Legal
MAYA Privacy Policy
Effective Date: April 24, 2026
Last Updated: April 24, 2026
This Privacy Policy describes how Modern Hospitality Solutions LLC (“MHS,” “we,” “us,” or “our”) collects, uses, and protects information in connection with MAYA, our revenue automation service (the “Service”), including our website and any integrations with third-party property management systems (“PMS”). MAYA is a product of Modern Hospitality Solutions LLC.
MAYA is a business-to-business service. Our customers are hotels and hospitality operators (“Customers”). We are not a consumer-facing service and do not have a direct relationship with hotel guests.
1. Our Role: Service Provider / Data Processor
For operational data we receive from a Customer's PMS or other connected systems, the Customer is the data controller (or “business” under applicable U.S. state privacy laws), and MAYA acts as a data processor / service provider. We process such data solely on the Customer's behalf, at the Customer's direction, and for the purpose of providing the Service.
Hotel guests seeking to exercise privacy rights regarding their personal information should direct requests to the hotel where they stayed. We will assist our Customers in responding to such requests as required by applicable law and our agreements.
A Data Processing Addendum (DPA) is available to Customers upon request at info@modern-hospitality-solutions.com.
2. Information We Collect
a. Customer Account Information. When a Customer registers for the Service, we collect business contact information such as name, business email address, hotel/property name, role, and billing information. Payment card details are processed by our third-party payment processor and are not stored on our systems.
b. Property Operational Data (via PMS Integration). With the Customer's authorization, we access data from the Customer's PMS through its authorized API, limited to what is necessary to provide revenue management functionality. This includes: room rates and rate plans, availability and occupancy data, reservation-level booking data (e.g., dates, room type, channel, rate paid, booking status), inventory and room type configuration, and historical performance data.
c. Guest Personal Information — Data Minimization. The Service does not require guest personal information (such as guest names, email addresses, phone numbers, or payment details) to function. We do not intentionally collect guest personal information. If guest personal information is incidentally included in API responses from a connected PMS, we do not use it, display it, or retain it beyond transient processing.
d. Usage and Technical Data. We collect standard technical information when Customers use the Service or visit our website, such as log data, IP address, browser type, device information, and usage analytics, collected via cookies or similar technologies.
3. How We Use Information
We use the information described above to:
- Provide, operate, maintain, and support the Service, including generating rate recommendations and executing automated pricing actions authorized by the Customer;
- Communicate with Customers about their account, the Service, and support requests;
- Process billing and payments;
- Monitor, secure, and improve the performance and reliability of the Service;
- Comply with legal obligations and enforce our agreements.
We do not use Property Operational Data to market to hotel guests, we do not use personal data received through PMS integrations to send unsolicited communications, and we do not sell personal information of any kind. Where a connected PMS platform notifies us of a data subject's opt-out or deletion instruction, we comply as required under our agreements with that platform and applicable law.
4. Aggregated and De-Identified Data
We may create aggregated, anonymized, or de-identified data derived from use of the Service (for example, market-level pricing trends that cannot reasonably be linked to any individual property or person). We may use such data for any lawful business purpose, including benchmarking, market analytics, research, and developing, improving, and offering new products and services, provided it does not identify any Customer, property, or individual. De-identified data will not be re-identified.
5. How We Share Information
We do not sell or rent personal information. We share information only with:
- Service providers / subprocessors that support our infrastructure (e.g., cloud hosting, analytics, payment processing, error monitoring), bound by confidentiality and data protection obligations, and only as necessary to provide the Service;
- Connected PMS and integration partners, as directed by the Customer through their authorized integration (e.g., pushing rate updates to the Customer's PMS);
- Legal and safety recipients, where required by law, legal process, or to protect the rights, safety, or property of MAYA, our Customers, or others;
- Business transfer recipients, in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy's protections.
6. PMS Integration Terms
Our access to Customer data through any PMS API is governed by the Customer's authorization and the applicable PMS platform's API terms. We use PMS data solely to provide the Service to the authorizing Customer. If a Customer disconnects the integration or terminates the Service, we cease accessing their PMS data immediately.
7. Data Retention and Deletion
We retain Property Operational Data for as long as needed to provide the Service, including maintaining historical data used for forecasting and rate recommendations. Upon termination of a Customer's account or written deletion request, we will delete or de-identify the Customer's Property Operational Data within a commercially reasonable period, not to exceed 90 days, except where retention is required by law, for backup integrity (with deletion on standard backup expiration cycles), or for legitimate business records (e.g., billing history). Data that has been de-identified or aggregated pursuant to Section 4 may be retained and used indefinitely.
8. Security
We implement commercially reasonable administrative, technical, and physical safeguards designed to protect information against unauthorized access, loss, misuse, or alteration, including encryption in transit, access controls, and credential management for API tokens. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Customers are responsible for maintaining the confidentiality and security of their own account credentials, API tokens, and PMS accounts, and for all activity occurring under their credentials.
9. International Data Transfers
We are based in the United States and process data on servers located in the United States. If we process personal data subject to GDPR or similar laws, we rely on appropriate safeguards such as Standard Contractual Clauses, as reflected in our DPA.
10. Your Rights
Customers and their authorized users may access, correct, or delete their account information by contacting us at info@modern-hospitality-solutions.com. Depending on your jurisdiction, you may have additional rights under applicable privacy laws (such as the GDPR or U.S. state privacy laws), including rights of access, deletion, correction, and portability. We will honor verified requests as required by law. As noted in Section 1, guest requests should be directed to the applicable hotel.
11. Children's Privacy
The Service is intended for business use by adults. We do not knowingly collect personal information from anyone under 18.
12. Third-Party Links and Services
The Service may link to or interoperate with third-party services (including PMS platforms). Their privacy practices are governed by their own policies, and we are not responsible for them.
13. Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a revised “Last Updated” date, and where changes are material, we will use reasonable efforts to notify Customers. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
This Policy describes our practices; it is not a contract and does not create rights enforceable by hotel guests or any other third parties. Our obligations to Customers are governed by our service agreements and, where applicable, our DPA.
14. Contact Us
Modern Hospitality Solutions LLC
1515 E Cesar Chavez St. Suite 100
Austin, TX 78702
info@modern-hospitality-solutions.com