A guest gives you their data once. You use it eleven times.
Booking engine, OTA, property management system, POS, WiFi captive portal, loyalty programme, WhatsApp campaigns. A guest hands over their details once and the group processes them in a dozen places, most of which were never designed to ask permission.
Built for: Hotel groups, resorts, restaurant and QSR chains, travel operators, OTAs and loyalty programmes.
The pressure points, specifically
The guest record is fragmented by design
The same person exists in the PMS, the POS, the loyalty database and three campaign tools, often under different identifiers. A withdrawal that only reaches one of them is not a withdrawal, and a regulator will treat it as a failure rather than an integration problem.
Marketing is the whole commercial model
Offers, re-booking nudges, birthday campaigns and loyalty tiers are how the business grows, and every one of them needs a lawful basis you can produce on demand. Bought and inherited lists are the exposure nobody wants to look at.
Franchise and management contracts blur the roles
When the brand, the owner and the operator are three different companies, it is genuinely unclear who is the Data Fiduciary for the guest. That question has to be answered in writing before an incident forces the answer.
Collection happens at the least convenient moment
Check-in queues, a WiFi splash page, a QR code on a table. Consent has to be captured in seconds, in the guest's language, on their phone, without a member of staff explaining a privacy notice at the desk.
The parts that matter here
One guest identity across every property
Consent is recorded against the data principal rather than the property or the channel, so a withdrawal captured at one hotel is visible to the loyalty programme and the campaign tool immediately, and the ledger shows when it took effect.
Capture in seconds, on the guest's phone
A hosted consent page you can put behind a QR code at check-in, on a WiFi captive portal or in a booking confirmation, built to load fast on a mobile connection and available in twenty-two Indian languages.
Self-service preferences the guest actually finds
An OTP-verified preference centre where a guest can turn marketing channels on and off themselves. It reduces the unsubscribe-by-complaint route, and every change lands in the same ledger as the original consent.
Bring an existing guest database into compliance
Import the contacts you already hold, run a re-consent campaign against them, and get a defensible position on a legacy list rather than quietly continuing to mail it.
Cookie and web consent that matches the record
A consent banner for the booking site and a scanner that tells you which trackers are actually firing, so the website story and the ledger story are the same story.
Hospitality and the DPDP Act
Yes, in almost every case. Marketing is not one of the legitimate uses the DPDP Act allows without consent, so a hotel sending promotional messages to a past guest needs a consent that was freely given, specific and informed for that purpose — and needs to be able to produce it. A booking made years ago under a general terms acceptance is unlikely to satisfy this on its own, which is why re-consenting an inherited guest list is usually the first piece of work.
It depends on who determines the purpose and means of processing, and it is frequently both, in different respects. A brand that runs the loyalty programme and the central reservation system is a Data Fiduciary for that processing; an owner-operator collecting guest data at the property is one for theirs. The practical answer is to write the split down and reflect it in the consent notice, because the guest is entitled to know who they are dealing with.
A captive portal is a collection point like any other and needs a notice and a consent before it takes personal data. In practice this is where hospitality groups are most exposed, because portals were built by a vendor years ago and quietly feed a marketing list. Sammati can sit behind the portal so the consent is recorded properly at the moment of connection.
A single-property pilot can be live in days, because the hosted consent page needs no integration work — a QR code and a notice are enough to start recording defensible consent. Deeper work, such as connecting the PMS and the loyalty database, follows once the record exists to connect to.
General information about the DPDP Act, 2023, not legal advice. For a position specific to your organisation, talk to us.
Find out where you actually stand.
The free self-assessment takes a few minutes and gives you a written position on your own setup, not a generic checklist.