Legal
Privacy Policy
Last updated: 22 August 2026
1. Who we are
ONLINERSV is a travel booking platform specialising in Umrah, global hotel and related travel services. This Privacy Policy explains how we collect, use, store, share and protect personal data when you use our website, applications and services.
For the purposes of this policy, “ONLINERSV”, “we”, “us” or “our” means the ONLINERSV platform and its operator. If you have questions about this policy, please contact us using the details in the “Your rights and contact” section below.
2. What data we collect
We collect only the information needed to provide and improve our travel booking services:
- Account data: name, email address, phone number, password hash and any profile information you choose to provide.
- Booking data: traveller names, passport or ID details (where required by travel suppliers), dates, destinations, room and rate preferences, special requests, and the party composition (adults, children).
- Payment data: billing address and transaction records. We do not store full card numbers or CVV codes; these are handled by our payment service provider.
- Communication data: emails, messages, support tickets and feedback you send us.
- Technical data: IP address, browser type, device information, cookies and similar identifiers used to keep you signed in and to improve security and performance.
- Google API data (with your consent): when you or an administrator choose to connect a Google account to send email, we access only the Gmail sending capability needed to deliver transactional or service messages on behalf of that configured account. We do not request access to your inbox, contacts, files or other Google data.
3. How we use your data
We use your personal data for the following purposes:
- To create and manage your account and to keep you signed in securely.
- To process and confirm bookings, modifications, cancellations and refunds.
- To send booking confirmations, itinerary updates, payment receipts, reminders and other service-related messages.
- To provide customer support and respond to your enquiries.
- To detect, prevent and investigate fraud, security incidents or misuse of the platform.
- To comply with legal, accounting, tax and regulatory obligations.
- With your consent, to communicate marketing or promotional offers (you may opt out at any time).
Google user data: If a Google account is connected for email sending, we use the associated Gmail sending capability solely to deliver transactional or service-related emails — such as booking confirmations and support replies — on behalf of the configured account. We do not use Google user data for advertising, profiling, sale, or any purpose unrelated to operating ONLINERSV.
4. Legal basis for processing
We process personal data where we have a legal basis to do so, including: performance of a contract with you; compliance with a legal obligation; protection of vital interests; our legitimate interests in operating a secure and reliable booking platform; or your consent, where required.
5. Sharing and service providers
We do not sell your personal data. We share data only with the parties necessary to deliver the services you request:
- Hotels, suppliers and partners: to confirm, modify or cancel your booking.
- Payment service providers: to process payments securely. Card details are never stored on our servers.
- Cloud/infrastructure providers: for hosting, database, email delivery and observability services, under contractual confidentiality and security obligations.
- Legal and regulatory authorities: when required by law, court order, or to protect our rights and users.
All third-party providers are contractually bound to use data only for the purposes of providing their services to ONLINERSV and to maintain appropriate security measures.
6. Google API Services compliance
ONLINERSV use and transfer of information received from Google APIs is limited to the practices described in the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We request only the minimum Gmail scope required to send email on behalf of the connected account (the
gmail.sendscope). - We do not use Google user data to serve advertisements, build advertising profiles, or sell personal information.
- We do not transfer Google user data to third parties except as necessary to provide the email-sending service or as required by law.
- Human review of Google user data is limited to customer support staff resolving a specific email delivery issue, and only with appropriate access controls.
7. International transfers
Travel bookings require us to share data with hotels and suppliers located in the destinations you book, including Saudi Arabia and other countries. We use appropriate safeguards, such as contractual protections, to ensure your data remains protected in accordance with this policy.
8. Data retention and deletion
We keep personal data for as long as necessary to provide our services, fulfil the purposes described in this policy, comply with legal, tax and accounting obligations, and resolve disputes:
- Account data is retained while your account is active and for a reasonable period afterwards to comply with legal obligations and prevent fraud.
- Booking and payment records are retained for the period required by applicable tax, accounting and travel-regulation laws.
- Marketing consents and opt-out records are retained for as long as necessary to respect your preferences.
- Google API tokens and logs are retained only as long as needed to maintain the email-sending connection and diagnose delivery issues.
You may request deletion of your personal data by contacting us. We will delete data unless we are required to retain it by law or for legitimate legal purposes. Some data may be anonymised rather than deleted where complete deletion would impair legal or accounting records.
9. Security
We protect personal data using industry-standard security measures, including:
- Encrypted data in transit using TLS/HTTPS.
- Encrypted sensitive data at rest.
- Role-based access controls, least-privilege database policies and row-level security.
- Audit logging and monitoring for suspicious activity.
- Strong authentication and multi-factor authentication for administrative access.
No online service can guarantee absolute security. If you believe your account or data has been compromised, please contact us immediately.
10. Your rights and requests
Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal data, or to object to certain processing. You may also have the right to withdraw consent where processing is based on consent.
To exercise these rights, or to ask questions about this Privacy Policy, please contact us at:
Email: privacy@onlinersv.com
We will respond to legitimate requests in accordance with applicable law and may need to verify your identity before acting on a request.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. The “Last updated” date at the top of this page shows when the policy was last revised. We encourage you to review the policy periodically.
12. Cookies and tracking
We use cookies and similar technologies to maintain your session, remember preferences, and understand how our platform is used. You can control cookies through your browser settings. Essential cookies required for security and authentication cannot be disabled without affecting your ability to use the service.
