Privacy Policy
How Caldurea collects, uses, shares, and protects the information readers give us.
Last revised: 2 September 2026
1. What this notice covers
Caldurea publishes hospitality reviews and passes reservation enquiries to properties. Guarding personal data and explaining our handling of it clearly is an obligation we hold across all reader touchpoints.
Below we explain the categories Caldurea gathers, the purposes they serve, the parties they may reach, and the safeguards applied — whether you are reading rankings, creating a profile, or sending a stay enquiry.
2. What we collect through the service
To return accurate availability, verified assessments, and reliable enquiry confirmations, we handle several categories of record:
- Who you are and how to reach you
- Full name, form of address, preferred language, region of residence, email address, and any telephone number you supply when registering or submitting an enquiry.
- Reservation preferences
- Check-in and check-out dates, room type and bedding choice, suite tier, dietary requirements, accessibility needs, and hotel loyalty references.
- Billing and payment confirmation records
- The cardholder's name, masked card identifiers, billing location, and confirmation tokens issued by certified payment intermediaries. Complete card numbers never reach Caldurea systems.
- Technical metadata
- Internet protocol address, browser and operating system version, referring URLs, regional time zone, device identifiers, and page interaction times.
3. Legal grounds and operational purposes
Caldurea processes records only where a recognised legal basis applies: performance of a contract, legitimate business interest, compliance with a statutory duty, or your explicit consent. The operational purposes are:
- Enquiry fulfilment
- Transmitting itinerary details to the partner resort so a room hold and arrival preparations can be arranged.
- Content customisation
- Presenting hospitality rankings and reviews aligned with the regions and property categories you browse.
- Fraud prevention and security
- Safeguarding digital infrastructure, validating the legitimacy of transactions, and shielding users from unauthorised profile access.
- Service messages
- Issuing reservation updates, confirmation vouchers, itinerary reminders, and essential service notifications.
- Regulatory compliance
- Fulfilling financial disclosure rules, tax obligations, and other legal mandates that apply to our operations.
4. Who receives your information
Personal identifiers are never sold, rented, or leased to unaffiliated businesses. Data moves only where a contract governs it, and only to these recipients:
- The hotels themselves
- Listed hotels receive the minimum needed — name, travel dates, and room requirements — to process your request.
- Certified payment gateways
- Billing information travels encrypted to accredited payment gateways that maintain current PCI-DSS validation.
- Infrastructure providers
- Enterprise-grade data centres and delivery networks store encrypted backups to maintain uptime and disaster resilience.
- Courts and regulators
- Information may be released where a lawful subpoena, court order, or official mandate requires it, or to protect vital interests.
5. Digital identifiers and measurement
We use cookies and local storage to recognise returning readers, retain display preferences, measure performance, and keep sessions intact. Browser settings give you full control over these, though disabling essential cookies will limit parts of the enquiry process.
6. Storage protection and retention
Layered administrative, technical, and physical controls protect records against unauthorised access, loss, alteration, or extraction. These include TLS 1.3 in transit, AES-256 at rest, segregated database clusters, and role-restricted credentials.
We retain data only for the time required to fulfil the request, handle follow-up questions, meet audit standards, or comply with a retention schedule set in law. After that, records are deleted or anonymised beyond recovery.
7. Your rights
Where your jurisdiction provides them, and once we have verified who you are, the following rights are available:
- Access and inspection
- Obtain a portable copy of the personal records we hold and confirm how they are being handled.
- Rectification
- Ask us to fix any record that is inaccurate, incomplete, or no longer current.
- Deletion
- Ask for records to be deleted where no statutory or contractual basis for keeping them remains.
- Limiting processing
- Pause processing activity while a record's accuracy or our legitimate interest is under review.
Choices you can exercise
You have the right to control how your personal information is collected and used. Depending on your location and the laws that apply to you, the following opt-out choices are available:
- Data sharing and sale
- You may opt out of the sale or sharing of your personal information with third parties where laws such as the CCPA/CPRA in California, or comparable legislation elsewhere, provide for it. While we do not sell personal information in the conventional sense, some data may be shared with trusted partners in order to provide or improve the service.
- Tracking technologies
- You can manage or refuse cookies and tracking technologies through your browser settings, or through the cookie consent tools provided on this site.
- Marketing communications
- Promotional email and newsletters can be discontinued through the unsubscribe link in any message or by contacting us directly.
- Withdrawal of consent
- Where you previously consented to processing, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it.
Write to [email protected], or use the contact form on this site, to exercise any right or lodge an opt-out request.
8. Updates to this document
This notice may be refined periodically in line with legal or architectural change. Any material modification is reflected on this page with an updated date, and further use of the service constitutes acknowledgement.