Privacy notice
Last updated: 6 October 2026 (draft)
Draft, pending legal review. This text may change before it is final.
In short. Hotels use Zikora to run their business. The hotel decides what it records about its guests and is responsible for it. We store that information for the hotel, we keep each hotel's data separate, and we never sell it.
1. Who we are
Zikora is provided by Evogue Consulting ("we", "us"). We run the software that hotels use. We run the software. Each hotel is responsible for the guest information it records.
2. Whose information this covers
- Hotel staff who sign in to Zikora.
- Hotel guests whose details a hotel records.
- Visitors to this website.
3. What we store
- Staff accounts: name, email address and sign-in details.
- Hotel records: bookings, rooms, bills, payments and invoices.
- Guest details the hotel records: for example name, phone, email, nationality and address. If the hotel enters them, ID document details. If the hotel allows it, a photo or scan of the ID document (see section 4). Only staff whose role allows it can see ID document details.
- A record of changes: who changed what and when. For guests it records which details changed, not the details themselves.
4. Photos of ID documents
- A hotel can choose to keep a photo or scan of a guest's ID, front and back. This is off unless the hotel switches it on.
- Why the hotel keeps it: to keep the guest register the law requires and to confirm who is staying (draft wording).
- Who can see it: only hotel staff whose role allows it, such as managers and front desk. Reservation staff and accountants cannot.
- How it is protected: stored privately, never at a public web address. A photo opens only through a link that works for 60 seconds. Every upload, view and deletion is recorded with who did it and when.
- Before upload, the photo is made smaller on the hotel's device. This also removes hidden details, such as where it was taken.
- How long it is kept: deleted automatically 12 months after the guest's last check-out, unless the guest has a stay that is not over. The hotel can ask for it to be deleted earlier (draft wording).
- It is deleted straight away when the guest's personal details are removed, or when a hotel manager deletes it.
- Where it is stored: in the European Union (Ireland), like the rest of the database. The files are private, encrypted in storage, and only people with permission at the hotel can open them (draft wording).
5. Where information is kept and who helps us
- The database is run by Supabase on servers in the European Union (Ireland).
- The website is served by Vercel.
- Sign-in and password emails are sent by Supabase. We plan to send these, and booking confirmations, through our email provider Resend.
6. Cookies and tracking
We use no advertising, no analytics and no tracking cookies. Your browser keeps your sign-in so you stay signed in. Our fonts are served from our own website, not from another company.
7. Who can see the information
Each hotel's information is kept separate from every other hotel's. Inside a hotel, each person sees only what their role allows. We do not sell information.
8. Keeping and removing information
- Bills, payments, invoices and the record of changes cannot be deleted, because they are financial records. Mistakes are corrected with a new entry that stays on record.
- A guest's personal details can be removed (anonymised) once the guest has no current or upcoming stay. Past stays and bills are kept without the personal details.
- After a hotel's account closes, we keep its information for 90 days, then delete it (draft wording).
9. Your rights and requests
You can ask what information we hold about you, ask us to correct it, or ask us to remove it. Write to our privacy contact at hello@zikorahq.com. If you are a hotel guest, you can also ask the hotel directly.
10. Changes to this notice
We will update this page when we change how we handle information, and we will change the date at the top. See also the security page and the terms of use.
