Newly Hotels

Privacy policy

Newly is a research site: you look dates up here and book at a partner. That keeps the data side small — and this page says exactly how small.

Pre-launch draft: the entries marked as still open are filled in before this site publishes hotel data. Everything else on this page already applies.

The short version

  • No accounts, no logins, no tracking cookies, no advertising network, no fonts or scripts loaded from other companies' servers.
  • Our own statistics are cookieless and aggregated, so there is nothing to consent to and no consent banner.
  • A click through to a booking partner is logged under a random ID — no IP address, no cookie, no fingerprint.

Who is responsible

Controller within the meaning of Art. 4 (7) GDPR is the site operator named in the imprint:

Name
added before launch· still open
Address
added before launch· still open
E-mail
added before launch· still open

No data protection officer is appointed — the thresholds of § 38 BDSG are not met. Privacy requests go to the address above.

Imprint →

Visiting the site

The site is delivered by Cloudflare from a data centre near you. To serve a page and to fend off attacks, Cloudflare processes connection data: IP address, time of the request, the requested URL, referrer and browser identification. Legal basis: Art. 6 (1)(f) GDPR — providing a working, protected website.

Cloudflare acts as our processor under Art. 28 GDPR and keeps these connection logs only briefly. We build no visitor profiles from them and keep no server logs of our own.

Cloudflare, Inc. is based in the United States. The transfer rests on the EU standard contractual clauses together with the EU-US Data Privacy Framework.

Statistics

not active yet

Described here in advance — this processing is not running.

We measure how often pages are read with Umami, running on our own server in Germany. It sets no cookies, stores no IP address and follows nobody across sites: a daily, non-reversible hash stands in for the count. What we see is page views per page and per country, not people.

Legal basis: Art. 6 (1)(f) GDPR — understanding which destinations are worth maintaining. Because nothing is stored on your device and nothing is read from it, § 25 TDDDG requires no consent.

Clicking through to a booking partner

Every outbound booking link runs through our own /go address. Logged there: a random ID for the click, the time, the hotel, the partner, the page language, the type of page you came from, and whether the request looked like a browser or a bot.

Not logged, at any point: IP address, cookie, device fingerprint, or anything that would let us recognise you on a later visit.

Purpose: matching a partner's commission statement to the page that earned it, and keeping bot clicks out of it. Legal basis: Art. 6 (1)(f) GDPR. Retention: 24 months, then deletion.

The click ID travels to the partner as a sub-ID, together with the hotel and any travel dates you entered. From there on the partner is the controller: its own cookies, its own privacy policy. Its reports tell us that a booking happened for one click ID and what commission it brought — never who booked what.

Partner verification script

One exception to "no third-party scripts", and a temporary one: our booking partner Travelpayouts verifies that this domain is ours by having a script of theirs load on the entry page of newlyhotels.com. It runs on that redirect page only — no content page carries it — and it can see the usual connection data your browser sends to their server. Once the check is complete it is removed. Legal basis: Art. 6 (1)(f) GDPR — access to the partner programme this site is funded by.

Newsletter

not active yet

Described here in advance — this processing is not running.

The monthly newsletter is announced but collects no addresses yet. When it starts: double opt-in (you confirm by e-mail before anything is stored), your address and the time of confirmation kept as the record of consent, a one-click unsubscribe in every issue — and nothing else sent to that address. Legal basis: Art. 6 (1)(a) GDPR, revocable at any time.

Hotels and hoteliers

not active yet

Described here in advance — this processing is not running.

To confirm an opening or renovation date we write to hotels — at business contact addresses from their own published pages, never at private ones. We ask at most three questions about dates, name ourselves and the purpose, and process only what the reply contains. Legal basis: Art. 6 (1)(f) GDPR; the interest is publishing correct dates about that hotel.

One "no" ends it for good: the objection is recorded against the hotel, honoured across every channel, and we do not write again. Objections and requests under Art. 15–21 GDPR go to the address above.

Confirming a date as a hotelier

not active yet

Described here in advance — this processing is not running.

The self-service form for hoteliers stores what makes a confirmation checkable: the confirmed date, the hotel, the time, and the e-mail address the confirmation link went to. It replaces an estimate on the hotel page — the name of the confirming person is never published.

E-mails to us

If you write to us, we process your message and address to answer it. Business correspondence has to be kept for 6 years under § 257 HGB and § 147 AO; anything beyond that we delete once the matter is settled.

Cookies

Newly sets no cookies at all — none technically necessary, none for statistics, none for advertising. Booking partners set their own as soon as you are on their site.

Automated processing and AI

We have a language model read dates out of public hotel and press pages. What goes in is published business information about hotels; visitor data never does. Nothing on this site makes automated decisions about people (Art. 22 GDPR), and we do no profiling.

Your rights

You have the right to information (Art. 15), correction (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21) — and you can withdraw a consent at any time. One message to the address above is enough.

One honest limit: the click log holds a random ID and nothing that points to you, so we cannot assign it to a person even on request (Art. 11 (2) GDPR).

You can also complain to a data protection authority (Art. 77 GDPR). The one responsible for us:

added before launch· still open

Changes to this policy

We update this page when the processing changes — when the statistics go live, when the newsletter starts collecting addresses, when the map or hotel photos load anything from elsewhere. Version: 30 July 2026.

The German version of this page is the legally binding one.

Once a month: what opened

No accounts, no reviews — we point you to the booking site.

Coming soon. Once a month, nothing else.