Last updated: August 10, 2026

1. What We Collect

When you submit a hotel booking to Rate Ranger, we collect:

We deliberately do not collect booking identifiers: no confirmation number, no guest name, nothing that could be used to alter your reservation.

We do not require you to create an account. Your email address is your identifier.

We also detect your approximate geographic region from your IP address when you submit a booking, stored as a two-letter country code. This is used to route you to the most relevant booking links. We do not store your IP address.

When you submit a booking we also record how you first reached our site during that visit: a traffic-source label (for example "organic_search" or the name of an AI assistant such as ChatGPT), the domain that referred you, and the first page of ours you landed on. This tells us which of our articles are useful enough to bring people here. It contains nothing about you personally, is never combined with third-party data or used to build a profile, and is deleted along with the rest of your booking data.

2. Lawful Basis for Processing (GDPR)

We process your personal data under the following lawful bases as defined by the General Data Protection Regulation (GDPR):

3. How We Use Your Data

We do not sell your personal data to third parties. We do not use your data for advertising.

4. Booking Data & Automated Processing

When you submit booking details, our system stores only the booking-relevant fields listed in Section 1. Guest names are deleted according to the retention schedule in Section 6.

To look up your hotel's rates we sometimes need to determine the hotel's country. When it isn't already known, we send the hotel name and city — and nothing else — to OpenAI (GPT-4o-mini) to resolve the hotel's location. No email address, name, or other personal identifier is ever included.

5. Third-Party Services & Data Processors

We use the following third-party services to operate Rate Ranger. Where data is transferred from the EU/EEA to processors in the United States, we rely on each processor's Data Processing Addendum and Standard Contractual Clauses (SCCs) to provide adequate safeguards under GDPR Chapter V.

6. Data Retention

We retain your data only as long as necessary to provide our service. The following retention periods are automatically enforced:

You may request immediate deletion of all your data at any time (see Section 7).

7. Your Rights (GDPR)

If you are located in the EU/EEA, you have the following rights under the General Data Protection Regulation:

How to exercise your rights:

We will respond to all data subject requests within 30 days, as required by GDPR Article 12(3).

8. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

To report a security concern, contact hello@rateranger.io.

9. Cookies & Analytics

We ask for your consent before any non-essential cookie or similar storage is set. You can change your choice at any time via the Cookie Settings link in the footer of every page — withdrawing consent is exactly as easy as giving it.

Category What it's for How long
Necessary Remembers your cookie choice, so we don't ask again. ~6 months
Necessary A quick, invisible check on the booking form that keeps out automated spam. It doesn't track you across other sites or build a profile of you. While you're on the form
Analytics (opt-in) Helps us see which pages and referral sources bring visitors who go on to submit a booking, so we know what's working. Only active if you say yes. Up to 2 years
Analytics (opt-in) Remembers which page or referral source brought you here for the rest of your visit, so a booking submitted a few clicks later still gets credited correctly. Only saved if you say yes; cleared as soon as you close the tab. Until you close the tab

We also use a separate, cookie-free analytics tool that only counts anonymous page views — it never identifies you and doesn't need your consent to run.

When you click a booking link in a Rate Ranger email or on this site and visit a third-party booking site (such as Agoda), that site may set its own cookies. These are governed by the respective third party's cookie policy, not ours.

We do not sell or share your personal information, and we do not use cookies for advertising or cross-site tracking of any kind.

For the specific services behind these cookies, see Section 5 above.

10. Security

We implement the following security measures to protect your data:

11. Children

Rate Ranger is not intended for use by individuals under 18 years of age. We do not knowingly collect data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at hello@rateranger.io.

12. International Data Transfers

Rate Ranger processes data in the United States via our sub-processors (AWS, Supabase, Resend, OpenAI). Our affiliate tracking partner (Agoda) may process click data in the US and EU. For users in the EU/EEA, we ensure adequate safeguards for international data transfers through Standard Contractual Clauses (SCCs) and Data Processing Addendums (DPAs) with each processor, as required by GDPR Chapter V.

13. Supervisory Authority

If you are located in the EU/EEA and believe we are processing your data unlawfully, you have the right to lodge a complaint with the Irish Data Protection Commission (DPC), our lead supervisory authority, or with the supervisory authority in your EU/EEA member state of residence.

Irish Data Protection Commission: www.dataprotection.ie

14. Changes

We may update this Privacy Policy from time to time. Material changes will be communicated via email to active users. The "Last updated" date at the top of this page indicates when the policy was last revised.

15. Contact

For questions about this Privacy Policy, your data, or to exercise your rights, contact us at hello@rateranger.io.