Privacy policy
Останнє оновлення: 3 жовтня 2026 р.
Ця сторінка доступна лише польською та англійською — нижче англійська версія. Юридично обов’язковою є польська версія.
1. Data controller
The controller of personal data is Artur Bashyrov, ul. Składowa 16, 30-010 Kraków, conducting unregistered activity within the meaning of Art. 5(1) of the Polish Act of 6 March 2018 – Entrepreneurs' Law. For matters concerning personal data, write to contact@hotrips.pl.
2. What data we process and why
HoTrips works without an account. We do not collect names, e-mail addresses or payment details.
- Technical connection data (IP address, address of the page visited, browser information) — necessary to display the page. Our server does not store IP addresses in logs. The server provider may process them for network security. Legal basis: the controller's legitimate interest — providing the service and keeping it secure (Art. 6(1)(f) GDPR).
- Search parameters (from, to, dates, number of travellers) — kept in the page address so that results can be shared. We do not link them to your identity and do not build profiles.
- Selected currency — remembered only in your browser (localStorage). It never reaches our server; you remove it by clearing the site data in your browser. The language is part of the page address (/en) and is not stored anywhere.
- Browser language (the Accept-Language header) — in the English version we use it to pick the default departure airport and currency (e.g. en-GB → London and pounds). It is read each time a page is shown and is not stored anywhere (Art. 6(1)(f) GDPR).
- Visits to partners — when you click a link to a partner, we record which service and which of our pages you went from, and the time. No IP address, cookies or browser data — this cannot identify you. It is used only for statistics on which parts of the service are useful (Art. 6(1)(f) GDPR).
- Correspondence — if you write to us, we process your e-mail address and message to reply (Art. 6(1)(f) GDPR), for as long as needed to handle the matter and no longer than 12 months.
The HoTrips mobile app
- The app works without an account. Your settings (language, currency, country) and saved trips and hotels are stored only on your phone — uninstalling the app removes them.
- To search, the app sends our server the search parameters and the country and language set on your phone (we use them to pick the default airport and currency). Photos are fetched through our server. Visits to partners are counted as on the website — without any phone data.
- Price-drop notifications for saved trips and hotels — the app's only notifications, and only if you allow them on your phone. Trips and hotels are saved separately. For each saved item we then store your phone's notification address (push token), the destination and dates, and in addition: for a trip — the flight price when you saved it; for a hotel — its name and the price of the stay when you saved it; plus the app's language and currency (when you change them, the app updates them with us so notifications arrive in the new language). All of this solely to check prices once a day and send at most one notification. Legal basis: your consent (Art. 6(1)(a) GDPR), which you withdraw by turning off the app's notifications in your phone settings or removing the item from your saved list. We delete the data when you remove the item or turn notifications off, after the travel date or when the app is uninstalled — whichever comes first.
3. Cookies
HoTrips does not use cookies or any tracking or analytics tools, which is why we show no consent banner. Once you go to a partner's website, the partner's cookie policy applies.
4. Recipients of data
- The server (hosting) provider — for technical connection data, under a data processing agreement.
- App notifications are sent through Expo (650 Industries, Inc., USA), which passes them to the Apple Push Notification service or Firebase Cloud Messaging (Google) — the providers of your phone's system. They receive the token and the notification text.
- Partners — only when you click a link to a partner yourself. We then pass the search parameters and our affiliate identifier, not your personal data. From that moment the partner is the controller of any data you give them.
City photos (from Wikipedia), weather forecasts and exchange rates are fetched by our server — your data is not passed on in the process.
Hotel photos from Nuitée also go through our server. The “Book” link to Nuitée contains the search parameters, the currency you selected and the language code of your browser (e.g. “en”) so the booking site opens in a familiar language — nothing that identifies you.
5. Transfers outside the EEA
We do not transfer data outside the European Economic Area — with one exception: if you turn on price notifications in the app, the token and the notification text go to Expo, Apple or Google in the USA, under standard contractual clauses or certification under the EU-U.S. Data Privacy Framework. The website and the app without notifications connect only to our server until you click a link to a partner.
6. Your rights
You have the right to access your data, to rectification, erasure and restriction of processing, and to object to processing based on legitimate interest. You may also lodge a complaint with the President of the Polish Personal Data Protection Office (UODO, ul. Stawki 2, 00-193 Warsaw) or with the supervisory authority in your country. We do not make decisions based solely on automated processing, including profiling.
7. Changes to this policy
If the way we process data changes (e.g. a newsletter or analytics is added), we will update this policy and the update date at the top of the page.
Див. також: Як працює HoTrips · Умови користування · Політика конфіденційності · Контакти