Skip to content

Legal & policies

Privacy Policy

Last updated: July 5, 2026

This Privacy Policy explains what personal data Book Funduq collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it.

At a glance

  • We collect only what we need to operate your booking: your name, contact details and stay details — we never see or store your full card number.
  • Your booking details are shared with the property you book, and payment is processed by our payment service provider; we do not sell your personal data.
  • You can access your data in your account and request correction or deletion at any time; deleting your account anonymises your past bookings.
  • We use only strictly necessary cookies and your saved preferences — no advertising or third-party marketing cookies.
On this page

1. Who we are and what this policy covers

This Privacy Policy applies to the personal data processed by Book Funduq (we, us, our) when you use the website bookfunduq.com and its associated services (the Platform) — whether you browse, create an account, or make a booking as a guest without an account. Book Funduq is the data controller for this processing; our contact details are at the bottom of this page and in the operator card below.

Each property you book also processes your booking data as an independent controller in order to host you; its own privacy practices apply to that processing. This policy should be read together with our Cookie Policy and forms part of our Terms of Service.

2. Personal data we collect

We practise data minimisation: we collect only what is needed to provide the service you ask for.

  • Booking data — lead guest full name, email address, phone number (optional), country, the property, room type, dates and party size you select, any special requests you write, your confirmation code, and your booking history.
  • Account data (only if you create an account) — name, email address and a hashed password, or your Google account identifier if you sign in with Google; plus your favourites and saved settings.
  • Payment metadata — the deposit amount, currency, payment status, a payment reference and the outcome returned by our payment provider. Your card number is entered directly into the payment provider's secure form and never reaches our servers.
  • Communications — messages you send to our support channels (email, WhatsApp) and the notification emails we send you.
  • Technical data — IP address, browser and device information, and server logs generated when you use the Platform, used for security, fraud prevention and troubleshooting.
  • Preferences — interface language and display currency, stored on your device (see the Cookie Policy).

If you book on behalf of other guests, you must have their permission to share their details with us, and you are responsible for informing them of this policy.

3. Why we use your data and on what legal basis

PurposeExamplesLegal basis
Providing the booking serviceCreating, confirming, changing and cancelling bookings; sending your confirmation email and QR document; processing the deposit and refundsPerformance of a contract
Customer supportAnswering questions, resolving complaints, assisting with cancellations and refundsPerformance of a contract; legitimate interests
Security and fraud preventionProtecting accounts, detecting fraudulent bookings and payments, rate limiting, server logsLegitimate interests; legal obligation
Legal and accounting obligationsKeeping transaction records, responding to lawful requests from authoritiesLegal obligation
Service communicationsEmails strictly related to your booking or account (confirmation, cancellation, password reset)Performance of a contract
Improving the PlatformAggregate, de-identified usage statistics and error diagnosticsLegitimate interests

We do not use your personal data for third-party advertising, we do not sell it, and we do not send marketing emails without your consent. If we introduce optional marketing communications in the future, they will be strictly opt-in with an unsubscribe link in every message.

4. Who we share your data with

  • The property you book — receives the lead guest name, contact details, stay details and special requests needed to host you. The property may not use this data for its own marketing without your separate consent.
  • Payment processing — our regulated payment service provider processes your card payment and refunds on PCI-DSS-compliant infrastructure. We receive only payment status and reference data, never your full card details.
  • Infrastructure providers — our database and authentication provider (Supabase), our hosting providers (Vercel, Railway) and our email delivery provider process data on our behalf under data-processing agreements, only on our instructions.
  • Authorities — where we are required to disclose data by law, or where disclosure is necessary to protect the rights, safety or property of guests, properties or Book Funduq.
  • Business transfers — if Book Funduq or its assets are acquired or merged, personal data may be transferred to the successor, which remains bound by this policy.

5. International data transfers

Our service providers may store or process data in countries other than your own — for example, our database is hosted in the European Union (Frankfurt, Germany) and our payment and hosting providers operate globally. Where data is transferred internationally, we rely on appropriate safeguards such as contractual data-protection clauses with our providers, and we choose providers with strong, industry-standard security certifications.

6. How long we keep your data

  • Booking and transaction records — kept for as long as needed to perform the contract and afterwards for the retention periods required by tax, accounting and consumer-protection law.
  • Account data — kept until you delete your account.
  • Support communications — kept for as long as reasonably needed to handle and document the matter.
  • Server and security logs — kept for short, rolling periods appropriate to security monitoring.

When a retention period ends, data is deleted or irreversibly anonymised.

7. How we protect your data

All traffic to the Platform is encrypted with HTTPS/TLS. Access to personal data is restricted by role-based access controls and row-level security in our database. Passwords are stored only in hashed form. Card payments are handled exclusively by our PCI-DSS-compliant payment provider. We apply rate limiting, logging and monitoring to detect abuse. No system can be guaranteed 100% secure, but we review and improve our safeguards continuously; if a breach affecting your rights occurs, we will notify you and the competent authority as required by law.

8. Your rights

Subject to applicable data-protection law (including the EU/UK GDPR and Türkiye's KVKK where they apply), you have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify inaccurate or incomplete data;
  • erase your data (see account deletion below);
  • restrict or object to processing based on legitimate interests;
  • data portability — receive data you provided in a structured, machine-readable format;
  • withdraw consent at any time, where processing is based on consent, without affecting prior processing;
  • complain to a supervisory authority — in particular the data-protection authority of your place of residence or, in Türkiye, the Personal Data Protection Authority (KVKK).

To exercise any of these rights, email us at info@bookfunduq.com. We respond within the time limits set by applicable law (normally within 30 days). You can also view and update your details directly on your account page.

9. Account deletion

You can delete your account at any time from your account settings. When you do, your login is permanently removed and your favourites are deleted. Records of past stays that we must keep for legal and accounting reasons are anonymised: your name, email and phone number are replaced with non-identifying values, so the records can no longer be linked to you. Contact details attached to a stay that has not yet taken place are retained until the stay completes or is cancelled, so the property can still host or reach you.

10. Children

The Platform is intended for adults. We do not knowingly collect personal data from anyone under 18, except guest names included in a booking made by an adult. If you believe a minor has provided us personal data directly, contact us and we will delete it.

11. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Automated fraud checks used by our payment provider during payment are subject to that provider's own safeguards; a declined payment can always be retried with another method or reviewed by contacting us.

12. Cookies and similar technologies

We use only strictly necessary cookies (such as your sign-in session and language) and device-stored preferences (such as your display currency). We currently use no advertising and no third-party analytics cookies. The full list and your choices are described in our Cookie Policy.

13. Changes to this policy

We may update this Privacy Policy from time to time, for example when we add features or when the law changes. The date of the latest version is shown at the top of this page. If a change materially affects how we use your personal data, we will notify you on the Platform or by email before it takes effect.

14. Contact

For any privacy question or to exercise your rights, contact us at info@bookfunduq.com or via our contact page. The identity and address of the service operator are shown in the operator card below.

Service operator

QUALIVO LTD (United Kingdom)

Questions about this policy?

Our support team is happy to help — we usually reply within 24 hours.

Contact us

Related policies