This policy explains what personal data Roomundo processes, why we need it and the choices and rights available to you.
It applies to the Roomundo website, accounts, accommodation searches, bookings, payment coordination, customer support and related security operations. A third party may provide separate privacy information when it acts as an independent controller for its own service.
Who controls your data
Visit Online B.V. is the controller for the personal data described in this policy. Roomundo is its hotel comparison and booking platform.
- Address: Lange Vonder 237, 1035 KW Amsterdam, the Netherlands
- Chamber of Commerce: 98009346
- Privacy contact:privacy@roomundo.com
Personal data we collect
The data we process depends on how you use Roomundo and may include:
- Identity and contact data: name, email address, telephone number, country or residency and account identifiers.
- Search and trip data: destination, dates, property, room occupancy, guest counts and child ages where needed for an accurate rate.
- Booking data: guest names, selected room and rate, booking reference, supplier identifiers, special requests, cancellation conditions and booking status.
- Payment records: amount, currency, payment status, processor reference, refund status and risk or authentication outcome. See the payment section below.
- Communications: support messages, complaints, attachments and records of our response.
- Technical and security data: IP address, browser, device, operating system, timestamps, request logs, identifiers and signals used to prevent abuse.
- Usage and preference data: language, currency, consent choices, searches, filters, pages viewed and interaction events.
Please do not send sensitive personal data unless it is genuinely necessary for a request and we have asked you to provide it through an appropriate channel.
Where personal data comes from
We receive personal data:
- directly from you when you search, create an account, book or contact us;
- from a lead guest or another person arranging travel on your behalf;
- automatically from your browser, device and use of the platform;
- from booking providers and properties when they confirm, change or cancel a reservation;
- from payment, authentication, fraud-prevention and support providers; and
- from public or licensed accommodation and review content sources.
How we use personal data
We process personal data to:
- return relevant accommodation, availability and price results;
- create, confirm, manage, change or cancel bookings;
- coordinate payments, refunds and booking recovery;
- send service messages, confirmations and important booking updates;
- provide customer support and resolve complaints or disputes;
- authenticate users, secure the platform and prevent fraud or misuse;
- measure reliability, diagnose errors and improve Roomundo;
- remember preferences and manage consent choices; and
- meet tax, accounting, regulatory and legal obligations.
We will not use personal data for an incompatible purpose without a valid legal basis and, where required, additional notice or consent.
Legal bases under the GDPR
Depending on the activity, we rely on:
- Contract: processing needed to provide a requested search or booking service and administer the resulting reservation.
- Legitimate interests: operating and improving Roomundo, securing systems, preventing fraud, handling claims and understanding service performance, balanced against your rights.
- Legal obligation: records and disclosures required by tax, accounting, consumer, sanctions or other applicable law.
- Consent: optional cookies, marketing or another activity where the law requires consent. You may withdraw it prospectively at any time.
Payment data
Payment credentials are collected and processed by our payment service providers through their secured payment interfaces. Roomundo generally receives a token or transaction reference, payment status, amount, currency and limited card information such as brand or last digits where the provider makes this available. Roomundo does not store full card details in its booking records.
Payment providers and banks may process additional identity, device, authentication and risk data under their own legal responsibilities.
How long we keep personal data
We keep personal data only for as long as needed for the purpose for which it was collected, including booking support, fraud prevention, dispute handling and legal compliance. Retention therefore varies by record type.
- Booking and payment records may be retained for the statutory accounting and tax period, which is generally seven years in the Netherlands.
- Account information is kept while the account is active and for a limited period afterward where needed for security, disputes or legal obligations.
- Support and security logs are retained for periods proportionate to troubleshooting, abuse prevention and claim handling.
- Consent records are kept as needed to demonstrate and honour your choices.
Data may be deleted, anonymised or retained longer where a legal hold, active dispute or specific legal obligation applies.
International data transfers
Hotel bookings are international by nature. A booking provider or property may be located outside the European Economic Area, including in the country where you choose to stay. Technology providers may also process data from other countries.
Where the GDPR requires transfer safeguards, we use a recognised legal mechanism such as an adequacy decision, contractual safeguards or an applicable statutory exception. You may contact us for information about safeguards relevant to your data.
Your privacy rights
Subject to the conditions in applicable law, you may ask us to:
- give you access to your personal data;
- correct inaccurate or incomplete data;
- erase data that we no longer have a lawful reason to keep;
- restrict processing in certain circumstances;
- provide eligible data in a portable format;
- stop processing based on legitimate interests where your objection prevails; or
- withdraw consent for future processing that relies on consent.
Send a request to privacy@roomundo.com. We may ask for information needed to verify your identity. We respond without undue delay and in principle within one month, subject to lawful extensions and exceptions. Exercising a right does not affect data we must retain or process under another valid legal basis.
Security
We use technical and organisational safeguards designed for the nature and risk of the data, including access controls, encryption in transit, monitoring, environment separation and controlled service-provider access. No internet service can guarantee absolute security.
If you believe your Roomundo account, booking or personal data may be at risk, contact us promptly and do not send passwords or full payment-card details by email or chat.
Children's data
A person must be at least 18 to make a booking. A lead guest may provide limited information about children travelling with them, such as age, where this is needed to price and fulfil the booking. The lead guest is responsible for having authority to provide that information.
Roomundo is not directed at children and does not knowingly invite them to create accounts or book independently.
Updates to this policy
We may update this policy when our services, providers or legal duties change. The date at the top identifies the current version. If a change materially affects how we use personal data, we will provide an additional notice where appropriate and seek consent where the law requires it.
Contact and complaints
Questions, concerns and privacy-rights requests can be sent to privacy@roomundo.com or by post to Visit Online B.V., Lange Vonder 237, 1035 KW Amsterdam, the Netherlands.
You also have the right to complain to the supervisory authority where you live or work. In the Netherlands this is the Autoriteit Persoonsgegevens.