies in your browser, or by using a browser that sends a Global Privacy Control signal — we treat GPC as a request to stop analytics collection.
We do not use advertising cookies, retargeting pixels, or session-replay tools. The IQRev application itself uses only the cookies needed to keep you signed in and secure.
| Data | Retention |
|---|---|
| Demo enquiries | Up to 24 months |
| Website analytics | Up to 14 months |
| Account data | For the life of the account, then deleted or de-identified within 90 days of termination |
| Usage and security logs | Retained for security and audit purposes |
| Billing records | As long as tax and accounting law requires |
| Customer Data | Per the customer’s agreement — export available for 30 days after termination, deletion within 90 days after that |
| De-identified and aggregated data | Retained indefinitely. It is no longer personal information and cannot be linked back to an individual |
Backups are overwritten on a rotating schedule, so deleted data may persist in an encrypted backup for a short period after deletion from our live systems.
We maintain administrative, technical and physical safeguards appropriate to the data we hold and the size of our business, including encryption in transit, multi-factor authentication on administrative access, least-privilege database credentials, access logging, and encrypted backups. The full schedule is published in Section 5 of the Data Protection and Security Addendum at iqrev.com/terms.
No system is perfectly secure. If a breach affects your information, we will notify you and any regulator as the law requires.
Depending on where you live, you may have the right to:
To make a request, email legal@iqrev.com. We will verify your identity — usually by confirming you control the email address on the account — and respond within the time the law allows, normally 45 days. You may use an authorised agent; we will ask for proof of their authority.
Two limits worth stating plainly:
If you are a hotel guest, we almost certainly cannot help you, and not because we won’t. We do not hold guest names or contact details, so we have no way to find or verify a record as yours. Contact the hotel you stayed at — they hold the information and the link to it.
If you are a hotel employee using IQRev, your employer controls your account. If you ask us to delete data your employer owns, we will refer your request to them and tell you we have done so.
IQRev is a business tool. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, email us and we will delete it.
We are a Wyoming limited liability company and we store and process information in the United States. We offer the service to businesses operating in the United States. If you access it from elsewhere, you are sending your information to the United States, where privacy laws differ from those in your country.
We will post any updated policy on this page with a new effective date. If a change materially affects how we use personal information, we will give notice to account holders before it takes effect.
IQRev LLC 30 N Gould St Ste R, Sheridan, WY 82801, United States
If you are unhappy with how we have handled a privacy question, tell us first — we would rather fix it. You also have the right to complain to your state attorney general or data protection authority.