Privacy Policy

Last updated: 14 July 2026
Operated by Hotelsrating LLC, Sharjah, UAE.

This policy describes what HotelsRating actually collects and does with it, no more, no less. We are a hotel rating service: most of what we publish is data about hotels, not about you, and we aim to keep it that way.

1. Who we are

HotelsRating (https://hotelsrating.com) is operated by Hotelsrating LLC, Sharjah, UAE ("we"). We publish the HotelsRating Index (HRI), an independent hotel rating with a public methodology. For anything in this policy, contact us at [email protected].

2. What we collect, why, and for how long

You can browse the site, including every hotel page and ranking, without an account. If you do nothing else, the only data involved is server logs and analytics (sections 2.7 and 2.8).

2.1 Account data

If you register, we collect your e-mail address and display name. Authentication is handled by Google Firebase Authentication acting as our processor; your password is stored by Firebase, not on our servers. If you enable two-factor authentication, we store the secret needed to verify your codes. Kept until you delete your account.

2.2 Travel preferences

If you complete the optional personalization onboarding, we store the travel archetypes and preferences you choose (for example "family" or "remote work"). They are used solely to compute your Personalized Fit Index on top of the public HRI. Kept until you change them or delete your account.

2.3 Hotel claim requests

If you claim a hotel page, we collect your name, position, work e-mail, optional phone number, the hotel you are claiming, and any proof documents you attach. Used to verify that you represent the property. Kept while the claim and the resulting ownership are active.

2.4 Hotel subscription billing

Hotel subscriptions are processed by Stripe. We store your Stripe customer reference and the subscription status and period; your card details go directly to Stripe and never touch our servers. Kept for the duration of the subscription plus the period required by accounting rules.

2.5 Content you submit

If you submit videos or link a social account, we store the video reference, the platform link, and the authorization tokens needed to read it. Kept until you remove the content or delete your account.

2.6 Outbound link clicks

When you click a partner booking link (for example "Book on Booking.com"), we log which hotel and partner were clicked, the time, and an anonymous session hash. The log contains no name or e-mail and is used to account for affiliate commissions and detect abuse. See the Affiliate Disclosure.

Likewise, when you click a hotel's published direct contact link (its website, phone, or social profiles), we log which hotel and which contact type was clicked, the time, and the same anonymous session hash. The log contains no name or e-mail. It gives the hotel owner an aggregate count of how often visitors engage with their contact details and helps us detect abuse; it is never used for advertising and is never shared.

2.7 Server logs

Like virtually every website, our servers log the IP address, browser user-agent, and requested URL of each request. Logs are used for security and operations and are rotated on a fixed schedule.

2.8 Analytics

We use Google Analytics 4 to understand aggregate usage of the site (which pages are visited, from which countries, on which devices). Google Analytics sets cookies listed in the Cookie Policy and processes data on our behalf. We look at this data in aggregate; we do not use it to build individual profiles.

2.9 Page-view counts

We keep a daily tally of how many times each hotel page is viewed, so the hotel's owner can see engagement. We store only the hotel, the date, and a count: no visitor identity, IP, or session is recorded (the browser user-agent is read momentarily to exclude automated traffic and is not kept). The tally also excludes an owner's views of their own page.

3. Contact information submitted by third parties

Contact details submitted on behalf of a hotel. Where our referral partners submit business contact information for a hotel (such as a general manager's name, business email or phone number) as part of introducing that hotel to HotelsRating, we process this information on the basis of our legitimate interest in operating a hotel referral program. We use it solely to contact the hotel about claiming and managing its page on HotelsRating, and to attribute the referral. We do not publish it, sell it, or use it for unrelated marketing.

What we store and for how long. We store the contact details, the identity of the submitting partner, and the date of submission, for as long as the referral is active and for up to 24 months afterwards for commission attribution, after which they are deleted or anonymized.

Your rights. If your contact details were submitted by a third party, you may at any time request access, correction or deletion by writing to [email protected]. Deletion requests are honored within 30 days and do not affect any hotel page content, which is managed separately by the hotel itself.

4. What we do not collect or do

  • We do not sell or rent personal data to anyone.
  • We do not store card numbers, payment details live with Stripe.
  • We do not collect precise location; country-level statistics come from analytics.
  • We do not run third-party advertising trackers on the site.
  • Personal data plays no role in hotel scores: the HRI is computed from hotel data and published sources, as described in the methodology.

5. Service providers we share data with

  • Google (Firebase Authentication), account sign-in; processor for account data.
  • Google (Google Analytics 4), aggregate usage analytics.
  • Stripe, payment processing for hotel subscriptions.
  • Resend, transactional e-mail delivery (confirmations, claim updates).

Each provider receives only what its function requires and acts under its own data processing terms. We do not share personal data with hotels beyond what you submit to them yourself (for example a claim request for their property).

Where the GDPR applies: account, preferences, claims, billing and content data are processed to perform our contract with you; server logs and click logs under our legitimate interest in running a secure service; analytics cookies on the basis of consent.

7. Your rights

You may request access to, correction of, or deletion of your personal data, object to or restrict processing, and receive a portable copy. Write to [email protected] and we will respond within one month. You also have the right to lodge a complaint with your local data protection authority.

8. Deleting your data

Account deletion is self-service and immediate: the Data Deletion page deletes your account, preferences, claims, submitted content and linked social accounts in one step. Residual copies in encrypted backups expire with the backup rotation cycle.

9. Children

The service is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child has created an account, contact us and we will delete it.

10. Changes to this policy

We will post any changes on this page and update the date at the top. Material changes will be announced on the site before they take effect.