OTA Systemsby Multisystems
Legal · Privacy

Privacy policy

How we collect, use, store, and share data for OTA Systems — the commission-reclaim and multi-OTA operations platform by Multisystems.

Last updated: August 18, 2026

1. Who this covers

This policy covers otasystems.ai, live.otasystems.ai, and every Multisystems account that accesses OTA Systems features. It does not cover sibling Multisystems products (ImageSystems, ReputationSystems, HotelSystems) — those have their own policies linked from their sites.

2. Data we collect from you directly

  • Account data. Name, email, phone, hotel/property name and address, role, billing address, payment method.
  • Property configuration. Expedia HTID, Booking.com chain IDs, PMS login credentials, rate-shopper login credentials (all encrypted at rest with AES-256).
  • Messages you send us. Support tickets, demo form submissions, in-app chat.

3. Data we read on your behalf

When you share credentials for an external system, we read data from that system strictly to power the features you enabled. We do not write back unless you explicitly ask us to.

  • Expedia Partner Central. Reservation records (guest name, email, check-in/out, amount, commission), rate records, invoice PDFs.
  • Booking.com Extranet. The same reservation stream.
  • Your PMS. Folio line items, housekeeping status, cancellation metadata. Read-only.
  • Your rate shopper (if connected). Competitor rate snapshots; no property-identifying data written back.

4. How we use the data

We use your data to:

  • Run the reclaim workflow (identify eligible commission, compute the dollar amount, pre-assemble dispute packages).
  • Show you the multi-OTA operations console and per-property analytics.
  • Train property-specific rate-recommendation models — never across properties or customers.
  • Send transactional emails (billing receipts, claim-deadline reminders, product updates).
  • Answer support requests and troubleshoot connection issues.

We do not use your data to train general-purpose AI models, sell anonymised data to third parties, or enrich any external database.

5. Who we share it with

Only with subprocessors under written DPAs, and only to the minimum extent needed to run the service (hosting, email delivery, error reporting, analytics). A current subprocessor list is available on request — email legal@multisystems.ai. We share no data with advertisers, data brokers, or AI-training datasets.

Law-enforcement requests are reviewed by counsel; we require valid legal process and we notify you unless legally prohibited.

6. How long we keep it

  • Account data: for the life of your subscription + 90 days after cancellation.
  • Reservation and reclaim records: for 7 years (US IRS audit window) unless you request earlier deletion.
  • Support tickets: 2 years for quality assurance.
  • Aggregated, de-identified metrics: retained indefinitely (no personal data).

7. Your rights

Depending on your location (GDPR for EU/UK, CCPA/CPRA for California, and equivalent laws elsewhere) you can request access to, correction of, or deletion of your personal data. Contact privacy@otasystems.ai. We respond within 30 days.

8. SMS & Text Messaging

When you provide your telephone number in a form on our website and check the SMS consent box, you consent to receive calls and text messages from Multisystems related to your inquiry, demo scheduling, and account or service notifications. Providing a phone number and consenting to messages is always optional and is never a condition of purchasing any product or service. Message frequency may vary, and message and data rates may apply.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are never sold, rented, or shared with any third party.

You can opt out at any time by replying STOP to any message from us, and reply HELP for assistance. Opt-in and opt-out are both handled on the same phone number our messages are sent from. You may also contact privacy@otasystems.ai to withdraw consent.

9. Security

All credentials are encrypted at rest (AES-256). All traffic in transit uses TLS 1.3. Infrastructure runs on SOC 2-compliant cloud providers. Engineering access to production data is logged, reviewed, and audited quarterly. We run incident-response drills twice a year.

10. Contact

Privacy questions: privacy@otasystems.ai. General: hello@otasystems.ai.

Note on legal review.This document is the product team's working draft pending Multisystems legal review. Final language may change before our public launch. If you're reviewing us for a procurement decision, email legal@multisystems.ai for the ratified version.