— Legal —
Privacy Policy
How we collect, use, and protect your personal data.
Last updated: 2026-06-08
Template — review with legal counsel and fill in company details before launch.
1. Who We Are
[COMPANY_NAME], located at [REGISTERED_ADDRESS] ("we", "us"), is the data controller responsible for your personal data when you use Travelissimo. For any privacy questions, contact [CONTACT_EMAIL].
2. Data We Collect
We collect: account details (name, email, phone), booking details (reference, dates, room preferences, special requests), payment metadata via Stripe (we do not store full card numbers), and technical data such as IP address, device, and cookie identifiers.
3. Purpose & Legal Basis
We process your data to: provide and confirm room locks and guarantees (performance of a contract), communicate status updates (legitimate interest / contract), process payments (contract and legal obligation), and improve and secure the Service (legitimate interest). Where required, we rely on your consent — for example, non-essential cookies.
4. Cookies
We use essential cookies needed to run the Service and, only with your consent, non-essential cookies for analytics. You can manage your choice at any time via the cookie banner. Declining non-essential cookies will not affect core functionality.
5. Sharing & Processors
We share data with partner hotels strictly to fulfil your booking, and with processors who act on our instructions — including Stripe (payments) and our hosting and email providers. We do not sell your personal data.
6. Retention
We keep personal data only as long as necessary for the purposes above: account data for the life of your account, and booking and payment records for the period required by applicable tax and accounting law. After that, data is deleted or anonymised.
7. International Transfers
Where data is transferred outside your region, we rely on appropriate safeguards such as standard contractual clauses or an adequacy decision, consistent with applicable data-protection law.
8. Your Rights
Subject to applicable law, you have the right to access, rectify, erase, restrict, or object to processing of your data, the right to data portability, and the right to withdraw consent at any time. You may also lodge a complaint with your local supervisory authority. To exercise any right, contact [CONTACT_EMAIL]; we respond within the time required by law.
9. Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Children
The Service is not directed to children under 18, and we do not knowingly collect their data. If you believe a child has provided us data, contact [CONTACT_EMAIL] and we will delete it.
11. Changes to This Policy
We may update this Policy from time to time. Material changes will be notified through the Service or by email, and the "last updated" date above will change.
Contact
Questions about this document? Reach us at [CONTACT_EMAIL] or write to [COMPANY_NAME], [REGISTERED_ADDRESS].