1. Scope
This policy covers the website top10hotelsca.com and the booking-request service operated by top10hotel ("we", "us"). It does not cover the websites of the hotels we list, or any booking channel you are redirected to; they have their own privacy policies.
2. What we collect
We collect only what we need to answer your request and run the site.
| Category | Examples | When |
|---|---|---|
| Contact details | Name, email address, phone number (optional) | When you submit the contact form |
| Trip details | Hotel, check-in and check-out dates, number of guests and rooms, special requests | When you use the booking form and send a request |
| Correspondence | Emails between you and our team, including hotel confirmations we forward | During and after a booking |
| Technical data | IP address, browser type, pages visited, approximate location derived from IP | Automatically, through server logs and analytics (if enabled) |
We do not ask for, and you should not send us, payment card numbers, passport numbers or other sensitive identity documents. Payment is made directly to the hotel.
3. How the booking form works
The date and hotel selections you make on the home page are processed in your browser. Nothing is transmitted to us until you open the contact form and press "Send request". The estimated total shown is calculated locally from the starting rate displayed on the page.
4. Why we use your data
- To answer your request and check availability with the hotel you chose. Legal basis: taking steps at your request before entering into a contract.
- To send you the hotel's offer, confirmation and any changes. Legal basis: performance of the arrangement you asked for.
- To keep records of completed bookings for accounting and commission reconciliation. Legal basis: legal obligation and legitimate interest.
- To keep the website secure and understand how it is used. Legal basis: legitimate interest.
- To send you occasional news about hotels on our list, only if you have asked for it. Legal basis: consent, which you can withdraw at any time.
We do not sell personal data, and we do not use it for automated decision-making or profiling.
5. Who we share it with
We share your name, contact details and trip details with the hotel, or its official reservations partner, that you asked us to book. That is the purpose of the request and cannot be avoided. We also use a small number of service providers who process data on our behalf: our email host, our web hosting provider, and, if enabled, an analytics service. Each is bound by a contract to use the data only for our instructions. We disclose data to authorities only when the law requires it.
6. Cookies
This site uses no cookies for tracking or advertising. The booking form stores nothing in your browser between visits. If we enable an analytics tool in future, we will use a cookie-free or consent-based configuration and update this section first. Google Fonts are loaded from Google's servers, which means Google receives your IP address when the page loads; you can block this with a browser extension without affecting the site's function.
7. How long we keep data
| Data | Retention |
|---|---|
| Requests that do not lead to a booking | Deleted 12 months after the last message |
| Completed bookings and related correspondence | 7 years, for accounting and tax purposes |
| Newsletter consent | Until you unsubscribe, then the address is removed within 30 days |
| Server logs | 90 days |
8. Where data is stored
Our systems are hosted in the United States. If you contact us from the European Economic Area, the United Kingdom or Switzerland, your data is transferred to the US under standard contractual clauses or an equivalent lawful mechanism. Hotels you book outside your own country will process your data under their local law.
9. Your rights
Depending on where you live, you may have the right to:
- Ask what personal data we hold about you and receive a copy.
- Have inaccurate data corrected.
- Have your data deleted, unless we must keep it for a legal reason.
- Restrict or object to how we use it.
- Receive your data in a portable format.
- Withdraw consent for marketing at any time.
- Complain to a supervisory authority. Residents of California can exercise their rights under the CCPA/CPRA by contacting us at the address below; we do not sell or share personal information for cross-context behavioural advertising.
To exercise any of these rights, email [email protected] from the address you used with us, or write to the postal address above. We reply within 30 days. We may ask for confirmation of your identity before releasing data.
10. Security
The site is served over HTTPS. Access to request emails is limited to the team members who handle bookings, protected by two-factor authentication. No method of transmission or storage is completely secure; if we become aware of a breach affecting your data, we will notify you and the relevant authority as the law requires.
11. Children
This site is intended for adults. We do not knowingly collect data from anyone under 18. If you believe a child has sent us personal data, contact us and we will delete it.
12. Changes to this policy
We will post any changes on this page and update the date at the top. Significant changes will be announced on the home page for at least 30 days.
13. Contact
Privacy questions and requests: [email protected]
top10hotel, 1200 Harbor View Drive, Suite 4, San Diego, CA 92101, USA
Phone: +1 (619) 555-0148