BookNLoop
GDPR Compliant

Privacy Policy

Last updated: March 4, 2026

1. Who We Are

BookNLoop is operated by Panagiotis Doganis ("Data Controller"), based in Athens, Greece. We are committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR — Regulation 2016/679) and applicable Greek data protection law (Law 4624/2019).

For any privacy-related questions or to exercise your rights, contact us at: p.doganis@booknloop.com

2. What Data We Collect

We collect different data depending on how you interact with the Platform:

Hotel Partners (Supply Partners)

When you register and use the hotel dashboard, we collect: email address, password (stored as a secure hash, never in plain text), hotel name, property details, room information, photos, amenities, contact phone number, and any auto-negotiation rules you configure.

Travelers

When you register or submit a bid, we collect: email address, password (stored as a secure hash), full name, phone number (optional), search queries, bid amounts, and booking details.

All Visitors

When you visit any page on BookNLoop, we automatically collect: IP address (anonymized for analytics), browser type and version, pages viewed, timestamps, referrer URL, and a randomly generated session identifier. We also collect data through Google Analytics 4 (see Section 5 on Cookies).

Contact Form

If you submit a message through our contact form, we collect: your email address and message content.

3. Why We Collect It (Legal Basis)

PurposeData UsedLegal Basis (GDPR)
Account creation and authenticationEmail, password hashContract performance (Art. 6(1)(b))
Facilitating bookings between partners and travelersName, email, phone, bid details, booking detailsContract performance (Art. 6(1)(b))
Sending booking notifications and bid updatesEmail addressContract performance (Art. 6(1)(b))
Hotel profile and room managementProperty details, room data, photosContract performance (Art. 6(1)(b))
Auto-negotiation (Autopilot)Bid data, negotiation rulesContract performance (Art. 6(1)(b))
Analytics and platform improvementPage views, session data, anonymized IPLegitimate interest (Art. 6(1)(f))
Responding to contact form inquiriesEmail, message contentLegitimate interest (Art. 6(1)(f))
Google Analytics trackingSee Section 5Consent (Art. 6(1)(a))

4. Who Has Access to Your Data

We share personal data only with the following categories of recipients, and only to the extent necessary:

Booking counterparties: When a booking is confirmed, the hotel receives the traveler's name, email, and phone number, and the traveler receives the hotel's name and contact details. This is necessary to fulfill the accommodation contract.

Service providers: We use the following third-party services that process data on our behalf:

ServicePurposeData SharedLocation
Railway (hosting)Platform hosting and databaseAll platform dataUS (with EU safeguards)
SendGrid (Twilio)Email notificationsEmail addresses, booking detailsUS (with EU safeguards)
OpenAIAI search parsing, hotel extraction, match scoringSearch queries, hotel website content (no personal data)US (with EU safeguards)
Google Analytics 4Website analyticsAnonymized browsing dataUS (with EU safeguards)

For US-based processors, data transfers are covered by the EU-US Data Privacy Framework or Standard Contractual Clauses as applicable. We do not sell, rent, or trade your personal data to third parties.

5. Cookies and Tracking

BookNLoop uses the following cookies and tracking technologies:

Cookie / TechnologyTypePurposeDuration
Session cookie (connect.sid)EssentialSite access authenticationSession
JWT token (hotel auth)EssentialHotel dashboard authentication24 hours
Traveler auth cookieEssentialTraveler account authentication7 days
bnl_sid (sessionStorage)AnalyticsSession-based event trackingSession
Google Analytics (_ga, _ga_*)AnalyticsUsage statistics, visitor behaviorUp to 2 years

Essential cookies are required for the Platform to function and cannot be disabled. Analytics cookies are used to understand how visitors interact with the Platform. You can manage cookie preferences through your browser settings. For Google Analytics specifically, you may opt out by installing the Google Analytics Opt-Out Browser Add-on.

6. Data Retention

We retain your data for as long as your account is active or as needed to provide services. Specifically: account data is retained until you request deletion; booking records are retained for 5 years for tax and legal compliance (Greek tax law); analytics data is retained for 26 months (Google Analytics default); contact form submissions are retained for 12 months; and server logs are retained for 30 days.

After the applicable retention period, data is permanently deleted or fully anonymized.

7. Your Rights Under GDPR

As a data subject in the EU, you have the following rights:

Right of access — You can request a copy of all personal data we hold about you. Right to rectification — You can request correction of inaccurate data. Right to erasure ("right to be forgotten") — You can request deletion of your data, subject to legal retention obligations. Right to restrict processing — You can request that we limit how we use your data. Right to data portability — You can request your data in a structured, machine-readable format. Right to object — You can object to processing based on legitimate interest. Right to withdraw consent — Where processing is based on consent (e.g., analytics cookies), you can withdraw consent at any time.

To exercise any of these rights, email us at p.doganis@booknloop.com. We will respond within 30 days as required by GDPR.

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA): www.dpa.gr

8. Security

We implement appropriate technical and organizational measures to protect your data, including: passwords stored using bcrypt hashing (never stored in plain text), HTTPS encryption for all data in transit, JWT-based authentication with expiring tokens, database hosted on secure cloud infrastructure, and access limited to the data controller.

9. Children

BookNLoop is not intended for use by individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Registered users will be notified of material changes via email.

11. Contact the Data Controller

Panagiotis Doganis
BookNLoop — Data Controller
Athens, Greece
p.doganis@booknloop.com
+30 6970557567

Terms of Service ← Back to BookNLoop
© 2026 BookNLoop · All rights reserved · Terms Privacy