Security & product boundaries
Know what you’re putting on your website.
The hotel concierge provides information configured for your property. Here’s what it does, what access it needs, and what information should stay out of the conversation.
Hotel information, approved by you.
The concierge uses configured information about your hotel’s rooms, amenities, and policies. Your hotel decides which facts to provide and approve; Palm Beach AI handles the configuration.
Treat information supplied for guest answers as public. Keep internal credentials, private guest records, and confidential operating details out of that information.
When a policy, fee, or opening time changes, send the update to Palm Beach AI so the configured information can be revised.
A website widget with a defined scope.
The standard concierge is installed on your website. It does not require a connection to your property management system, reservation database, or payment system.
Installation requires a way to add the widget to the agreed website. Website editing access or coordination with your website provider is arranged during setup.
A limited integration reduces the access required. It does not make a website or widget immune to security risks.
Information, without booking authority.
The concierge does not check live room availability or make reservations. It also does not change or cancel an existing booking.
Any configured rate or fee is informational, not a live quote or booking confirmation. Guests should use the hotel’s official booking channel to confirm availability, final pricing, and reservation details.
Keep sensitive information out of chat.
Guests do not need to provide payment or identity documents to ask about hotel information. Please do not enter:
- Card numbers, security codes, or bank details.
- Passwords, access codes, or account credentials.
- Passport numbers or other identity documents.
- Private medical information or confidential guest records.
Use the hotel’s designated channels for payments, identity verification, and matters involving personal booking details.
How our contact form is protected.
The Palm Beach AI website uses HTTPS. Contact submissions are checked on the server, including reCAPTCHA verification, field validation, and request-size limits.
The form sends inquiries to a fixed Palm Beach AI support address. Its email password and reCAPTCHA secret are stored in Google Cloud Secret Manager and used by the backend, rather than included in the public page.
These controls help protect the contact form from misuse. They do not guarantee that every unwanted submission will be blocked.
Report a security concern.
Email support@palmbeachai.io with the affected page or widget, what you observed, and the steps needed to reproduce it.
Please leave passwords, payment information, and other people’s personal data out of the report.