This Policy is written under the Law of Georgia on Personal Data Protection (adopted 14 June 2023, in force since 1 March 2024) and is supervised by the Personal Data Protection Service of Georgia.
1. Who we are
Hotel Rancho Uplistsikhe (“the Hotel”, “we”, “us”, “our”) operates the accommodation, tours, airport transfers and vehicle rental described on uplistsikhehotel.ge, and operates the online booking system on that website itself.
| Address | Uplistsikhe Museum Street, Kvakhvreli, Gori, Shida Kartli, Georgia |
| Phone / WhatsApp | +995 555 410 205 |
| uplistsikhehotel@gmail.com | |
| Privacy matters | Mark your message “Personal data request” and send it to the address above |
We are the data controller: we decide what personal data is collected, why, and how long it is kept. We do not use a third-party booking engine, and no external reservation platform holds a copy of your booking. The booking system, the database and the staff dashboard are built for and run by this Hotel.
2. What this Policy covers
It covers personal data we process when you:
- browse uplistsikhehotel.ge;
- search availability, request a quote, or place a booking for a room, tour, airport transfer or vehicle;
- create a guest account, verify your email, or reset your password;
- send us a message through the contact form, by email, phone or messenger;
- stay with us, or use one of our services;
- receive an email from us about your booking.
It does not cover websites we merely link to — Google Maps, our Facebook page, WhatsApp, or the Kuula 360° tour. Those services have their own policies.
3. What personal data we collect
3.1 Data you give us
| Category | Fields |
|---|---|
| Identity | First name, last name. At check-in, our staff may record the type and number of an identity document, as required by the rules on registering guests. We never ask for identity documents when you book online. |
| Contact | Email address, phone number |
| Guest account | Email address, password (stored only as a hash — see section 5), name, phone, whether the address has been confirmed |
| Booking | Arrival and departure dates, the number of guests and the age of each child, room type and rate, expected arrival time, language, tour dates and head count, airport transfer airport and direction, vehicle rental dates, pickup and drop-off points, and anything you write in a notes or special-requests box |
| Vehicle rental | The name, telephone number and driving-licence details of the person who will drive, and your flight number and time where you give them to us |
| Tours and transfers | Your answers to any question a particular tour or transfer asks — for example a pickup address or a flight number |
| Payment | A reference to your order, the amount, the currency, the payment status, and the address of the payment page our provider last issued for you so that you can return to an unfinished payment. We never receive or store your card number, expiry date or security code — see section 5 |
| Messages | Anything you write to us in the contact form, by email or by messenger, and anything you write when asking us to cancel part of a booking, together with the email address you give us for that request |
| Staff notes | Notes our staff write about your booking so that we can look after you — a room preference, an arrival arrangement, something you told us on the phone |
3.2 Data created automatically when you use the site
| Category | Fields |
|---|---|
| Technical | The network (IP) address your request came from, and the language you select |
| Security | Login attempts, failed logins, account lockouts, registration and password-reset attempts, and the outcome of each. The email address in these records is stored only as a fingerprint — a SHA-256 hash — never as readable text. We also record the network address the request came from |
| Email delivery | Which category of email was sent to which address and when, so we can answer “did my confirmation arrive?” |
| Analytics | Only in the limited form described in section 8 |
3.3 Data about other people
Other guests on your booking. If you book for more than one person, you give us their names, and the ages of any children so that we can price the stay and prepare the room. At check-in our staff may record identity details for each guest staying.
The driver of a rented vehicle. If that is not you, you give us their name, telephone number and licence details.
3.4 Sensitive information you may choose to tell us
We never ask you for information about your health, your beliefs, or anything else the law treats as sensitive, and you do not need to give us any in order to book. But our booking form, our contact form and the questions some tours ask all have boxes you can type anything into — and guests sometimes use them to tell us about a food allergy, a disability, a mobility need or a religious observance, so that we can look after them properly.
If you write something like that to us, we use it only to provide what you have asked for — to prepare your room, your meal or your transport — and we share it only with the member of staff or the partner who needs it to do that. We do not use it for any other purpose, we do not use it to make decisions about you, and you can ask us to remove it at any time.
4. Why we use it, and our legal ground
Under Georgian law we may only process your data where we have a ground for it. Ours are:
| Purpose | Ground under the Law of Georgia on Personal Data Protection |
|---|---|
| Take and confirm your booking; hold a room, tour, transfer or vehicle for you; send your confirmation and pre-arrival information | Necessary for concluding and performing a contract with you |
| Process your payment and issue receipts | Performance of a contract; compliance with our obligations under Georgian accounting and tax legislation |
| Register your stay and, where required, record identity documents | Compliance with an obligation imposed by Georgian legislation |
| Answer your messages, calls and requests | Performance of a contract, or our legitimate interest in responding to enquiries |
| Operate your guest account and let you see your bookings | Performance of a contract |
| Protect the site and accounts from fraud, password guessing, spam and abuse; keep a security audit trail | Our legitimate interest in keeping the service and our guests’ accounts secure |
| Improve our rooms, services and website, including aggregated statistics | Our legitimate interest, and your consent where cookies are involved |
| Send you occasional emails about our own offers and news, where you gave us your email address in the course of a booking | Our legitimate interest in marketing our own similar services to our own guests. You may object at any time and we will stop — see section 9 |
| Defend or bring legal claims, resolve disputes | Our legitimate interest; protection of important legal interests |
Where we rely on legitimate interest, we have weighed it against your rights and freedoms, and you may object at any time (see section 9).
Service messages are not marketing. Even if you object to marketing, we will still email you your booking confirmation, changes to your booking, payment receipts, verification codes and password resets — these are part of providing the service you asked for.
5. How we store and protect your data
This section describes what our system actually does.
Where the data lives. All booking, guest and account data is held in a single PostgreSQL database on a dedicated server that we rent and administer, hosted by Hostinger in France. The public website, the booking API and the staff dashboard run on that same server. There is no third-party booking platform, channel manager or CRM holding a duplicate of your booking data.
A guest account works across our properties, while the booking records themselves are held separately for each one. If you have stayed with us more than once, you may appear in our records more than once.
In transit. The website (uplistsikhehotel.ge), the booking API (api.uplistsikhehotel.ge) and the staff dashboard (admin.uplistsikhehotel.ge) are served over HTTPS only. Certificates are issued and renewed automatically, and plain HTTP requests are redirected to HTTPS. Your data is encrypted between your browser and our server.
Payment card details never reach us. When you pay by card, you are handed over to the hosted checkout page of our payment provider, Flitt, and you enter your card details there, on their systems. Flitt tells our server only whether the payment succeeded, for which order, and for how much. Our database contains a reference to your order, the amount, the currency and a status — never a card number, expiry date or security code. We could not disclose your card number if we were asked to, because we do not have it.
Passwords are never stored. A guest-account password is stored only as a salted PBKDF2-HMAC-SHA-512 hash. We cannot read it, recover it, or tell you what it is — we can only offer you a reset. Password-reset and email-verification codes expire 15 minutes after they are issued, may be attempted only a few times, and are deleted once expired.
Sessions. Signing in issues a short-lived access token (valid about 15 minutes) alongside a refresh token (valid about 14 days) that can be revoked. Resetting your password revokes every existing session: the refresh tokens are revoked immediately, and an access token already issued remains usable for up to 15 minutes more.
Abuse and security logging is deliberately minimised. Our security log has to record failed logins and registration attempts, but the email address in each record is stored as a SHA-256 fingerprint rather than as readable text — so if that log were ever exposed, it could not simply be read off as a list of addresses. We should be precise about what that does and does not mean: the fingerprint is calculated the same way every time, so someone who already knew an address could confirm whether it appears. It stops the log becoming a mailing list; it is not anonymity. We also record the network address the request came from — for IPv6 we keep only the first half of the address, which is enough to recognise a source and not enough to single out a device. These records are deleted after 90 days.
Access is limited to Hotel staff. The staff dashboard is on a separate address and requires an individual account per staff member. Each account has a role that determines what it can reach — reception staff, managers and administrators do not see the same things. We hold our staff’s own names, email addresses and telephone numbers for this purpose. We do not sell personal data, and we do not give any third party access to our database for their own purposes.
Automatic deletion runs on a schedule. Our system removes some data on its own, without anyone having to remember:
- an unpaid, unfinished order is cancelled and the room, tour or vehicle goes back on sale within about 60 minutes. The order itself stays in our records, marked unpaid — it is the room that is released, not the order that is erased;
- a guest account created but never confirmed by email is deleted after 7 days, together with its verification codes and sign-in tokens. If that person had already started a booking, the booking and the contact details on it remain, and are dealt with under section 7;
- verification and password-reset codes are deleted as soon as they expire;
- sign-in tokens are deleted 30 days after they expire or are revoked;
- the security log and the email-delivery log are deleted after 90 days.
Everything else — your bookings, your account once confirmed, and messages you send us — is kept until we delete it on the timetable in section 7, or until you ask us to.
If something goes wrong. No system is perfectly secure. We use the measures above and review them, but we cannot guarantee that transmission over the internet or electronic storage is completely safe. We keep an internal register of data-security incidents. Where an incident may cause significant harm or pose a significant threat to your rights, we notify the Personal Data Protection Service of Georgia within 72 hours of identifying it, and we inform you directly and without delay, telling you what happened, what it may mean for you, and what we are doing about it.
6. Who else sees your data
We do not sell your data and we do not share it for anyone else’s marketing. We use a small number of service providers, each acting as our data processor and bound to use the data only to deliver their service to us:
| Provider | What they do | What they see |
|---|---|---|
| Flitt | Processes card payments and refunds | Your card details, which you enter on their page; your email address, the amount, and a reference to your order |
| Google (Gmail / Google Workspace) | Delivers our outgoing email | The content of emails we send you, and your email address |
| Google Analytics 4 | Website statistics | Pseudonymous usage data, as described in section 8 |
| Google Maps, Kuula | Map and 360° tour embedded on our site | Your IP address and browser data when the embed loads |
| Hostinger | Runs the server our system sits on | Holds the server; does not access data in the ordinary course |
We also disclose data where Georgian law obliges us to: to Georgian authorities and courts, to our accountants and auditors, and to legal advisers if we need to defend a claim. If you book a tour, transfer or activity operated by a partner, we pass that partner only what they need to deliver it — normally your name, the date, the head count and a contact number.
Transfers outside Georgia. Our server is in France, and Google and Flitt process data outside Georgia. Under Georgian law we may transfer data abroad only where the receiving country or organisation is on the list of those recognised by the Personal Data Protection Service as ensuring adequate protection, or where the transfer rests on another ground allowed by the Law — including a written agreement with the recipient providing appropriate safeguards, made with the permission of the Personal Data Protection Service. You can ask us which safeguard applies to a particular transfer.
7. How long we keep your data
| Data | Kept for |
|---|---|
| Booking, stay and payment records | At least 6 years from the end of the year of your stay, to meet Georgian accounting and tax obligations. After that we remove the personal details and keep the financial entry itself |
| Guest account (name, email, phone, preferences) | Until you ask us to delete it. We review dormant accounts periodically |
| Unverified guest account | 7 days, automatically |
| Contact-form messages and correspondence | Until the matter is closed and we no longer need them; we review and clear these periodically |
| Marketing history (which mailing went to which address, and when) | Kept as a record that a mailing was sent; removed when you ask us to erase your data |
| Identity-document details recorded at check-in | The period required by the applicable rules, then removed |
| Security log, email-delivery log | 90 days, automatically |
| Session tokens | 30 days after expiry or revocation, automatically |
| Analytics data | Per Google Analytics retention settings — 14 months |
Where we say “periodically” or “we review”, we mean a person does it, not a machine. We would rather tell you that plainly than promise an automatic deletion we do not perform. Where a row says “automatically”, the system does it on its own.
When a period ends, the data is deleted or irreversibly anonymised. We keep the minimum needed to show that a legal claim is time-barred, or that an objection to marketing was recorded.
9. Your rights
Under the Law of Georgia on Personal Data Protection you have the right to:
- be informed about what data we process about you, why, on what ground, who receives it, how long we keep it, and where it came from;
- access your data and receive a copy of it, free of charge;
- have it corrected, updated or completed if it is inaccurate or incomplete;
- have processing stopped, and the data erased or destroyed, where there is no longer a ground to keep it;
- have your data blocked while a dispute about its accuracy or the lawfulness of processing is being resolved;
- receive your data in a portable, machine-readable format, and have it transmitted to another controller, where processing is automated and based on your consent or on a contract;
- object to processing we base on legitimate interest — including our marketing emails;
- withdraw your consent at any time, in the same form in which you gave it. For analytics cookies, use the button in section 8. Withdrawal does not make earlier processing unlawful;
- not be subject to a decision made solely by automated means. We do not make any such decision about you;
- complain to the Personal Data Protection Service of Georgia (personaldata.ge) or to a court. If we refuse a request, we will tell you the legal ground for the refusal and how to appeal it.
Stopping marketing emails. Write to uplistsikhehotel@gmail.com and we will remove you from every future mailing. We are building a one-click unsubscribe link into those emails; until it is live, an email to us is the way to stop them, and we act on it at once.
How to exercise your rights. Email uplistsikhehotel@gmail.com with your request and enough detail to find your record — normally the booking reference and the email address you booked with. We verify your identity using information we already hold, and we will not ask for new documents in order to do so.
How quickly we answer. Within 10 working days of your request. In exceptional cases, where the request is complex, we may extend this by up to a further 10 working days — we will tell you immediately if we need to. There is no charge, except where Georgian legislation provides for a fee, or where the cost of producing the copy in a form other than the one we hold it in is reasonable to pass on.
If we have to keep something you asked us to delete — an invoice we are legally required to retain, for example — we will tell you exactly what we kept and why. In that case we remove your name and contact details from the record and keep the financial entry alone.
10. Other guests, and children
If you give us another person’s details when booking, you confirm you may do so and that you have told them about this Policy. We ask you to share it with them.
Our services are booked by adults. We do not knowingly collect data about a child except what a parent or guardian gives us as part of a family booking — normally the age of each child, used to price the stay and prepare the room. If you believe a child’s data has reached us in any other way, tell us and we will delete it.
11. Changes to this Policy
We may update this Policy. The version on this page is always the current one, and the “Last updated” date shows when it changed. If a change materially affects how we use your data, we will make that clear on the website and, where the law requires, ask for your consent again. Continuing to use the site after a change means the updated Policy applies to your future use of it — it does not, by itself, count as consent to a new use of data that requires consent.
12. Contact us
Hotel Rancho Uplistsikhe — Uplistsikhe Museum Street, Kvakhvreli, Gori, Shida Kartli, Georgia.
Email uplistsikhehotel@gmail.com · Phone / WhatsApp +995 555 410 205. For privacy matters, mark your message “Personal data request”.