Privacy policy
Last updated October 7, 2026
MyHotelAuditor is a product of Doubled Rook ("we", "us"). This policy explains what personal information we collect through myhotelauditor.com and while we produce the reports you order, how we use it, who we share it with, and the choices and rights you have. If you have a question, email info@myhotelauditor.com.
The short version
- We collect what you give us: your contact details, your property and your order. We use it to produce and deliver your report, bill you and answer you.
- Google Analytics runs when you visit, so we can see how the site is used. In the EU and the UK, it sets no cookies until you accept. Advertising tools do not run until you allow them. You can change your choices at any time with Your privacy choices, at the foot of every page.
- We do not sell your personal information. If you allow advertising, we share limited information about your visit with OpenAI to measure our ads.
- The reports are about hotels, built from public sources and official data services. A person reviews every finding before a report is delivered.
What we collect
Information you give us
- The intake. Your answers to the intake questionnaire stay in your browser until you continue to payment. At that point we send the report you chose, your property's name and website, your name, your title, your hotel type, whether you chose rush delivery and your work email to our payment processor, Stripe, to create your order.
- Checkout. Stripe collects your payment details and billing address on its own secure page. Stripe tells us your name, email address, billing address and what you bought. We never see your full card number.
- Our mailing list. If you subscribe from the footer or the pop-up, we add your email address to our mailing list.
- Messages. If you email us, we keep the message and our reply.
Information collected automatically
- Every visit. Our host, Cloudflare, processes your IP address, browser details and the pages you request, to deliver the site and keep it secure. Pages load the Open Sans typeface from Google Fonts, so Google also receives your IP address and browser details when a page loads.
- Unless you turn analytics off. Google Analytics, loaded through Google Tag Manager, records the pages you visit, how you arrived, your device and browser, your approximate location and, on the payment confirmation page, the value and contents of a completed order. In the EU and the UK, it sets no cookies until you allow it.
- Only if you allow advertising. OpenAI's advertising pixel records your visit, such as the page, your browser and your IP address. When you complete an order it also records that an order was completed, though not what you ordered or what you paid. This lets OpenAI and us tell whether our ads on OpenAI's services lead to visits and orders.
Information about the hotels we audit
When you order a report, we collect publicly available information about your property: its website, its listings on booking and review sites, search results, its maps and business profiles, its social media profiles, archived copies of its website and the answers AI assistants give about it. We collect it as an ordinary logged-out visitor or through each source's official data service, and never by getting around a site's protections.
Some of this information names people, such as guests who wrote reviews and staff they mention. We keep names only as they were published, use them only to produce the report the property commissioned, never combine them with other information about those people, and can leave reviewer names out of a report. If you are named in a public review and want to ask about it, contact us.
How we use information
The legal basis column applies if you are in the European Economic Area, the United Kingdom or Switzerland.
| Why we use it | What we use | Legal basis |
|---|---|---|
| Produce, deliver and support the reports you order | Your order and intake details, information about your property | Performing our contract with you |
| Take payment, issue invoices and keep accounting records | Order and billing details | Contract, and our legal obligations |
| Email you your report and follow-up about it | Your work email | Contract, and the consent you give at the intake |
| Send news about new reports and offers | Your email address, if you subscribe | Consent, which you can withdraw with the unsubscribe link |
| Understand how the site is used and improve it | Analytics information | Legitimate interests, and your consent for analytics cookies in the EU and the UK |
| Measure our advertising | Advertising information | Consent |
| Keep the site and the service secure and working | Visit and log information | Our legitimate interest in a secure, working service |
| Analyze public evidence about a property, including public reviews that name people | Information about the hotels we audit | Our legitimate interest in producing the audit the property commissioned |
We use AI models to help analyze the evidence and draft findings. A person reviews every finding before a report is delivered, and every score is calculated by fixed rules, not by a model.
Cookies and similar technologies
Google Analytics runs unless you turn it off, and in the EU and the UK it sets no cookies until you allow it. Nothing that advertises loads until you allow it. Necessary storage is always on, because the site cannot remember your intake, your cart or your choices without it. Stripe sets its own cookies on its checkout page, under Stripe's privacy policy.
| Name | Set by | Purpose | Category | How long |
|---|---|---|---|---|
mha.consent.v1 | MyHotelAuditor, in your browser's storage | Remembers your privacy choices | Necessary | 12 months, then we ask again |
mha.intake.v1, mha.cart.v1 | MyHotelAuditor, in your browser's storage | Saves your intake answers and your cart so you can pick up where you left off | Necessary | Until you clear your browser's storage |
mha.checkout.session | MyHotelAuditor, in your browser's storage | Keeps your order's reference for this tab, so the confirmation page can show your order's status after a refresh | Necessary | Until you close the tab |
mha_subscribe, mha.purchases.v1 | MyHotelAuditor, in your browser's storage | Remembers that you subscribed or closed the pop-up, and which completed orders were already counted | Necessary | Until you clear your browser's storage |
| Security cookies | Cloudflare | May be set to tell people from automated traffic | Necessary | Short-lived |
mha.ad_conversions.v1 | MyHotelAuditor, in your browser's storage | Remembers which completed orders were already reported to OpenAI, so each is reported once | Advertising, only if you allow it | Until you refuse advertising or clear your browser's storage |
_ga, _ga_* | Google Analytics | Tells visits apart for analytics | Analytics, unless you turn it off (in the EU and the UK, only if you allow it) | Up to 2 years |
| Pixel identifiers | OpenAI | Measures whether our ads lead to visits and orders | Advertising, only if you allow it | Set by OpenAI, see OpenAI's privacy policy |
Who we share information with
We do not sell personal information, and we share it only as this section describes.
- Service providers that run the service for us: Cloudflare (hosting, storage and security), Neon (our database), Stripe (payments and invoices), Resend (email, including our mailing list) and Anthropic (the AI models that help analyze evidence). Each processes information to provide its service to us, under its own terms and privacy policy.
- Analytics, unless you turn it off: Google (Tag Manager and Analytics). In the EU and the UK, Google sets no analytics cookies until you allow it. Google Fonts receives the information described above when a page loads.
- Advertising, only with your permission: OpenAI (the advertising pixel).
- Sources we query to build a report: data services such as Google (Places and PageSpeed Insights), SerpApi (search results), Tripadvisor, Yelp, Reddit and the Internet Archive, and AI assistants reached through OpenRouter. What we send them is information about the property, such as its name, website and city, not information about you.
- Legal and safety reasons: when the law requires it, or to protect our rights, our customers or the public.
- Business changes: if Doubled Rook is involved in a merger, an acquisition or a sale of assets, information may pass to the new owner under this policy.
Your privacy choices
Open your privacy choices to turn analytics off or on, and to allow or refuse advertising. The same link is at the foot of every page, and a change takes effect at once. Turning off a category that was running clears the cookies it set on our site and reloads the page.
If your browser sends a Global Privacy Control signal, we treat it as a request to opt out of sharing for advertising: advertising stays off unless you turn it on yourself in your privacy choices.
Every email from our mailing list has an unsubscribe link. Your intake answers stay in your browser until you check out, and clearing your browser's site data removes them.
Your rights
Wherever you live, you can ask us what personal information we hold about you, ask for a copy, and ask us to correct or delete it. Email info@myhotelauditor.com from the address we know you by, or tell us how we can confirm it is you. We answer within the time the law where you live requires, for example one month under the GDPR and 45 days under California law. We will not treat you differently for using your rights.
In the European Economic Area, the United Kingdom and Switzerland
You also have the right to object to processing based on our legitimate interests, to restrict processing, to receive your information in a portable form, and to withdraw your consent at any time without affecting what was done before. You can complain to your data protection authority.
In California and other US states with privacy laws
Residents of California, Colorado, Connecticut, Virginia and other states with comprehensive privacy laws have the right to know what we collect, to access, correct and delete it, and to opt out of the sale of personal information, of sharing for cross-context behavioral advertising and of targeted advertising. We do not sell personal information. We share it for advertising only if you allow advertising, and you can opt out at any time with your privacy choices or a Global Privacy Control signal. We do not collect sensitive personal information as these laws define it. You can use an authorized agent, and we will ask the agent for proof of your permission. If we decline your request, you can appeal by replying to our answer, and if you disagree with the outcome you can contact your state attorney general.
In the last 12 months we collected these categories of personal information: identifiers (such as your name, email address, IP address and cookie identifiers), customer records (such as your billing address), commercial information (what you bought), professional information (your title and your property), internet activity (the pages you visited, with your permission) and approximate location from your IP address. We collect them from you, from your browser and from the services described above, for the purposes in How we use information, and disclose them to the recipients in Who we share information with.
How long we keep information
- Orders, invoices and payment records: as long as tax and accounting rules require.
- Reports and the evidence behind them: for the life of the report, so every finding can be traced to its source. Some sources limit how long we may keep what they send us. We delete that raw content on their schedule, from one day to 30 days, and keep only the facts we drew from it.
- Our mailing list: until you unsubscribe. We then keep your address marked as unsubscribed so we do not email you again.
- Analytics: Google Analytics keeps event data for up to 14 months.
- Your browser: what the site keeps in your browser stays until you clear it, and we ask for your privacy choices again after 12 months.
- Server logs: kept by Cloudflare for a short period, to run and secure the site.
Security
The site and our systems use encrypted connections (HTTPS). Reports are delivered through signed links, our staff tools sit behind access control, and service keys are kept as encrypted secrets, never in our code. Payment card details are handled by Stripe and never reach our servers. No system is perfectly secure, so if you believe something is wrong, please tell us.
International transfers
We and our service providers operate in the United States and other countries. If you are in the European Economic Area, the United Kingdom or Switzerland, your information is transferred to countries whose laws may differ from yours. We rely on safeguards such as the European Commission's standard contractual clauses or the EU-US Data Privacy Framework, as our providers offer them.
Children
MyHotelAuditor is a service for hotel businesses and is not directed to children. We do not knowingly collect personal information from anyone under 16.
Changes to this policy
We will post any change here and update the date at the top. If a change is significant, we will ask for your privacy choices again or tell you before it applies.
Contact us
Doubled Rook, MyHotelAuditor
Email: info@myhotelauditor.com