Privacy Policy
How Suquerena collects, uses, shares, and protects the information readers give us.
Current as of: 2 September 2026
1. Scope and application
As an editorial catalogue and booking-enquiry directory for premier accommodation, Suquerena takes on a firm duty to protect individual records and to maintain transparency wherever readers interact with the service.
This document sets out what Suquerena collects, how it is organised and used, when it is transferred, and how it is protected when you browse the catalogue, read ratings, register a profile, or submit an accommodation request.
2. Information we collect
Delivering accurate lodging information, verified reviews, and dependable enquiry handling requires us to process the following categories:
- Who you are and how to reach you
- Your name, title, language preference, country or region, email contact, and telephone details provided during profile creation or enquiry submission.
- Reservation preferences
- Dates of travel, room configuration and category, bedding selection, dietary and accessibility requests, and loyalty programme identifiers.
- Payment verification data
- The cardholder's name, masked card identifiers, billing location, and confirmation tokens issued by certified payment intermediaries. Complete card numbers never reach Suquerena systems.
- Technical and device data
- Internet protocol address, browser and operating system version, referring URLs, regional time zone, device identifiers, and page interaction times.
3. Lawful bases and purposes
Suquerena processes records only where a recognised legal basis applies: performance of a contract, legitimate business interest, compliance with a statutory duty, or your explicit consent. The operational purposes are:
- Passing on your request
- Relaying your dates and requirements to the property's reservations desk so it can answer with current availability.
- Content customisation
- Adjusting the rankings and guides we surface to match the destinations and property styles you have shown interest in.
- Protecting the service
- Safeguarding digital infrastructure, validating the legitimacy of transactions, and shielding users from unauthorised profile access.
- Operational communication
- Sending enquiry updates, confirmations, itinerary reminders, and necessary customer service notices.
- Statutory adherence
- Fulfilling financial disclosure rules, tax obligations, and other legal mandates that apply to our operations.
4. Authorised disclosures
We do not sell, rent, or lease personal identifiers to unconnected commercial parties. Transfers happen only under contractual safeguards, and only to the following categories of recipient:
- Hospitality partners
- Listed hotels receive the minimum needed — name, travel dates, and room requirements — to process your request.
- Accredited payment intermediaries
- Where payment is involved, encrypted billing details are routed to PCI-DSS validated processing partners.
- Infrastructure providers
- Enterprise-grade data centres and delivery networks store encrypted backups to maintain uptime and disaster resilience.
- Courts and regulators
- Information may be released where a lawful subpoena, court order, or official mandate requires it, or to protect vital interests.
5. Cookies, storage, and analytics
Digital identifiers and local storage support returning-visitor recognition, preference retention, performance measurement, and session continuity. Control rests with you via browser configuration; blocking essential cookies will impair some features.
6. Storage protection and retention
Layered administrative, technical, and physical controls protect records against unauthorised access, loss, alteration, or extraction. These include TLS 1.3 in transit, AES-256 at rest, segregated database clusters, and role-restricted credentials.
Records are held only as long as needed to complete an enquiry, resolve a question, satisfy audit requirements, or meet a statutory retention period. Once that period ends, records are permanently erased or irreversibly anonymised.
7. Rights and choices available to you
Depending on where you live, and after identity verification, you can exercise these rights:
- Right of access
- Receive a copy of the data we hold about you, in a portable form, along with an explanation of its use.
- Correction
- Have inaccurate, incomplete, or outdated details corrected without undue delay.
- Erasure
- Have your data removed once processing is no longer required by law or by the purpose it served.
- Restriction
- Pause processing activity while a record's accuracy or our legitimate interest is under review.
Opt-out and your choices
You have the right to control how your personal information is collected and used. Depending on your location and the laws that apply to you, the following opt-out choices are available:
- Sharing and sale of your data
- Where the CCPA/CPRA in California or similar laws in other jurisdictions apply, you can opt out of your personal information being sold or shared with third parties. We do not sell personal information in the ordinary meaning of the term, though some data is shared with trusted partners to deliver or improve the service.
- Tracking technologies
- Cookies and similar tracking tools can be managed or declined via your browser configuration or the consent controls published on this website.
- Promotional email
- You can stop receiving promotional email or newsletters at any time by using the unsubscribe link in any message, or by contacting us directly.
- Consent withdrawal
- Where you previously consented to processing, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it.
Write to [email protected], or use the contact form on this site, to exercise any right or lodge an opt-out request.
8. Updates to this document
We may update this notice as regulations or our systems change. Significant revisions are published here with a fresh effective date; continuing to use the site afterwards signifies acceptance.