Privacy Policy
Rialto Travel ("we," "us," or "our") operates the website rialto.travel (the "Site") and provides hotel booking and travel agency services (the "Services"). This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use our Site and Services.
By using our Site or Services, you consent to the practices described in this Privacy Policy. If you do not agree, please do not use our Site or Services.
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email address, phone number when you create an account or sign in via email magic link, Google OAuth, or passkey.
- Booking Information: Guest name, email, phone number, hotel loyalty program number, special requests, travel arranger details, and notes.
- Payment Information: Cardholder name, credit card number, and expiration date. Card numbers are encrypted client-side using RSA-OAEP encryption before transmission and are never stored in plaintext.
- Communications: Any messages, feedback, or correspondence you send to us.
Sensitive Personal Information: We collect financial data (credit/debit card numbers) as necessary to process hotel bookings. This data is encrypted client-side before transmission and is processed only as permitted by applicable law.
All personal information you provide must be true, complete, and accurate. You must notify us of any changes to your personal information.
1.2 Information Collected Automatically
When you visit or use our Site, we automatically collect certain information, including:
- Log and Usage Data: Pages visited, features used, search queries, booking activity, interaction patterns, date/time stamps, and referring URLs.
- Device & Browser Data: IP address, browser type and version, operating system, device type, screen resolution, language preferences, and unique device identifiers.
- Location Data: Approximate geographic location inferred from your IP address. We do not collect precise GPS-based geolocation.
- Cookies & Similar Technologies: We use essential cookies for authentication (session cookies) and site access. We use privacy-friendly analytics tools that provide aggregated website analytics and do not track individual users across sites. We do not use cookies for targeted advertising.
1.3 Information from Third Parties
- Authentication Providers: If you sign in via Google, we receive your name, email address, and profile identifier from Google. We do not receive or store your Google password.
- Hotel Partners & Booking Systems: We receive booking confirmations, cancellation details, and rate information from our hotel booking partners.
- Google Maps Platform APIs: Our Site uses Google Maps Platform APIs (including Places API) for location search and autocomplete. When you use location search features, information such as your search queries may be shared with Google in accordance with Google's Privacy Policy.
2. How We Use Your Information
We process your personal information for the following purposes:
- Provide our Services: Process and manage hotel bookings on your behalf, create and maintain your user account.
- Communicate with you: Send booking confirmations, updates, cancellation details, and administrative information about changes to our terms or policies.
- Improve our Services: Pre-fill booking forms for returning users, analyze usage trends, and improve the Site and user experience.
- Security and fraud prevention: Detect and prevent fraud, unauthorized access, and abuse of our Services.
- Legal compliance: Comply with legal obligations and enforce our Terms of Service.
- AI-powered features: Our platform uses artificial intelligence and machine learning to enhance search results, surface relevant hotel options, and improve the booking experience. Personal information processed through AI-powered features is handled in accordance with this Privacy Policy.
We do not sell your personal information to third parties. We do not use your personal information for targeted advertising. We have not sold or shared personal information to third parties for business or commercial purposes in the preceding 12 months.
Legal Bases for Processing
We process your personal information based on the following legal grounds:
- Consent: When you have given us permission to process your information for a specific purpose. You may withdraw consent at any time.
- Contract Performance: When processing is necessary to fulfill our contractual obligations to you, including processing bookings and providing the Services.
- Legitimate Interests: When processing is reasonably necessary for our legitimate business interests (improving our Services, fraud prevention, security) and those interests do not override your rights and freedoms.
- Legal Obligations: When processing is necessary to comply with applicable laws and regulations.
3. How We Share Your Information
We may share your information with the following categories of third parties:
- Hotel Partners & Booking Systems: We share guest name, contact information, loyalty numbers, special requests, and payment details with hotels and our hotel booking partners to fulfill your reservations. This is necessary to provide the Services.
- Email Service Providers: We use third-party email service providers to send transactional emails (booking confirmations, magic link authentication, cancellation notices). These providers process your email address and message content on our behalf.
- Hosting & Infrastructure Providers: Our Site is hosted on third-party cloud hosting and database providers. These providers process data as necessary to operate our infrastructure.
- Location Services: Google Maps Platform APIs process location search queries as described in Section 1.3.
- Analytics Providers: We use privacy-friendly analytics tools that provide aggregated website analytics without tracking individual users across sites.
- Legal Requirements: We may disclose your information if required by law, regulation, legal process, or governmental request, or to protect our rights, property, or safety, or the rights, property, or safety of others.
- Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you of any such change.
All third-party service providers are contractually bound to protect your data, process it only as instructed, and not share it with other organizations.
4. Cookies and Tracking Technologies
We use cookies and similar technologies for the following purposes:
- Essential Cookies: Required for authentication (session cookies), site access (site password), and basic site functionality. These cannot be disabled without impairing the Services.
- Analytics: We use privacy-friendly analytics tools that provide aggregated website analytics, do not track individual users across sites, and do not use cookies for tracking.
We do not use cookies or tracking technologies for targeted advertising, retargeting, or cross-site behavioral tracking. We do not use third-party advertising cookies.
Under certain US state privacy laws, some forms of online tracking may be considered a "sale" or "sharing" of personal information. We do not engage in such tracking.
5. Data Retention
We retain your personal information for as long as necessary to provide the Services, maintain your account, comply with legal obligations, and resolve disputes. Specifically:
| Data Category | Retention Period |
|---|---|
| Account Data (name, email, phone) | As long as your account is active. You may request deletion at any time. |
| Booking Data (reservations, confirmations) | Minimum 7 years for tax, legal, and regulatory compliance. |
| Payment Data (encrypted card numbers) | Only until the booking is confirmed with the hotel, then purged. Plaintext card numbers are never stored. |
| Session Data (auth sessions) | Expires after inactivity and is periodically purged. |
| Usage/Analytics Data | Aggregated and anonymized; not tied to individual users. |
| Location Search Queries | Not retained by Rialto Travel beyond the search session. |
When no legitimate business need exists for retaining your personal information, we will delete or anonymize it. If deletion is not immediately possible (e.g., backup archives), we will securely store and isolate the information from further processing until deletion is possible.
6. Data Security
We implement reasonable technical and organizational measures to protect your personal information, including:
- RSA-OAEP client-side encryption of credit card numbers before transmission
- HTTPS encryption for all data in transit
- Secure, access-controlled database infrastructure
- Session-based authentication with secure, HTTP-only cookies
- Regular security reviews of our infrastructure and dependencies
No method of transmission or storage is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security. Transmission of personal information to and from our Services is at your own risk. You should access the Services only within a secure environment.
7. Your Privacy Rights
7.1 All Users
Regardless of your location, you may:
- Access the personal information we hold about you
- Correct inaccurate personal information
- Delete your account and associated personal data (subject to legal retention requirements)
- Obtain a copy of your personal data in a portable format
- Opt out of non-essential communications
To exercise these rights, contact us at the address listed in Section 12.
Account Information: You may review or change your account information at any time by logging into your account settings or by contacting us. Upon account termination request, we will deactivate or delete your account and information from active databases, though we may retain some information as required for legal compliance, fraud prevention, and dispute resolution.
7.2 United States Residents — State Privacy Rights
If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, or any other state with applicable consumer privacy legislation, you may have additional rights under your state's privacy laws.
Core rights available to US residents with applicable state privacy laws include:
- Right to Know: Request that we disclose what personal information we have collected, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share it.
- Right to Access: Obtain a copy of the specific personal information we have collected about you.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Delete: Request the deletion of personal information we have collected from you, subject to certain exceptions (e.g., legal retention obligations, completing a transaction).
- Right to Data Portability: Obtain a copy of your personal data in a readily usable format.
- Right to Opt Out: Opt out of the sale of personal data, sharing for cross-context behavioral advertising, and profiling that produces legal or similarly significant effects. We do not engage in any of these activities, so no opt-out is necessary.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
- Right to Limit Use of Sensitive Personal Information: Where applicable, you may request that we limit use and disclosure of sensitive personal information. We only use sensitive personal information (financial data) as necessary to provide the Services.
Additional state-specific rights:
- California (CCPA/CPRA): Right to know categories of third parties receiving disclosed data. Right to limit use of sensitive personal information.
- Connecticut: Right to obtain a list of third parties to which personal data was sold.
- Minnesota, Oregon: Right to obtain a list of specific third parties who have received your personal data.
- Florida: Right to opt out of sensitive data collection and voice/facial recognition processing. We do not collect biometric data.
Categories of Personal Information Collected (preceding 12 months):
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Name, email, phone, IP address, account name | Yes |
| B. CA Customer Records (Cal. Civ. Code § 1798.80(e)) | Name, contact information, financial information | Yes |
| C. Protected Classifications | Race, gender, age, national origin | No |
| D. Commercial Information | Booking history, hotel preferences, transaction details | Yes |
| E. Biometric Information | Fingerprints, voiceprints, facial recognition | No |
| F. Internet/Electronic Activity | Site usage, search queries, pages visited, interaction data | Yes |
| G. Geolocation Data | Approximate location from IP address | Yes |
| H. Audio/Visual Information | Photographs, audio or video recordings | No |
| I. Professional/Employment Information | Job title, employer | No |
| J. Education Information | Student records | No |
| K. Inferences | Profiles reflecting preferences or characteristics | No |
| L. Sensitive Personal Information | Credit/debit card numbers (encrypted) | Yes |
How to Exercise Your Rights: Contact us via the information in Section 12. We will verify your identity before processing your request by matching information you provide against our records.
Authorized Agents: You may designate an authorized agent to submit a privacy request on your behalf. We may require the agent to provide written, signed authorization from you and may contact you directly to verify the request.
Response Timing: We will respond to verifiable consumer requests within 45 days. If we need additional time, we will inform you of the reason and extension period (up to an additional 45 days).
Appeals: If we decline your privacy request, you may appeal by emailing us at the address in Section 12 with the subject line "Privacy Appeal." We will provide a written response with our reasoning. If your appeal is denied, you may submit a complaint to your state's attorney general.
7.3 CalOPPA Compliance
In accordance with the California Online Privacy Protection Act (CalOPPA):
- This Privacy Policy is accessible from our homepage via a conspicuous link.
- You will be notified of any material changes to this Privacy Policy.
- You may visit our Site anonymously (browsing does not require an account).
8. Do-Not-Track Signals
California law requires us to disclose how we respond to Do Not Track (DNT) browser signals. There is currently no uniform technology standard for recognizing or implementing DNT signals. Our Site does not track users across third-party websites and does not use tracking technologies for targeted advertising. As such, we do not currently respond to DNT signals because our practices already align with the privacy expectations DNT signals are intended to express. If a standard for responding to DNT signals is adopted that we must follow, we will inform you in a revised version of this Privacy Policy.
9. AI-Powered Features
Our platform incorporates artificial intelligence and machine learning technologies to enhance the user experience, including search optimization and hotel recommendations. All personal information processed through these features is handled in accordance with this Privacy Policy and is not used to build profiles for purposes outside of providing the Services. We do not use AI to make automated decisions that produce legal or similarly significant effects on users without human oversight.
10. Children's Privacy
Our Site and Services are not directed to children under 18 years of age. We do not knowingly collect, solicit data from, or market to children under 18. We do not knowingly sell the personal information of minors. By using the Services, you represent that you are at least 18 years of age or that you are the parent or guardian of a minor and consent to such minor's use of the Services. If we learn that we have collected personal information from a child under 18, we will promptly deactivate the account and take reasonable measures to delete the data. If you believe a child has provided us with personal information, please contact us at the address in Section 12.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the "Last Updated" date. Your continued use of the Site or Services after any changes constitutes your acceptance of the updated Privacy Policy. For material changes, we will provide notice via email (if you have an account) or a prominent notice on our Site prior to the change becoming effective. We encourage you to review this Privacy Policy periodically.
12. Contact Us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or need to submit an appeal regarding a privacy request, please contact us at:
Rialto Travel Email: privacy@rialto.travel