FluxPMS Privacy Policy

Effective Date: July 26, 2026

1. Who this policy covers

This Privacy Policy explains how FluxSoft Technologies, LLC ("FluxSoft", "we", "us") collects, uses, and protects information in connection with FluxPMS, our cloud property management system for hotels, hostels, and other lodging businesses.

FluxPMS is used in two ways, and this policy covers both:

  • You are a hotel signing up for FluxPMS. We collect your account, billing, and hotel details to provide the Service to you.
  • You are a guest of a hotel that uses FluxPMS. The hotel enters or collects your booking information in the system. In that relationship, the hotel is the data controller and FluxSoft is the data processor — we hold and process guest data on the hotel's instructions, under a data processing agreement with that hotel. Requests about a specific booking (access, correction, deletion) should go to the hotel first; we support the hotel in fulfilling them.

2. Information we collect

Account & billing information (from the hotel signing up): name, email, phone (optional), hotel/business name, hotel city and country, and billing details. Payment is handled by Stripe — we do not store your card number on our own systems.

Hotel operating data (entered by the hotel or its staff): property, room, and rate configuration; booking and reservation records; guest names, contact details, and stay information; payment and transaction records tied to bookings; staff accounts and permissions.

Usage data: standard web/application logs — IP address, browser/device type, pages requested, timestamps, and error logs — collected for security, debugging, and reliability.

Product analytics: we track feature usage and page views within FluxPMS itself (self-hosted, first-party) to understand what's working and fix what isn't. We do not use third-party advertising trackers or sell this data.

Email engagement: transactional and marketing emails we send may include an open/click tracking pixel or link, so we know an email was delivered and read. You can opt out of marketing email at any time via the unsubscribe link in the email; you cannot opt out of essential transactional email (receipts, security notices) while your account is active.

Cookies: we use a session cookie and a CSRF (security) cookie required for the site and app to function, and a small browser-local preference that remembers whether you accepted or declined our cookie banner. We do not use third-party advertising cookies.

3. How we use information

  • Operate and provide the Service you or your hotel signed up for
  • Process payments and manage your subscription (via Stripe)
  • Send transactional email (receipts, confirmations, security alerts)
  • Provide support when you contact us
  • Monitor for abuse, fraud, and security issues
  • Improve the product based on aggregate usage patterns
  • Comply with legal obligations (e.g., tax and accounting records)

We do not use your data, or your guests' data, to train third-party AI models, and we do not sell personal information to anyone.

4. Where data is processed and stored

FluxPMS is hosted on infrastructure in Germany, within the EU (Hetzner). Application sessions and cache are held in Redis; uploaded files (logos, documents, guest ID scans if a hotel chooses to store them) are held in MinIO object storage — both on the same EU infrastructure. Our network sits behind Cloudflare for DDoS protection and content delivery; Cloudflare may see connection metadata (like your IP address) as part of routing traffic to our servers.

If you are located outside the EU, using FluxPMS means your data is transferred to, and processed in, the EU.

Sub-processors we use:

Provider Purpose Location
Hetzner Server hosting Germany (EU)
Stripe Payment processing USA
Cloudflare CDN / DDoS protection Global network

We do not currently use any other third-party service that receives personal data from FluxPMS.

5. Data ownership and your rights

Hotel operating data belongs to the hotel that entered it. We process it as a processor, under the hotel's instructions, and we do not use it for any purpose other than providing the Service, unless the hotel asks us to.

Subject to that, and to the extent the law gives you rights over your own data (as an account holder or as a guest), you can ask us to:

  • Access a copy of the personal data we hold about you
  • Correct inaccurate data
  • Delete your data, subject to what we and the relevant hotel are required to keep for accounting, tax, or fraud-prevention purposes
  • Export your data in a portable format
  • Object to certain processing, or withdraw consent where we rely on it

To exercise any of these, email [email protected]. We will respond as promptly as we can, and in any event within the time required by applicable law. If you're a guest asking about a specific stay, we may direct you to the hotel first, since they control that booking record.

6. How security actually works today

We want this section to be accurate rather than reassuring, so here is what we do, plainly:

  • All traffic to FluxPMS travels over HTTPS/TLS — nothing is sent in the clear.
  • Each hotel's data is logically isolated at the application layer: every database query FluxPMS runs is scoped to the requesting hotel's tenant ID, so one hotel's staff cannot see another hotel's bookings, guests, or payments through the product.
  • We run regular backups of the database and retain them under our internal backup policy.
  • Access to production servers and infrastructure is restricted to authorized FluxSoft personnel.

What we don't claim: we are not SOC 2 or ISO 27001 certified, we do not currently guarantee database-level encryption at rest, and no system — ours included — is unbreakable. If you have specific security or compliance requirements for your hotel group, contact us before signing up and we'll tell you plainly what we can and can't support today.

7. Data retention

We keep hotel operating data for as long as the hotel's account is active. If an account is cancelled, we aim to delete the underlying data within a reasonable period afterward, though a copy may remain in encrypted backups for a limited time until those backups age out naturally. Billing and transaction records may be kept longer where we're required to for tax or accounting purposes.

8. Children

FluxPMS is a business tool for hotel operators, not intended for use by individuals under 18. Guest records entered by a hotel (including, where relevant, minors staying at a property) are the hotel's data, handled under their instructions as described in Section 1.

9. Automated decisions

We do not make fully automated decisions about you that have a legal or similarly significant effect, without a human able to review them.

10. Changes to this policy

If we make a material change to this policy, we'll update the effective date above and, where practical, notify account holders by email. Continuing to use FluxPMS after a change means you accept the updated policy.

11. Contact

FluxSoft Technologies, LLC 131 Continental Dr, Suite 305 Newark, Delaware 19713, USA

Privacy requests: [email protected] Website: https://fluxpms.com


Controlling language: This document is also published in other languages for convenience. If there is any conflict or inconsistency between translations, the English-language version controls.

This policy works alongside our Terms of Service.