Home › Security
How your reports are handled
Your night audit PDFs go to a machine we operate ourselves in the United States — not a shared cloud platform. Guest names and card fragments are replaced with one-way hashes on arrival. We never log in to your PMS, your brand portal or your bank. One email deletes everything within 14 days.
What we read, and what we never touch
We read
- The nightly report bundle your PMS emails (PDF)
- Your house rules — five questions, answered once
- Optional: settlement emails, OTA invoices, housekeeping photos
- Which login belongs to which shift
We never ask for
- PMS, brand-portal or bank logins
- Bank statements or account access
- Software installed at the front desk
- Full card numbers — never stored, in any form
Where a pack goes
1 · Your inboxPMS emails the pack; you forward it
2 · Our mail addressRouted by Cloudflare; nothing stored there
3 · Our machineNames and card fragments hashed, then read
4 · Your phoneOne WhatsApp per hotel before sunrise
The machine is under our physical control in Wisconsin, encrypted at rest, reachable only by the people who operate DeskWatch, with keys rotated when anyone leaves. No customer data is used to train any model. Messages name a PMS login and, if you've told us, the person behind it — nothing about guests.
Who else handles it
| Provider | What passes through it | Why |
|---|---|---|
| Cloudflare | Website; inbound email routing | DNS, hosting, mail forwarding |
| FormSubmit | Contact-form fields only | Form delivery |
| WhatsApp (Meta) | The morning message | Delivery to your phone |
We tell customers by email before adding a provider to this list.
Deleting everything
Email hello@watchmydesk.com. Reports, results and rules for your properties are deleted within 14 days and we confirm in writing. Reports are otherwise kept for 90 days after a subscription ends. The full policy is on the privacy page.
Questions from a franchise or IT reviewer? Send them over — we answer in writing.