Privacy policy
We process as little as possible, only what a booking requires, and no more. This page sets out exactly what, why and for how long.
1 · Data controller
The data controller is BookHonest, CVR 45847683. BookHonest is a personally owned business, not a limited company.
This policy applies to both of our addresses, bookhonest.com and bookhonest.dk. It is the same site, the same business and the same handling of information whichever address you came in through; one forwards automatically to the other.
We sell from Denmark, and we are subject to Danish data protection supervision. A .com address does not change that.
Questions about your information: support (at) bookhonest.com.
2 · What information, and why
| Search | Destination, dates, the number of guests and the ages of any children, your preferences and whatever you write in your own words. Used to find and sort hotels. The search is then kept in our own search log, so that we can see what guests are looking for and what we cannot supply. The search log holds no names, email addresses or telephone numbers, and it is not linked to your booking or your account. |
| Booking | Full name, email address and telephone number. The name and email address are used to complete the reservation with the hotel and for the receipt. We pass the telephone number on to the hotel, so that they can reach you about the stay if they need to. |
| Reservation without a card | If you choose to ask us to reserve manually instead of paying straight away, you send us your name, email address, telephone number and the stay you want. We use that to set up the reservation and send you a secure payment link. See section 7 for how long we keep that enquiry. |
| Card details | We never see them. Card number, expiry date and security code are entered in the payment window from our payment provider, which runs in your own browser and sends the card data straight to them. Our server receives only a payment id and a yes or a no. |
| Messages to us | When you search, or put a question to the butler, the server sends a short message to our telephone with the destination, the dates, the number of guests and your own words. Name, email address and telephone number never go with it. |
| Booking data | Hotel, room, dates, price and booking number. Used for customer service, cancellations and the accounts we are required by law to keep. |
| Technical operation | The server's log of API calls: path, time and the search parameters that appear in the address, that is destination, dates and number of guests. Our own log does not record your IP address; the hosting platform log at Fly.io does. Used for operational reliability and fault-finding, not for profiling. |
3 · Legal basis
- Booking and customer service: performance of the contract with you, Article 6(1)(b) of the General Data Protection Regulation.
- Reservation without a card: steps taken at your own request before a contract is entered into, Article 6(1)(b).
- Accounting: a legal obligation under the Danish Bookkeeping Act, Article 6(1)(c).
- Technical operation and security: our legitimate interest in a site that works, Article 6(1)(f).
4 · Automated sorting of search results
What you write in your own words is processed automatically for one purpose only: to sort the hotels according to your preferences. The text is sent, together with the list of hotels, to an AI service that carries out the sorting itself. We use NVIDIA (NVIDIA NIM) as the primary service and Anthropic as the fallback if the primary one does not answer. Both process the text on our behalf as data processors.
We never send your name, email address or telephone number along with it, only the search text and the list of hotels. The text is not used for anything else, not for marketing, and it is not the basis of any decision producing legal effects concerning you. It is kept in our search log and sent as a message to our telephone, see sections 2 and 7.
Both services process the text on servers in the United States. The transfer takes place on the basis of the European Commission's standard contractual clauses and, where the service takes part in it, the EU-US Data Privacy Framework. See section 5 for the full list.
Do not write sensitive information in the free-text field. Leave out health, disability, allergies, religion and similar sensitive personal data. We do not ask for it, and it is not needed to find a hotel. If the hotel needs to know something about accessibility, for instance, contact us directly at support (at) bookhonest.com and we will arrange it outside the automated sorting.
5 · Who we share with
When you book, your name, email address, telephone number and booking data are passed on to our hotel wholesale supplier and to the hotel. Otherwise the stay cannot be delivered.
The roles are these: during the search, the wholesale supplier handles enquiries on our behalf as a data processor. From the moment you book, the supplier and the hotel are independent data controllers for their part of the processing. The hotel, for example, has to know your name itself in order to check you in.
If you book a hotel outside the EU or the EEA, the information is transferred there, because it is necessary in order to perform the contract, Article 49(1)(b) of the General Data Protection Regulation.
In addition, we use these data processors to run the service. The right-hand column shows where the information is processed, and on what basis it is transferred outside the EU or the EEA, where it is:
| Hotel wholesale supplier | Passes the booking on to the hotel. Receives name, email address, telephone number and booking data. EU or UK, and third countries as required. Standard contractual clauses. |
| NVIDIA (NIM) | Sorts search results according to your own words, see section 4. Never sees name, email address or telephone number. United States. Standard contractual clauses, Data Privacy Framework. |
| Anthropic | Fallback for the sorting, see section 4. Never sees name, email address or telephone number. United States. Standard contractual clauses, Data Privacy Framework. |
| Resend | Sends receipt, cancellation and payment emails (name, email address and the contents of the booking). United States. Standard contractual clauses, Data Privacy Framework. |
| Supabase | Stores your booking list and account, if you choose to log in, and the hotels you have saved with the heart, so that the list follows the account. Of the saved hotels we store only the hotel's id, never the name or the price. Servers in the EU. No transfer outside the EU. |
| Fly.io | Hosts the site and the server that handles your information along the way. Servers in the EU (Amsterdam). Standard contractual clauses for support from the United States. |
| Google (Gmail) | Our mailboxes. A copy of every booking receipt, cancellation and payment email is sent as a blind copy to our support mailbox and to the owner's own Gmail account, so that we can follow up. The copy contains the guest's name, email address and the contents of the booking. Requests to reserve without a card land in the same place. United States. Standard contractual clauses, Data Privacy Framework. |
| ntfy.sh | Delivers the short operational messages to our telephone, see section 2. Receives destination, dates, number of guests and your own words, never name, email address or telephone number. The message sits on the service's server until the telephone has fetched it. |
| Esri (ArcGIS Online) | Supplies the map tiles for the map on the hotel page, and for the map on the results page if the style file cannot be fetched. Your browser fetches the tiles itself, so Esri sees your IP address while the map is drawn, and nothing else. United States. We have no agreement with Esri; the tiles are fetched from a service that is open to all. |
We never sell your information, and we share nothing for marketing.
6 · Content from third parties
The typefaces are on our own server, so no fonts are fetched from outside. What is fetched from outside is this: the map tiles on the hotel page from Esri (ArcGIS Online), the map on the results page from OpenFreeMap with Esri's tiles as the fallback if the style file cannot be fetched, the map libraries Leaflet and MapLibre from unpkg, and the login library from jsDelivr on the pages where you can log in. If you pay by card, the payment window itself is loaded from our payment provider and runs in your browser; the card details go straight there. When your browser fetches this, the services in question see your IP address. Esri is a United States company, so the map tiles are fetched from there, see section 5. The surroundings on the hotel map, that is landmarks, beaches and the airport, are fetched from Wikipedia and Wikidata through our own server, so your browser sends nothing there, and no personal data goes with it. More about storage in the browser is in the cookie policy.
7 · How long we keep it
- Booking data and supporting documents: 5 years from the end of the financial year the booking belongs to. The Danish Bookkeeping Act requires it.
- The search log, including your own words: kept without name and contact details. We will say it plainly: there is at present no automatic deletion of the search log. If you ask us to delete a search, we do it.
- Requests to reserve without a card: held in our database and in our mailbox. Those too we delete when you ask us to, not after a fixed period.
- The operational log: follows the hosting provider's own retention at Fly.io. We have not set a shorter period.
That is how it stands today, and that is why it says so here. If we get automatic deletion in place, we will write the periods in here with a new date at the top.
8 · Your rights
Under the General Data Protection Regulation you have the right of access to your information and the right to have it rectified, erased or restricted. You have the right to data portability and the right to object to the processing.
Write to support (at) bookhonest.com and we will answer as soon as we can, and within one month at the latest. One exception we state plainly: booking data covered by the bookkeeping obligation cannot be deleted until the 5-year period has run out.
9 · Complaints to the Danish Data Protection Agency
You can complain about our handling of your information to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, datatilsynet.dk. If you live in another EU or EEA country, you can complain instead to the supervisory authority where you live or work. You are always welcome to write to us first, so that we can try to resolve it directly.
10 · Changes to this policy
If we change this policy, the new version is published here with a new date at the top. Material changes are notified to guests with an active booking.