RoomDeck

Privacy Policy

Draft v20 · 10 September 2026
Before public launch: the legal identity and contact details of the data controller must be completed below. The current document is suitable as an implementation draft for the RoomDeck demo, not as a final signed-off legal notice.

1. Data controller

Controller: [TO COMPLETE — legal name / individual name]

Contact: [TO COMPLETE — privacy email and, where applicable, address]

2. What RoomDeck processes

RoomDeck is a room-search and comparison service. The public website does not require an account to search. The application currently processes:

  • Essential technical data needed to deliver and secure the website. Infrastructure provider Cloudflare may process request information such as IP address, device/browser metadata and security logs as part of hosting and network protection. RoomDeck does not intentionally write those identifiers into its custom analytics KV records.
  • Essential browser preferences: language preference and the user's privacy choice.
  • Optional first-party analytics, only after consent: a pseudonymous session identifier, timestamp, search city/query, stay dates, budget and selected filters, result counts, listing views, comparisons, provider views, Rent clicks, provider/offer identifiers and price/cost information attached to the viewed offer.

The custom analytics implementation is not designed to collect names, email addresses, account identifiers or device fingerprints.

3. Purposes and legal bases

Technical processing is used to provide, maintain and protect the service. Optional analytics is used to understand demand and the search funnel, improve RoomDeck and create aggregated market insights. Optional analytics runs only after the user has accepted analytics. Consent can be withdrawn at any time through “Privacy settings”; withdrawal stops future optional analytics.

4. Aggregated market insights

RoomDeck may use statistics derived from consented analytics to produce aggregated market intelligence, for example demand by city, budget band or provider performance. The current design does not make raw session-level analytics records available to accommodation providers. If that model changes, this notice and the consent mechanism must be reviewed before the change goes live.

5. Retention

Custom analytics events and consented outbound Rent-click records are configured with a 90-day retention period. The privacy-choice record is stored in the browser and is re-requested after approximately six months, unless the user changes or clears it earlier. A pseudonymous analytics session identifier is stored only for the browser session.

6. Recipients and infrastructure

RoomDeck uses Cloudflare for hosting, edge/network services and Workers/KV infrastructure. Cloudflare may act as a processor for relevant personal data under its contractual data-protection terms. Where international transfers apply, appropriate safeguards described in Cloudflare's applicable DPA may be used.

If the user voluntarily follows a link to an accommodation provider, the destination website will process the visit under its own privacy information and technical configuration.

7. Rights

Where the GDPR applies, users may exercise the rights available under applicable law, including access, rectification, erasure, restriction, objection where applicable, data portability where applicable, and withdrawal of consent. Users also have the right to lodge a complaint with the competent supervisory authority. Requests should be sent to the controller contact shown above.

8. Changes

RoomDeck will update this notice when the purposes, technologies, recipients or data flows materially change.

Cookie & tracking technologies policy

← RoomDeck