Last updated: July 21, 2026
HotelOil ("Hoteloil," "we," "us," or "our") is a hotel digital advertising analytics and marketing platform operated by Reviewstay, LLC. This Privacy Policy explains how we collect, use, disclose, and protect information when you use hoteloil.com, our web application, APIs, Folio public hotel sites, and related services (collectively, the "Service").
By creating an account or using the Service, you acknowledge that you have read this Privacy Policy. If you do not agree, please do not use the Service.
This policy applies to HotelOil Pro (analytics dashboard), HotelOil Autopilot (managed advertising services), Folio (hotel website builder and social publishing), team workspaces, and optional integrations you connect, such as advertising platforms, calendar and notification services, and social networks.
ReviewStay and SMS RS are separate products in the Reviewstay family. When you connect ReviewStay to a hotel workspace, we process only the review and reputation data needed to display that integration inside HotelOil and Folio.
When you register, we collect information such as your name, email address, authentication credentials, and account preferences. If you join a team workspace, we also store your role, permissions, and membership status.
To provide analytics, reporting, and Autopilot services, we process hotel performance data you upload or connect, including campaign metrics, spend, revenue, pace reports, and custom data sources (for example, Expedia, Booking.com, Koddi, and other channels you configure). This may include property names, campaign identifiers, dates, and financial metrics contained in your files or connected sources.
Paid subscriptions are processed by Stripe. We receive billing status, plan identifiers, invoice references, and limited payment metadata from Stripe. We do not store full credit card numbers on our servers.
If you use Folio, we store site configuration, page content, media, domain settings, event listings, geo content, and other materials you publish to your hotel's public site.
We automatically collect technical information when you use the Service, such as IP address, browser type, device identifiers, pages viewed, timestamps, referral URLs, and error logs. We use this data to operate, secure, and improve the Service.
If you contact us, we retain the content of your messages and any information you choose to provide so we can respond and maintain support records.
We use the information we collect to:
We do not sell your personal information. We do not use hotel analytics data or connected account data for third-party advertising.
Where applicable under data protection laws such as the GDPR, we process personal data based on: (a) performance of our contract with you; (b) your consent (for example, optional analytics cookies or third-party connections you authorize); (c) our legitimate interests in operating and securing the Service; and (d) compliance with legal obligations.
We share information only as described below:
Our infrastructure and operations rely on third-party processors, including Supabase (database and authentication), Vercel (application hosting), Stripe (billing), Resend (transactional email), Sentry (error monitoring), and OpenAI (in-app documentation assistant). We configure these services to access only the data necessary for their function.
When you connect Google Calendar from Notifications settings, HotelOil uses Google's OAuth 2.0 service with the calendar.events scope. We use this access solely to create and update calendar events you configure through notification rules—for example, daily HotelOil metric digests, Autopilot invoice due dates, or Folio event alerts.
We store an encrypted OAuth access token and refresh token, the Google account's selected calendar identifier, and a display name for your connection. During setup we may read your calendar list so you can choose which calendar receives events. We do not read, export, or sell the contents of your existing calendar events for advertising or unrelated purposes.
You can disconnect Google Calendar anytime from Notifications in your account, or revoke access from your Google Account permissions. Disconnecting removes stored tokens and connection metadata from HotelOil.
When you connect Outlook Calendar, HotelOil uses the Microsoft Graph API with delegated permissions to read your profile (User.Read), maintain offline access (offline_access), and create or update events on calendars you can access (Calendars.ReadWrite). We use this access only to add or update calendar events for notification rules you configure in HotelOil.
We store an encrypted OAuth access token and refresh token, the selected Outlook calendar identifier, and a display name for your connection. We do not read your email, contacts, or unrelated Microsoft 365 data, and we do not sell Microsoft account data or use it for advertising.
You can disconnect Outlook anytime from Notifications in your account, or revoke HotelOil's access from your Microsoft account app permissions. Disconnecting removes stored tokens and connection metadata from HotelOil.
When you connect Slack from Notifications settings, you may authorize HotelOil via Slack OAuth or provide an incoming webhook URL. With OAuth, we request permission to post messages and to list channels you can target (chat:write, channels:read, groups:read). With a webhook, you supply a URL that posts to a workspace channel you configure in Slack.
We store an encrypted OAuth token or webhook URL, your selected Slack workspace and channel identifiers where applicable, and a display name for the connection. We use Slack only to deliver notification messages you enable—for example, HotelOil metric digests, Autopilot billing alerts, or Folio event updates. We do not read your Slack message history, direct messages, or files, and we do not sell Slack data or use it for advertising.
You can disconnect Slack anytime from Notifications in your account, remove the incoming webhook, or revoke the app from your Slack app management settings. Disconnecting removes stored tokens, webhook URLs, and connection metadata from HotelOil.
When you connect Meta properties for Folio social publishing, HotelOil uses Meta's APIs to publish content you authorize and to store connection metadata (OAuth tokens, page or profile identifiers, and display handles). We do not read your personal feed, direct messages, or unrelated Meta data, and we do not sell Meta account data or use it for advertising.
You can disconnect Meta anytime from Folio social settings or remove HotelOil from your Meta account under Facebook Settings → Apps and Websites. Meta may notify us via our data deletion callback when you remove the app; see Data deletion status for details.
When you connect a LinkedIn account, HotelOil uses LinkedIn's Marketing and Share on LinkedIn APIs solely to publish content you authorize and to display your account name. We store your OAuth access and refresh tokens, LinkedIn member or organization identifiers, and handles. We do not read your personal feed, connections, or messages, and we never sell LinkedIn data or use it for advertising.
LinkedIn tokens are used only to post on your behalf and are retained until you disconnect. You can revoke HotelOil's access anytime from LinkedIn Settings → Data privacy → Permitted services, or from within HotelOil under Folio → Social → Disconnect.
When you connect an X account for social publishing, HotelOil stores encrypted OAuth tokens and account identifiers needed to publish posts you schedule or approve. We do not read your direct messages, timeline, or unrelated X data, and we do not sell X account data or use it for advertising. You can disconnect X anytime from Folio social settings or revoke the app from your X account settings.
You can remove HotelOil from your Meta account in Facebook Settings → Apps and Websites. Meta will notify us via our data deletion callback and we will delete stored OAuth tokens, handles, and external account identifiers for your Meta social connections.
After submitting a deletion request through Meta, you can check status using the confirmation code at /data-deletion.
Hotel team admins can also disconnect social platforms anytime under Folio → Social → Disconnect.
We retain information for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. When you delete your account or disconnect an integration, we delete or anonymize associated data within a reasonable period, except where retention is required by law or legitimate business needs (such as billing records).
We implement administrative, technical, and organizational measures designed to protect information, including encryption of OAuth tokens, role-based access controls, and row-level security on workspace data. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to or withdraw consent for certain processing. You can update account settings in the Service, disconnect integrations, manage cookie preferences per our Cookie Policy, or contact us to exercise your rights.
If you are in the European Economic Area or United Kingdom, you may lodge a complaint with your local data protection authority.
HotelOil is operated from the United States. If you access the Service from other regions, your information may be transferred to, stored in, and processed in the United States and other countries where our service providers operate. We take steps designed to ensure appropriate safeguards for such transfers where required by law.
The Service is intended for business users and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe we have collected such information, please contact us so we can delete it.
We may disclose account data where required by valid legal process from a public authority, such as a subpoena, court order, or warrant. We review the legality of each request, challenge requests we consider unlawful, disclose only the minimum information necessary, and document each request and our response.
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the "Last updated" date. Material changes may also be communicated by email or in-app notice where appropriate.
For privacy or data deletion questions, contact Reviewstay, LLC at reports@hoteloil.com.