RGRateGoblin
Free TrialTerms

Legal

RATEGOBLIN PRIVACY POLICY

Last updated: 5 August 2026

IMPORTANT: This Privacy Policy is a working draft prepared for legal review. It should be reviewed and approved by a qualified lawyer before RateGoblin launches or begins collecting personal information from customers.

1. ABOUT THIS PRIVACY POLICY

1.1 RateGoblin respects your privacy and is committed to handling personal information openly, fairly and responsibly.

1.2 This Privacy Policy explains how [INSERT LEGAL ENTITY NAME AND ABN/ACN] trading as RateGoblin (RateGoblin, we, us or our) collects, uses, stores, discloses and protects personal information when you use our websites, applications, dashboards, hotel-price monitoring tools, booking-upload tools, alerts, subscription services and related products (together, the Service).

1.3 This Policy applies to users around the world. Depending on where you live, additional privacy rights and obligations may apply under local law.

1.4 This Policy should be read together with our Terms of Service, Cookie Policy and any privacy notice provided when we collect specific information.

1.5 If you do not agree with this Policy, you should not use the Service.

2. WHO WE ARE

RateGoblin provides software that helps users monitor hotel and accommodation prices and identify potential savings opportunities.

Our current contact details are:

RateGoblin

Legal entity: [INSERT LEGAL ENTITY NAME]

ABN/ACN: [INSERT]

Registered address: [INSERT]

Email: hello@rategoblin.com

For privacy questions, requests or complaints, contact hello@rategoblin.com.

3. WHAT PERSONAL INFORMATION MEANS

3.1 Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable.

3.2 Depending on applicable law, similar terms may include personal data, personally identifiable information or protected personal information.

3.3 Personal information does not include information that has been properly aggregated or de-identified so that an individual is no longer reasonably identifiable.

4. INFORMATION WE COLLECT

We collect only information reasonably necessary to provide, secure, support and improve the Service.

4.1 Account and identity information

This may include your name, email address, account identifier, login and authentication information, country, region, language, time zone, communication preferences and information used to verify account ownership or recover an account.

We generally do not need your passport, driver licence or other government-issued identification to provide the Service. We may request limited verification information where reasonably necessary for security, fraud prevention, legal compliance or account recovery.

4.2 Booking and accommodation information

When you add or upload a Booking, we may collect:

(a) hotel or accommodation name and location;

(b) check-in and check-out dates;

(c) room type and room description;

(d) number and age category of guests;

(e) board basis and inclusions, such as breakfast or full board;

(f) booking price and currency;

(g) taxes, fees and payment conditions;

(h) cancellation terms and deadlines;

(i) booking provider or booking source;

(j) confirmation or reference number;

(k) loyalty or membership information where relevant to matching a rate;

(l) notes or preferences you provide; and

(m) hotel rates, availability, inclusions and monitoring results identified over time.

4.3 Uploaded PDF booking documents

You may choose to upload a PDF booking confirmation so RateGoblin can extract the details needed to create or monitor a Booking.

RateGoblin does not store uploaded PDF files. The file is used only for transient processing to extract relevant booking information and is not retained by RateGoblin after that processing is complete.

The structured booking details extracted from the PDF may be stored in your Account so the Service can monitor the Booking and display it in your dashboard and history.

You should remove or obscure information that is not required for hotel-price monitoring, including passport details, payment card details, government identification numbers and health information.

4.4 Payment and subscription information

If you purchase a Paid Plan, we may collect billing details, subscription status, transaction identifiers, plan information, invoice information, payment status and limited payment-method information supplied by our payment processor.

RateGoblin does not intend to store complete payment card numbers or card security codes. Payments are processed by third-party payment providers such as Stripe.

4.5 Technical, device and usage information

We may collect:

(a) IP address;

(b) browser type and version;

(c) device type, operating system and device identifiers;

(d) approximate location derived from IP address;

(e) pages, screens and features used;

(f) dates and times of access;

(g) referral source;

(h) clicks, actions, search activity and session information;

(i) error logs, performance logs and security logs; and

(j) cookie and similar technology identifiers.

4.6 Communications and support information

If you contact us, we may collect your message, contact details, support history, feedback, complaint information and any files or information you choose to provide.

4.7 Marketing information

If you opt in to marketing, we may collect your marketing preferences, campaign engagement and information about whether you opened or interacted with a message.

4.8 Information from third parties

We may receive information from payment processors, authentication providers, analytics providers, email delivery providers, affiliate partners, hotel-pricing providers and other Service Providers.

5. INFORMATION WE DO NOT INTEND TO COLLECT

5.1 The Service is not designed to collect sensitive personal information such as health information, biometric data, political opinions, religious beliefs, sexual orientation, criminal records or government identification documents.

5.2 We do not need users to upload payment card details, passport information or other sensitive travel documents.

5.3 If you provide unnecessary sensitive information, we may delete or restrict it where reasonably possible.

6. HOW WE COLLECT INFORMATION

We collect information:

(a) directly from you when you create an Account, enter Booking information, upload a PDF for transient processing, purchase a plan, change settings or contact us;

(b) automatically when you use the Service;

(c) from Service Providers that operate parts of the Service;

(d) from publicly available hotel and accommodation sources; and

(e) where permitted, from affiliate or referral partners.

7. WHY WE USE PERSONAL INFORMATION

We may use personal information to:

(a) create and manage your Account;

(b) authenticate you and keep your Account secure;

(c) extract booking details from an uploaded PDF without retaining the PDF itself;

(d) create, monitor and manage Bookings;

(e) search for and compare hotel rates and availability;

(f) calculate potential savings and identify Opportunities;

(g) send alerts, service messages and billing communications;

(h) process subscriptions, payments, refunds and invoices;

(i) provide support and respond to questions or complaints;

(j) maintain, troubleshoot, secure and improve the Service;

(k) prevent fraud, misuse, unauthorised access and security incidents;

(l) understand product usage and performance;

(m) comply with legal obligations and enforce our Terms;

(n) manage affiliate relationships;

(o) send marketing where permitted; and

(p) develop new features and services.

8. LEGAL BASES FOR PROCESSING

Where laws such as the GDPR or UK GDPR apply, we process personal information on one or more of the following legal bases:

8.1 Contract

Processing is necessary to provide the Service, manage your Account, monitor Bookings, deliver alerts and administer your subscription.

8.2 Legitimate interests

We may process information for legitimate interests such as securing and improving the Service, preventing fraud, understanding usage, supporting customers and operating our business, provided those interests are not overridden by your rights.

8.3 Consent

We may rely on consent for optional marketing, non-essential cookies and other activities where consent is required.

8.4 Legal obligations

We may process information to comply with tax, accounting, regulatory, law-enforcement or other legal requirements.

8.5 Vital interests or public interest

We may rely on these bases only where applicable and legally permitted.

9. PDF PROCESSING

9.1 Uploaded PDFs are used only to extract booking information needed to create or monitor a Booking.

9.2 RateGoblin does not retain or store uploaded PDF files after processing.

9.3 The extracted structured data may be stored in your Account, including hotel name, dates, room type, inclusions, price, currency, cancellation conditions and booking reference information.

9.4 If PDF processing is performed using a Service Provider, the file may be transmitted to that provider solely for transient processing under contractual and security controls. The provider must not use the file for its own independent purposes unless separately disclosed and lawfully permitted.

9.5 You are responsible for ensuring you have authority to upload the document and that it does not contain unnecessary sensitive information.

10. AUTOMATED PROCESSING AND AI

10.1 RateGoblin may use automated systems, machine learning or artificial intelligence to extract booking details, classify rates, compare inclusions, prioritise Opportunities, identify anomalies or summarise information.

10.2 Automated outputs may be incomplete or inaccurate. Important booking and rebooking decisions remain yours.

10.3 RateGoblin does not use identifiable Booking Content to train general-purpose AI models unless we clearly disclose that practice and obtain any consent required by law.

10.4 Where automated decision-making has legal or similarly significant effects and applicable law gives you rights, we will provide the required information and review options.

11. DISCLOSURE OF PERSONAL INFORMATION

We may disclose personal information to the following categories of recipients where reasonably necessary.

11.1 Cloud, database and authentication providers

These providers may host the Service, manage Accounts, support authentication, store structured booking data and maintain security logs. This may include providers such as Supabase and their infrastructure partners.

11.2 Payment providers

Payment providers such as Stripe may process payment and billing information.

11.3 Hotel pricing, search and data providers

We may send limited Booking criteria, such as hotel, dates, occupancy and room requirements, to providers that perform or support hotel-rate searches.

We aim to avoid sending directly identifying customer information where it is not needed for the search.

11.4 Email and communications providers

These providers help send alerts, service messages, support communications and marketing messages.

11.5 Analytics, monitoring and security providers

These providers help us understand usage, diagnose errors, monitor performance and protect the Service.

11.6 Professional advisers

We may disclose information to lawyers, accountants, auditors, insurers and other professional advisers.

11.7 Business transactions

Information may be disclosed in connection with a proposed or completed investment, financing, merger, acquisition, restructure, sale or transfer of all or part of RateGoblin, subject to appropriate confidentiality protections.

11.8 Legal and safety reasons

We may disclose information where we reasonably believe it is necessary to comply with law, respond to lawful requests, enforce our agreements, investigate fraud or protect the rights, safety and security of RateGoblin, users or others.

11.9 Development and source-code systems

RateGoblin uses development and source-code platforms, including GitHub, to store and manage application code, database migrations, configuration and technical documentation.

We do not intentionally store ordinary customer Booking data, uploaded PDFs, production database exports or directly identifying customer records in GitHub. Where technical logs, screenshots, support examples or test fixtures are needed for development or troubleshooting, we aim to remove or minimise personal information and use anonymised or synthetic data wherever reasonably possible.

12. INTERNATIONAL DATA TRANSFERS

12.1 RateGoblin is operated from Australia, but our Service Providers may process information in Australia, the United States, the European Economic Area and other countries.

12.2 These countries may have privacy laws different from those in your country.

12.3 Where required by law, we use appropriate safeguards for international transfers, such as contractual protections, adequacy decisions, approved transfer mechanisms or other lawful safeguards.

12.4 You may contact hello@rategoblin.com for more information about applicable transfer safeguards.

13. DATA RETENTION

13.1 We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Service, complying with law, resolving disputes and protecting the Service.

13.2 Uploaded PDF files are not stored by RateGoblin after processing.

13.3 Active Accounts and History

Structured Booking information, archived Bookings, search results, Opportunities and related History records remain available while your Account is active, unless you separately delete particular information where that functionality is available.

13.4 Paused or cancelled subscriptions

Pausing or cancelling a subscription does not delete your Account or History. Monitoring, searches, alerts and paid features may stop or become restricted, but your existing Account, Bookings and History remain stored so that you can continue to access them or reactivate the Service later.

13.5 Account deletion request and 30-day recovery period

When you request deletion of your Account, your subscription is cancelled and hotel-price monitoring, searches and alerts stop immediately. Your Account is then placed into a 30-day pending-deletion period.

During this recovery period, your Account information, Bookings, History, search records, Opportunities and related identifiable information are retained only so that you can restore the Account if the deletion request was made by mistake or without authorisation.

You may cancel the deletion request and restore the Account at any time during the 30-day recovery period. Restoring the Account does not automatically restart a paid subscription or monitoring.

13.6 Permanent deletion after 30 days

If you do not restore the Account during the 30-day recovery period, RateGoblin will permanently delete the Account and associated identifiable customer information. This includes the authentication account, profile and agency records, Bookings, booking settings, History, search runs, search results, Opportunities, validation records, customer-linked evidence records, usage records and other customer-linked operational records.

We may delete information or irreversibly de-identify it, depending on the type of record and the reason it was collected.

13.7 Information retained after Account deletion

We may retain limited information where required or permitted for tax, accounting, payment reconciliation, fraud prevention, security, legal claims, regulatory compliance or dispute resolution. We will limit retained information to what is reasonably necessary for those purposes and restrict its use accordingly.

Stripe and other payment providers may retain payment and transaction records under their own legal and compliance obligations.

13.8 Security logs and backups

Security, access, error and deletion-process logs may be retained for a reasonable period to protect the Service, investigate incidents and demonstrate that a deletion request was completed.

Residual copies may remain temporarily in encrypted backups until they are overwritten or securely deleted through normal backup cycles. Information retained only in backup systems will not be restored to active use except where necessary for disaster recovery, security or legal compliance.

13.9 Aggregated and de-identified information

Properly aggregated or de-identified hotel pricing, savings and usage information may be retained indefinitely because it no longer reasonably identifies you.

14. AGGREGATED AND DE-IDENTIFIED DATA

14.1 We may create aggregated, statistical or de-identified data from Booking and usage information.

14.2 We may use this data to understand hotel pricing trends, measure savings, improve matching, develop features, analyse business performance and support future commercial use.

14.3 We will not treat information as de-identified where it can reasonably be linked back to an individual.

14.4 We do not sell identifiable customer Booking information.

15. SECURITY

15.1 We use reasonable administrative, technical and organisational safeguards designed to protect personal information.

15.2 These may include access controls, authentication, encryption in transit, restricted production access, logging, monitoring, backups and security reviews.

15.3 We choose Service Providers based in part on their security capabilities, but no online system is completely secure.

15.4 You are responsible for using a strong password, protecting your devices and keeping your login details confidential.

15.5 If you believe your Account or personal information has been compromised, contact hello@rategoblin.com promptly.

16. DATA BREACHES

16.1 We maintain processes to assess and respond to suspected data breaches.

16.2 If a breach is likely to result in serious harm or otherwise triggers a legal notification requirement, we will notify affected individuals and relevant regulators as required by applicable law.

17. COOKIES AND SIMILAR TECHNOLOGIES

17.1 We may use cookies, local storage, pixels and similar technologies to keep you signed in, remember preferences, secure the Service, understand usage and support marketing.

17.2 Essential technologies may be required for the Service to function.

17.3 Non-essential analytics or marketing technologies will be managed according to applicable consent requirements.

17.4 More information will be provided in our Cookie Policy and cookie preference controls.

18. MARKETING COMMUNICATIONS

18.1 We may send marketing communications where you have consented or where otherwise permitted by law.

18.2 You can unsubscribe using the link in the message or by contacting hello@rategoblin.com.

18.3 Unsubscribing from marketing does not stop essential service, security, billing or legal communications.

19. YOUR PRIVACY RIGHTS

Depending on where you live, you may have rights to:

(a) access personal information we hold about you;

(b) correct inaccurate or incomplete information;

(c) request deletion;

(d) restrict or object to processing;

(e) receive certain information in a portable format;

(f) withdraw consent;

(g) object to direct marketing;

(h) request information about automated decision-making;

(i) complain to a privacy regulator; and

(j) not be discriminated against for exercising a privacy right.

These rights may be subject to legal exceptions and verification requirements.

20. HOW TO EXERCISE YOUR RIGHTS

20.1 Send your request to hello@rategoblin.com.

20.2 Describe the right you wish to exercise and provide enough information for us to identify your Account and understand the request.

20.3 We may need to verify your identity before acting on a request.

20.4 We will respond within the timeframe required by applicable law.

20.5 We generally do not charge for privacy requests, but may charge a reasonable fee or refuse a request where permitted by law, including where a request is manifestly unfounded, excessive or repetitive.

21. AUSTRALIAN USERS

21.1 Where the Privacy Act 1988 (Cth) and Australian Privacy Principles apply, we will handle personal information consistently with those requirements.

21.2 You may request access to or correction of personal information by contacting hello@rategoblin.com.

21.3 If you are not satisfied with our response to a privacy complaint, you may be entitled to complain to the Office of the Australian Information Commissioner.

22. EUROPEAN ECONOMIC AREA, UNITED KINGDOM AND SWITZERLAND

22.1 Where the GDPR, UK GDPR or Swiss data protection law applies, RateGoblin is generally the controller of personal information described in this Policy.

22.2 You may have rights of access, correction, deletion, restriction, objection, portability and withdrawal of consent.

22.3 You may also complain to your local supervisory authority.

22.4 Where we rely on legitimate interests, you may request information about the relevant balancing assessment.

22.5 Where required, we will appoint an EU or UK representative or data protection contact and update this Policy accordingly.

23. UNITED STATES USERS

23.1 Depending on your state, you may have rights to know, access, correct, delete or obtain a copy of personal information, and to opt out of certain targeted advertising, sale or sharing practices.

23.2 RateGoblin does not sell personal information for money.

23.3 If our use of advertising or analytics technologies constitutes a sale, sharing or targeted advertising under applicable state law, we will provide any required opt-out mechanism.

23.4 We will not discriminate against you for exercising applicable privacy rights.

24. CHILDREN

24.1 The Service is intended for adults aged 18 and over.

24.2 We do not knowingly collect personal information directly from children for the purpose of creating an Account.

24.3 Booking information may include the age category of a child traveller where needed to search for an accurate hotel rate. The Account holder is responsible for ensuring they are authorised to provide that information.

24.4 If you believe a child has created an Account or provided personal information without proper authority, contact hello@rategoblin.com.

25. THIRD-PARTY WEBSITES AND SERVICES

The Service may link to hotels, booking platforms, payment providers and other third parties. Their privacy practices are governed by their own policies, not this Policy.

26. CHANGES TO THIS PRIVACY POLICY

26.1 We may update this Policy to reflect changes to the Service, our practices or applicable law.

26.2 We will update the “Last updated” date when changes are made.

26.3 If a change materially affects how we use personal information, we will provide reasonable notice and obtain consent where required by law.

27. COMPLAINTS

27.1 If you have a privacy concern, contact hello@rategoblin.com and provide details of the issue.

27.2 We will investigate and respond within a reasonable period and within any timeframe required by law.

27.3 If you remain dissatisfied, you may have the right to complain to the privacy or data protection authority in your country.

28. CONTACT US

RateGoblin

Legal entity: [INSERT LEGAL ENTITY NAME]

ABN/ACN: [INSERT]

Registered address: [INSERT]

Email: hello@rategoblin.com

For privacy requests, questions or complaints, email hello@rategoblin.com.

© 2026 RateGoblinTerms · Privacy