eeHMS PressHotel Finance Practice Library
BooksDecision GuidesKnowledgeToolsCoursesFor TeamsAbout
BooksDecision GuidesKnowledgeToolsCoursesFor TeamsAbout
Log in

Privacy · version 2026-09-08

Privacy policy

Effective 8 September 2026

1. Who is responsible for your data

eHMS Press, the publishing imprint of eHotel Management School, determines why and how personal data is used for the Hotel Finance Practice Library. Privacy enquiries and rights requests may be submitted through the contact page.

2. Data we collect

  • Account data: email address, authentication identifiers, login method, and basic identity information supplied by Google or entered by you.
  • Profile data: display name, hotel or organisation, and position title.
  • Learning data: reading progress, chapter status, quiz attempts, scores, and flashcard confidence where those tools are available or retained historically.
  • Chapter discussions: signed-in account identifier, displayed profile name, book and chapter reference, response or reply text, relationship to a parent response, publication time, visibility, featured status, and moderation records. Visible contributions and the displayed name are public.
  • Reader questions and feedback: the signed-in account, email address, exact page path, page title, book reference, message type, question or comment, submission time, review status, and any administrator response.
  • Testimonials: signed-in account, email address, publication name, position, selected book, testimonial text, optional photograph and file metadata, publication consent, review status, administrator note, and approval or archive timestamps.
  • Automated direct-purchase data: book, price, currency, checkout-attempt identifiers, PayPal order and capture identifiers, transaction status, entitlement status, accepted legal-policy version, and related audit information. We do not store your complete card or bank details.
  • UPI, bank-transfer, and external-purchase verification: purchase channel, payer name where supplied, payment date, amount, UPI application, UTR or order reference, notes, uploaded receipt or payment evidence, review status, administrator notes, proof version, and decision audit events. Payment evidence may incidentally display limited account or transaction information; do not upload a UPI PIN, password, one-time password, complete bank statement, or unrelated transaction history.
  • Transactional email records: recipient address, event type, subject, related purchase or access identifier, delivery status, provider message identifier, failure information, and delivery timestamps. These records support duplicate prevention, support, reconciliation, and delivery troubleshooting.
  • Enquiry and update-list data: name, email, company, message, interests, source page, consent record, selected book, chapter-summary sequence position, next scheduled delivery, unsubscribe status, and email delivery results such as sent, failed, bounced, complained, or suppressed.
  • Discovery and referral data: when a browser reaches a public page from an external referrer or a tagged campaign, we may record an anonymous browser-session hash, the referring hostname only, the landing path, campaign parameters such as UTM source, medium, campaign, term and content, Google advertising click identifiers such as GCLID, GBRAID or WBRAID when present, a broad source category, and the event time. This first-party discovery record does not contain the raw referring URL, referring search query, account identifier, email address, or reader profile.
  • Analytics and advertising-measurement data: where Google or Meta measurement is configured, the Google tag and Meta Pixel may receive page and event information, consent state, campaign or referral information, and browser or device information. Google measurement may additionally receive verified purchase events including a transaction identifier, product reference, value and currency. Optional analytics and advertising technologies follow the choices made through the site's privacy controls.
  • Optional chapter video: eHMS Press does not record a reader's YouTube playback activity in its own database. When a reader chooses to load an embedded YouTube player, YouTube may receive connection, browser, device, and interaction information under its own policy.
  • Technical data: IP-derived request information held in provider logs, browser or device information, user agent, security events, timestamps, and essential session or authentication cookies.

3. Why we use the data

  • to create and secure reader accounts;
  • to provide public, registered-reader, purchaser, reviewer, and institutional access;
  • to save learning progress and deliver reader tools;
  • to publish and moderate constructive chapter discussions and replies;
  • to receive, organise, answer, and act on page-specific reader questions, corrections, and feedback;
  • to receive, moderate, publish, archive, or remove reader testimonials where the reader has expressly consented;
  • to understand, at an aggregate level, which external search, AI, referral, advertising, or campaign sources lead readers to public library pages and which landing pages they reach;
  • to measure campaign performance and attribute verified purchases without changing the underlying payment or entitlement decision;
  • to improve explanations, examples, navigation, figures, and future editions;
  • to process, validate, reconcile, and audit purchases;
  • to match UPI or bank-transfer evidence against a receiving-account credit before granting access;
  • to send requested authentication, payment, verification, access, and organisation-licence service messages and prevent duplicate delivery;
  • to review external-purchase evidence and prevent fraudulent access;
  • to answer enquiries, provide support, and send requested book updates and chapter-summary emails;
  • to operate, troubleshoot, secure, and improve the platform;
  • to comply with accounting, tax, fraud-prevention, legal, and regulatory obligations.

4. Legal bases where applicable

Depending on your location and the activity, processing may be based on performance of a contract, steps taken at your request before a contract, legitimate interests in operating and improving the service, compliance with legal obligations, or your consent. Testimonial publication, optional photograph display, optional chapter-summary communications, and optional analytics or advertising measurement technologies, including Google measurement and Meta Pixel, are based on consent where applicable. Chapter discussion publication occurs at the reader's request when the reader posts a response. You may withdraw consent for optional communications, testimonial publication, analytics storage, or advertising measurement at any time, without affecting earlier lawful processing.

5. Service providers and recipients

Data may be processed by providers used to operate the service, including Supabase for authentication, database, private storage, and first-party discovery measurement; Render for hosting and server logs; Resend for authentication messages, payment and access notifications, requested book updates, chapter-summary delivery, bounce handling, and unsubscribe processing; PayPal for international direct checkout; Google for optional sign-in, consent-aware analytics and advertising measurement, and, where configured, enquiry storage; Meta for consent-aware advertising measurement through Meta Pixel; YouTube for optional chapter videos loaded only after a reader chooses to open the embedded player; and other email or support providers used to respond to readers. UPI and bank transfers are processed outside the website by the buyer's selected bank or UPI application, relevant payment-network participants, and the receiving bank. Amazon and other retailer links take you to independent services governed by their own privacy policies.

Access is limited to the author, authorised administrators, and providers that need the information to perform their contracted role. Personal data is not sold to advertisers. Visible chapter-discussion names and responses, and approved testimonial names, positions, selected books, comments, and optional photographs, are intentionally made public.

6. International processing

Because the library serves readers internationally and uses global service providers, information may be processed outside your country. Where required, we rely on provider safeguards, contractual protections, or other lawful transfer mechanisms.

7. Purchase-proof handling

Purchase evidence is stored in a private bucket and accessed by administrators through short-lived signed links. Approved proof files are deleted after review. Replacement proof supersedes the earlier stored file. Pending proof is retained for a limited review period, while declined or information-requested proof is retained temporarily to permit reconsideration or replacement. Decision, entitlement, payment-reference, and audit records may be retained after proof deletion for fraud prevention, support, accounting, tax, dispute handling, and legal obligations.

8. Reader feedback and discussion handling

Questions, corrections, and feedback submitted through the page panel are linked to the signed-in account and exact page. They are visible to authorised administrators and may be used to answer the reader, correct the book or platform, improve future editions, and identify recurring learning difficulties.

Chapter-discussion responses and replies are intentionally public together with the reader's displayed profile name. Administrators may hide, restore, feature, or unfeature contributions and retain a moderation audit. Contributions should not contain confidential hotel information, personal data about other people, passwords, payment credentials, legally privileged material, or content the reader is not authorised to disclose.

9. Testimonial handling

Testimonials are linked to a signed-in reader account for moderation and authenticity checks. A submission is private while pending, declined, or archived. Only an administrator can approve publication. Approved testimonials display the submitted name, position, selected book, testimonial text, and optional photograph. Photographs are held in private storage and displayed through short-lived signed links rather than a public storage bucket.

You must have the right to submit any photograph and should not include confidential, misleading, defamatory, or third-party personal information. You may request that an approved testimonial or photograph be removed through the contact page. Declined testimonial photographs are deleted automatically where the storage operation succeeds.

10. Retention

We retain data only for as long as reasonably necessary for the stated purpose, account administration, dispute handling, security, product improvement, and applicable legal requirements. Reader progress generally remains while the account is active. Visible discussion responses may remain while the relevant chapter and community exchange are supported; hidden responses and moderation records may be retained to document safety and editorial decisions. Feedback and question records may be retained while the relevant edition is supported and afterwards where needed to document corrections, responses, or editorial decisions. Pending testimonials are retained for moderation; approved testimonials are retained while published; archived or declined records may be retained for a reasonable period to document consent and moderation, while declined photographs are deleted. Payment, UTR, entitlement, decision, and transactional delivery records may be retained for the applicable accounting, tax, fraud, support, dispute, and limitation periods. Discovery-referral records are retained only as reasonably necessary to evaluate aggregate search, AI, referral, and campaign performance and may later be aggregated or deleted when the detailed record is no longer needed. Chapter-summary subscription and delivery records are retained while the sequence is active and afterwards for a reasonable period to document consent, unsubscribe requests, suppression, delivery failures, and duplicate-send prevention. Enquiry records are removed or anonymised when no longer needed. Browser consent preferences are retained locally until you change them or clear site data. Google and Meta retain measurement information under their applicable service settings and policies. Backup copies may persist for a limited period before routine deletion.

11. Cookies and similar technologies

The site uses essential technologies needed for authentication, security, reader sessions, purchases, and reader preferences. For first-party discovery measurement, browser session storage may hold a random session value and a flag indicating that an external landing has already been recorded during that browser session. This is used to avoid counting repeated page views as separate external-discovery sessions and is not used to build an advertising profile.

When Google measurement is enabled, the site uses Google Consent Mode v2. Before a visitor makes a choice, analytics storage, advertising storage, ad-user-data processing, and ad-personalisation signals are set to denied. Visitors can accept all optional measurement, reject optional storage, or choose analytics and advertising measurement separately. The saved choice can be changed later using Cookie settings in the site footer. When optional storage is denied, Google may receive limited cookieless measurement signals where supported, but optional Google analytics and advertising storage remain denied.

Meta Pixel is not loaded unless the visitor allows Advertising measurement. When allowed, Meta Pixel may receive page-view, browser or device, and campaign or referral information for advertising measurement. If the visitor later withdraws advertising consent, the site stops sending further Meta Pixel tracking events.

The YouTube player is not loaded until the reader selects Play video. After it is loaded, YouTube may use its own cookies, local storage, or similar technologies under its policy. When you leave the site for PayPal, Amazon, LinkedIn, Google, Meta, YouTube, your bank or UPI application, or another provider, that provider may use its own cookies and tracking under its own policy.

12. Security

We use access controls, server-side entitlement checks, row-level database policies, private storage, short-lived proof and testimonial-photo links, secret-management controls, transaction audit records, discussion rate limits and moderation records, idempotent email-delivery records, email campaign controls, delivery logs, and encrypted provider connections. Manual payment approval requires confirmation of the receiving-account credit rather than reliance on an uploaded screenshot alone. No online system is risk-free, and absolute security cannot be guaranteed. Report suspected account or data misuse through the contact page.

13. Your rights

Depending on applicable law, you may have rights to be informed, access your data, correct inaccurate data, request deletion, restrict processing, object to certain processing, receive portable data, withdraw consent, and complain to a data-protection authority. Some records may need to be retained despite a request where required for payment, fraud, accounting, legal claims, correction history, moderation history, suppression of unwanted email, or other lawful obligations.

You can change optional analytics and advertising choices at any time through Cookie settings in the site footer. To make another privacy request, use the contact page and identify the email address used for the account. We may need to verify identity before acting.

14. Automated decisions

The site uses automated checks for authentication, access, PayPal payment matching, email duplicate prevention, file type, discussion posting frequency, abuse prevention, and scheduled delivery of communications a reader requested. It does not intentionally make solely automated decisions that produce legal or similarly significant effects. UPI or bank-transfer proof approval, external-purchase approval, reader-feedback review, discussion moderation, testimonial publication, and campaign activation are administrator activities.

15. Children

The service is intended for professional, higher-education, and adult readers. A person who cannot legally consent to the processing, public discussion or testimonial publication, optional communications, optional analytics or advertising measurement, or purchase in their jurisdiction should use the service only with appropriate parent, guardian, institution, or authorised representative involvement.

16. Changes

We may update this policy as the platform, providers, or legal requirements change. The current version and effective date will be displayed on this page. Material changes will be highlighted through the site or account email where reasonably practicable.

eHMS Press

Practical hospitality finance for real management decisions.

Books for deeper capability, Decision Guides for focused problems, Knowledge for understanding, courses for guided practice, and tools and companions for application.

BooksDecision GuidesKnowledgeCoursesToolsDigital companionsResearch & practice papers
For hotel teams & institutesAuthorAbout eHMS PressContactReader logineHotel Management School

© 2026 Manish Gupta. Published by eHMS Press. Independent educational commentary; not an official HFTP or USALI publication. Content is not legal, tax, audit, accounting, investment, or other professional advice. Readers remain responsible for decisions and consequences.

TermsPrivacyRefundsDisclaimerCopyright & trademarks