Privacy policy

This policy explains, in plain terms, what personal data Traveloh collects, why, how long we keep it and what you can ask us to do about it. We collect as little as we can: no advertising cookies, no cross-site tracking, and nothing sold to anyone.

1. Who is responsible for your data

Traveloh ("we", "us") publishes this site and is the data controller for the personal data described below. The quickest way to reach us about anything in this policy — including a rights request — is the contact page.

This policy covers traveloh.uk and our sister domains in other languages, which are the same service in a different language.

2. What we collect when you browse

We log one record for each page served, so we can see which pages are useful, spot errors and protect the site from abuse. That record contains:

  • the page you viewed, any filters or search terms in the address, and the page that referred you
  • your IP address, and an approximate location derived from it — country, region and city, never a precise position
  • the language your browser asks for, your user-agent string, and the browser, operating system and device type we read from it
  • your screen and window size, pixel ratio and time-zone, sent by a small script after the page loads
  • the response status and how long the page took to build

We do not ask for your name, log in, build an advertising profile or follow you across other websites.

3. Cookies

We set no advertising, profiling or cross-site tracking cookies, and we run no third-party advertising or analytics tags. The optional first-party cookie that would group page views into a visit is switched off, so as things stand the site sets no analytics cookies at all — which is why you are not asked to dismiss a cookie banner.

If we ever switch that on, we will ask for your consent first and update this policy before we do.

4. When you contact us

The contact form asks for your name, your email address and your message; a subject line is optional. We also record the IP address and browser the message was sent from, to help us deal with automated abuse.

We store the message and forward it to our own inbox so we can reply. We use it only to answer you and to keep a record of the exchange — never to add you to a mailing list, and never for marketing.

5. Why we may process it

Under Article 6 of the UK GDPR we rely on:

  • Legitimate interests for page-view records — understanding how the site is used, diagnosing faults and preventing abuse. We use the minimum data that achieves that, and none of it is used to make decisions about you as an individual.
  • Legitimate interests for handling an enquiry you send us: you asked us a question and expect an answer.
  • Consent, asked for separately and beforehand, for anything that ever needs it — such as a non-essential cookie.

6. Who else is involved

We do not sell, rent or trade personal data, and we share none of it with advertisers. A small number of suppliers process data strictly on our instructions:

  • DigitalOcean — hosting for the website and its database, in a European data centre
  • Microsoft Azure AI Search — the index behind the site search box; a search you type is sent to it to be matched
  • our email provider, which delivers a contact-form message to our inbox

Each is bound by a data-processing agreement. We may also disclose data where the law requires it, or to establish or defend a legal claim.

7. Where your data is held

The site, its database and its logs are hosted in the European Union. Where a supplier processes data outside the UK or the EEA, that transfer is covered by UK International Data Transfer Agreement clauses, the European Commission’s Standard Contractual Clauses, or an adequacy decision.

8. How long we keep it

  • Page-view records: 14 months, then deleted.
  • Contact-form messages and our replies: 24 months after the matter is closed, unless we need them longer for a legal claim.
  • Aggregate statistics that identify nobody — visits per page, per country, per month — may be kept indefinitely.

9. Your rights

Under the UK GDPR you have the right to ask us to:

  • confirm what personal data we hold about you and give you a copy
  • correct it if it is wrong, or complete it if it is partial
  • delete it, where we have no overriding reason to keep it
  • restrict how we use it, or object to our use of it under legitimate interests
  • provide it in a portable, machine-readable form, where that right applies

Send a request through the contact page and we will answer within one month. There is no charge.

If you are unhappy with how we have handled your data you can complain to the UK supervisory authority, the Information Commissioner’s Officeico.org.uk or 0303 123 1113. We would rather you told us first so we can put it right.

10. Children

This site is aimed at adults planning a holiday and is not directed at children. We do not knowingly collect personal data from a child. If you believe a child has sent us personal data through the contact form, tell us and we will delete it.

11. No automated decisions about you

We take no decisions about you by automated means and we do not profile you. The order hotels appear in is worked out from the hotels’ own data — how complete and how recently refreshed each listing is — and is the same for every visitor.

12. Keeping it safe

The site is served only over HTTPS, and connections to our database are encrypted and certificate-verified. Access to the database is limited to the small number of people who operate the service. No system is perfectly secure, but we take the measures appropriate to data of this kind.

13. Changes to this policy

We will update this policy when what we do changes, or when the law does. The date at the foot of the page shows when it last changed; if a change materially affects you we will make that clear on the site rather than quietly revising the text.

Questions? Get in touch