Last updated: 25 August 2026
This policy explains what OODA does with your personal information when you use ooda.online to book a hotel room for the day.
We have written it to describe what the website actually does today, not what a template says it might do. If you find something here that does not match your experience, tell us at [email protected] and we will fix the policy or the website.
1. Who we are
OODA is a day-use hotel booking platform operating from Jounieh, Lebanon.
| Contact | [email protected] |
| Bookings | [email protected] |
| Phone / WhatsApp | +961 71 284 112 |
| Address | Jounieh, Lebanon |
OODA is the data controller for the information described below. Each partner hotel is a separate controller for the information it receives about your booking.
2. The short version
- We collect what we need to pass your booking to the hotel, and little else.
- We never collect or store card or payment details. You pay the hotel directly at reception. No payment happens on this website.
- When you book, we share your name, phone number, email and booking details with that hotel only — because otherwise they cannot hold your room.
- We use Google Analytics, Hotjar and a Meta (Facebook) pixel to understand how the site is used and to measure advertising. These are described in section 6.
- You can ask us to show, correct or delete your data at any time.
3. What we collect
3.1 When you make a booking
To send a booking request to a hotel we ask for, and the hotel receives:
- First name and last name
- Email address
- Phone number
- Any message you add to the booking
- The date, the time window (for example 06:00–12:00), the room or rooms you selected, and the number of guests
3.2 Your account
The website creates an account for you automatically when you complete your first booking, using a username and password you choose on the confirmation page. We store the username and a cryptographically hashed version of the password — we cannot read your password. The account exists so you can see your bookings and leave a review.
3.3 If you contact us
If you message us on WhatsApp using the button on the site, or email us, we keep that conversation and the phone number or address it came from so we can answer you and handle any follow-up about a booking.
3.4 If you subscribe to updates
If you give us your email address for launch offers or day-use deals, we keep it until you unsubscribe.
3.5 Reviews
Only guests who have completed a booking can leave a review. A published review shows the name on the account and the rating and text you wrote.
3.6 Technical information
Like any website, ooda.online records information sent by your browser: IP address, browser and device type, operating system, the pages you visit, how long you stay, and the page or advertisement that referred you.
3.7 What we do not collect
- Card numbers, bank details or any payment credentials. There is no payment step on this website; nothing to pay online means nothing to store.
- Passport or ID document data. A hotel may ask to see ID at check-in — that is between you and the hotel, and OODA never receives it.
- Any special category data (health, religion, political views and the like). Please do not put such information in the booking message field.
4. Why we use it, and on what basis
| What we do | Why | Basis |
|---|---|---|
| Send your booking to the hotel and confirm it to you | Without it there is no booking | Performance of a contract you asked for |
| Create and maintain your account | So you can view and manage bookings | Performance of a contract |
| Contact you about a booking (change, question, cancellation) | To make the booking work | Performance of a contract |
| Answer WhatsApp and email enquiries | To help you | Legitimate interest |
| Publish your review | Social proof for other guests | Consent — you choose to post it |
| Send offers and updates | Marketing | Consent — you subscribed, and you can stop |
| Measure how the site is used and how ads perform | To improve the site and spend advertising money sensibly | Legitimate interest, and consent where the law requires it |
| Prevent fraud, abuse and fake bookings | To protect guests and hotels | Legitimate interest |
| Keep records we are legally required to keep | Compliance | Legal obligation |
5. Who we share it with
The hotel you booked. Name, phone, email, date, time window, room and guest count. This is the whole point of the booking, and it is the only sharing that is not optional. Once the hotel has your details it handles them under its own privacy practices and its obligations under Lebanese law.
Service providers who run the site for us:
| Provider | What they do | Where |
|---|---|---|
| Hostinger | Website hosting and outgoing email | EU / Lithuania |
| Cloudflare | Security, performance and basic traffic analytics | Global |
| Google (Analytics, Tag Manager) | Site usage measurement | Global |
| Hotjar | Heatmaps and session recordings | EU / Malta |
| Meta Platforms | Advertising measurement (see 6.3) | Global |
We do not sell your personal data. We do not share it with other hotels, other guests, or any data broker. We will disclose data if a Lebanese court or competent authority lawfully requires it.
6. Cookies, analytics and advertising
The site sets cookies that are necessary for it to work — keeping you logged in, remembering your booking selection while you complete it, and security. It also loads the following third-party tools:
6.1 Google Analytics 4, via Google Tag Manager
Container GTM-TLVBT9WQ, measurement ID G-RPLR9N8M6N. Tells us how many people visit, which pages they read, and where they came from. IP addresses are handled by Google.
6.2 Hotjar
Site ID 5293959. Records heatmaps and session recordings — a replay of mouse movement, scrolling, clicks and typing on the page — so we can see where the booking form confuses people. Hotjar is configured to suppress the content of text inputs, but please avoid typing anything sensitive into free-text fields on any website.
6.3 Meta (Facebook) pixel
Pixel ID 25526406686983671. Reports which visits and bookings came from our advertising on Facebook and Instagram, and allows us to show ads to people who have visited the site. Meta may combine this with data it already holds about you.
6.4 Cloudflare Insights
Basic, privacy-oriented traffic statistics.
Your choices. You can block or delete cookies in your browser; the booking flow will still work, though you may have to re-enter details. You can opt out of Google Analytics with Google’s browser add-on, opt out of Hotjar via the Do Not Track setting Hotjar honours, and control Meta advertising in your Facebook or Instagram ad settings.
7. How long we keep it
| Data | Kept for |
|---|---|
| Booking records | 3 years after the booking date, for accounting and dispute handling |
| Your account | Until you ask us to delete it, or after 3 years of inactivity |
| WhatsApp and email conversations | 2 years |
| Newsletter subscription | Until you unsubscribe |
| Reviews | Until you ask us to remove them |
| Analytics data | Per each provider’s own retention settings, up to 26 months |
8. Your rights
You can ask us to:
- Show you the personal data we hold about you
- Correct anything wrong
- Delete your data and close your account
- Stop using it for marketing — always, immediately, no reason needed
- Object to our analytics and advertising tracking
Email [email protected] and we will respond within 30 days. If you booked a hotel, note that we cannot delete the copy the hotel already holds — you would need to ask them directly, and we will give you their contact details.
These rights are given under Lebanese Law No. 81/2018 on Electronic Transactions and Personal Data. If you are in the European Union or United Kingdom, we will honour the equivalent rights under the GDPR, including the right to complain to your national data protection authority.
9. Security
The site runs over HTTPS. Passwords are stored hashed, never in readable form. Booking notifications are sent over authenticated SMTP with SPF and DMARC configured on the ooda.online domain. Access to the booking dashboard is limited to OODA staff and the hotel that received the booking.
No system is perfectly secure. If we discover a breach affecting your data we will tell you and the competent authority without undue delay.
10. International transfers
Our hosting is in the European Union. Google, Meta, Hotjar and Cloudflare are international providers and may process data outside Lebanon and the EU under their own standard contractual safeguards.
11. Children
OODA is not intended for children under 18, and we do not knowingly collect their data. Children may of course stay as guests on a booking made by an adult; we only ever receive the number of guests, not their details. If you believe a child has given us personal data, contact us and we will delete it.
12. Changes
We will post any change here and update the date at the top. If a change materially affects how we use your data, we will tell subscribers by email.
13. Contact
Questions, requests or complaints about this policy:
[email protected] · WhatsApp +961 71 284 112 · Jounieh, Lebanon