Last updated: August 21, 2026

1. What We Collect

When you submit a hotel booking to Rate Ranger, we collect:

We deliberately do not collect booking identifiers: no confirmation number, no guest name, nothing that could be used to alter your reservation.

We do not require you to create an account. Your email address is your identifier.

We also detect your approximate geographic region from your IP address when you submit a booking, stored as a two-letter country code. This is used to route you to the most relevant booking links. We do not store your IP address.

When you submit a booking we also record how you first reached our site during that visit: a traffic-source label (for example "organic_search" or the name of an AI assistant such as ChatGPT), the domain that referred you, and the first page of ours you landed on. This tells us which of our articles are useful enough to bring people here. It contains nothing about you personally, is never combined with third-party data or used to build a profile, and is deleted along with the rest of your booking data.

2. Lawful Basis for Processing (GDPR)

We process your personal data under the following lawful bases as defined by the General Data Protection Regulation (GDPR):

3. How We Use Your Data

We do not sell your personal data to third parties. We do not use your data for advertising.

4. Booking Data & Automated Processing

When you submit booking details, our system stores only the booking-relevant fields listed in Section 1. Guest names are deleted according to the retention schedule in Section 6.

To look up your hotel's rates we sometimes need to determine the hotel's country. When it isn't already known, we send the hotel name and city, and nothing else, to OpenAI (GPT-4o-mini) to resolve the hotel's location. No email address, name, or other personal identifier is ever included.

5. Third-Party Services & Data Processors

We use the following third-party services to operate Rate Ranger. Where data is transferred from the EU/EEA to processors in the United States, we rely on each processor's Data Processing Addendum and Standard Contractual Clauses (SCCs) to provide adequate safeguards under GDPR Chapter V.

6. Data Retention

We retain your data only as long as necessary to provide our service. The following retention periods are automatically enforced:

You may request immediate deletion of all your data at any time (see Section 7).

7. Your Rights (GDPR)

If you are located in the EU/EEA, you have the following rights under the General Data Protection Regulation:

How to exercise your rights:

We will respond to all data subject requests within 30 days, as required by GDPR Article 12(3).

8. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

To report a security concern, contact hello@rateranger.io.

9. Cookies & Analytics

Rate Ranger sets no analytics cookies, no advertising cookies, and nothing that follows you between sites. That is why this site has no cookie banner: there is nothing to ask you to agree to. We removed Google Analytics on 21 August 2026.

One cookie remains, and only while you are using the booking form. Cloudflare Turnstile sets it to run a brief, invisible check that keeps automated spam off the form. It is required for the form to work safely, it expires when you leave, and it does not build a profile of you or follow you anywhere else.

To count visits we use Cloudflare Web Analytics, which is cookie-free. It records anonymous page views without identifying you, without collecting your IP address, and without fingerprinting your browser.

We also note which page you were reading when you came to the booking form, so we know which articles are worth writing. That travels in the page address as you click, is removed from the address bar as soon as the page loads, and is never saved on your device.

When you click a booking link in a Rate Ranger email or on this site and visit a third-party booking site (such as Agoda), that site may set its own cookies. These are governed by the respective third party's cookie policy, not ours.

We do not sell or share your personal information, and we do not use cookies for advertising or cross-site tracking of any kind.

For the specific services behind this, see Section 5 above.

10. Security

We implement the following security measures to protect your data:

11. Children

Rate Ranger is not intended for use by individuals under 18 years of age. We do not knowingly collect data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at hello@rateranger.io.

12. International Data Transfers

Rate Ranger processes data in the United States via our sub-processors (AWS, Supabase, Resend, OpenAI). Our affiliate tracking partner (Agoda) may process click data in the US and EU. For users in the EU/EEA, we ensure adequate safeguards for international data transfers through Standard Contractual Clauses (SCCs) and Data Processing Addendums (DPAs) with each processor, as required by GDPR Chapter V.

13. Supervisory Authority

If you are located in the EU/EEA and believe we are processing your data unlawfully, you have the right to lodge a complaint with the Irish Data Protection Commission (DPC), our lead supervisory authority, or with the supervisory authority in your EU/EEA member state of residence.

Irish Data Protection Commission: www.dataprotection.ie

14. Changes

We may update this Privacy Policy from time to time. Material changes will be communicated via email to active users. The "Last updated" date at the top of this page indicates when the policy was last revised.

15. Contact

For questions about this Privacy Policy, your data, or to exercise your rights, contact us at hello@rateranger.io.