Last updated: September 2, 2026
Sumi ("we", "our", or "us") operates an AI-powered guest communication platform for hotels and hospitality businesses. This Privacy Policy explains how we collect, use and protect information when hotels use our service and when hotel guests interact with our system via WhatsApp, Facebook Messenger, Instagram or other messaging channels.
Our service integrates with the WhatsApp Business API via Meta. Messages sent to a hotel's WhatsApp number are received by our platform and processed by our AI. We comply with Meta's Platform Terms and Messaging Policies. Guest phone numbers and message content are stored securely and used solely to operate the hotel's communication service.
Hotels can connect their Facebook Page and the Instagram professional account linked to it so that Sumi answers Messenger and Instagram direct messages. When a hotel does this, Meta sends us the messages guests write to that Page or account, together with the guest's page-scoped or Instagram-scoped user ID and the name and profile picture Meta makes available for messaging. We use this data only to answer the guest on behalf of the hotel, to show the conversation to hotel staff in the dashboard, and to hand the chat to a staff member when needed.
Replies that hotel staff send from the Facebook or Instagram apps are also delivered to us so that Sumi can pause its automatic replies on that chat. We store the access token Meta issues for the hotel's Page, encrypted at rest, and use it solely to read and send messages for that Page and account. Disconnecting Messenger in the Sumi dashboard deletes the token and stops all further data flow.
We comply with Meta's Platform Terms and Developer Policies. Messenger and Instagram data is never used for advertising, never sold, and never used to train models. Guests and hotels can request deletion of this data at any time; see our data deletion instructions.
We do not sell personal data. We share data only:
Conversation history is retained for as long as the hotel account is active. Hotels may request deletion of guest data at any time via the dashboard or by contacting us. Guest data is deleted within 30 days of a valid deletion request. Step-by-step instructions are on our data deletion page.
We use industry-standard security measures including encryption in transit (TLS), encrypted storage and access controls. WhatsApp message signatures are verified using Meta's HMAC protocol on every request.
Hotel guests who wish to access, correct or delete their personal data should contact the hotel they communicated with directly, as the hotel is the data controller for guest conversations. Hotels may contact us to action these requests. Guests may also write to us directly using the data deletion instructions.
Our hotel dashboard uses session cookies for authentication. We do not use tracking or advertising cookies.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date. Continued use of the platform after changes constitutes acceptance.
For privacy questions or data requests, contact us at privacy@getsumi.co.