Legal

Privacy Policy

Book2dream is built on a simple principle: the data your hotel and its guests entrust to you belongs to you. This policy explains what we collect, why, and how we keep it safe.

Last updated: 8 August 2026

1Who we are

Book2dream ("Book2dream", "we", "us") provides an AI-powered direct booking engine for hotels, lodges and boutique properties. This Privacy Policy explains how we handle personal data across our website at book2dream.com, the booking engines we operate for our customers, and the administrative tools we provide to them.

It applies to three groups of people: visitors to our website, staff at hotels that use Book2dream ("Hotel Customers"), and guests who make or manage a booking through a booking engine we run on a Hotel Customer's behalf.

2Our role: your hotel owns its data

For guest and booking data flowing through the booking engine, the hotel is the data controller and Book2dream is the data processor. The hotel decides what is collected and why. We act only on the hotel's documented instructions.

Put plainly: that data belongs to the hotel, not to us. We do not sell it, we do not rent it, we do not disclose it to other hotels, and we do not use one hotel's guest data to build features that serve anybody else.

For our own website, marketing and account administration, Book2dream is the controller, and this policy describes our own practices directly.

3Information we collect

What we collect depends on how you interact with us.

  • Hotel account data — names, work email addresses, phone numbers and roles of the people at a Hotel Customer who administer the booking engine, plus billing and contract details.
  • Guest and booking data, processed on behalf of a Hotel Customer — guest name and contact details, stay dates, room and rate selection, number of guests, special requests, language and currency preferences, and booking status.
  • Payment data — handled by PCI-DSS compliant payment providers. Book2dream does not store full card numbers or security codes on its own systems.
  • Enquiry data — what you send through our demo request form: your name, work email, hotel name, property type, room count and any message you write.
  • Technical and usage data — IP address, browser and device type, pages viewed, referring page, and approximate location derived from IP. On booking engines this includes the signals our pricing and personalisation features rely on.

4How we use personal data

  • To operate, maintain and secure the booking engine, and to take bookings on a hotel's behalf.
  • To personalise availability, pricing and content for a guest, on the hotel's instructions and within the rules the hotel configures.
  • To send transactional messages such as booking confirmations, modifications and cancellations.
  • To provide support, respond to demo requests, and manage contracts and billing with Hotel Customers.
  • To detect and prevent fraud, abuse and security incidents.
  • To produce aggregated, de-identified statistics about how the product performs. These never identify a guest or expose one hotel's commercial data to another.

6Data ownership and portability

All guest, booking, rate and content data a hotel puts into Book2dream, or that is generated by guests booking through it, remains the hotel's property. Our rights to it extend no further than what we need in order to run the service for that hotel.

A Hotel Customer can export its data at any time in a structured, machine-readable format, and can ask us to delete it. On termination we return or delete it as described in the Terms of Service.

7How we keep data secure

Storing a hotel's data securely is part of the product, not an add-on. These are the controls we operate:

  • Encryption in transit using TLS 1.2 or higher on every connection, and encryption at rest using AES-256 for databases, backups and file storage.
  • Least-privilege access: only the Book2dream staff who need production access to run the service have it, each through a named account with mandatory multi-factor authentication.
  • Logical separation of every hotel's data, so one Hotel Customer can never reach another's records.
  • Continuous logging and monitoring of access to production systems, with alerting on anomalous activity.
  • Encrypted backups, tested regularly, with defined recovery point and recovery time objectives.
  • Vulnerability scanning, prompt dependency patching and periodic penetration testing.
  • Vetted infrastructure providers operating certified data centres.
  • A documented incident response plan. If a breach affects a hotel's data, we notify that hotel without undue delay and within 72 hours of becoming aware, with what we know and what we are doing about it.

8Service providers and subprocessors

We keep the vendor list short and work with established providers under written data processing agreements. Today they are:

  • Vercel — hosting and content delivery for our website and booking engines.
  • Resend — delivery of transactional and notification email.
  • Google Analytics — aggregate measurement of how our marketing website is used.
  • PCI-DSS certified payment providers, where a hotel takes payment at the time of booking.

9International transfers

Book2dream serves hotels across Latin America and guests from around the world, so personal data may be processed outside the country where it was collected, including in the United States and the European Union where our infrastructure providers operate.

Where we transfer personal data out of a jurisdiction that restricts it, we rely on recognised safeguards such as the European Commission's Standard Contractual Clauses, alongside the technical measures described above.

10How long we keep data

  • Guest and booking data: for as long as the hotel instructs us to keep it, then deleted or returned according to the hotel's retention settings and our agreement with it.
  • Hotel account and billing data: for the life of the contract, plus the period Chilean commercial and tax law requires.
  • Demo requests and enquiries: up to 24 months from our last contact, unless you ask us to erase them sooner.
  • Server and security logs: normally 12 months.
  • Aggregated, de-identified statistics: indefinitely, because they can no longer identify anyone.

11Your rights

Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to how we use it, receive a portable copy, and withdraw consent at any time. Exercising these rights is free, and we respond within the period the applicable law sets — 30 days in most cases.

If you are a hotel guest, the hotel that took your booking is the controller of your data, so please contact the hotel first. If you come to us instead, we will pass your request on and help the hotel answer it.

You also have the right to complain to your data protection authority.

12Cookies and similar technologies

Our website sets strictly necessary cookies to remember your language and to record your cookie decision. Before you decide, those are the only cookies present.

Analytics cookies are off until you turn them on. We ask on your first visit, and Google Analytics is loaded only if you accept — if you refuse, no request is made to Google and no analytics cookie is set. Refusing is one click, exactly like accepting.

You can change or withdraw your choice at any time through the Cookie Preferences link in our footer. Withdrawing also deletes the analytics cookies already stored on your device.

Booking engines we run for hotels use session cookies needed to hold a reservation in progress, plus any analytics the hotel chooses to enable under its own privacy policy.

13Children

Book2dream is a business tool, and the booking engines we operate are intended for adults. We do not knowingly collect personal data directly from children, other than details an adult provides as part of a booking, such as the number and ages of children in a party. If you believe a child has given us data directly, write to us and we will delete it.

14Changes to this policy

We update this policy when the product or the law changes. The date at the top always reflects the current version, and we give Hotel Customers reasonable advance notice of material changes affecting how we handle guest data.

15Contact us

Questions, requests or complaints about privacy can be sent to contact@book2dream.com.

Questions about this document?

Write to us and a person will answer. If your question is about a booking you made at a specific hotel, tell us which hotel so we can route it correctly.

contact@book2dream.com