Privacy Policy
mrhost Co., Ltd. (猴思特股份有限公司) · Effective 8 October 2026
mrhost Co., Ltd. ("mrhost", "we", "us") provides revenue-management services to hotels and guesthouses. This Privacy Policy explains how we collect, use, disclose and protect personal data when you visit our websites (mrhost.com.tw and its subdomains, including the owner portal at signup.mrhost.com.tw and the revenue-management console at staff.mrhost.com.tw) or use our services. Where our service agreement with your property says something more specific about your property's data, the service agreement applies.
1. Personal data we collect
1.1 Personal data you provide to us
- Account information. When you sign in to the owner portal with Google, Google sends us the email address and the account identifier of the Google account you chose. We never receive your Google password, and we do not request your name or profile photo. When you sign in by email link, we collect the email address you enter.
- Enquiry and consultation information. When you fill in a consultation or diagnostic form, we collect what you enter: name, phone number, messaging app ID, property name and type, number of rooms, website, country or region, and your message.
- LINE account linking. When you link a LINE account to your property, we collect the LINE user identifier of that account so our AI concierge can recognise you as the owner, together with the messages you exchange with us on LINE.
- Property and business data. Rates, inventory, bookings, channel settings and similar information about your property that you give us, or that we receive on your behalf from booking platforms, under our service agreement.
- Payment information. Payments are processed by licensed payment providers. We do not store full card numbers; we keep only what the provider returns to us, such as a transaction reference and the last four digits of a card.
1.2 Personal data we receive automatically
- Log data. IP address, browser type and settings, device information, the date and time of your request and the pages you viewed.
- Sign-in and security events. The time, IP address and browser of each sign-in to the owner portal, successful or not, so that we can detect misuse.
- Cookies and similar technologies. Cookies that keep you signed in and protect our forms (Cloudflare Turnstile), and advertising measurement tags (Meta Pixel) on our marketing landing pages. See section 5 for your choices.
1.3 Personal data we receive from other sources
- Google, when you choose to sign in with Google (see 1.1).
- LINE, when you message us or link a LINE account.
- The booking platforms we operate for your property under the service agreement, which send us bookings and availability.
- Advertising platforms, which tell us which campaign brought you to our site.
2. How we use personal data
- To provide, operate and improve the revenue-management service you signed up for.
- To let you sign in securely, keep your account safe and detect fraud or misuse.
- To communicate with you: replying to enquiries, sending sign-in links and invitations, and sending service notices.
- To measure and improve our websites, services and advertising.
- To comply with legal obligations, including accounting and tax law, and to protect our rights.
3. Disclosure of personal data
We do not sell your personal data. We disclose it only in these cases:
- Service providers that process data for us under contract: Google (sign-in and email), LINE (messaging), Meta (advertising measurement), Cloudflare (security and delivery), payment providers and cloud hosting providers.
- Booking platforms that we operate on your behalf under the service agreement.
- Legal requirements: when the law, a court or a competent authority requires it, or to protect the rights, safety or property of mrhost, our customers or others.
- Business transfers: if mrhost is involved in a merger, acquisition or sale of assets, personal data may be transferred as part of that transaction, subject to this policy.
4. Retention and security
We keep account and property data for the duration of our service agreement and afterwards for as long as the law requires. Sign-in and security records are kept for a limited period and then deleted. Enquiry data is kept until the enquiry is closed and for a reasonable follow-up period, unless you ask us to delete it earlier. We protect personal data with access controls, encryption of credentials and logging, but no method of transmission or storage is completely secure.
5. Your rights and choices
Under Taiwan's Personal Data Protection Act you may ask us to let you access, copy, correct or supplement your personal data, to stop collecting, processing or using it, or to delete it. You may also:
- remove a linked LINE account yourself in the owner portal, or ask us to unlink your Google account;
- decline marketing communications at any time;
- block or delete cookies in your browser (some features, such as staying signed in, will then not work).
To exercise these rights, contact us as described in section 9. We may need to verify your identity first, and some data may have to be retained where the law requires it.
6. International transfers
mrhost is based in Taiwan. Some of the service providers listed in section 3 store or process data outside Taiwan (for example in the United States or Japan). We rely on our contracts with those providers and on their security commitments to protect your data wherever it is processed.
7. Children
Our websites and services are intended for business owners and are not directed at children under 18. If you believe a child has given us personal data, please contact us and we will delete it.
8. Changes to this policy
We may update this policy from time to time. We will publish the new version on this page with a new effective date; for significant changes we will also notify owners through the owner portal or by email.
mrhost Co., Ltd. (猴思特股份有限公司), Taiwan
Email: [email protected]
Or use our contact page.