Datenschutzerklärung
Version v0.1-draft · Datum des Inkrafttretens Sa., 11. Juli
Englische Fassung. Übersetzte Fassungen stellt die Agentur bereit.
Hotel Booking (the “agency”, a licensed travel agency) is the controller of the personal data you provide when you search, book, or contact us. This policy explains what we collect, why, and your rights under the GDPR.
What we collect
Booking data: the lead guest and each guest’s name, your contact email and (optional) phone, your stay details, and — only when a specific hotel or rate requires it — a guest date of birth. We do not collect passport or ID numbers by default.
Payment data: card details are entered directly into our payment provider (Stripe) and never reach our servers. We store only Stripe’s opaque reference identifiers and the payment status — never your card number, CVC, or expiry.
Technical data: minimal server logs and the strictly-necessary cookies needed to run the site and process your booking.
Why we use it and our legal basis
To take and fulfil your booking with the hotel via our supplier (performance of a contract).
To send your confirmation, voucher and service messages (contract / legitimate interest).
To meet legal and tax obligations as a licensed travel agency (legal obligation).
Sharing and sub-processors
We share booking data only as needed to fulfil your reservation: with the hotel-inventory supplier (SANTSG/Sejour), the payment processor (Stripe), our hosting provider, and our email provider. See the Sub-processors page for the current list.
We do not sell your personal data.
Retention
We anonymize guest personal data a defined period after your stay or cancellation, while retaining the financial records we are legally required to keep. See our data-retention policy.
Your rights
You may request access, correction, export, or erasure of your personal data, and object to certain processing. Erasure removes identifying data while keeping the financial records tax law requires. Contact us to exercise a right; you may also complain to your data-protection authority.