◗ NightdeskBack

Privacy

Last updated 6 August 2026

Nightdesk answers overnight booking enquiries on Instagram for hotels and short-let operators in Nigeria. This page explains what we collect, why, and how long we keep it. It is written to be read, not to be survived.

Who is responsible for what

The property you are messaging is the data controller — it decides why your details are collected. Nightdesk is the data processor: we handle that data on the property's instructions in order to answer you and complete a booking. If you want your data removed, the property can ask us and we will do it.

What we collect from guests

  • The messages you send to the property on Instagram, and the replies sent back
  • Your Instagram account identifier — a number the platform gives us. We do not receive your password, email, or profile details.
  • Any name or phone number you choose to give while booking
  • Booking details: which room, which night, the amount, and whether payment succeeded

We do not receive or store your card details. Payments are handled by Paystack and settle directly into the property's own bank account. Nightdesk never holds your money and never sees the card.

What we collect from properties

  • Your name, email address, and the property's details
  • Room types, rates, and nightly availability
  • Your Paystack secret key and Instagram access token, both encrypted at rest and decrypted only for the moment they are needed to take a payment or send a reply

Why we hold it

To answer a guest, quote a real price, hold a room, take payment, and issue a confirmation code the front desk can check. We also count how many enquiries arrived and how many were missed, so a property can see whether the service is earning its fee.

We do not sell data, we do not share it between properties, and we do not use it for advertising. One property cannot see another's guests — that separation is enforced by the database itself, not only by application code.

Who else processes it

  • Meta (Instagram) — delivers the messages in both directions
  • Neon — hosts the database, in Frankfurt, Germany
  • Render — runs the application, in Frankfurt, Germany
  • Vercel — serves this website
  • Paystack — processes payments to the property's account
  • Groq — generates the wording of replies. Message text is sent for this purpose and is not used to train models.
  • Resend — sends account emails such as password resets

Data is stored in Germany. If you are in Nigeria, that means your information is processed outside the country.

How long we keep it

  • Conversations and bookings — kept while the property is a customer, so it has a record of who stayed and what was paid
  • Login sessions — refresh tokens expire after 14 days
  • Password reset links — expire shortly after being sent and can be used once

When a property stops using Nightdesk, its data — including guest conversations — is deleted on request, and otherwise within 90 days of the account closing.

Your rights

Under the Nigeria Data Protection Act you can ask for a copy of your data, ask for it to be corrected, or ask for it to be deleted. Email hello@nightdesk.com.ng and we will respond within 30 days. If you booked through a property, you can also ask them directly.

Security

Payment keys and access tokens are encrypted before they are written to the database. Every request from Instagram and Paystack is checked against a cryptographic signature before it is acted on, so a forged message cannot make a property sell a room. Access between properties is separated at the database level.

No system is perfect. If you find a security problem, please email hello@nightdesk.com.ng rather than posting it publicly, and we will fix it.

Children

Nightdesk is for businesses and their adult guests. We do not knowingly collect data from anyone under 18.

Changes

If this policy changes materially, we will tell customers by email before it takes effect. The date at the top always reflects the current version.

Contact

Nightdesk, Abuja, Nigeria — hello@nightdesk.com.ng