Legal · updated 28 July 2026

Acceptable Use Policy

RIGHT HOTELS SAS · Hotelminder (mindermod.org)

1. Purpose

Hotelminder is an editorial advisory and a hand-picked marketplace of add-on modules for independent boutique hotels running SiteMinder. This Acceptable Use Policy (the “AUP”) describes the way in which we expect subscribing hoteliers, their staff, their third-party consultants and any visitor to mindermod.org to use the advisory conversations, the shortlist, the modules and the SiteMinder-connected surface. Its tone is advisory rather than adversarial — we prefer a private note with a customer over a suspension notice — but its authority is contractual: this AUP forms an integral part of the Terms of Service at /legal/terms and any material breach may lead to the consequences described at Section 10 below. The AUP is written to be reasonable for a boutique-scale operator running one to twenty properties; if your operational footprint is materially different, please raise it with your advisor before you subscribe rather than after.

2. Fair-use principle

The overarching principle of this AUP is fair use in the boutique-hotel sense: use the shortlist for the property or the small portfolio in front of you, use the modules for the operational purposes for which each one was vetted, respect the shared platform on which every subscriber depends, respect the third parties (SiteMinder, guests, sub-processors) whose surface we integrate with, and respect the collective work of the advisory team. Fair use is not a set of arbitrary quotas invented after the fact; it is the honest, day-to-day usage a serious boutique operator would expect a serious peer to make of the same tools.

3. Permitted uses

You may, without any specific authorisation from Hotelminder, do the following:

  • Browse the shortlist and read the editorial guides at mindermod.org for internal decision-making at the hotel.
  • Request a scoping call, discuss operational questions with an advisor and share the documents strictly required to make the call useful.
  • Subscribe to one or more modules and configure them against your SiteMinder tenant using API Credentials you own.
  • Use the subscribed modules in the day-to-day operation of the hotel, including for revenue management, guest communication, distribution optimisation and reporting, within the boundaries of the module’s documentation.
  • Invite members of your team to the dashboard with the appropriate role, and add or remove roles as your operational team changes.
  • Extract and export your own data through the dashboard exports at any time.
  • Refer other hoteliers to the shortlist through the personal referral link visible in your dashboard.

4. Prohibited uses

Regardless of any authorisation you might infer from your subscription, you may not, directly or through a third party:

  • Use the Service to send unsolicited bulk communication (“spam”) to guests, to prospects or to any other recipient, whether by email, SMS, WhatsApp or any comparable channel. Every guest communication triggered through a subscribed module must be based on a lawful legal basis under the RGPD and must respect the guest’s prior choices, including opt-outs.
  • Use the Service for any unlawful purpose, including but not limited to the processing of stolen credit-card data, the laundering of proceeds of crime, the harbouring of trafficked persons, the storage of illegal content, or any activity infringing French or EU criminal law.
  • Use the Service to harass, intimidate, defame or otherwise wrongfully target any natural person, whether a guest, a member of Hotelminder staff, a member of a peer hotel’s staff or a third party.
  • Infringe any intellectual property right — including copyright, trademark, design right, database right or trade-secret right — of Hotelminder, of SiteMinder or of any third party, whether by scraping, mirroring, decompiling or otherwise.
  • Introduce or distribute any form of malware, worm, virus, spyware, keylogger, cryptominer, ransomware or comparable malicious code through the Service.
  • Scrape the shortlist, the module catalogue, the editorial guides or the pricing pages by automated means for the purpose of a competitive intelligence operation, a directory or a comparison product without our prior written consent.
  • Misrepresent your affiliation with Hotelminder or with SiteMinder, including by using our name, logo, screenshots or editorial content to imply a partnership, an endorsement or a resale relationship where none exists.
  • Attempt to gain unauthorised access to the Service, to another subscriber’s tenant, to the underlying infrastructure or to any account other than your own; probe, scan or test the vulnerability of the Service without our written authorisation delivered ahead of the test.
  • Circumvent, disable or otherwise interfere with the authentication, rate-limiting, logging or security features of the Service.
  • Use the Service in a way that overloads the SiteMinder tenant to which it connects, in violation of SiteMinder’s own rate-limits or terms of use.
  • Impersonate any other person or entity, or falsely state or otherwise misrepresent your affiliation with any person or entity.
  • Share credentials to your dashboard account with anyone; every human user must have their own account, secured with multi-factor authentication.

5. Reasonable use of the API and rate-limit guidance

The subscribed modules connect to your SiteMinder tenant and to the Hotelminder platform through documented interfaces. To keep the platform fair for every subscriber, the following reasonable-use guidance applies. Each guideline is calibrated to a boutique-scale operator running properties of one to eighty rooms; edge cases can be discussed at any time with your advisor.

  • Modules per API key — up to ten (10) modules per API key. Multi-key configurations for portfolios of several properties are set up during onboarding.
  • Requests per property — up to five hundred (500) requests per minute per property, sustained over a sliding one-minute window, for the aggregate of read and write calls issued by every module against a given property.
  • Long-lived polling — no unattended scraping of guest data; webhook-based delivery is provided as the recommended pattern for near-real-time updates.
  • Bulk exports — bulk export of guest data is available through the dashboard once every twenty-four (24) hours per property, in JSON or CSV, encrypted at rest during transit through the export queue.
  • Test versus production — please use the sandbox tenant credentials that we provide during onboarding when you run non-production tests; production credentials are for production traffic only.
  • Retry policy — clients that receive a 429 Too Many Requests response should honour the Retry-After header; exponential backoff with jitter is recommended.

The full technical documentation, including the exact quota headers returned by the API and the recommended retry patterns, is maintained at /docs/rate-limits.

6. Respect for guest data

Where a subscribed module reads or writes guest-level personal data, the subscribing hotel remains the controller of that data within the meaning of the RGPD. This means: you determine the purposes and means of the processing, you are responsible for informing the guest as required by Articles 13 and 14 RGPD, you are responsible for the legal basis on which the processing rests (typically the performance of the reservation contract, a legal obligation for tax invoicing, or the guest’s prior consent for optional communications), and you are responsible for honouring any guest right (access, rectification, erasure, portability, objection) exercised on the basis of that processing. Hotelminder acts as processor on your instructions, as detailed in the Data Processing Addendum at /legal/dpa. Any use of the Guest CRM extensions or of the guest-communication modules must respect the guest’s prior choices, in particular any opt-out registered in the SiteMinder tenant or communicated to the property. Sending a marketing communication to a guest who has not consented is a material breach of this AUP and can lead to immediate suspension.

7. Respect for SiteMinder

Hotelminder integrates with SiteMinder through the documented public interfaces exposed by SiteMinder. This means, on the operational side, that (i) every action performed by a subscribed module counts against your SiteMinder tenant’s own quotas, (ii) SiteMinder’s own terms of use apply to the API Credentials you supply, and (iii) SiteMinder retains the sole discretion to decide whether a given usage pattern is acceptable on its own platform. Please treat SiteMinder’s platform with the same care you would treat a critical supplier: do not intentionally overload it, do not test destructive operations on your production tenant, do not attempt to reverse-engineer proprietary logic, and do not misrepresent Hotelminder’s modules as being endorsed by SiteMinder.

8. Advisor conduct

The advisory conversations are personal and specific. Each scoping call, each on-property visit and each editorial follow-up is calibrated to the property in front of the advisor. You may share the advisor’s recommendations internally at your hotel or with your ownership; you may not republish, sell or repackage those recommendations as a stand-alone product, nor may you use them to train a foundation model without our prior written consent. Similarly, please do not record scoping calls without informing the advisor at the beginning of the call, in application of the applicable rules on consent to recording under French law and under Article 226-1 of the Code pénal.

9. Reporting abuse

If you observe conduct that appears to breach this AUP — for instance a peer subscriber sending phishing content through the platform, or a suspicious login on your dashboard — please report it to abuse@mindermod.org. We commit to an initial acknowledgement within one (1) business day of receiving the report, followed by a substantive response within five (5) business days. If your report concerns a security vulnerability rather than a usage-policy breach, please additionally add the string “SECURITY” in the subject line, so that the on-call security engineer is paged directly. Responsible disclosure is welcomed and we commit not to bring any legal action against a researcher who reports a vulnerability in good faith, provided the researcher has not accessed or exfiltrated data beyond what was strictly necessary to demonstrate the finding.

10. Consequences of breach

Enforcement follows a graduated escalation designed to give the subscriber every reasonable opportunity to remedy an issue before losing access to the Service:

  • Advisory warning — a private note from an advisor describing the observed behaviour and asking for context or for a change of pattern; a reasonable deadline (typically 7 days) is set.
  • Throttling — if the observed behaviour is objectively degrading platform performance and did not stop after the advisory warning, temporary quantitative limits are placed on the affected feature; the subscriber is notified before the limit takes effect.
  • Suspension — where the breach is severe, wilful or persistent, access to the affected feature or to the dashboard is suspended for up to thirty (30) days; suspension is a temporary measure while the situation is investigated.
  • Termination — where the breach cannot be remedied or where suspension has not addressed the underlying issue, the subscription is terminated in accordance with Section 6 of the Terms of Service.
  • Emergency measure — in cases involving imminent risk to the Service, to a guest, to a third party or to us, Hotelminder may take an immediate emergency measure (typically an emergency suspension) without going through the graduated steps, followed by a written justification within forty-eight (48) hours.

None of the above escalations excludes any other remedy Hotelminder may have under the Terms of Service, under French law or under any binding regulatory instrument.

11. Compliance with law

The Service is offered from France and is subject to French law. Regardless of your location, you undertake to use the Service in a way that complies with all laws applicable to you, including data-protection law, consumer law, tax and accounting law, sectorial hotel-industry regulation (in France, for instance, the requirement to file the fiche de police for certain guest categories under Article R611-42 of the Code de l’entrée et du séjour des étrangers), competition law and export-control law. Hotelminder’s modules provide operational infrastructure but do not, by themselves, guarantee compliance with any specific sectorial rule — the operational responsibility remains yours.

12. Changes to this AUP

We may amend this AUP from time to time to reflect changes in law, in the composition of the Service or in the observed usage patterns of the community. Material changes are notified to dashboard administrators at least thirty (30) days before the effective date. Non-material changes (clarifications, corrections, additions to the reasonable-use guidance) may be published silently, with the updated date at the top of the page always reflecting the most recent revision.

13. Contact

Reports of abuse or security concerns: abuse@mindermod.org. General advisory questions: advisor@mindermod.org. Data protection: Camille Dubois-Renard, dpo@mindermod.org. Registered office: RIGHT HOTELS SAS, 7 Allée Jacques Cartier, 93160 Noisy-Le-Grand, France. Regulator: CNIL, cnil.fr — déclaration n° 2224789. Hosting: OVHcloud Roubaix, France.