1. What We Collect
When you submit a hotel booking to Rate Ranger, we collect:
- Your email address: so we can send you price alerts and booking confirmations.
- Booking details: hotel name, city, check-in/check-out dates, room type, number of guests and rooms, price, currency, and the site you booked on.
We deliberately do not collect booking identifiers: no confirmation number, no guest name, nothing that could be used to alter your reservation.
We do not require you to create an account. Your email address is your identifier.
We also detect your approximate geographic region from your IP address when you submit a booking, stored as a two-letter country code. This is used to route you to the most relevant booking links. We do not store your IP address.
When you submit a booking we also record how you first reached our site during that visit: a traffic-source label (for example "organic_search" or the name of an AI assistant such as ChatGPT), the domain that referred you, and the first page of ours you landed on. This tells us which of our articles are useful enough to bring people here. It contains nothing about you personally, is never combined with third-party data or used to build a profile, and is deleted along with the rest of your booking data.
2. Lawful Basis for Processing (GDPR)
We process your personal data under the following lawful bases as defined by the General Data Protection Regulation (GDPR):
- Contract performance (Article 6(1)(b)): When you submit booking details to us, you are requesting a service. Processing your data is necessary to perform that service (monitoring hotel prices and sending alerts).
- Legitimate interest (Article 6(1)(f)): We have a legitimate interest in improving our service, preventing abuse, and communicating relevant updates. This processing does not override your fundamental rights.
3. How We Use Your Data
- Price monitoring: We use your booking details to search for lower prices across publicly available hotel booking websites.
- Email notifications: We send you price drop alerts, booking confirmations, and cancellation deadline reminders.
- Service improvement: We may use aggregated, anonymized data to improve our price-monitoring accuracy and service reliability.
We do not sell your personal data to third parties. We do not use your data for advertising.
4. Booking Data & Automated Processing
When you submit booking details, our system stores only the booking-relevant fields listed in Section 1. Guest names are deleted according to the retention schedule in Section 6.
To look up your hotel's rates we sometimes need to determine the hotel's country. When it isn't already known, we send the hotel name and city — and nothing else — to OpenAI (GPT-4o-mini) to resolve the hotel's location. No email address, name, or other personal identifier is ever included.
5. Third-Party Services & Data Processors
We use the following third-party services to operate Rate Ranger. Where data is transferred from the EU/EEA to processors in the United States, we rely on each processor's Data Processing Addendum and Standard Contractual Clauses (SCCs) to provide adequate safeguards under GDPR Chapter V.
- Amazon Web Services (AWS): Compute (Lambda), file storage (S3), and email reception (SES) for messages sent to our contact address. Data is processed in the US East (N. Virginia) region. AWS provides GDPR DPA and SCCs. Data shared: booking data (processed in Lambda).
- Supabase: Database hosting (Postgres) for booking records, price checks, alerts, and user data. Hosted in the US. Supabase provides GDPR DPA. Data shared: all structured booking and user data.
- Resend: Outbound email delivery for all transactional emails. Data shared: your email address and email content.
- SerpAPI: Hotel price lookups via Google Hotels search results. Data shared: hotel name, city, and dates only. No personal information (email, name) is sent to SerpAPI.
- DataForSEO: Hotel price lookups via Google Hotels data. Data shared: hotel name, city, country, and stay dates only. No personal information (email, name) is sent to DataForSEO.
- OpenAI: GPT-4o-mini for resolving a hotel's location (country) from its name and city when needed for rate lookups. Data shared: hotel name and city only (no personal identifiers). OpenAI provides GDPR DPA and does not use API data for model training.
- Cloudflare: Privacy-friendly website analytics (Cloudflare Web Analytics). Cloudflare collects aggregated, anonymous page view data including: pages visited, referrer URL, browser type, device type, and country. Cloudflare Web Analytics does not use cookies, does not track individual users, does not collect IP addresses, and does not fingerprint browsers. No personal data is shared with Cloudflare through this service. Data shared: anonymous page view metadata only. Cloudflare also runs a brief, invisible security check on our booking form to keep out automated spam; it does not build a profile of you or track you across other sites.
- Google Analytics: Website usage analytics, only if you accept the "Analytics" cookie category (see Section 9). Data shared: pages viewed, referral source, and general device/browser information. No booking or account data is shared with Google Analytics.
- Agoda International: Affiliate tracking via a CID parameter on Agoda booking links. Data shared: click event only. No personal data is sent to Agoda beyond what appears in the booking URL.
6. Data Retention
We retain your data only as long as necessary to provide our service. The following retention periods are automatically enforced:
- Active bookings: Retained while being monitored. Automatically set to "expired" 30 days after your check-out date.
- Price check history: Deleted after 90 days.
- Your account and email address: Retained as long as you have active or recent bookings. Automatically deleted 90 days after your last check-out if you have no active bookings.
You may request immediate deletion of all your data at any time (see Section 7).
7. Your Rights (GDPR)
If you are located in the EU/EEA, you have the following rights under the General Data Protection Regulation:
- Right of access (Article 15): You can request a copy of all data we hold about you.
- Right to erasure (Article 17): You can request permanent deletion of all your data.
- Right to data portability (Article 20): You can receive your data in a structured, machine-readable format (JSON).
- Right to rectification (Article 16): You can correct inaccurate booking data by using the "Need to update your booking details?" link in any email we send you or contacting us.
- Right to object (Article 21): You can stop monitoring for any booking via the unsubscribe link in every email.
How to exercise your rights:
- Unsubscribe from a booking: Click the "Unsubscribe" link in any Rate Ranger email.
- Delete all your data: Click the "Delete my data" link in any Rate Ranger email, or email hello@rateranger.io.
- Export your data: Email hello@rateranger.io to request a data export.
We will respond to all data subject requests within 30 days, as required by GDPR Article 12(3).
8. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority (the Irish Data Protection Commission) within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
- Notify affected users via email without undue delay, as required by GDPR Article 34, when the breach is likely to result in a high risk to your rights and freedoms.
- The notification will describe the nature of the breach, the likely consequences, and the measures taken to address it.
To report a security concern, contact hello@rateranger.io.
9. Cookies & Analytics
We ask for your consent before any non-essential cookie or similar storage is set. You can change your choice at any time via the Cookie Settings link in the footer of every page — withdrawing consent is exactly as easy as giving it.
| Category | What it's for | How long |
|---|---|---|
| Necessary | Remembers your cookie choice, so we don't ask again. | ~6 months |
| Necessary | A quick, invisible check on the booking form that keeps out automated spam. It doesn't track you across other sites or build a profile of you. | While you're on the form |
| Analytics (opt-in) | Helps us see which pages and referral sources bring visitors who go on to submit a booking, so we know what's working. Only active if you say yes. | Up to 2 years |
| Analytics (opt-in) | Remembers which page or referral source brought you here for the rest of your visit, so a booking submitted a few clicks later still gets credited correctly. Only saved if you say yes; cleared as soon as you close the tab. | Until you close the tab |
We also use a separate, cookie-free analytics tool that only counts anonymous page views — it never identifies you and doesn't need your consent to run.
When you click a booking link in a Rate Ranger email or on this site and visit a third-party booking site (such as Agoda), that site may set its own cookies. These are governed by the respective third party's cookie policy, not ours.
We do not sell or share your personal information, and we do not use cookies for advertising or cross-site tracking of any kind.
For the specific services behind these cookies, see Section 5 above.
10. Security
We implement the following security measures to protect your data:
- Encryption in transit (TLS/HTTPS) for all data transfers.
- Row-level security (RLS) policies on our database to restrict access.
- HMAC-signed tokens for all email action links to prevent unauthorized access.
- API keys and credentials stored in environment variables, never in source code.
- CORS restrictions on our API to prevent cross-origin abuse.
- No password storage (email-only identification eliminates password breach risk).
11. Children
Rate Ranger is not intended for use by individuals under 18 years of age. We do not knowingly collect data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at hello@rateranger.io.
12. International Data Transfers
Rate Ranger processes data in the United States via our sub-processors (AWS, Supabase, Resend, OpenAI). Our affiliate tracking partner (Agoda) may process click data in the US and EU. For users in the EU/EEA, we ensure adequate safeguards for international data transfers through Standard Contractual Clauses (SCCs) and Data Processing Addendums (DPAs) with each processor, as required by GDPR Chapter V.
13. Supervisory Authority
If you are located in the EU/EEA and believe we are processing your data unlawfully, you have the right to lodge a complaint with the Irish Data Protection Commission (DPC), our lead supervisory authority, or with the supervisory authority in your EU/EEA member state of residence.
Irish Data Protection Commission: www.dataprotection.ie
14. Changes
We may update this Privacy Policy from time to time. Material changes will be communicated via email to active users. The "Last updated" date at the top of this page indicates when the policy was last revised.
15. Contact
For questions about this Privacy Policy, your data, or to exercise your rights, contact us at hello@rateranger.io.