Hotel Rancho Uplistsikhe

Privacy and Cookie Policy

Effective 24 August 2026 · Last updated 24 August 2026

This Policy is written under the Law of Georgia on Personal Data Protection (adopted 14 June 2023, in force since 1 March 2024) and is supervised by the Personal Data Protection Service of Georgia.

1. Who we are

Hotel Rancho Uplistsikhe (“the Hotel”, “we”, “us”, “our”) operates the accommodation, tours, airport transfers and vehicle rental described on uplistsikhehotel.ge, and operates the online booking system on that website itself.

AddressUplistsikhe Museum Street, Kvakhvreli, Gori, Shida Kartli, Georgia
Phone / WhatsApp+995 555 410 205
Emailuplistsikhehotel@gmail.com
Privacy mattersMark your message “Personal data request” and send it to the address above

We are the data controller: we decide what personal data is collected, why, and how long it is kept. We do not use a third-party booking engine, and no external reservation platform holds a copy of your booking. The booking system, the database and the staff dashboard are built for and run by this Hotel.

2. What this Policy covers

It covers personal data we process when you:

  • browse uplistsikhehotel.ge;
  • search availability, request a quote, or place a booking for a room, tour, airport transfer or vehicle;
  • create a guest account, verify your email, or reset your password;
  • send us a message through the contact form, by email, phone or messenger;
  • stay with us, or use one of our services;
  • receive an email from us about your booking.

It does not cover websites we merely link to — Google Maps, our Facebook page, WhatsApp, or the Kuula 360° tour. Those services have their own policies.

3. What personal data we collect

3.1 Data you give us

CategoryFields
IdentityFirst name, last name. At check-in, our staff may record the type and number of an identity document, as required by the rules on registering guests. We never ask for identity documents when you book online.
ContactEmail address, phone number
Guest accountEmail address, password (stored only as a hash — see section 5), name, phone, whether the address has been confirmed
BookingArrival and departure dates, the number of guests and the age of each child, room type and rate, expected arrival time, language, tour dates and head count, airport transfer airport and direction, vehicle rental dates, pickup and drop-off points, and anything you write in a notes or special-requests box
Vehicle rentalThe name, telephone number and driving-licence details of the person who will drive, and your flight number and time where you give them to us
Tours and transfersYour answers to any question a particular tour or transfer asks — for example a pickup address or a flight number
PaymentA reference to your order, the amount, the currency, the payment status, and the address of the payment page our provider last issued for you so that you can return to an unfinished payment. We never receive or store your card number, expiry date or security code — see section 5
MessagesAnything you write to us in the contact form, by email or by messenger, and anything you write when asking us to cancel part of a booking, together with the email address you give us for that request
Staff notesNotes our staff write about your booking so that we can look after you — a room preference, an arrival arrangement, something you told us on the phone

3.2 Data created automatically when you use the site

CategoryFields
TechnicalThe network (IP) address your request came from, and the language you select
SecurityLogin attempts, failed logins, account lockouts, registration and password-reset attempts, and the outcome of each. The email address in these records is stored only as a fingerprint — a SHA-256 hash — never as readable text. We also record the network address the request came from
Email deliveryWhich category of email was sent to which address and when, so we can answer “did my confirmation arrive?”
AnalyticsOnly in the limited form described in section 8

3.3 Data about other people

Other guests on your booking. If you book for more than one person, you give us their names, and the ages of any children so that we can price the stay and prepare the room. At check-in our staff may record identity details for each guest staying.

The driver of a rented vehicle. If that is not you, you give us their name, telephone number and licence details.

3.4 Sensitive information you may choose to tell us

We never ask you for information about your health, your beliefs, or anything else the law treats as sensitive, and you do not need to give us any in order to book. But our booking form, our contact form and the questions some tours ask all have boxes you can type anything into — and guests sometimes use them to tell us about a food allergy, a disability, a mobility need or a religious observance, so that we can look after them properly.

If you write something like that to us, we use it only to provide what you have asked for — to prepare your room, your meal or your transport — and we share it only with the member of staff or the partner who needs it to do that. We do not use it for any other purpose, we do not use it to make decisions about you, and you can ask us to remove it at any time.

4. Why we use it, and our legal ground

Under Georgian law we may only process your data where we have a ground for it. Ours are:

PurposeGround under the Law of Georgia on Personal Data Protection
Take and confirm your booking; hold a room, tour, transfer or vehicle for you; send your confirmation and pre-arrival informationNecessary for concluding and performing a contract with you
Process your payment and issue receiptsPerformance of a contract; compliance with our obligations under Georgian accounting and tax legislation
Register your stay and, where required, record identity documentsCompliance with an obligation imposed by Georgian legislation
Answer your messages, calls and requestsPerformance of a contract, or our legitimate interest in responding to enquiries
Operate your guest account and let you see your bookingsPerformance of a contract
Protect the site and accounts from fraud, password guessing, spam and abuse; keep a security audit trailOur legitimate interest in keeping the service and our guests’ accounts secure
Improve our rooms, services and website, including aggregated statisticsOur legitimate interest, and your consent where cookies are involved
Send you occasional emails about our own offers and news, where you gave us your email address in the course of a bookingOur legitimate interest in marketing our own similar services to our own guests. You may object at any time and we will stop — see section 9
Defend or bring legal claims, resolve disputesOur legitimate interest; protection of important legal interests

Where we rely on legitimate interest, we have weighed it against your rights and freedoms, and you may object at any time (see section 9).

Service messages are not marketing. Even if you object to marketing, we will still email you your booking confirmation, changes to your booking, payment receipts, verification codes and password resets — these are part of providing the service you asked for.

5. How we store and protect your data

This section describes what our system actually does.

Where the data lives. All booking, guest and account data is held in a single PostgreSQL database on a dedicated server that we rent and administer, hosted by Hostinger in France. The public website, the booking API and the staff dashboard run on that same server. There is no third-party booking platform, channel manager or CRM holding a duplicate of your booking data.

A guest account works across our properties, while the booking records themselves are held separately for each one. If you have stayed with us more than once, you may appear in our records more than once.

In transit. The website (uplistsikhehotel.ge), the booking API (api.uplistsikhehotel.ge) and the staff dashboard (admin.uplistsikhehotel.ge) are served over HTTPS only. Certificates are issued and renewed automatically, and plain HTTP requests are redirected to HTTPS. Your data is encrypted between your browser and our server.

Payment card details never reach us. When you pay by card, you are handed over to the hosted checkout page of our payment provider, Flitt, and you enter your card details there, on their systems. Flitt tells our server only whether the payment succeeded, for which order, and for how much. Our database contains a reference to your order, the amount, the currency and a status — never a card number, expiry date or security code. We could not disclose your card number if we were asked to, because we do not have it.

Passwords are never stored. A guest-account password is stored only as a salted PBKDF2-HMAC-SHA-512 hash. We cannot read it, recover it, or tell you what it is — we can only offer you a reset. Password-reset and email-verification codes expire 15 minutes after they are issued, may be attempted only a few times, and are deleted once expired.

Sessions. Signing in issues a short-lived access token (valid about 15 minutes) alongside a refresh token (valid about 14 days) that can be revoked. Resetting your password revokes every existing session: the refresh tokens are revoked immediately, and an access token already issued remains usable for up to 15 minutes more.

Abuse and security logging is deliberately minimised. Our security log has to record failed logins and registration attempts, but the email address in each record is stored as a SHA-256 fingerprint rather than as readable text — so if that log were ever exposed, it could not simply be read off as a list of addresses. We should be precise about what that does and does not mean: the fingerprint is calculated the same way every time, so someone who already knew an address could confirm whether it appears. It stops the log becoming a mailing list; it is not anonymity. We also record the network address the request came from — for IPv6 we keep only the first half of the address, which is enough to recognise a source and not enough to single out a device. These records are deleted after 90 days.

Access is limited to Hotel staff. The staff dashboard is on a separate address and requires an individual account per staff member. Each account has a role that determines what it can reach — reception staff, managers and administrators do not see the same things. We hold our staff’s own names, email addresses and telephone numbers for this purpose. We do not sell personal data, and we do not give any third party access to our database for their own purposes.

Automatic deletion runs on a schedule. Our system removes some data on its own, without anyone having to remember:

  • an unpaid, unfinished order is cancelled and the room, tour or vehicle goes back on sale within about 60 minutes. The order itself stays in our records, marked unpaid — it is the room that is released, not the order that is erased;
  • a guest account created but never confirmed by email is deleted after 7 days, together with its verification codes and sign-in tokens. If that person had already started a booking, the booking and the contact details on it remain, and are dealt with under section 7;
  • verification and password-reset codes are deleted as soon as they expire;
  • sign-in tokens are deleted 30 days after they expire or are revoked;
  • the security log and the email-delivery log are deleted after 90 days.

Everything else — your bookings, your account once confirmed, and messages you send us — is kept until we delete it on the timetable in section 7, or until you ask us to.

If something goes wrong. No system is perfectly secure. We use the measures above and review them, but we cannot guarantee that transmission over the internet or electronic storage is completely safe. We keep an internal register of data-security incidents. Where an incident may cause significant harm or pose a significant threat to your rights, we notify the Personal Data Protection Service of Georgia within 72 hours of identifying it, and we inform you directly and without delay, telling you what happened, what it may mean for you, and what we are doing about it.

6. Who else sees your data

We do not sell your data and we do not share it for anyone else’s marketing. We use a small number of service providers, each acting as our data processor and bound to use the data only to deliver their service to us:

ProviderWhat they doWhat they see
FlittProcesses card payments and refundsYour card details, which you enter on their page; your email address, the amount, and a reference to your order
Google (Gmail / Google Workspace)Delivers our outgoing emailThe content of emails we send you, and your email address
Google Analytics 4Website statisticsPseudonymous usage data, as described in section 8
Google Maps, KuulaMap and 360° tour embedded on our siteYour IP address and browser data when the embed loads
HostingerRuns the server our system sits onHolds the server; does not access data in the ordinary course

We also disclose data where Georgian law obliges us to: to Georgian authorities and courts, to our accountants and auditors, and to legal advisers if we need to defend a claim. If you book a tour, transfer or activity operated by a partner, we pass that partner only what they need to deliver it — normally your name, the date, the head count and a contact number.

Transfers outside Georgia. Our server is in France, and Google and Flitt process data outside Georgia. Under Georgian law we may transfer data abroad only where the receiving country or organisation is on the list of those recognised by the Personal Data Protection Service as ensuring adequate protection, or where the transfer rests on another ground allowed by the Law — including a written agreement with the recipient providing appropriate safeguards, made with the permission of the Personal Data Protection Service. You can ask us which safeguard applies to a particular transfer.

7. How long we keep your data

DataKept for
Booking, stay and payment recordsAt least 6 years from the end of the year of your stay, to meet Georgian accounting and tax obligations. After that we remove the personal details and keep the financial entry itself
Guest account (name, email, phone, preferences)Until you ask us to delete it. We review dormant accounts periodically
Unverified guest account7 days, automatically
Contact-form messages and correspondenceUntil the matter is closed and we no longer need them; we review and clear these periodically
Marketing history (which mailing went to which address, and when)Kept as a record that a mailing was sent; removed when you ask us to erase your data
Identity-document details recorded at check-inThe period required by the applicable rules, then removed
Security log, email-delivery log90 days, automatically
Session tokens30 days after expiry or revocation, automatically
Analytics dataPer Google Analytics retention settings — 14 months

Where we say “periodically” or “we review”, we mean a person does it, not a machine. We would rather tell you that plainly than promise an automatic deletion we do not perform. Where a row says “automatically”, the system does it on its own.

When a period ends, the data is deleted or irreversibly anonymised. We keep the minimum needed to show that a legal claim is time-barred, or that an objection to marketing was recorded.

8. Cookies and similar technologies

We use very few. Our website carries no advertising cookies, no retargeting pixels and no social-media trackers.

TypeWhat it doesConsent needed?
Strictly necessaryKeeps you signed in to your guest account, keeps your basket during checkout, protects forms from abuse. The site cannot work without theseNo — but you can block them in your browser and accept that booking will stop working
PreferenceRemembers the language you chose and your answer to the cookie banner. Stored in your own browserNo
Analytics (Google Analytics 4)Counts visits, shows which pages and rooms are looked at, and which bookings resultedYes

How consent works here. Analytics starts in a denied state before you decide anything: no analytics cookie is written and no advertising identifier is created. Google still receives a signal that a page was viewed, without anything that identifies you or your device between visits — this is Google’s Consent Mode, and it is how a visit can be counted without being tracked. If you press Accept, analytics storage is switched on for you and your visits can be linked into a session. If you press Reject, nothing changes — it stays denied. Your answer is stored in your own browser, under the key cookie-consent, and never on our server.

What we measure about a booking. When a booking is completed we send Google the booking reference, the amount, and which rooms, tours or vehicles were bought, so that we can see which pages lead to bookings. We do not send your name, email address, telephone number, or anything you wrote in a notes field. The page address we send includes anything after the question mark in the URL, which is how we recognise which advertisement or link brought you to us.

Changing your mind. Use the button below to reopen the cookie banner and answer differently. You can also clear your browser’s site data for uplistsikhehotel.ge, which has the same effect, or block and delete cookies entirely in your browser settings. Blocking strictly necessary cookies will prevent sign-in and checkout from working.

Third-party embeds. The Google Maps map and the Kuula 360° tour load from those companies’ servers, which can set their own cookies once the embed loads. If you do not open those parts of the site, they do not load.

We do not currently respond to browser “Do Not Track” signals, because there is no agreed standard for what they should mean.

9. Your rights

Under the Law of Georgia on Personal Data Protection you have the right to:

  • be informed about what data we process about you, why, on what ground, who receives it, how long we keep it, and where it came from;
  • access your data and receive a copy of it, free of charge;
  • have it corrected, updated or completed if it is inaccurate or incomplete;
  • have processing stopped, and the data erased or destroyed, where there is no longer a ground to keep it;
  • have your data blocked while a dispute about its accuracy or the lawfulness of processing is being resolved;
  • receive your data in a portable, machine-readable format, and have it transmitted to another controller, where processing is automated and based on your consent or on a contract;
  • object to processing we base on legitimate interest — including our marketing emails;
  • withdraw your consent at any time, in the same form in which you gave it. For analytics cookies, use the button in section 8. Withdrawal does not make earlier processing unlawful;
  • not be subject to a decision made solely by automated means. We do not make any such decision about you;
  • complain to the Personal Data Protection Service of Georgia (personaldata.ge) or to a court. If we refuse a request, we will tell you the legal ground for the refusal and how to appeal it.

Stopping marketing emails. Write to uplistsikhehotel@gmail.com and we will remove you from every future mailing. We are building a one-click unsubscribe link into those emails; until it is live, an email to us is the way to stop them, and we act on it at once.

How to exercise your rights. Email uplistsikhehotel@gmail.com with your request and enough detail to find your record — normally the booking reference and the email address you booked with. We verify your identity using information we already hold, and we will not ask for new documents in order to do so.

How quickly we answer. Within 10 working days of your request. In exceptional cases, where the request is complex, we may extend this by up to a further 10 working days — we will tell you immediately if we need to. There is no charge, except where Georgian legislation provides for a fee, or where the cost of producing the copy in a form other than the one we hold it in is reasonable to pass on.

If we have to keep something you asked us to delete — an invoice we are legally required to retain, for example — we will tell you exactly what we kept and why. In that case we remove your name and contact details from the record and keep the financial entry alone.

10. Other guests, and children

If you give us another person’s details when booking, you confirm you may do so and that you have told them about this Policy. We ask you to share it with them.

Our services are booked by adults. We do not knowingly collect data about a child except what a parent or guardian gives us as part of a family booking — normally the age of each child, used to price the stay and prepare the room. If you believe a child’s data has reached us in any other way, tell us and we will delete it.

11. Changes to this Policy

We may update this Policy. The version on this page is always the current one, and the “Last updated” date shows when it changed. If a change materially affects how we use your data, we will make that clear on the website and, where the law requires, ask for your consent again. Continuing to use the site after a change means the updated Policy applies to your future use of it — it does not, by itself, count as consent to a new use of data that requires consent.

12. Contact us

Hotel Rancho Uplistsikhe — Uplistsikhe Museum Street, Kvakhvreli, Gori, Shida Kartli, Georgia.

Email uplistsikhehotel@gmail.com · Phone / WhatsApp +995 555 410 205. For privacy matters, mark your message “Personal data request”.