Version 1.0 · [Insert date before publishing]

Privacy Policy

This legal text is a starting template and must be reviewed and approved by qualified Ethiopian legal counsel before publication. It does not constitute legal advice.

1. Introduction

Ethiopia Bookings (operated by [Company Name], registered in Ethiopia under registration number [XXX]) explains here what personal data the platform collects, how it is used, who it is shared with and what choices you have.

This policy applies to everyone who uses the Ethiopia Bookings website and related services: travellers with accounts, guests who book without an account, property owners and visitors.

2. Data We Collect

2.1 Account data

  • Email address and password (stored only as a one-way hash by our authentication provider — we never see it)
  • Full name and phone number, where you provide them
  • Optional avatar image, stored in our file storage under your own user folder
  • Your role on the platform (traveller, property owner, administrator), stored separately from your profile
  • Language and currency preferences

2.2 Booking data

  • Lead guest name, email address and phone number
  • Stay details: property, room type, check-in and check-out dates, number of nights and guests, special requests
  • Prices calculated by our servers: nightly rates, subtotal, service fee, platform commission and total
  • A snapshot of the property name, room name, prices and cancellation policy taken at the moment of booking, kept as the contractual record of the reservation
  • Booking status history, cancellation reason and refund records
  • You can book as a guest without an account. Private access to a guest booking is granted through a single, randomly generated secure link emailed to you — the booking reference alone does not grant access.

2.3 Payment data

  • We do not collect or store card numbers, expiry dates or security codes. There are no card fields on our checkout.
  • Payment is completed on the payment provider's own hosted checkout. We store only the provider name, our transaction reference, the amount, currency, payment status and the provider's returned status data.
  • Bank transfer bookings are recorded as a manual payment and confirmed by our team.

2.4 Property owner data

  • Listing content: property name, description, address and location, photos, amenities, room types, pricing and availability
  • Verification documents you upload. These are held in a private storage bucket accessible only to you and platform administrators.
  • Payout account details (bank or mobile money) and payout records

2.5 Reviews and communications

  • Reviews you submit after a completed stay, with your rating and comments. Reviews are held for moderation before they appear publicly, and are shown alongside your display name.
  • Messages you send us by email or WhatsApp

2.6 Technical data

  • Error and diagnostic logs from the website and our servers, used to detect and fix faults. These logs carry a request correlation identifier and booking or transaction references, and are filtered to strip passwords, authentication tokens, payment keys and similar sensitive values.
  • Audit records of sensitive actions such as booking expiry, refunds, payouts and administrator decisions
  • Browser storage described in our Cookie Policy

3. How We Use Your Data

  • To operate the service: creating accounts, checking real availability, holding rooms, creating bookings, processing payments, handling cancellations and refunds, and paying property owners
  • To communicate about your booking: booking and payment confirmations, secure booking access links, cancellation and refund notices, and owner notifications. These are service messages, not marketing.
  • To keep the platform safe and correct: preventing double-booking, detecting payments that arrive after a hold has expired, reconciling stuck transactions, moderating reviews and verifying listings
  • To fix problems: monitoring errors and investigating support requests
  • To meet legal and accounting obligations that apply to our business

4. How We Share Your Data

  • With property owners: when you book, the owner sees the booking details and lead guest contact details needed to host you. Owners cannot see your payment data or any bookings other than those at their own properties.
  • With payment providers: we send the amount, currency, our transaction reference and the contact details required by the provider so it can process the payment. The provider handles the payment instrument under its own privacy policy.
  • With infrastructure providers: our hosting, database, file storage and authentication run on a managed cloud platform, and transactional email is sent through an email delivery provider. They process data on our instructions.
  • With authorities: where we are legally required to disclose data.

We do not sell your personal data and we do not share it with advertisers.

5. Data Retention

Booking, payment, refund, payout and audit records are retained as business and accounting records for as long as we are required to keep them. Account and profile data is retained while your account exists. Diagnostic logs are kept only as long as needed to investigate faults. Specific retention periods are set by [Company Name] and will be published here once confirmed.

6. Your Rights and Choices

  • Access and correction: you can view and edit your profile in your account settings, and request a copy of the data we hold about you.
  • Deletion: you can request deletion of your personal data. We may need to retain booking, payment and accounting records, in which case we will explain what is being kept and why.
  • Reviews: you can ask us to remove a review you wrote.
  • Communications: service messages about your bookings cannot be switched off while a booking is active. Any future marketing email will include an unsubscribe link.

To make a request, email [email protected] or contact us through the support page.

7. Security

The platform is served over encrypted connections. Database access is restricted by row-level access rules so that travellers, owners and administrators can only reach the records they are entitled to see. Verification documents and other private files are stored in private buckets and served through short-lived signed links. Payment secrets and service keys are held server-side only and are never exposed to the browser. No system can be guaranteed to be completely secure; if a breach affects your data we will act on it and notify affected users as required.

8. Changes to This Policy

We may update this policy. Material changes will be posted on this page, and we will notify registered users where appropriate.

9. Contact Us