ALVEARY, LLC (“Alveary”) is a Tennessee limited liability company.
Who we are
Alveary operates Vault, Alveary OS, and the other products and resources described in this notice.
You can reach Alveary about this notice or your information at support@alvearyos.com.
What this notice covers
This notice describes what we collect when you request an Alveary resource, create an Alveary account, read or download standards in Vault, record a self-assessment in Comb Check, or pay for a membership. It covers Alveary’s public resource library, Vault, Comb Check, and the other products published on Alveary OS. It does not cover what your employer does with information inside its own systems.
This notice also describes information processed through Alveary Guard for customer-operated valet and arrival services and Alveary-operated demonstrations, testing and proof-of-concept sessions. A participant does not need an Alveary account or hotel reservation. For an actual valet service, the property or other identified valet operator is responsible for its operation and acts as controller or business as applicable; Alveary supplies software and acts as processor or service provider as applicable. The operator's own privacy notice also applies. For its own demonstration program, Alveary is responsible for the participant information it collects. Demonstrations are identified in advance and simulate vehicle events without taking custody of a vehicle or representing affiliation with a real hotel.
What we collect, why, and how long we keep it
Account and profile
Your email address, and — if you provide them — your name, display name, job title, and the name you want printed on standards you download. We also record whether you have opted in to marketing email. If you give us your mobile number, we record it together with whether you consented to receive text messages, the date and time of that consent, and the exact text of the consent you were shown.
We collect this to create and operate your account, to show you the right content for your membership, and to put the correct name on licensed downloads. The lawful basis, where GDPR applies, is performance of a contract — this is the account you asked us to create.
We never store a password. Signing in works by emailed link, so there is no password on our side to lose, reset, or breach.
Kept for the life of your account. Deleted when you close it or ask us to delete it, subject to the evidence exception described below. Your mobile number is deleted with your account, subject to applicable holds. Messaging-consent evidence follows its separate schedule: five years after the later of the date consent ceases to be operative or the last message sent in reliance on it. Guard guest and demonstration participant identity follows the transaction-based schedule described under Valet and arrival records.
Resources you request
When you ask us for a downloadable resource — such as a field guide, checklist, or template — we ask for your work email address. You may also give us your first name, role, and information about the size of your property or portfolio. Those fields are optional.
The resource opens in your browser after you submit the form. We use your work email to provide access to the gated resource, record the request, operate and secure the resource library, and understand how our professional resources are being used.
You do not need an Alveary account to receive a resource, and asking for one does not create an account.
We also record the resource and version requested, the date and time of the request, the allowlisted Alveary route from which the request was made, bounded campaign labels, and the referring domain only. While that information remains linked to your work email, we treat all of it as personal information.
Where GDPR applies, our lawful basis for providing and controlling access to the resource, recording and understanding its distribution, maintaining security and abuse controls, and responding to support issues concerning the resource is legitimate interests under Article 6(1)(f). Those are Alveary’s legitimate interests in operating a professional resource library. We limit this processing to what is reasonably necessary for those purposes and do not use the information for a new, unrelated purpose without identifying an appropriate lawful basis and giving any notice required by law.
Marketing is separate. If you affirmatively check the optional marketing box, we record your choice, the date and time, and the exact version of the checkbox and form disclosure shown to you. We preserve the exact checkbox and form-disclosure text and a cryptographic fingerprint of that text so we can establish what choice was presented. Declining marketing does not affect access to the resource. Where GDPR applies, the lawful basis for marketing email is consent under Article 6(1)(a). You may withdraw that consent at any time through Alveary’s marketing-preference page, through the unsubscribe link in any marketing email, or by contacting support@alvearyos.com. The marketing-preference page is available without an Alveary account. Declining or withdrawing marketing consent does not affect access to a resource.
Alveary will not send marketing email to this resource audience unless, at minimum, the sending provider is accurately disclosed, a functioning unsubscribe process and the suppression controls described below are operational, each commercial message includes a valid non-residential physical postal address, and all other applicable marketing-law requirements are met.
If you do not choose marketing. We delete your identifiable resource-lead information 30 days after the resource request.
If you choose marketing. We keep your identifiable consented-resource-lead information for 24 months after your most recent affirmative marketing consent or affirmative renewed consent, unless you withdraw consent sooner. An email open, passive browsing, failure to unsubscribe, or continued presence in our records does not renew that period. Renewal requires another affirmative consent event. When the period expires, we stop marketing and delete the identifiable lead unless another lawful purpose independently requires particular information to be retained.
If you withdraw. We stop using the address for marketing, remove the identifiable lead from the normal marketing audience, and retain only the minimum suppression record needed to honor the withdrawal and demonstrate that we did so. That record contains a versioned, keyed one-way code derived from the email address, the key version, the date of suppression, the source or reason for suppression, and, where necessary, the applicable consent-copy version. It contains no plaintext email address, first name, role, property information, source route, campaign label, referring domain, or free-text note.
The suppression code remains pseudonymous personal information. We use it only to prevent the address from being added to marketing again and to demonstrate compliance; we do not use it to reconstruct a marketing profile. The lawful basis for this minimum suppression record is compliance with applicable marketing law and Alveary’s legitimate interest in honoring a person’s withdrawal and demonstrating that it did so. We keep the suppression record for as long as Alveary operates a commercial email-marketing program for which the address could otherwise be re-added, or until another reliable mechanism guarantees that the withdrawal will continue to be honored.
Where GDPR applies, the lawful bases for this minimum suppression record and privacy-request evidence are compliance with applicable legal obligations where those obligations apply, and Alveary’s legitimate interests in honoring a person’s choice, preventing accidental re-enrollment, demonstrating how a request was handled, and establishing, exercising, or defending legal claims. We do not rely on withdrawn marketing consent to keep these records.
Access, correction, restriction, and erasure. Depending on where you live and subject to applicable law, you may ask what resource-lead information we hold about you; ask us to correct it; ask us to restrict its use; or ask us to erase it. A request made using the work email address stored on the resource record is ordinarily sufficient for this limited dataset after we confirm control of that address. We do not rely only on an unverified sender address displayed in a message. If a request comes from another address, we do not disclose whether the target address has a record until ownership is reasonably verified. We may ask for the minimum additional information reasonably necessary if we have reasonable doubts about identity.
After verification, an access response includes the resources and versions requested, the personal fields supplied, consent state and consent history, source and campaign information still retained, and current marketing-suppression status. You may correct an inaccurate first name, role, property or portfolio information, or email address. An email-address change requires verification of the new address and, where reasonably available, the prior address.
When we honor an erasure request, we delete the identifiable resource-request records and any remaining row-level pseudonymous resource data that is no longer required, and we remove the person from any marketing audience. We retain only an active suppression record, minimal privacy-request evidence, and information another applicable legal exception requires us to retain. If the resource requester also has an Alveary account, an account-erasure request reaches the resource-lead information as well. Erasing a resource lead does not erase an independently existing Alveary account unless the person asks us to erase that account too.
Your right to object. Where GDPR applies and we rely on legitimate interests, you may object on grounds relating to your particular situation. We will stop the challenged processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed to establish, exercise, or defend legal claims. You may object to direct marketing or withdraw marketing consent at any time, and we will stop using your information for that purpose. A minimum suppression record may remain solely to honor that choice.
We retain the minimum event record of a completed access, correction, or erasure request for seven years after completion. A marketing-withdrawal record may remain longer while it serves as the active suppression record described above.
Aggregate statistics. Before deleting an identifiable resource-request row, we may include the event in separately held whole-number totals grouped only by resource, resource version, and calendar month or a longer reporting period. We keep a total only if, considering the information reasonably available to Alveary, it does not identify or reasonably permit anyone to single out a person. A total contains no email address, email digest, keyed code, exact request timestamp, source route, campaign or referral information, optional form field, or other row-level identifier. Low-volume totals are combined or withheld when necessary to meet that standard. We do not link these totals back to personal information or attempt to reidentify anyone from them. Totals meeting this standard may be retained separately after the person-level row is deleted. Information that does not meet this standard remains personal information and is deleted under the applicable period above.
Membership and billing
Your plan, subscription status, renewal date, and cancellation state, together with the identifiers Stripe uses for you as a customer. We also store the payment events Stripe sends us, which can include billing details Stripe chooses to include in them.
Card numbers never reach our servers. Payment details are entered on Stripe's own checkout pages and stay with Stripe.
We hold this to give you the access you paid for, to handle renewals and cancellations, and to keep the accounting records a business is required to keep. Lawful bases: contract for the access, legal obligation for the accounting records.
Kept for seven years from the end of the relationship, in line with tax and accounting record-keeping.
What you do in the Vault
Which standards you have unlocked, which you have saved, which you have downloaded and under what name, and which standards and versions you have opened. We record the version because a standard changes over time and "which one did they read" is a different question from "did they read it."
This runs the product — your permanent unlocks, your saved list, your download history. Basis: contract.
It also serves a second purpose described in the next section, and where the two purposes diverge, so does the retention period.
What you record in Comb Check
Comb Check lets you walk a set of standards and record, for each one, how your operation actually stands. We store the title and scope you chose, which property the check belongs to, who started it and when, and — for every standard in the check — the standard's code, the version you assessed against, your verdict of meets, gap, or not applicable, a severity from 1 to 3 where you record a gap, and any note you write.
We record the version for the same reason we record it elsewhere: standards change, and "we met the September text" is a different statement from "we meet the current one."
This runs the feature. Basis: contract.
Who can see it. A check you run for yourself is visible to you. A check you run against a property is visible to colleagues who hold a membership at that property, or at the organization above it — the same way access to a property's Vault content works. It is not visible to other customers. We do not publish your results, benchmark them, score you against anyone else, or disclose them to regulators, franchisors, brands, insurers, or any other third party. We do not report your gaps to anybody.
Notes are a free-text box, so please keep people out of them. A note reading "the annual drill was not logged" is a record about your operation. A note naming a colleague is a record about a person — and one you become responsible for. Describe the gap, not the individual.
Kept for as long as the account or the property the check belongs to exists. Close your account and your checks are deleted with it. Unlike the agreement records described next, self-assessments are not covered by the retention carve-out further down this notice, because they are not evidence of what you agreed to.
Beeline work records
When a property uses Beeline, Alveary processes operational work records on the property's behalf. Those records may concern guest needs, repairs, preventive-maintenance work, inspections, recurring work, or handoff issues. Depending on the work, the record may include a room, location or asset reference; ownership and routing information; completion and verification events; and the members who performed those acts.
Beeline is not an incident-reporting system. If a user reports that a guest or employee was harmed and takes the applicable harm fork, Beeline stops collecting the incident narrative and routes the matter to the property's configured process. The retained fork record is evidence that Beeline recognized and routed the report; it is not the property's incident, workers' compensation, medical, or investigation file.
Guest-request narrative and stay-reference information is reduced ninety days after the work item closes.
Remaining non-narrative guest-request information is retained for three years after the work item closes.
Non-guest work items and their completion or verification records are retained for three years after the work item closes.
Guest-harm and employee-harm fork evidence is retained for seven years after the applicable fork is taken. After the ordinary three-year work-item period expires, only the minimum non-narrative routing evidence remains: the work-item identifier, property, work type, which fork was taken and when, that Beeline stopped accepting the narrative, and where the matter was routed. For an employee-harm fork, the retained evidence may also identify the configured receiving role and whether the alert could be delivered under the property's configuration.
The seven-year fork record does not retain the guest's identity or stay reference, incident narrative, room or asset detail, employee-performance history, completion time, technician history, or other ordinary operational content merely because a harm fork occurred.
Beeline property configuration, including work catalogs, request categories, priority targets and routing contacts, is retained for the life of the applicable property relationship and then follows the termination treatment described in the Terms.
Where Beeline processes Guest Service Data for a customer, the customer is the controller or business and Alveary acts as its processor or service provider under the applicable Beeline Data Processing Addendum. The customer's own privacy, employment, safety, incident-reporting and record-retention obligations remain the customer's responsibility.
Valet and arrival records
Depending on the features enabled and used, Guard records a visit or demonstration identifier, the operator or program, vehicle make, model and color, license plate, VIN, parking and key-tag information, intake and return times, attendant or presenter identities, and handoff and retrieval events. A recorded attendant observation about visible valuables is separate from a guest's statement about valuables. A workflow may also record completion of the operator's valuables procedure. Describing a category here does not mean it is collected in every visit or demonstration.
When photographic capture is enabled and used, records may include photographs taken at intake and return of the vehicle's corners, wheels and visible condition, the VIN at the windshield or door label, and the keys. Records may include capture times, the capturing attendant and file fingerprints. The capture workflow is intended to minimize incidental images of people, interiors and neighboring vehicles. Original retained photographs are not overwritten; annotations and corrections are recorded separately. This workflow does not perform facial recognition, plate recognition or automated valuables inference. A photograph or timestamp does not itself establish responsibility for loss or damage.
At pickup, when handoff capture is enabled, Guard may record the guest's signature, its time and associated visit, or the attendant's entry that the guest declined to sign or was unavailable to sign. This is a handoff record, not enrollment in text messages.
Alveary demonstrations use simulated vehicle and service events. If a participant chooses to receive real demonstration texts, their mobile number, permission and confirmation events, replies and message delivery information are real personal information and follow the identity and text-consent schedules below. A demo label does not make that information anonymous or exempt it from those schedules. A demonstration does not require photographs of a participant's real vehicle, VIN, keys or signature.
Vehicle custody and claim-defense records: when collected and retained through an enabled operational workflow, kept for seven years after the valet transaction closes, when custody ends. These records include retained condition photographs, vehicle information, key records and handoff records. They support operations and the establishment, exercise or defense of claims. Seven years is Alveary's evidentiary standard, not a statement that every state's limitation period is seven years. A scoped legal hold may extend retention of relevant records.
Guest and demonstration participant identity: plaintext mobile number, guest last name and other transient messaging identity information are deleted thirty days after the associated visit or demonstration session closes, except particular information independently required for a claim or applicable hold. If identity is shared across associated active visits, the period begins when all those visits close. Closing an Alveary account is not the event that starts this transaction-based clock.
Text-consent evidence: kept for five years after the later of the date consent ceases to be operative or the last message sent in reliance on it. Evidence includes permission and confirmation events, exact script and message versions and fingerprints, operator or program, initiating attendant or presenter, dates, withdrawal where applicable and provider message identifiers where available. After the thirty-day identity period, the plaintext number is not kept merely to prove consent. Instead, the retained evidence contains a keyed code derived from the normalized number and the key version. This code is pseudonymous personal information; it can be compared with a number later supplied in a claim without retaining that number in plaintext.
Guard records are not used by Alveary to rank employees or produce employee-performance assessments. Possession of a phone or text thread alone does not authorize release of a vehicle. The operator remains responsible for custody and retrieval verification.
Agreement and acknowledgment records
When you activate your account or acknowledge a disclosure on a regulated standard, we record the fact of that agreement together with what you were actually shown. That record contains your account identifier, the name and email address as they stood at that moment, the date and time in UTC, the version of every document named on the screen, a cryptographic fingerprint of the text presented, and a reference to an archived copy of that screen. We also record the browser your request identified itself as, and a one-way hash of your IP address — we do not keep the address itself.
We keep these because Alveary needs to be able to establish, exercise, or defend legal claims about what was agreed and what was disclosed. Where GDPR applies, the basis is legitimate interests, documented separately — not your consent, and not the fact that you accepted our Terms.
Kept for seven years from the later of the date your account closes and the date your last subscription or license relationship ends. A legal hold suspends deletion until the hold is released.
Security and diagnostics
Ordinary technical records generated by our hosting and database providers when your browser talks to the service.
Used to keep the service available, to investigate faults, and to detect abuse. Basis: legitimate interests.
Kept for up to 30 days, after which they age out on our providers' own schedules. Where a record is part of an open security investigation we retain it until that investigation closes.
Text messages
Guard visits and demonstrations
Staff operational texting is described at SMS Terms. Guard texting is a separate, transaction-specific program for an actual valet visit or an identified Alveary demonstration session. The attendant or presenter first asks permission to send one property-neutral verification message. Only an affirmative YES to that message enrolls the number for further optional updates about that visit or session. Declining or not replying does not prevent use of valet service or participation in a demonstration. Guard consent is not consent to hotel, operator or Alveary marketing.
Messages may include check-in updates, retrieval-request acknowledgments and vehicle-ready notifications; vehicle events in demonstrations are simulated. Message frequency varies. Message and data rates may apply. Reply STOP to end optional messages from the service, or HELP for assistance. You may also use the valet stand or demonstration presenter, or contact support@alvearyos.com. Restarting carrier delivery does not replace confirmation for the current transaction or session. See Terms of Use, Valet and arrival services for Guard texting terms.
We do not sell mobile numbers or text-message opt-in information, and do not share them with third parties or affiliates for marketing or promotional purposes. Texting consent does not transfer to another operator or campaign. We disclose information needed to deliver and support the requested service to service providers such as Twilio acting for that purpose, and as required by law; those disclosures do not permit the recipients to use Guard opt-in information for their own marketing. The operator of an actual valet service receives information needed to run that visit. Alveary runs its own demonstration program.
Staff operational messages
Your mobile number. If you give us your mobile number and consent to receive text messages, we use it to send the operational messages described at alvearyos.com/legal/sms-terms — your work schedule, changes to it, offers of open shifts you may accept or decline, and notices about coverage at your property.
We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes. We provide your number to the messaging provider that delivers these messages on our behalf, for that purpose and no other.
Message frequency varies with your schedule and your property's operations. Message and data rates may apply.
How to stop. Reply STOP to any message and we stop. Reply HELP, or write to support@alvearyos.com, for help.
Who else handles your information
We use a small number of service providers, and they process your information on our instructions rather than for their own purposes:
| Provider | What they handle |
|---|---|
| Supabase | The database and the sign-in system |
| Resend | Delivering your sign-in links and account email |
| Vercel | Website hosting and delivery |
| Stripe | Payments, cards, invoices, and the billing portal |
| Google Workspace | The mailboxes you reach us at |
| Twilio | Delivering staff operational, guest valet and Alveary demonstration text messages |
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We run no advertising trackers in the Vault.
Deleting your account, and the part that survives
Ask us to delete your account and we delete your account: profile, saved list, unlock history, download history, memberships, self-assessments, and the sign-in identity itself.
What does not automatically disappear is the minimum record of what you agreed to and what you paid for. We are permitted to retain that to establish, exercise, or defend legal claims, and to meet accounting obligations. Retaining it is not us ignoring your request — it is the narrow carve-out the law provides for exactly this situation, and we hold it to the minimum the purpose requires.
What we do instead is put it beyond ordinary use. Retained evidence is moved into a restricted state where it cannot be used to run the product, to analyze behavior, to personalize anything, to market to you, or for any ordinary account operation. It is technically separated from the systems that serve the website, and it is not reachable from them. It sits there until its retention period expires, and then it is destroyed.
If you would like the specific detail of what was retained about you and why, ask and we will tell you.
Your rights
For requests involving an actual valet record, contact the operator or support@alvearyos.com. We will help route the request to the responsible operator as applicable. For an Alveary demonstration record, contact support@alvearyos.com directly. You may exercise applicable privacy rights without creating an Alveary account. Particular records may remain subject to the retention periods and scoped legal holds described above; where a request cannot be fulfilled in full, the response will explain the applicable limitation.
Depending on where you live, you may have the right to ask for a copy of the information we hold about you, to have it corrected, to have it deleted, to receive it in a portable form, to object to or restrict certain processing, and to withdraw consent to marketing at any time. We will not discriminate against you for exercising a privacy right. A request may affect a feature only where the information is reasonably necessary to provide that feature; if so, we will explain the effect. Declining or withdrawing marketing consent does not affect access to a resource.
Ask us at support@alvearyos.com and we will respond within the period the applicable law allows. If we have to decline part of a request — usually because of the retention carve-out above — we will tell you which part and why.
If you are in the UK or EEA, you may also complain to your national data protection authority. We would rather you came to us first, but that route is yours regardless.
Automated decisions, and children
Nothing in the Vault or Comb Check makes an automated decision about you that produces a legal effect or something similarly significant. Standards are reference material and a Comb Check score is arithmetic on answers you gave; the decisions stay with you and your organization.
The Vault is a professional tool for people working in hospitality and is not directed to children. We do not knowingly collect information from anyone under 16.
Changes to this notice
When this notice changes materially we will tell you, and the version and date at the top will change. Previous versions are retained, so it is always possible to establish which version was in force on a given date — the same discipline we apply to our Terms and to every standard in the library.