Este documento se ofrece en inglés hasta que se publique una traducción. Para el derecho alemán y los procedimientos en Alemania prevalece el texto alemán de las condiciones.
Privacy policy
Effective date: 9 September 2026
This privacy policy explains how TRAVELDATASERVICE (“we”, “us”, “our”) processes personal data when you visit our website, create a hotel-owner account, pay a SaaS subscription, or use the TravelDataService Hotel Booking Engine booking engine.
It does not replace a hotel’s own privacy policy. Guest stays are booked with the property. That hotel is the controller of the guest’s booking file (see Roles).
1. Controller
TRAVELDATASERVICE Greece specialist travel agency & travel shop Owner: Jean Ioannis Arampatsis (sole proprietorship (Einzelunternehmen)) Müllerstr. 47 80469 Munich Germany Phone: +49 (0) 89 2609410 Email: info@tdsreisen.com VAT identification number: DE455705699
Contact for privacy requests: info@tdsreisen.com
We are established in Munich, Germany. The competent data-protection supervisory authority for Bavaria is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.
2. What this service is
TravelDataService Hotel Booking Engine is a white-label booking engine for hotels and property managers who already use Beds24. We do not replace Beds24. We provide a website widget and a billed SaaS dashboard.
- Guests book on the hotel’s website.
- Inventory, prices, extras, deposits, booking questions, and confirmation emails stay in Beds24.
- If the property uses Stripe in Beds24, the guest pays through that Stripe account. We never take lodging money on our Stripe account and we do not use Stripe Connect for guest stays.
- The hotel owner pays us a monthly subscription on our Stripe account.
TRAVELDATASERVICE also operates a travel-agency business. That retail travel activity is separate from this SaaS. This policy covers the TravelDataService Hotel Booking Engine website, owner dashboard, widgets, and related billing.
3. Roles (GDPR)
| Party | Role |
|---|---|
| Hotel / property manager | Controller of guest booking data (they own the stay) |
| TRAVELDATASERVICE (TravelDataService Hotel Booking Engine) | Processor of guest data we pass to Beds24; controller of owner accounts, SaaS billing, operational logs, and this website |
| Beds24 | Separate processor / PMS chosen by the hotel |
| Stripe (our billing) | Processor for owner subscription payments |
| Stripe (Beds24) | Processor for guest cards; we never see PAN/CVC |
When a hotel signs up, they accept our Terms of use, which include a data-processing agreement (Art. 28 GDPR) in section 15 of those terms for guest data we handle as processor.
4. Categories of data we process
4.1 Website visitors
- Technical logs needed to operate HTTPS (IP address, time, URL, user agent) for a short period, for security and abuse prevention
- Language preference cookie for the public marketing page
- No analytics cookies and no advertising cookies unless we add them later and obtain consent
4.2 Hotel owners (our customers)
- Email, hashed password, company name
- Locale preference
- IP and time on login if needed for security
- Beds24 refresh tokens (secret; never shown in the browser or in admin)
- Our Stripe customer id, subscription id, plan, status, invoices
- Optional commission settings
- Account timezone / date format as synced from Beds24 or set in the dashboard
- Photos the owner uploads or imports (stored on our disk to display the booking engine)
- Support correspondence you send to info@tdsreisen.com
4.3 Guests (hotel customers)
We do not keep a guest profile. Name, email, phone, address, custom question answers, and comments are sent to Beds24 when the booking is created and stay there.
Our thin bookings log (for the hotel dashboard, optional commission, and disputes) contains: Beds24 booking number, dates, occupancy counts, property/room, amounts, currency, status, language, and our checkout reference. No guest name, email, phone, or card data.
Webhook bodies from Beds24 contain personal data. We parse what we need for the columns above and do not store the raw body.
4.4 What we never store
- Card numbers, CVC, or full Stripe guest payment methods
- Passwords in plaintext
- Beds24 v1 API key or propKey (photo import is one-shot; keys exist only in memory for that request, then are discarded)
5. Purposes and legal bases (Art. 6 GDPR)
| Purpose | Legal basis |
|---|---|
| Provide the SaaS account, dashboard, widgets, and booking engine | Art. 6(1)(b) contract |
| Owner subscription billing on our Stripe | Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation (tax invoices) |
| Create the guest booking in Beds24 and pass the answers Beds24 requires | Art. 6(1)(b) contract with the hotel (we act as processor) |
| Session cookies for dashboard, admin, and the booking-engine iframe | Art. 6(1)(f) legitimate interests / Art. 6(1)(b); strictly necessary (TTDSG / § 25 TDDDG) |
| Security, fraud prevention, audit of staff actions | Art. 6(1)(f) and, where relevant, Art. 6(1)(c) |
| Optional owner-invoiced commission on bookings | Art. 6(1)(b) contract with the hotel |
| Marketing emails from us to owners | None in the current product unless we later collect a separate opt-in |
| Guest marketing | We do not send guest marketing. Beds24 emails are the hotel’s |
We do not sell personal data.
6. Guest bookings and payments
If the hotel collects a card, we create the Beds24 booking first, then open Beds24 Stripe Checkout. Unpaid holds are cancelled immediately if Checkout is abandoned, or after 15 minutes. We never store PAN/CVC.
Confirmation, request, and cancellation emails are sent by Beds24 (direct-booking templates). We do not send a second booking email from our servers.
The guest must tick the hotel’s privacy policy and general policy (and cancellation policy when shown) before pay or submit. Agreement (name + date) is written to the Beds24 Info tab. That record lives in Beds24, not in our database.
7. Recipients
We disclose data only as needed:
- Beds24 — guest booking payload; property sync; webhooks
- Stripe — owner billing (our account); guest charges only via the hotel’s Beds24 Stripe session
- Hosting — the application and MySQL run on our Plesk (production) or local development. Name the data-centre country/region here before relying on this paragraph. Default for a typical Plesk package: EU/EEA; if the host is outside the EEA, state the country and the transfer tool in section 8
- Staff of TRAVELDATASERVICE who need access to operate the SaaS (no Beds24 refresh tokens in the admin UI)
- Authorities when required by law
Sub-processors we use as processor of guest data (see Terms section 15): hosting (Plesk/MySQL) and Stripe for owner SaaS invoices only. Beds24 is the hotel’s processor, not ours.
The hotel may independently disclose guest data inside Beds24 (for example to OTAs). That is outside this policy.
8. International transfers
Stripe may process billing data in the United States and other countries. Stripe uses GDPR transfer tools (including Standard Contractual Clauses) as described in Stripe’s own privacy policy.
Beds24’s location is determined by that provider and by the hotel’s contract with Beds24.
If our Plesk host is outside the EEA, we will name the country here and the transfer safeguard. Default assumption for this installation: hosting is configured by us; if it is not in the EU/EEA, this paragraph must be updated in Admin → Legal before relying on it.
9. Cookies
We use only strictly necessary cookies until we add a consent banner for anything else:
- Owner session (ms_owner) — hotel dashboard
- Staff session (ms_staff) — platform admin
- Landing language (ms_land_lang) — remembers the public-site language
The booking engine runs in an iframe on our origin. That cookie is first-party to the iframe, not to the hotel domain. Hotels must mention us and Beds24 in their privacy policy. We provide a paste-in paragraph in the owner dashboard Help.
No analytics, advertising, or social-media tracking cookies in the current product.
10. Retention
- Owner account: for the life of the contract, then deletion on owner request subject to legal holds
- Stripe invoices and tax records: as required by German commercial and tax law (typically 10 years, §§ 257 HGB, 147 AO)
- Bookings log amounts, ids, dates, status: as needed for tax, commission, and disputes (aligned with invoice retention when commission was billed)
- Security logs: short period
- Room and property photos: until the owner deletes the gallery or the organisation
- Guest identity data: not retained by us after transit to Beds24 (except the thin log above)
11. Security (Art. 32)
Technical and organisational measures for this product include:
- Encryption in transit (HTTPS) in production
- Passwords stored only as hashes, never in plaintext
- Tenant isolation: queries filtered by organisation; hotel sessions cannot open platform admin
- Secrets (Beds24 refresh tokens, our Stripe keys, webhook secrets) stay on the server; none in the widget or browser
- Webhook authenticity checks (Beds24 custom header; Stripe signature)
- No storage of guest PAN/CVC; unpaid card holds cancelled immediately on abort or after 15 minutes
- Beds24 v1 photo keys exist only in memory for the import request, then discarded
- Raw Beds24 webhook bodies are not stored (they contain guest PII)
- Access limited to TRAVELDATASERVICE staff who need it to operate the SaaS
- Optional origin allowlist for widget APIs
- Rate-limiting of public booking APIs
These measures are also part of the Art. 28 terms in section 15 of the Terms of use.
12. Your rights
Depending on your role:
Hotel owners: access, rectification, erasure, restriction, portability, objection (Art. 15–21). The dashboard Settings page offers organisation export and delete (live engines are cancelled, tokens deleted, Stripe keeps invoices as legally required). Beds24 bookings already created are not deleted by us.
Guests: the hotel is the controller. Requests go to the hotel / Beds24. Our log has no guest name or email to erase; we can still delete or flag a row on the hotel’s instruction.
You may lodge a complaint with BayLDA or another EU supervisory authority of your habitual residence.
No automated decision-making producing legal effects (Art. 22).
13. Children
The SaaS is for business customers. We do not knowingly create owner accounts for children. Guest occupancy (including children as guests of a hotel) is processed only as booking facts the hotel’s Beds24 setup requires.
14. Changes
We may update this policy. The effective date above will change. Material changes that affect owners will be indicated on this page and, where required, in the dashboard.
15. Contact
TRAVELDATASERVICE, Jean Ioannis Arampatsis, Müllerstr. 47, 80469 Munich, Germany info@tdsreisen.com · +49 (0) 89 2609410