Privacy
This website collects almost nothing.
Two different things get called privacy on a site like this: what happens when you read these pages, and what happens to a hotel guest’s data inside the product. They are separate, and this page covers both in that order.
- No cookies set by us
- No analytics or tracking scripts
- Hosted in the EU
This website
What we do and do not collect here
- No cookies
- These pages set no cookies. There is no consent banner because there is nothing to consent to — which is the correct reason not to have one.
- No analytics
- No Google Analytics, no tag manager, no session recording, no advertising or social pixels. We do not know which pages you read or how long you spent here.
- No third-party embeds
- Nothing on these pages loads from a service that would see your address as a side effect. Typefaces are served from the same place as the site.
- Server logs
- Our host records ordinary request logs — the page requested, a timestamp, a user agent and an IP address — for operating and securing the service. They are kept briefly and are not used to build a profile of you.
- If you email us
- Writing to hello@mpify.com means we hold your message and your address for as long as we are talking, and afterwards for our own records. We do not add you to a mailing list, and there is no drip sequence.
Inside the product
Guest data belongs to the hotel
When a property runs Experience 360, that property is the controller of its guests' data and we are the processor. We act on their instructions.
Guest records — a name, a room, the dates of a stay, orders placed, messages sent — are stored in Frankfurt, in the European Union. Each property’s data is isolated from every other property’s by policies applied inside the database on every query, not by application code that has to remember.
Each property agrees a retention window with us, after which guest personal data is purged automatically. A guest can be erased on request: their personal data goes and the operational record — that an order happened and what it cost — remains without them attached to it.
Where a property collects identity or passport details to meet a local legal requirement, those are encrypted at rest and carry the shortest retention of anything in the system.
Guest data is not used to train models, is not sold, and is not pooled across properties. A guest at one hotel is not joined to a guest at another.

Notifications
What a push message contains
A notification carries only the words to show and where to go — no order contents, no guest name and no room number. It travels through Apple’s or Google’s push service and arrives on a lock screen that may be read by anyone standing nearby, so anything private is fetched behind the session when the guest taps through.
A guest is asked for browser permission before anything can be sent, and can withdraw it at any time in their own browser settings. Promotional messages are capped per guest per day across the whole property.
Your rights
Asking us anything
If you are a guest of a hotel that uses Experience 360, your first contact is that hotel, because it is their data and their decision. If it is easier to reach us, write to hello@mpify.com and we will pass it on and help them answer it.
Under the GDPR you may ask for a copy of your data, ask for it to be corrected or erased, object to processing, or complain to your national data protection authority. In Malta that is the Office of the Information and Data Protection Commissioner.
“These pages set no cookies, so there is no consent banner — which is the correct reason not to have one.”
Changes
If this page changes
We will update it here. If a change is material for a property running the product, it reaches them through their data processing agreement rather than by being quietly edited on a website.