Privacy & Global Data Protection Policy
How RapidRoomz collects, encrypts, processes, and protects your personal information under GDPR (EU/UK), CCPA/CPRA (California), and global privacy frameworks.
- Zero Data Monetization: We never sell, rent, or trade your personal data or travel history to third-party ad brokers.
- GDPR Data Rights: Full access to exercise your right to access, rectify, port, or permanently delete personal data.
- Bank-Grade Security: 256-bit SSL encryption and tokenized payment processing via Stripe & PayPal.
- Data Minimization: We only collect data required for booking fulfillment, fraud prevention, and regulatory compliance.
1 EU / UK General Data Protection Regulation (GDPR) Compliance
Under the EU Regulation 2016/679 (GDPR) and UK Data Protection Act 2018, RapidRoomz acts as a Data Controller for personal data processed during account registration and room reservations.
We process personal data under the legal bases of: (a) Performance of Contract (fulfillment of room reservations), (b) Compliance with Legal Obligations (financial reporting & tax laws), and (c) Legitimate Business Interest (fraud detection and platform security).
2 Your Statutory Rights (Right to Erasure & Access)
Regardless of your geographic location, RapidRoomz provides all users with comprehensive data rights:
- Right to Access (Article 15): Request a copy of all personal data held about you in a structured, machine-readable JSON format.
- Right to Erasure / "Right to be Forgotten" (Article 17): Request permanent deletion of your profile, search history, and marketing preferences.
- Right to Portability (Article 20): Transfer your data seamlessly to another travel platform.
To submit a Data Subject Access Request (DSAR), contact our Data Protection Officer at dpo@rapidroomz.com.
3 California Consumer Privacy Act (CCPA / CPRA) Statement
For residents of California, USA: RapidRoomz complies fully with the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).
Privacy FAQs & Data Queries (AEO)
How can I request deletion of my account and personal data?
You can request full data erasure under GDPR Article 17 by contacting our Data Protection Officer at dpo@rapidroomz.com or submitting a request via your Account Privacy Dashboard.
Does RapidRoomz store my credit card numbers?
No. RapidRoomz operates under PCI-DSS SAQ-A compliance. Payment details are tokenized directly through Stripe PCI Level 1 certified infrastructure. We never store raw card numbers.
How does RapidRoomz comply with California CCPA / CPRA rights?
California residents have the right to know what personal information is collected, request erasure, and opt-out of data sharing. RapidRoomz honors all CCPA requests without discrimination.