Privacy Policy
Your privacy is important to us.
Privacy Policy — Vicatoo
Version: 2.0
Last Updated: April 25, 2026 (Previous version 1.0 — March 29, 2026)
Key changes in v2.0:
- Added §17 — GCC Personal Data Protection Law (Saudi PDPL + UAE Federal Decree-Law 45/2021)
- Added §13.1 — Data Protection Officer (DPO) and dedicated contact channels
- Added detailed Retention Periods table (§7)
- Added §9.1 — Children Protection (COPPA / GDPR-K)
- Added §16.1 — Right to Human Review of automated decisions (GDPR Article 22)
- Clarified Microsoft Clarity input masking in Cookie Policy
- Unified communication channels: privacy@ for privacy, legal@ for legal, support@ for support
This Privacy Policy explains how Vicatoo, Inc. (doing business as "Vicatoo") ("Company", "we", "us", or "our") collects, uses, shares, and protects your information when you use www.vicatoo.com (the "Site") and our services.
By using the Site, creating an account, filling out a contact form, or communicating with us via WhatsApp/Email, you agree to the practices described in this policy. Please also review our Terms of Use and Booking & Cancellation Policy.
Official Channels: [email protected] for general inquiries, [email protected] for privacy and data protection requests, and [email protected] for legal matters, in addition to the WhatsApp number mentioned in the "Contact Us" section. Any communication from other channels is not considered official.
1. Information We Collect
We collect information you provide directly to us and information collected automatically.
1.1 Information You Provide
We may collect:
- Account Data: Name (if applicable), email, phone/WhatsApp number, username, and password (encrypted).
- Contact Form: Name, email, phone number, message subject, and content.
- Booking Request Data: Destination, stay dates, number of guests, preferences (e.g., view type, quiet room, kitchen availability...), and any details you enter during the search and booking process on the Site.
- Support Communications: Content of chats and correspondence with our team.
Notice: Please do not share sensitive data (such as health information) through unsecured channels. If we receive such data by mistake, we will endeavor to delete it where possible and reasonable.
Payment Processing: Payments on the platform are processed via Stripe (a PCI DSS Level 1 certified payment provider). VICATOO does not store any payment card data on its servers — all sensitive data is processed and stored directly by Stripe in accordance with their security standards.
1.2 Information Collected Automatically (Cookies & Analytics)
When using the Site, we may collect:
- IP address, browser type and device, operating system, pages visited, visit duration, and referral source.
- Data via Cookies and similar technologies.
We use Google Analytics to understand site usage and improve performance. Google may use cookies and similar identifiers to collect usage data in an aggregated form.
We use Google Tag Manager (GTM) to manage and deploy analytics and marketing tags. GTM itself does not collect personal data but facilitates the operation of the tools described below.
We use Meta (Facebook) Pixel to measure the effectiveness of our advertising campaigns, deliver targeted ads, and understand user actions on our site. This tool may collect browsing data and share it with Meta Platforms, Inc. It is activated only with your consent.
We use TikTok Pixel to measure and optimize our advertising campaigns on TikTok. This tool may collect browsing data and share it with TikTok (ByteDance Ltd). It is activated only with your consent.
We use Microsoft Clarity to understand how users interact with our site through session recordings and heatmaps. Clarity may collect anonymized browsing data. It is activated only with your consent.
We use Sentry to monitor technical errors and fix them quickly. When an error occurs, technical data is automatically sent to Sentry including: IP address, browser type, the URL where the error occurred, and session information (if applicable). This data is used exclusively for technical debugging and improving your experience. Sentry privacy policy: https://sentry.io/privacy/
Important: Meta Pixel, TikTok Pixel, and Microsoft Clarity are loaded only after you consent to non-essential cookies via our cookie banner. If you choose "Essential Only", these tools will not be activated.
2. How We Use Your Information
We use information to:
- Manage Account & Service Delivery: Create accounts, login, and manage settings.
- Process Bookings: Execute your booking automatically through our technical partners (RateHawk for accommodation, Stripe for payment), and send the Confirmation Message immediately upon booking completion.
- Customer Service: Respond to inquiries and resolve issues.
- Product & Site Improvement: Analyze performance, improve user experience, and develop features.
- Security & Fraud Prevention: Protect accounts and the Site, and verify suspicious activities.
- Marketing & Advertising (with your consent or where permitted by law): Send newsletters/offers, and manage contact lists and ad campaigns.
3. Marketing (Newsletters & Offers)
We may send you marketing messages (newsletters/offers/updates) via email and/or WhatsApp (depending on your preferences or consent). You can opt out at any time by:
- Clicking the "Unsubscribe" link if available in the message, or
- Emailing us at [email protected] requesting removal from lists.
Even after unsubscribing, we may send necessary "operational" messages (e.g., related to your account or a booking you requested).
4. Where We Store Your Data
Some WhatsApp conversations may remain within the WhatsApp platform itself.
We may also record contact data and client requests (such as Name/Phone/Email and request summary) in internal tools and CRM systems to organize work, follow-ups, and marketing.
We implement internal access controls so that data is accessed only by authorized team members. We limit access permissions based on need, and may review/update permissions periodically.
5. Sharing Information
We do not sell your personal information. We may share it only in the following cases:
5.1 With Hotels
We share necessary information to confirm the booking (Name, stay dates, number of guests, preferences) with the hotel or its representative.
5.2 With Service Providers (Processors)
We may share limited data with providers who help us operate the Site and Service, such as:
- Hotel suppliers and booking partners — to fulfill reservations,
- Payment service providers — to process transactions securely,
- Hosting, security, and CDN providers — to operate the platform,
- Analytics and advertising providers (Google Analytics, Google Tag Manager, Meta Pixel, TikTok Pixel, Microsoft Clarity) — to improve user experience and measure ad effectiveness (with your consent),
- Newsletter and marketing tools (if used).
Each provider is selected to ensure appropriate data protection standards. These providers process data on our behalf, under our instructions, and only as needed to provide the service.
5.3 Legal Reasons
We may disclose data if required to comply with the law, protect Company/User rights, prevent fraud, or for system security.
5.4 Business Transactions
In the event of a merger, acquisition, or asset sale, data may be transferred as part of the process in accordance with the law, with appropriate notice where required.
6. Cookies & Tracking Management
You can control cookies through your browser settings. Disabling cookies may affect some Site functions (e.g., login).
We may display a notice or banner to manage cookie preferences according to the country or regulatory requirements, allowing you to accept/reject certain types of cookies.
7. Data Retention
We retain data only for the period necessary to fulfill the stated purposes. The table below outlines specific retention periods:
| Data Category | Retention Period |
|---|---|
| Active account data | For as long as you use the service |
| Data after account deletion | Up to 30 days (recovery window) |
| Booking & invoice records | 7 years (accounting & tax requirements) |
| Security logs | 12 months |
| Cookies | Up to 13 months (per ePrivacy guidance) |
| Marketing data after opt-out | 6 months (to prevent accidental re-subscription) |
| Support & dispute records | 3 years from last interaction |
When the period ends, we delete, minimize, or anonymize data wherever possible. To request immediate deletion, contact [email protected].
8. Information Security
We use reasonable security measures (e.g., access controls, protection technologies, password encryption). However, no transmission or storage method is 100% secure.
9. Your Rights & Choices
Depending on applicable laws, you may have the right to:
- Request access to, correction of, or deletion of your data,
- Withdraw consent for marketing,
- Request restriction of certain processing.
We may request additional information to verify identity before executing requests to protect your account and prevent unauthorized access.
To submit a data-related request, contact [email protected]. We will respond to all verified requests within 30 days at the latest.
9.1 Children (COPPA / GDPR-K)
Our services are not directed to anyone under 13 years old (or the minimum age set by your local EEA jurisdiction, typically 16). We do not knowingly collect their data. If you believe a child has provided us personal information, please notify us immediately at [email protected] and we will delete it promptly.
10. Third-Party Links
The Site may contain links to other websites. We are not responsible for the privacy practices of those sites.
11. International Data Transfers
Data may be processed in other countries (e.g., USA) depending on hosting locations or service providers (e.g., Google). By using the Site, you understand that data processing may occur across borders in accordance with this policy.
12. Changes to This Privacy Policy
We may update this policy from time to time. We will update the "Last Updated" date at the top. Continues use of the Site after updates constitutes acceptance of the updated policy.
13. Contact Us
13.1 Data Protection Officer (DPO)
In accordance with GDPR Article 37, Saudi PDPL Implementing Regulation Article 32, and UAE Federal Decree-Law 45/2021 Article 11, we have appointed a Data Protection Officer (DPO) as the official contact point for all privacy and data protection inquiries.
DPO dedicated email: [email protected]
Postal address: Vicatoo, Inc., Attn: Data Protection Officer, 1111B S Governors Ave, STE 55694, Dover, DE 19904, USA
Response time: The DPO will respond to all verified inquiries within 30 calendar days maximum (per GDPR Art. 12(3) and PDPL Art. 8).
For data-related rights (access, rectification, erasure, portability), you may also use our online Data Subject Request form.
Security breach reporting: If you notice any leak or unauthorized access to your data, please notify the DPO immediately at [email protected]. We will notify the relevant regulators (SDAIA / UAE Data Office / EU DPA) within 72 hours as required by law.
14. Privacy Rights for California Residents (CCPA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
- The right to know what personal data we collect about you
- The right to request deletion of your personal data
- The right to opt out of the sale of your personal data
- The right to non-discrimination for exercising your rights
We do not sell your personal data to third parties. We only share data with service providers necessary to operate our platform (payment processing, hotel booking infrastructure, analytics).
To exercise any of your rights, contact us at: [email protected]
We will respond to all verified requests within 45 days, as required by California law.
15. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA), we process your personal data based on the following legal grounds under the General Data Protection Regulation (GDPR):
- Performance of a Contract: Processing necessary to fulfill our obligations to you, such as processing bookings, managing your account, and providing customer support.
- Consent: Where you have given us explicit consent, such as subscribing to our newsletter, accepting non-essential cookies, or enabling marketing communications. You may withdraw consent at any time.
- Legitimate Interests: Processing necessary for our legitimate business interests, such as improving our services, preventing fraud, ensuring platform security, and conducting analytics — provided these interests do not override your rights.
- Legal Obligation: Processing required to comply with applicable laws, regulations, or legal proceedings.
Your GDPR Rights
In addition to the rights listed in Section 9, EEA residents may also:
- Request data portability (receive your data in a structured, machine-readable format)
- Object to processing based on legitimate interests
- Lodge a complaint with your local Data Protection Authority (DPA)
To exercise any of these rights, contact us at [email protected].
16. Use of Artificial Intelligence & Automated Decision-Making
Vicatoo uses artificial intelligence (AI) technologies to enhance your experience:
- Smart Search: AI-powered natural language search to help you find hotels matching your preferences (e.g., "family hotel near the beach with a pool").
- Content Generation: AI may assist in generating or translating hotel descriptions and room summaries to provide you with relevant information in your preferred language.
- Personalized Suggestions: AI may analyze your search patterns and preferences to suggest hotels and destinations that may interest you.
- Third-party AI providers (sub-processors): To power these features, limited data may be processed by external AI providers: OpenAI (to understand your search queries and to assist our customer-support chat) and Anthropic (Claude) (used together with our human team for post-booking customer support). We never share your name, email, or payment details with them. They act as data processors under their own privacy and security terms and do not use API data to train public AI models.
No Automated Decisions with Legal Effect: We do not use AI or automated processing to make decisions that produce legal effects or similarly significant effects on you (such as credit decisions or pricing discrimination). All booking confirmations and payment decisions involve human oversight or direct user action.
Right to Human Review (GDPR Article 22): If you are significantly affected by any automated decision, you have the right to request human review, express your view, and contest the decision. Send your request to [email protected] and we will respond within 30 days.
AI features process your search queries and interaction data. This data is handled in accordance with the data protection principles described throughout this policy.
17. Personal Data Protection in GCC States (PDPL)
If you are a resident of the Kingdom of Saudi Arabia, the United Arab Emirates, or any GCC country, the following rights apply to you under:
- Saudi Arabia: Personal Data Protection Law (PDPL) — Royal Decree No. M/19 of 2021 and 2023 amendments.
- United Arab Emirates: Federal Decree-Law No. (45) of 2021 on Personal Data Protection.
Your rights include:
- Right to Be Informed: Know the legal basis for collecting your data and its purpose.
- Right of Access: View your stored personal data.
- Right to Correction: Request correction of inaccurate data.
- Right to Erasure: Request deletion of your data (subject to legal obligations).
- Right to Object: Object to processing that contradicts your legitimate expectations.
- Right to Withdraw Consent: Withdraw your consent to processing at any time.
- Right to Portability: Request transfer of your data in a structured format to another service provider.
To file a complaint with regulators: Saudi Arabia: Saudi Data & AI Authority (SDAIA) — sdaia.gov.sa. UAE: UAE Data Office — u.ae.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
17.2 UAE Federal Decree-Law on Personal Data Protection (45/2021)
If you are a resident or citizen of the United Arab Emirates, the processing of your data is also governed by UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, supervised by the UAE Data Office.
We commit to:
- Obtaining your explicit consent (Article 6): before any processing of your personal data unless another legal basis applies.
- Guaranteeing your rights (Articles 13-19): right of access, rectification, erasure, restriction of processing, data portability, and objection.
- Security breach reporting (Article 9): We will notify the UAE Data Office and affected users within 72 hours of discovering any breach.
- Cross-border data transfer (Articles 22-23): We apply strict contractual and technical safeguards when transferring your data to overseas processors (such as Stripe in the US, ETG (RateHawk) in Turkey, HostGator/cPanel for server hosting).
- Parental consent for minors: UAE law sets the age of consent at 21 years — we do not accept registrations from minors without verified parental consent.
Filing a complaint: For any complaint regarding the processing of your data, you may contact the UAE Data Office or write to our DPO at [email protected].
Penalties under UAE law may reach AED 5 million (~USD 1.36M) per violation, plus service suspension. We take our obligations toward UAE users with utmost seriousness.
Vicatoo, Inc.
Doing business as "Vicatoo"
Email:
WhatsApp:
+1 (775) 547-2405
Address:
1111B S Governors Ave, STE 55694
Dover, DE 19904, US