MyHotelAuditor MyHotelAuditor · by Doubled Rook
The problem The solution Sample report Pricing About Run an Audit
Privacy

Privacy policy

Last updated October 7, 2026

MyHotelAuditor is a product of Doubled Rook ("we", "us"). This policy explains what personal information we collect through myhotelauditor.com and while we produce the reports you order, how we use it, who we share it with, and the choices and rights you have. If you have a question, email info@myhotelauditor.com.

IN THIS POLICY
  1. The short version
  2. What we collect
  3. Information about the hotels we audit
  4. How we use information
  5. Cookies and similar technologies
  6. Who we share information with
  7. Your privacy choices
  8. Your rights
  9. How long we keep information
  10. Security
  11. International transfers
  12. Children
  13. Changes to this policy
  14. Contact us

The short version

  • We collect what you give us: your contact details, your property and your order. We use it to produce and deliver your report, bill you and answer you.
  • Google Analytics runs when you visit, so we can see how the site is used. In the EU and the UK, it sets no cookies until you accept. Advertising tools do not run until you allow them. You can change your choices at any time with Your privacy choices, at the foot of every page.
  • We do not sell your personal information. If you allow advertising, we share limited information about your visit with OpenAI to measure our ads.
  • The reports are about hotels, built from public sources and official data services. A person reviews every finding before a report is delivered.

What we collect

Information you give us

  • The intake. Your answers to the intake questionnaire stay in your browser until you continue to payment. At that point we send the report you chose, your property's name and website, your name, your title, your hotel type, whether you chose rush delivery and your work email to our payment processor, Stripe, to create your order.
  • Checkout. Stripe collects your payment details and billing address on its own secure page. Stripe tells us your name, email address, billing address and what you bought. We never see your full card number.
  • Our mailing list. If you subscribe from the footer or the pop-up, we add your email address to our mailing list.
  • Messages. If you email us, we keep the message and our reply.

Information collected automatically

  • Every visit. Our host, Cloudflare, processes your IP address, browser details and the pages you request, to deliver the site and keep it secure. Pages load the Open Sans typeface from Google Fonts, so Google also receives your IP address and browser details when a page loads.
  • Unless you turn analytics off. Google Analytics, loaded through Google Tag Manager, records the pages you visit, how you arrived, your device and browser, your approximate location and, on the payment confirmation page, the value and contents of a completed order. In the EU and the UK, it sets no cookies until you allow it.
  • Only if you allow advertising. OpenAI's advertising pixel records your visit, such as the page, your browser and your IP address. When you complete an order it also records that an order was completed, though not what you ordered or what you paid. This lets OpenAI and us tell whether our ads on OpenAI's services lead to visits and orders.

Information about the hotels we audit

When you order a report, we collect publicly available information about your property: its website, its listings on booking and review sites, search results, its maps and business profiles, its social media profiles, archived copies of its website and the answers AI assistants give about it. We collect it as an ordinary logged-out visitor or through each source's official data service, and never by getting around a site's protections.

Some of this information names people, such as guests who wrote reviews and staff they mention. We keep names only as they were published, use them only to produce the report the property commissioned, never combine them with other information about those people, and can leave reviewer names out of a report. If you are named in a public review and want to ask about it, contact us.

How we use information

The legal basis column applies if you are in the European Economic Area, the United Kingdom or Switzerland.

Why we use itWhat we useLegal basis
Produce, deliver and support the reports you orderYour order and intake details, information about your propertyPerforming our contract with you
Take payment, issue invoices and keep accounting recordsOrder and billing detailsContract, and our legal obligations
Email you your report and follow-up about itYour work emailContract, and the consent you give at the intake
Send news about new reports and offersYour email address, if you subscribeConsent, which you can withdraw with the unsubscribe link
Understand how the site is used and improve itAnalytics informationLegitimate interests, and your consent for analytics cookies in the EU and the UK
Measure our advertisingAdvertising informationConsent
Keep the site and the service secure and workingVisit and log informationOur legitimate interest in a secure, working service
Analyze public evidence about a property, including public reviews that name peopleInformation about the hotels we auditOur legitimate interest in producing the audit the property commissioned

We use AI models to help analyze the evidence and draft findings. A person reviews every finding before a report is delivered, and every score is calculated by fixed rules, not by a model.

Cookies and similar technologies

Google Analytics runs unless you turn it off, and in the EU and the UK it sets no cookies until you allow it. Nothing that advertises loads until you allow it. Necessary storage is always on, because the site cannot remember your intake, your cart or your choices without it. Stripe sets its own cookies on its checkout page, under Stripe's privacy policy.

NameSet byPurposeCategoryHow long
mha.consent.v1MyHotelAuditor, in your browser's storageRemembers your privacy choicesNecessary12 months, then we ask again
mha.intake.v1, mha.cart.v1MyHotelAuditor, in your browser's storageSaves your intake answers and your cart so you can pick up where you left offNecessaryUntil you clear your browser's storage
mha.checkout.sessionMyHotelAuditor, in your browser's storageKeeps your order's reference for this tab, so the confirmation page can show your order's status after a refreshNecessaryUntil you close the tab
mha_subscribe, mha.purchases.v1MyHotelAuditor, in your browser's storageRemembers that you subscribed or closed the pop-up, and which completed orders were already countedNecessaryUntil you clear your browser's storage
Security cookiesCloudflareMay be set to tell people from automated trafficNecessaryShort-lived
mha.ad_conversions.v1MyHotelAuditor, in your browser's storageRemembers which completed orders were already reported to OpenAI, so each is reported onceAdvertising, only if you allow itUntil you refuse advertising or clear your browser's storage
_ga, _ga_*Google AnalyticsTells visits apart for analyticsAnalytics, unless you turn it off (in the EU and the UK, only if you allow it)Up to 2 years
Pixel identifiersOpenAIMeasures whether our ads lead to visits and ordersAdvertising, only if you allow itSet by OpenAI, see OpenAI's privacy policy

Who we share information with

We do not sell personal information, and we share it only as this section describes.

  • Service providers that run the service for us: Cloudflare (hosting, storage and security), Neon (our database), Stripe (payments and invoices), Resend (email, including our mailing list) and Anthropic (the AI models that help analyze evidence). Each processes information to provide its service to us, under its own terms and privacy policy.
  • Analytics, unless you turn it off: Google (Tag Manager and Analytics). In the EU and the UK, Google sets no analytics cookies until you allow it. Google Fonts receives the information described above when a page loads.
  • Advertising, only with your permission: OpenAI (the advertising pixel).
  • Sources we query to build a report: data services such as Google (Places and PageSpeed Insights), SerpApi (search results), Tripadvisor, Yelp, Reddit and the Internet Archive, and AI assistants reached through OpenRouter. What we send them is information about the property, such as its name, website and city, not information about you.
  • Legal and safety reasons: when the law requires it, or to protect our rights, our customers or the public.
  • Business changes: if Doubled Rook is involved in a merger, an acquisition or a sale of assets, information may pass to the new owner under this policy.

Your privacy choices

Open your privacy choices to turn analytics off or on, and to allow or refuse advertising. The same link is at the foot of every page, and a change takes effect at once. Turning off a category that was running clears the cookies it set on our site and reloads the page.

If your browser sends a Global Privacy Control signal, we treat it as a request to opt out of sharing for advertising: advertising stays off unless you turn it on yourself in your privacy choices.

Every email from our mailing list has an unsubscribe link. Your intake answers stay in your browser until you check out, and clearing your browser's site data removes them.

Your rights

Wherever you live, you can ask us what personal information we hold about you, ask for a copy, and ask us to correct or delete it. Email info@myhotelauditor.com from the address we know you by, or tell us how we can confirm it is you. We answer within the time the law where you live requires, for example one month under the GDPR and 45 days under California law. We will not treat you differently for using your rights.

In the European Economic Area, the United Kingdom and Switzerland

You also have the right to object to processing based on our legitimate interests, to restrict processing, to receive your information in a portable form, and to withdraw your consent at any time without affecting what was done before. You can complain to your data protection authority.

In California and other US states with privacy laws

Residents of California, Colorado, Connecticut, Virginia and other states with comprehensive privacy laws have the right to know what we collect, to access, correct and delete it, and to opt out of the sale of personal information, of sharing for cross-context behavioral advertising and of targeted advertising. We do not sell personal information. We share it for advertising only if you allow advertising, and you can opt out at any time with your privacy choices or a Global Privacy Control signal. We do not collect sensitive personal information as these laws define it. You can use an authorized agent, and we will ask the agent for proof of your permission. If we decline your request, you can appeal by replying to our answer, and if you disagree with the outcome you can contact your state attorney general.

In the last 12 months we collected these categories of personal information: identifiers (such as your name, email address, IP address and cookie identifiers), customer records (such as your billing address), commercial information (what you bought), professional information (your title and your property), internet activity (the pages you visited, with your permission) and approximate location from your IP address. We collect them from you, from your browser and from the services described above, for the purposes in How we use information, and disclose them to the recipients in Who we share information with.

How long we keep information

  • Orders, invoices and payment records: as long as tax and accounting rules require.
  • Reports and the evidence behind them: for the life of the report, so every finding can be traced to its source. Some sources limit how long we may keep what they send us. We delete that raw content on their schedule, from one day to 30 days, and keep only the facts we drew from it.
  • Our mailing list: until you unsubscribe. We then keep your address marked as unsubscribed so we do not email you again.
  • Analytics: Google Analytics keeps event data for up to 14 months.
  • Your browser: what the site keeps in your browser stays until you clear it, and we ask for your privacy choices again after 12 months.
  • Server logs: kept by Cloudflare for a short period, to run and secure the site.

Security

The site and our systems use encrypted connections (HTTPS). Reports are delivered through signed links, our staff tools sit behind access control, and service keys are kept as encrypted secrets, never in our code. Payment card details are handled by Stripe and never reach our servers. No system is perfectly secure, so if you believe something is wrong, please tell us.

International transfers

We and our service providers operate in the United States and other countries. If you are in the European Economic Area, the United Kingdom or Switzerland, your information is transferred to countries whose laws may differ from yours. We rely on safeguards such as the European Commission's standard contractual clauses or the EU-US Data Privacy Framework, as our providers offer them.

Children

MyHotelAuditor is a service for hotel businesses and is not directed to children. We do not knowingly collect personal information from anyone under 16.

Changes to this policy

We will post any change here and update the date at the top. If a change is significant, we will ask for your privacy choices again or tell you before it applies.

Contact us

Doubled Rook, MyHotelAuditor
Email: info@myhotelauditor.com

Stay ahead

Occasional notes on hotel marketing, plus first word on new reports and offers. No spam, unsubscribe anytime.

© 2026 Doubled Rook · MyHotelAuditor
Privacy policyYour privacy choices
LinkedIn
AI-Powered marketing & operational audits for hotels & resorts