Data protection

Privacy Policy

How Arbelinta collects, uses, shares, and protects the information readers give us.

Last updated: 2 September 2026

1. Scope and application

As an editorial catalogue and booking-enquiry directory for premier accommodation, Arbelinta takes on a firm duty to protect individual records and to maintain transparency wherever readers interact with the service.

This document sets out what Arbelinta collects, how it is organised and used, when it is transferred, and how it is protected when you browse the catalogue, read ratings, register a profile, or submit an accommodation request.

2. Categories of information gathered

To return accurate availability, verified assessments, and reliable enquiry confirmations, we handle several categories of record:

Identity and contact details
Name, salutation, chosen language, residential region, the email address you authorise, and telephone contact points given at registration or enquiry.
Stay preferences and requirements
Check-in and check-out dates, room type and bedding choice, suite tier, dietary requirements, accessibility needs, and hotel loyalty references.
Billing verification records
The cardholder's name, masked card identifiers, billing location, and confirmation tokens issued by certified payment intermediaries. Complete card numbers never reach Arbelinta systems.
Device telemetry and technical metadata
Internet protocol address, browser and operating system version, referring URLs, regional time zone, device identifiers, and page interaction times.

3. Legal grounds and operational purposes

Processing takes place only under an established lawful ground — contractual necessity, legitimate interest, legal obligation, or consent you have given. Those grounds support the following purposes:

Enquiry fulfilment
Transmitting itinerary details to the partner resort so a room hold and arrival preparations can be arranged.
Editorial personalisation
Adjusting the rankings and guides we surface to match the destinations and property styles you have shown interest in.
Security and verification
Keeping the infrastructure secure, verifying that requests are legitimate, and preventing unauthorised access to reader profiles.
Operational communication
Issuing reservation updates, confirmation vouchers, itinerary reminders, and essential service notifications.
Regulatory compliance
Satisfying accounting disclosure, tax reporting, and other duties imposed by the jurisdictions in which we operate.

4. Disclosure and partners

We do not sell, rent, or lease personal identifiers to unconnected commercial parties. Transfers happen only under contractual safeguards, and only to the following categories of recipient:

Partner properties
Resorts receive the guest name, dates, and accommodation specifics strictly necessary to respond to a request or honour a reservation.
Payment processors
Encrypted billing data passes to certified financial gateways operating to current PCI-DSS validation standards.
Infrastructure providers
Encrypted database backups sit with tier-1 hosting and content distribution providers to ensure availability.
Legal and regulatory authorities
Disclosure may follow a valid legal demand, court order, or regulatory mandate, or be necessary to protect someone's vital interests.

5. Cookies and analytics

Digital identifiers and local storage support returning-visitor recognition, preference retention, performance measurement, and session continuity. Control rests with you via browser configuration; blocking essential cookies will impair some features.

6. Safeguards and how long we keep records

Layered administrative, technical, and physical controls protect records against unauthorised access, loss, alteration, or extraction. These include TLS 1.3 in transit, AES-256 at rest, segregated database clusters, and role-restricted credentials.

Retention lasts no longer than the enquiry, any related correspondence, audit obligations, or a statutory holding period demand. At expiry, records are erased permanently or anonymised irrevocably.

7. Individual rights

Where your jurisdiction provides them, and once we have verified who you are, the following rights are available:

Access
Receive a copy of the data we hold about you, in a portable form, along with an explanation of its use.
Rectification
Request prompt correction of profile information that is wrong, partial, or out of date.
Erasure
Ask for records to be deleted where no statutory or contractual basis for keeping them remains.
Restriction
Restrict our use of your data during any dispute over accuracy or over our grounds for processing.

Choices you can exercise

How your personal information is gathered and used remains under your control. Subject to your location and the applicable legislation, you may exercise these opt-outs:

Sharing and sale of your data
You may opt out of the sale or sharing of your personal information with third parties where laws such as the CCPA/CPRA in California, or comparable legislation elsewhere, provide for it. While we do not sell personal information in the conventional sense, some data may be shared with trusted partners in order to provide or improve the service.
Tracking technologies
Cookies and similar tracking tools can be managed or declined via your browser configuration or the consent controls published on this website.
Marketing messages
Opt out of promotional messages and newsletters using the unsubscribe link in any communication, or by writing to us.
Consent withdrawal
Where you previously consented to processing, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it.

Requests to exercise these rights, or to opt out, can be sent to [email protected] or submitted through our contact form.

8. Updates to this document

This notice may be refined periodically in line with legal or architectural change. Any material modification is reflected on this page with an updated date, and further use of the service constitutes acknowledgement.