Privacy Policy
Effective 24 September 2026 · Version 2026-09-24
This policy explains how [Company legal name] ("we") collects and uses personal data when you use onwardhotel.io. We are the controller of your personal data. We process it in line with the EU General Data Protection Regulation (GDPR), the UK GDPR and other applicable data protection laws, including the California Consumer Privacy Act (CCPA) where it applies.
1. Data we collect
- Identity and contact: your name as in your passport, email address.
- Reservation data: destination, dates, number of guests and rooms, the hotel and room booked, confirmation numbers and Reservation status.
- Payment data: plan, amounts, payment status and Stripe identifiers. Card details are collected and processed by Stripe; we never see or store your full card number.
- Account and security data: sign-in codes (stored only in hashed form), session identifiers, IP address and browser information recorded when you accept the Terms and when you sign in.
- Usage data: anonymous counts of page visits and steps in the booking flow, used to measure how the site performs. We don't use advertising trackers.
- Correspondence: messages you send us, and documents you provide for a refund request (for example a visa refusal letter).
2. Why we use it and our legal basis
| Purpose | Legal basis |
|---|---|
| Creating and holding your Reservation, sending the confirmation, voucher and service emails, managing your account | Performance of a contract |
| Taking payments, managing subscriptions, refunds and disputes | Performance of a contract; legal obligation (accounting) |
| Preventing fraud and misuse, securing the service | Legitimate interests |
| Measuring and improving the site with aggregated statistics | Legitimate interests |
| Keeping records required by tax and accounting law | Legal obligation |
We don't sell your personal data, and we don't use it for automated decisions that have legal or similarly significant effects on you.
3. Who we share it with
- Hotelbeds (our accommodation Supplier) and the hotel: guest name and stay details, to make and cancel the Reservation.
- Stripe: payment processing and fraud prevention. Stripe acts as an independent controller for some purposes; see stripe.com/privacy.
- Email delivery provider: to send codes, confirmations and vouchers.
- Cloudflare: content delivery, protection against attacks and cookieless, aggregated traffic statistics.
- Hosting and infrastructure providers: to run the site.
- Authorities and advisers: where required by law, or to establish or defend legal claims.
Our service providers process data only on our instructions and under written data processing terms.
4. International transfers
Hotels, our Supplier and service providers may be located outside your country, including outside the EEA/UK. Where we transfer personal data to a country without an adequacy decision, we use safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. Contact us for a copy.
5. How long we keep it
- Account and Reservation data: while your account is active and for up to 24 months after your last Reservation.
- Payment and invoice records: for as long as tax and accounting law requires (typically 6 to 10 years).
- Sign-in codes: 10 minutes. Sessions: 30 days. Aggregated usage statistics: up to 24 months.
6. Your rights
Depending on where you live, you have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. California residents have the right to know, delete and correct personal information and not to be discriminated against for exercising these rights; we do not sell or share personal information for cross-context behavioural advertising. To exercise any right, email [email protected]. We reply within one month. You may also complain to your data protection authority (for us, [Lead supervisory authority]).
7. Cookies
We use only strictly necessary cookies. See our Cookie Policy.
8. Security
We use encryption in transit (HTTPS), hashed sign-in codes, access controls and payment processing by a PCI DSS Level 1 certified provider. No system is completely secure; we will notify you and the authorities of a personal data breach where the law requires.
9. Children
The service is not intended for anyone under 18, and we don't knowingly collect their data. A Reservation for a travelling minor must be made by a parent or guardian.
10. Changes
We will post any changes here and, if they are significant, notify account holders by email.
11. Contact
[Company legal name], [Registered office address]. Data protection enquiries: [email protected].