BookingDesigner connector privacy policy
What data the BookingDesigner MCP connector processes when you connect it to Claude, ChatGPT or another assistant, why, who receives it and how long we keep it.
Last updated: September 28, 2026. This page supplements the BookingDesigner privacy policy, which still applies to the rest of the service.
Who processes the data
The connector is part of BookingDesigner, a service of I/O NET S.r.l., via Racale 90, 73040 Melissano (LE), Italy, VAT IT04864110756.
- Booking and guest data. The controller is the accommodation business that is a BookingDesigner customer. I/O NET processes this data on its behalf, as a processor, under the BookingDesigner terms of service. The property decides whether to enable the connector, for which people and with which data areas.
- Connector usage data (described below, in What we record). I/O NET processes it to provide, secure and measure the service.
How it works
An authorized person connects their assistant to the connector and consents, with their BookingDesigner account, on a page that lists properties and data areas. From then on, when the person asks a question, the assistant calls one of the connector's tools, for example “occupancy for August”. The connector returns the requested data and the assistant uses it to answer.
The connector does not receive the conversation. For each call it only receives the tool name and its arguments: dates, properties, options such as “by channel”. It does not read the assistant's messages, history, memory or files.
What data it returns to the assistant
- By default, aggregates only. Occupancy, ADR, RevPAR, production, channels, requests and conversions, guest origin and age by group: numbers, not people.
- Personal data, only if the administrator grants it. The Bookings by name and Notes areas are off by default and are turned on per person. They include the booking name, room, room type, board, dates, number of guests, channel and stay total; for birthdays, the guest's name and the age they turn, only from age 14 up: for younger guests only the number of birthdays per day is returned, with no name or room; and, with the Notes area, the booking notes, from which we remove links, email addresses, phone numbers and guest page access codes.
- Never. Guests' email, phone, identity documents and payment data, and the codes that open a guest's private pages, are not returned by any tool.
Each call only returns the properties where the person has the Analytics permission in the BMS, and only the areas granted to them. Permissions are checked again on every call.
What we record
- The connection: the person and the organization, the name of the connected application (for example Claude), the connection date, the last use with the IP address it came from, the number of calls.
- Sessions: the application's name and version, as it declares them at start-up, and the last activity.
- Each call: person, tool, time, duration, response size, number of properties, outcome, any error message, and a fingerprint (hash) of the arguments, used to recognize repeated questions without storing them. We do not record the content of responses, nor the booking data returned.
- Credentials: access tokens and keys are stored only as a SHA-256 fingerprint, never in clear text. The code that completes the consent is valid for 10 minutes and can be used once.
- Applications: the name and redirect addresses the application publishes or declares to connect. This is not personal data.
- Administrators' actions in the BMS (access granted, areas, keys created, revocations), in the BMS activity log, with the person who performed them.
Why
- Providing the service: recognizing who is calling and with which permissions.
- Security: rate limiting, spotting abnormal use, revoking a connection at once.
- Measurement: knowing how much the service is used, as it is sold by subscription.
- Support: reconstructing which tool, over which period and with data updated to when, produced a disputed answer.
We do not use this data for advertising, we do not sell it and we do not use it to train artificial intelligence models.
Who receives it
- The assistant you connected. The connector's responses reach the provider of the assistant chosen by the person or the property (for example Anthropic for Claude, OpenAI for ChatGPT), which processes them under its own terms and privacy policy and under the agreement between that provider and its user. I/O NET has no agreement with these providers for the connector and sends them no data for other purposes. Before granting the areas with personal data, the property assesses whether the assistant it uses is suitable to receive it.
- BookingDesigner's infrastructure. The connector runs on BookingDesigner's servers on Amazon Web Services, in the European Union, like the rest of the service.
We do not share this data with anyone else, except where required by law.
How long we keep it
| Data | Retention |
|---|---|
| Call log and sessions | 12 months, then deleted automatically |
| Last IP address of a connection | Deleted after 12 months without use |
| Access tokens | Valid for 1 hour; the refresh token for 60 days. Deleted 30 days after expiry or revocation |
| Consent codes | Valid for 10 minutes, deleted within one day |
| Revoked connection | Kept, with no valid credentials, as a reference for the call log, until the service ends for the organization |
| Booking data | The connector makes no copies: it stays in BookingDesigner, under the contract with the property |
Data already delivered to the assistant is kept by its provider under its own rules: to delete it, use the assistant's features, for example by deleting the conversation.
Security
- Encrypted connection (HTTPS) and sign-in with OAuth 2.1 and PKCE: the BMS password stays on the BookingDesigner page and never reaches the assistant.
- Every tool is read-only.
- Permissions checked on every call: a person who is deactivated or no longer authorized stops receiving data from the next call.
- A per-minute call limit for each connection, and immediate revocation from the BMS.
Your rights
- Guests of the properties: for access, rectification, erasure, objection and the other GDPR rights, contact the property, which is the controller of their data. If the property asks us, we assist it.
- BMS users: for connector usage data, write to support@ionet.it.
- You can always lodge a complaint with the Italian data protection authority (Garante per la protezione dei dati personali) or the authority of your country.
Contact
I/O NET S.r.l., via Racale 90, 73040 Melissano (LE), Italy. Email: support@ionet.it.
Changes
If the connector changes the data it processes, we update this page and the date at the top. A new area with personal data always starts switched off and has to be granted by the administrator.