Data protection

Privacy Policy

How Caldurea collects, uses, shares, and protects the information readers give us.

Last revised: 2 September 2026

1. What this notice covers

Caldurea publishes hospitality reviews and passes reservation enquiries to properties. Guarding personal data and explaining our handling of it clearly is an obligation we hold across all reader touchpoints.

Below we explain the categories Caldurea gathers, the purposes they serve, the parties they may reach, and the safeguards applied — whether you are reading rankings, creating a profile, or sending a stay enquiry.

2. What we collect through the service

To return accurate availability, verified assessments, and reliable enquiry confirmations, we handle several categories of record:

Who you are and how to reach you
Full name, form of address, preferred language, region of residence, email address, and any telephone number you supply when registering or submitting an enquiry.
Reservation preferences
Check-in and check-out dates, room type and bedding choice, suite tier, dietary requirements, accessibility needs, and hotel loyalty references.
Billing and payment confirmation records
The cardholder's name, masked card identifiers, billing location, and confirmation tokens issued by certified payment intermediaries. Complete card numbers never reach Caldurea systems.
Technical metadata
Internet protocol address, browser and operating system version, referring URLs, regional time zone, device identifiers, and page interaction times.

3. Legal grounds and operational purposes

Caldurea processes records only where a recognised legal basis applies: performance of a contract, legitimate business interest, compliance with a statutory duty, or your explicit consent. The operational purposes are:

Enquiry fulfilment
Transmitting itinerary details to the partner resort so a room hold and arrival preparations can be arranged.
Content customisation
Presenting hospitality rankings and reviews aligned with the regions and property categories you browse.
Fraud prevention and security
Safeguarding digital infrastructure, validating the legitimacy of transactions, and shielding users from unauthorised profile access.
Service messages
Issuing reservation updates, confirmation vouchers, itinerary reminders, and essential service notifications.
Regulatory compliance
Fulfilling financial disclosure rules, tax obligations, and other legal mandates that apply to our operations.

4. Who receives your information

Personal identifiers are never sold, rented, or leased to unaffiliated businesses. Data moves only where a contract governs it, and only to these recipients:

The hotels themselves
Listed hotels receive the minimum needed — name, travel dates, and room requirements — to process your request.
Certified payment gateways
Billing information travels encrypted to accredited payment gateways that maintain current PCI-DSS validation.
Infrastructure providers
Enterprise-grade data centres and delivery networks store encrypted backups to maintain uptime and disaster resilience.
Courts and regulators
Information may be released where a lawful subpoena, court order, or official mandate requires it, or to protect vital interests.

5. Digital identifiers and measurement

We use cookies and local storage to recognise returning readers, retain display preferences, measure performance, and keep sessions intact. Browser settings give you full control over these, though disabling essential cookies will limit parts of the enquiry process.

6. Storage protection and retention

Layered administrative, technical, and physical controls protect records against unauthorised access, loss, alteration, or extraction. These include TLS 1.3 in transit, AES-256 at rest, segregated database clusters, and role-restricted credentials.

We retain data only for the time required to fulfil the request, handle follow-up questions, meet audit standards, or comply with a retention schedule set in law. After that, records are deleted or anonymised beyond recovery.

7. Your rights

Where your jurisdiction provides them, and once we have verified who you are, the following rights are available:

Access and inspection
Obtain a portable copy of the personal records we hold and confirm how they are being handled.
Rectification
Ask us to fix any record that is inaccurate, incomplete, or no longer current.
Deletion
Ask for records to be deleted where no statutory or contractual basis for keeping them remains.
Limiting processing
Pause processing activity while a record's accuracy or our legitimate interest is under review.

Choices you can exercise

You have the right to control how your personal information is collected and used. Depending on your location and the laws that apply to you, the following opt-out choices are available:

Data sharing and sale
You may opt out of the sale or sharing of your personal information with third parties where laws such as the CCPA/CPRA in California, or comparable legislation elsewhere, provide for it. While we do not sell personal information in the conventional sense, some data may be shared with trusted partners in order to provide or improve the service.
Tracking technologies
You can manage or refuse cookies and tracking technologies through your browser settings, or through the cookie consent tools provided on this site.
Marketing communications
Promotional email and newsletters can be discontinued through the unsubscribe link in any message or by contacting us directly.
Withdrawal of consent
Where you previously consented to processing, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it.

Write to [email protected], or use the contact form on this site, to exercise any right or lodge an opt-out request.

8. Updates to this document

This notice may be refined periodically in line with legal or architectural change. Any material modification is reflected on this page with an updated date, and further use of the service constitutes acknowledgement.