Gratias

Privacy and personal data

Gratias is a digital thank-you platform serving fine hotels. This page describes, for each person concerned, the data processed, its purpose, its recipients and how long it is kept.

You are thanking a member of staff

  • No account is created and no registration is required. You choose an amount, perhaps a few words, and that is all.
  • The payment is handled by the payment provider Stripe, a regulated entity: your card details are entered in its secure interfaces and never pass through the platform.
  • The message you leave is delivered to its sole recipient. An automated courtesy screen may hold back an inappropriate turn of phrase; when enabled, it may rely on Anthropic's artificial-intelligence service.
  • If you return, the page may recognise you through a strictly local memory held in your browser: nothing is sent to the server or shared.
  • These pages set no tracking, advertising or audience-measurement cookies.

You receive thank-yous

  • Your personal space holds your professional identity (display name, role, optional photo, optional email address) together with the history of your thank-yous and transfers, visible to you alone.
  • Your payment account and identity verification are handled by Stripe Connect, regulated entities: the requested documents are sent directly to Stripe and are not kept by the platform.
  • Email notifications are sent through the provider Resend, and only if you have enabled them; an email never mentions an amount.
  • The assistance features of your space (such as the tax companion) may call the Anthropic API when they are enabled; otherwise an answer prepared by the platform is served without any external call.
  • Management never sees the individual amounts of your thank-yous: this is a structural commitment of the platform, which shows managers anonymised aggregate figures only.

Management and group

Management and head-office accounts hold an email address and a password (stored as a non-reversible hash). Dashboards show anonymised aggregate figures only, never an individual record.

Who is responsible for what

  • The establishment is the controller of its staff members' data.
  • The publisher of the Gratias platform operates the service on its behalf, as a processor.
  • Payments are processed by Stripe as regulated entities, bound by their own obligations.

Recipients and processors

  • Stripe: payment processing, payment accounts and identity verification.
  • Resend: delivery of notification emails.
  • Anthropic: assistance features and the courtesy screen, when enabled.
  • Railway: hosting of the platform, in a European Union region.

Retention periods

The following periods are enforced by an automatic purge:

  • Guests' messages and stay references: anonymised after 2 years.
  • Notification delivery log: deleted after 90 days.
  • Linking codes between personal spaces: valid for ten minutes, deleted no later than the day after they lapse.
  • Audit log: kept for 3 years.
  • Anti-fraud alerts: kept for 5 years, under anti-money-laundering obligations.

Your rights

You have the rights of access, rectification, erasure, restriction, objection and portability over your data. Please address your request to the management of your establishment, which passes it on to the platform's publisher where needed.

Cookies

The platform uses strictly necessary cookies only: session cookies for the signed-in spaces and a cookie remembering the chosen language. No advertising or audience-measurement cookies.

The legal identity and contact details of the platform's publisher are provided by the management of your establishment.