One guest. One journey. Many systems and partners.
Follow one guest or traveller's information through search and booking, identity and passport collection, payment, airlines and hotels, transfers, check-in, the stay itself, Wi-Fi and CCTV, guides and activity partners, complaints and reviews, loyalty programmes and long-term archives - and count every place it ends up, and where you lose control of it.
- 1
Search, enquiry & booking-channel capture control breaks
+7 places · 7 so farA guest searches, taps an OTA listing, fills the website form, phones the desk or messages on WhatsApp. Within minutes the same person exists on a booking platform you do not own, in an ad platform's audience, on a reservation executive's own handset and in a lead sheet.
Where control breaks: The guest exists on the OTA before they exist with you
Moving hereGuest & traveller identity (new at this stage)Companions, children & emergency contacts (new at this stage)Booking, reservation & itinerary (new at this stage)Corporate & employer travel records (new at this stage)Preferences, occasions & special requests (new at this stage)Health, dietary & accessibility needs (new at this stage)+3 moreDPDPAThis is the moment to say what you collect and why. An enquiry about one stay or one trip is not permission to hold that person and market to them for years, and an OTA booking arrives with terms about the guest that you still have to be able to explain.
- 2
Reservation, quotation & guest profile creation control breaks
+4 places · 11 so farThe booking or quotation is built, and with it a guest profile: names of everyone travelling, dates, room or package, rate, corporate code, preferences and the executive's own notes. The same person is now created separately in the OTA, the channel manager, the reservation system and the CRM.
Where control breaks: Everyone on shift can read the allergy, the complaint and the note
Moving herePayment, deposit & billing (new at this stage)Guest & traveller identityCompanions, children & emergency contactsBooking, reservation & itineraryCorporate & employer travel recordsPreferences, occasions & special requests+4 moreDPDPADuplicate guest records are a rights problem before they are a data-quality one - a correction or deletion applied to one of four copies has not been applied. Decide which record is the master and keep companions as separate people, not fields.
- 3
Passport, visa & identity-document collection control breaks
+5 places · 16 so farPassports, visas, photographs, dates of birth, nationality and - for a visa file - bank statements, employment letters and family papers arrive by WhatsApp, by email, as photographs and as hard copies, and are saved into whichever folder the coordinator uses.
Where control breaks: Passports arrive on WhatsApp and are still there years later
Moving herePassport, visa & identity documents (new at this stage)Guest & traveller identityCompanions, children & emergency contactsDPDPAThese are the highest-impact documents in the sector. Collect them only when the booking genuinely needs them, use one controlled channel, record the verification outcome where a full copy is unnecessary, and know which copies exist where.
- 4
Payment, deposit, billing & corporate settlement
+6 places · 22 so farDeposits, pre-authorisations, instalments, folios and invoices move through gateways, terminals, banks, the accounting system and - for a business trip - the employer's travel desk and expense platform, which receives an itemised account of what the person did.
Moving hereDining, spa, housekeeping & activity records (new at this stage)Complaints, incidents & lost property (new at this stage)Guest & traveller identityBooking, reservation & itineraryPayment, deposit & billingCorporate & employer travel records+1 moreDPDPANever store card credentials, and treat the corporate invoice as a disclosure: an employer needs the amount, not a line-by-line record of the spa, the bar and the second guest in the room. Financial retention is its own clock, separate from the guest record.
- 5
Pre-arrival documents, itineraries & special requests control breaks
+4 places · 26 so farConfirmations, final itineraries, rooming lists, arrival manifests, transfer sheets and emergency-contact lists are assembled and sent - by email, in a WhatsApp group, as a printed travel pack - and with them arrive allergies, celebrations, mobility needs and flight numbers.
Where control breaks: One sheet shows every traveller to every other traveller
Moving hereLocation, transport & movement (new at this stage)Access, Wi-Fi & monitoring records (new at this stage)Guest & traveller identityCompanions, children & emergency contactsBooking, reservation & itineraryPreferences, occasions & special requests+3 moreDPDPAA consolidated list is a disclosure to everyone who receives it. Give each traveller their own document, keep dietary, health and accessibility details with the team that needs them, and expire shared links rather than leaving them live.
- 6
Arrival, check-in & guest registration
+2 places · 28 so farAt the desk the guest is registered: name, address, nationality, identity document, signature, vehicle, companions. The document is scanned or photocopied, the register is filled in front of the next guest in the queue, and for a foreign national a report goes to the authorities.
Moving hereGuest & traveller identityPassport, visa & identity documentsCompanions, children & emergency contactsBooking, reservation & itineraryPreferences, occasions & special requestsHealth, dietary & accessibility needs+3 moreDPDPASeparate what the law requires you to submit from what you chose to keep a copy of. Government-reported records are authority-controlled and not yours to amend; the scan sitting on the front-desk desktop is entirely yours, and usually nobody has decided how long it stays.
- 7
Access, Wi-Fi, CCTV & movement records control breaks
+5 places · 33 so farThe journey starts recording where the person physically is: key-card and mobile-key events, Wi-Fi logins and device identifiers, CCTV, parking and lift access, transport GPS, a shared live location, and a tour manager's running note of where the group has got to.
Where control breaks: The stay records where the guest was, and nobody set a retention period
Moving hereGuest & traveller identityLocation, transport & movementAccess, Wi-Fi & monitoring recordsComplaints, incidents & lost propertyDPDPASafety and marketing are different purposes and should not share a database. Set a retention period for footage, logs and location history, keep room and location data away from general staff visibility, and close credentials the moment the stay or trip ends.
- 8
Stay, dining, activities & guest services control breaks
+2 places · 35 so farService creates the behavioural half: room-service orders, dining and bar history, spa treatments, housekeeping notes, minibar use, excursion attendance, guide and driver assignments, and a running commentary of service-recovery notes and staff opinion.
Where control breaks: Every guide, driver and vendor gets the whole list because it is quicker
Moving hereGuest & traveller identityCompanions, children & emergency contactsBooking, reservation & itineraryPayment, deposit & billingPreferences, occasions & special requestsHealth, dietary & accessibility needs+5 moreDPDPAOperational notes become a profile whether or not anyone intended one. Keep them factual, restrict them to the department that needs them, give each partner and vendor the minimum the service requires, and do not reuse service history for marketing by default.
- 9
Checkout, complaints, reviews & lost property
+4 places · 39 so farDeparture produces the last cluster: the final folio, a feedback form, a public review and your reply to it, a complaint thread, a refund file, a photograph of a lost item, a compensation note - and a quiet internal label about how the guest behaved.
Moving hereGuest & traveller identityPassport, visa & identity documentsBooking, reservation & itineraryPayment, deposit & billingCorporate & employer travel recordsAccess, Wi-Fi & monitoring records+4 moreDPDPAA public reply that mentions the room, the dates or the complaint discloses the stay. Keep internal notes factual and correctable, separate the public record from the guest file, and set a retention period for lost-property photographs and refund evidence.
- 10
Loyalty, marketing & cross-property profiling control breaks
+3 places · 42 so farThe completed stay or trip becomes a loyalty tier, a stay frequency, a spend profile, a preferred property, a churn score, a WhatsApp broadcast list, an uploaded lookalike audience and a cross-brand campaign that runs indefinitely.
Where control breaks: One stay becomes permission to market forever, across every brand
Moving hereStaff, device & access records (new at this stage)Guest & traveller identityBooking, reservation & itineraryCalls, messages, photos & reviewsScores & labels about the guest· inferredLoyalty & marketing profile· inferredDPDPAFinishing the service is not permission to market. Keep booking communication separate from promotion, hold one suppression list every channel must check, and make a withdrawal reach the agency export and the uploaded audience, not only the CRM flag.
- 11
Archive, vendor copies & deletion control breaks
+2 places · 44 so farEverything settles: reservation and travel-system archives, the CRM, loyalty, folders of passport scans, Wi-Fi and CCTV stores, finance records, supplier and GDS systems, backups, staff phones, the physical register - and a guest history kept because it is what makes the next stay easier to sell.
Where control breaks: Checking out does not delete anything
Moving hereGuest & traveller identityPassport, visa & identity documentsCompanions, children & emergency contactsBooking, reservation & itineraryPayment, deposit & billingCorporate & employer travel records+9 moreDPDPARetention has to be decided per category, not for the guest as a whole. Tax records, a filed government report and a ticketed booking have grounds to be kept; a five-year-old passport scan taken for a stay that ended does not.
Top risk hotspots - where control usually breaks
The 8 places guest data most often slips out of your control. Each links to the matching check in the readiness assessment.
- Hotspot 1 Critical risk
Passport and visa pages, photographs and ID cards come in as images and email attachments, get saved to a folder, scanned again at the desk, downloaded to a laptop to attach to a supplier email, printed for the file and backed up overnight.
Why this matters
It is the highest-impact collection in the sector, and it exists in five places at once because it was never collected through one. Long after the guest has gone, a copy of their passport is still sitting in a folder nobody owns - and no one in the business can say how many copies there are.
Fix: Collect through one secure upload link, keep one folder per booking with named access, record that the document was checked instead of keeping a full copy wherever that is enough, and delete the scans on a clock once the stay or trip has closed.
Check this in the assessment - Hotspot 2 Critical risk
Guides, excursion and safari operators, event vendors, photographers, spa and restaurant partners and transfer drivers are each sent what they need to do the job - which in practice is the entire party list, with names, numbers, ages, room allocations and dietary and medical notes, forwarded into a WhatsApp group.
Why this matters
The guest file is broken up and handed to a long tail of small independent operators, none of whom has a contract, a retention rule or any reason to delete anything. When the guest later asks who holds their details, this is the part of the answer no business in this sector can give.
Fix: Send each partner only the rows and fields their job actually needs, use a booking reference in place of the guest's number where the partner has no reason to call, put deletion terms into the contracts of the partners you use repeatedly, and stop forwarding party lists into vendor group chats.
Check this in the assessment - Hotspot 3 Critical risk
Past reservations, cancelled and no-show bookings, enquiries that never converted, folios, preferences, complaint notes and passport scans from stays years ago all settle into the archive - and stay, because past-guest history is what makes the next booking easier to sell.
Why this matters
Most of the people in it have had no relationship with the business for years, and many never had one at all. This is the single place where a retention decision would do the most good and is least likely to have been taken - and it is where a deletion request quietly fails.
Fix: Set a retention period per category - enquiry, booking, identity document, financial record - and run it on a clock. An identity document almost never needs to survive the stay; a tax record does. Separate what you must keep from what you have merely never deleted.
Check this in the assessment - Hotspot 4 Critical risk
Most bookings are collected by an online travel agency, a metasearch listing or a booking engine first - name, contact, dates, party size, sometimes a card - then synced to your systems by a channel manager, leaving the same guest in four places within minutes.
Why this matters
A large share of your guests were collected under somebody else's notice, on terms you did not set. Deleting your copy leaves theirs untouched, and when a guest asks what you hold and who else has it, the honest answer starts with a platform you do not control.
Fix: Read what each platform's contract actually permits, pull only the fields you need into your own systems, decide which record is your master so a correction lands in one place, and tell guests plainly which parts of their booking record you cannot reach.
Check this in the assessment - Hotspot 5 High risk
The guest profile holds companions, preferences, dietary and medical notes, past complaints, a value band and whatever the last executive typed into the notes field - open to nearly everyone on duty, exportable by most of them, and kept indefinitely.
Why this matters
Housekeeping does not need the medical note and marketing does not need the complaint history, but both can usually see them. A guest can ask to see and correct what you hold, including the opinions - and a departing employee can export the lot on their way out.
Fix: Move to role-based access so each team sees the service note and not the whole profile, keep notes factual and separate observation from opinion, restrict exports to named people, and put a retention clock on guest history.
Check this in the assessment - Hotspot 6 Critical risk
Key-card and mobile-key events, Wi-Fi logins and device identifiers, lift and parking access, CCTV, transfer GPS and a live location a coordinator asked someone to share - all generated continuously, and on a trip, often still updating days after everyone got home.
Why this matters
This is the only record in the series that says where a named person physically was, at what time - and by implication, when their home was empty. It is created without a decision, viewable by staff who have no need for it, and it outlives the stay it belonged to.
Fix: Write down the purpose and the retention period for each kind of movement record, keep safety records out of marketing and analytics, restrict access to named accounts with a viewing log, and close credentials and stop location sharing the moment the stay or trip ends.
Check this in the assessment - Hotspot 7 High risk
The final itinerary, the rooming list, the arrival manifest, the transfer schedule and the emergency-contact sheet are assembled into one document and sent to the group by email, dropped into a WhatsApp group, forwarded to the hotel and the transfer vendor, and printed for the folder.
Why this matters
It discloses room allocations, who is travelling with whom, who needs a wheelchair and whose emergency contact is whose - to everybody who receives it. It is forwarded onward more often than any other file in the sector, and no version of it can be recalled.
Fix: Send each traveller their own document, give each partner only the rows they need, keep health, accessibility and emergency details on a separate need-to-know sheet, and use links that expire rather than attachments that do not.
Check this in the assessment - Hotspot 8 High risk
The completed booking becomes a loyalty tier, a spend band, a churn score, a seasonal campaign list, a WhatsApp broadcast sent from a manager's own number and an audience uploaded back to the ad platform - and at a group, a stay at one property starts marketing from all of them.
Why this matters
Marketing permission is usually bundled into the booking, and a withdrawal recorded in the CRM does not reach the uploaded audience, the agency's export or the broadcast list on somebody's personal phone. The guest keeps hearing from you after asking you to stop, which is the complaint that actually gets made.
Fix: Separate booking communication from promotion, keep one suppression list that every channel and agency must check before sending, remove uploaded audiences when someone withdraws, and set an inactivity rule that closes dormant loyalty profiles.
Check this in the assessment
What happens when someone asks
The map above shows where guest data ends up. This is what that means the day someone asks you to find it, fix it or remove it - including the places a request realistically cannot reach.
Who asks: A past guest who has started getting calls and offers from businesses they never dealt with
Where you have to look
- Property management / travel management systemYour business
- Passport, visa & ID document folderYour business
- Shared enquiry & lead spreadsheetYour business
- Staff phones & guest WhatsApp threadsYour business
- Loyalty, CRM campaigns & broadcast listsYour business
- Guest history archive & old-booking databaseYour business
- Accounting, invoicing & tax recordsYour business
- Access, Wi-Fi & movement record trailYour business
Where this usually cannot reach
- OTA, booking engine & channel managerPlatforms, systems & service vendors
- Guides, activity partners & on-ground vendorsAirlines, hotels, guides & partners
- Departed staff's devices & exportsAirlines, hotels, guides & partners
- Ad platforms, pixels & analyticsPlatforms, systems & service vendors
What has to happen
- Confirm who is asking, using the number or email the booking was made on.
- Search on more than the name - the same person is usually in the reservation system, the lead sheet, the archive and the loyalty record under slightly different spellings.
- Include what you created about them, not only what they gave you: the preference notes, the value band, the complaint history and any behaviour flag.
- Include the identity documents you still hold, and say where each copy is.
- List who the booking was shared with - the platform it came from, the transfer vendor, the partners who delivered the service.
- Say plainly which of those recipients you can reach and which you cannot.
The part that usually fails: The honest answer has two halves. You can account for what is inside your systems. You cannot account for the platform that collected them in the first place, or for the guides, drivers and local vendors who were sent a list over WhatsApp - and those are the recipients the guest is usually asking about.
Check whether you could answer this todayWhen it has already gone wrong
An operational response reference for the incidents this sector actually has - what to do in the first hour, what to put right afterwards, and the control that stops a repeat. Whether an incident needs to be reported is a decision to take with your own advisers.
How you find out: A stranger replies to say they have received somebody's passport, or the guest calls having been told by a friend
Systems involved
- Staff phones & guest WhatsApp threadsYour business
- Passport, visa & ID document folderYour business
- Property management / travel management systemYour business
- Complaint & guest-support deskYour business
First - stop it spreading
- Delete the message for everyone immediately - the window is short, so do this before anything else.
- Establish exactly what was sent, to which number, and whether it was forwarded on.
- Ask the recipient to delete it, in writing, and keep their reply.
- Check whether the same file was sent to any other wrong recipient in the same thread.
Then - correct it and record it
- Tell the guest what happened, what was in it and what you have done - before they hear it from someone else.
- Write down the facts: the file, the recipient, the time, the steps taken and the outcome.
- Assess whether the exposure needs to be escalated, and record the reasoning either way.
- Check whether the document needed to be held at all, and delete the remaining copies if not.
The control that prevents a repeat: Stop sending identity documents through personal chat in either direction. A controlled upload link into the booking record removes both the wrong-number risk and the copy that stays on the handset.
How to read this journey
Pick your model
Switch between Hotel / resort, Travel agency / tour operator and Integrated hospitality & travel group to see the journey each kind of business actually runs. This is not a filter over one journey - a hotel owns the stay, registers the guest against an identity document and generates access, Wi-Fi and CCTV records on its own premises; an agency never owns a bed and instead distributes the traveller's passport and itinerary across airlines, hotels, wholesalers, visa consultants and guides; a group runs both and then joins them into a single cross-brand profile. The stage count and the place-counter recalculate for the model you choose.
When it leaves you
A violet left edge and a tag mark everything outside your business - the OTA and channel manager that collected the guest before you did, airlines and GDS, partner hotels and wholesalers, visa consultants and insurers, transfer vendors, guides and activity operators, payment and Wi-Fi providers, employers receiving an itemised invoice, immigration authorities, and anything that becomes a public review. Once data is there your control is indirect at best: it runs through your instructions and your contract, not your systems. Risk is shown separately, as an amber or red fill - so an outside system can be low risk, and your own reservations executive's phone can be one of the worst things on the page.
Where control breaks
Red flags mark the hotspots - the eight places hospitality and travel businesses most often lose control of guest data, from a passport photographed onto WhatsApp and never deleted, to a party list forwarded into a vendor group chat, to a key-card and Wi-Fi trail that records where a named person was and has no retention period. Tap any system to see what it holds and how to fix it.
Now check whether your controls hold up
The map shows where guest and traveller data travels in a typical hospitality or travel business. The 3-minute readiness scan checks whether your business has the controls that matter at each hotspot - and the Discovery tool builds your own data inventory.
Educational reference model - not legal advice, and not a scan of your actual systems.