0

Cloudbeds Integration Privacy Notice

This Privacy Notice explains how PayNow (“PayNow”, "PayNowSolution", “we”, “us”, “our”) processes personal data when a property connects and uses our Cloudbeds integration.

This notice applies only to the Cloudbeds integration. For general information about how we process personal data on our website, please see our main Privacy Policy:
https://www.paynowsolution.com/en/privacy-policy/

1. Who we are

This Privacy Notice applies to the processing of personal data in connection with ARRIVAL SAFE through Cloudbeds.

PAYNOW TRAVEL CARE S.L.U.
NIF: B70908363
Calle Domingo J. Navarro 1
35002 Las Palmas de Gran Canaria, Spain
Email: info@paynowsolution.com

 

2. What the Cloudbeds integration does

The Cloudbeds integration allows hospitality properties to offer and resell Arrival Safe through Cloudbeds rate plans, packages, add-ons, or similar Cloudbeds configuration options.

The Arrival Safe service is a travel assistance and claim handling service. If an eligible guest misses the first hotel night because of a sudden and unjustified flight cancellation, PayNow may advance the related first-night hotel cost up to EUR 200, within 96 business hours, subject to the applicable service terms.

The service may also include airline claim handling with no commission and free legal assistance, subject to eligibility and applicable terms.

The service is not an insurance policy or insurance product.

3. Our role under GDPR

Depending on the processing activity, PayNow may act as:

  • data processor, when we process Cloudbeds reservation data on behalf of the property and under the property’s instructions;
  • independent data controller, when we process personal data to activate and manage the service, handle claims, provide assistance, prevent fraud, comply with legal obligations, manage accounting, or defend legal claims.

Where required, PayNow and the property enter into appropriate data protection terms or a Data Processing Agreement.

4. Personal data we process

Through the Cloudbeds integration, we may process the following categories of personal data:

  • Property data: property name. property address, property contact details, Cloudbeds property ID, integration settings.
  • Reservation data: reservation ID, booking date, check-in and check-out dates, reservation status, room, rate plan, package, add-on, or item information, booking value or service-related amount, where needed.
  • Guest data: guest name and surname, email address, phone number, where available, country or nationality, where available, stay details linked to the service.
  • Service data: service activation status, case or claim ID, service notes, eligibility status, links or documents related to the service, operational updates written back to Cloudbeds.
  • Claim and travel disruption data, where provided: flight details, flight cancellation or disruption proof, booking confirmations, receipts, invoices, or payment evidence, communications with airlines or travel providers, documents needed to assess or manage the claim.
  • Technical data: API logs, webhook logs, timestamps, error logs, connection status, IP address or user agent where relevant for security and troubleshooting.

We do not intentionally request special categories of personal data unless strictly necessary for a specific service request, legal requirement, or claim handling activity.

5. How we collect data

We may collect personal data:

  • from Cloudbeds, when the property authorizes our app;
  • from the property;
  • directly from the guest, when the guest submits information or documents related to the service;
  • from airlines, travel providers, legal partners, or advisors, where needed to handle the claim;
  • from our systems when the integration is used.

6. Why we process personal data

We process personal data for the following purposes:

  • to connect PayNow with Cloudbeds;
  • to identify the property and manage integration settings;
  • to detect whether the Arrival Safe service was included or purchased in a reservation;
  • to activate and manage the service;
  • to communicate with the property;
  • to communicate with the guest where required for the service;
  • to manage airline claim handling;
  • to provide legal assistance where applicable;
  • to write operational information back to Cloudbeds, such as service status, case ID, notes, links, or documents;
  • to provide support and troubleshooting;
  • to prevent fraud, abuse, or misuse;
  • to ensure security and reliability of the integration;
  • to comply with legal, tax, accounting, and regulatory obligations;
  • to establish, exercise, or defend legal claims.

7. Legal bases

Depending on the processing activity, we rely on one or more of the following legal bases under the GDPR:

  • performance of a contract or pre-contractual steps;
  • legitimate interests, including providing and securing the service, supporting properties, preventing fraud, and managing claims;
  • legal obligations, including accounting, tax, compliance, and regulatory obligations;
  • consent, where required by law or where the guest voluntarily provides optional information for a specific claim.

8. What we write back to Cloudbeds

When the service is detected, activated, updated, cancelled, or completed, PayNow may write operational information back to Cloudbeds, such as:

- service status;
- case or claim ID;
- operational notes;
- links to service information;
- documents related to the service;
- cancellation or update status.

This information is written only where needed to help the property manage the reservation and service.

9. Data sharing

We may share personal data with:

  • the property that enabled the Cloudbeds integration;
  • Cloudbeds, through the integration;
  • airlines or travel providers, where needed for claim handling;
  • legal partners, lawyers, or advisors, where needed for legal assistance;
  • IT, hosting, cloud, email, CRM, help desk, analytics, logging, and security providers;
  • accounting, billing, or administrative service providers;
  • public authorities, courts, regulators, or law enforcement bodies where legally required.

Where our service providers act as data processors, they process personal data only under our instructions and subject to appropriate confidentiality and security obligations.

10. International transfers

Where personal data is transferred outside the European Economic Area, we use appropriate safeguards required by the GDPR, such as adequacy decisions, European Commission Standard Contractual Clauses, or other lawful transfer mechanisms.

11. Retention

We keep personal data only for as long as necessary for the purposes described in this notice.

In general:

  • integration and API logs are kept only for the period necessary for security, troubleshooting, and audit purposes;
  • reservation and service activation records are kept for the duration needed to provide the service and manage related obligations;
  • claim files are kept for as long as needed to handle the claim, comply with limitation periods, and defend legal rights;
  • accounting and tax records are kept for the period required by applicable law;
  • support communications are kept for as long as needed to handle the request and maintain service records.

When personal data is no longer needed, it is deleted, anonymized, or securely archived according to our internal retention rules and legal obligations.

12. Security

We apply appropriate technical and organisational measures designed to protect personal data, including access controls, secure credential storage, logging, encryption where appropriate, confidentiality obligations, and restricted access to production systems.

13. Property responsibilities

The property is responsible for informing guests that the Arrival Safe service is offered and that relevant reservation and service data may be processed for service activation, claim handling, support, and related purposes.

The property should ensure that its own privacy notice and guest-facing terms correctly describe the service and the related data processing.

14. Cloudbeds connection and disconnection

When a property connects PayNow through Cloudbeds, Cloudbeds may provide PayNow with access to the data authorized by the property through the selected permission scopes.

If the property disconnects the app, PayNow will no longer receive new Cloudbeds data for that property. Existing service cases activated before disconnection may still be processed where necessary to complete the service, manage claims, comply with legal obligations, or resolve disputes.

15. Your rights

Under the GDPR, individuals may have the right to:

  • access their personal data;
  • request correction of inaccurate data;
  • request deletion;
  • restrict processing;
  • object to processing;
  • request data portability;
  • withdraw consent, where processing is based on consent;
  • lodge a complaint with a competent data protection authority.

Requests can be sent to: privacy@paynowsolution.com

If we process personal data as processor on behalf of a property, we may need to forward the request to the property or handle it according to the property’s instructions.

16. Changes to this notice

We may update this Cloudbeds Integration Privacy Notice from time to time. The latest version will always be available on this page.

17. Contact

For privacy questions or requests, please contact: privacy@paynowsolution.com

Visa Mastercard Amex JCB Discover Apple Pay Google Pay
Stripe
made by