• Startseite
  • Angebote
    • Discovery
    • Channel Manager
    • Agentenbasierte Zahlungen
    • Globale Auszahlungen
    • On/Off-Ramp
  • Pricing
  • Verzeichnisse
    • Hotels402
    • Publishers402
    • Bluerails402
  • Resources
    • Blog
      Blog
    • Case Studies
      Case Studies
    • Docs
  • Über uns
Jetzt starten
English Deutsch
Last updated: Aug 10, 2026

Privacy Policy

1. Who we are

Bluerails is a European company building AI visibility and payment infrastructure for the hotel and hospitality industry. This Privacy Policy explains how we collect, use, store, and share personal information when you visit our website, sign up for our services, or otherwise interact with us.

Data controller for services provided in the European Economic Area, the United Kingdom, and Switzerland:

Bluerails GmbH

Neue Schönhauser Straße 2, 10178 Berlin, Germany

Registered at Amtsgericht Berlin, HRB 286638 B

Contact: privacy@bluerails.com

Data controller for services provided in Canada and by the Canadian entity

Bandra Railz Finance Inc., a Money Services Business (MSB) registered with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC), and a Payment Service Provider (PSP) registered with the Bank of Canada under the Retail Payment Activities Act.

Together, "Bluerails," "we," "us," or "our."

2. Who this policy applies to

This Privacy Policy applies to:

  • Visitors to our website (bluerails.com and related properties)
  • Business customers, including hotels, publishers, tour operators, platforms, and other businesses that use our services
  • Individuals interacting with our customers' offerings through AI agents, where Bluerails processes personal data on behalf of the business customer
  • Prospective customers who contact us or request an AI visibility check
  • Anyone who communicates with us for support, sales, or partnership purposes

3. What personal information we collect

We collect personal information in the following categories.

Business contact information. Name, business name, business address, email address, phone number, job title, and other contact details you provide when you sign up for our services or contact us.

Business and website data. Information about your business, including your website URL, the content of your public web pages, published rates and availability, published amenities and services, and any information you upload to your Bluerails dashboard.

Identity verification information. For customers subscribing to Commerce or Settlement plans, we collect information necessary for KYC/KYB (know-your-customer and know-your-business) checks, including business registration numbers, beneficial owner information, and government-issued identification documents.

Payment information. Payment details you provide during signup, such as billing address and payment method. We do not store full payment card details; these are handled directly by our regulated payment processors.

Guest data, as processor on your behalf. Where you subscribe to our Commerce or Settlement plans and a guest books your property through an AI agent, we may process minimal information required to facilitate the booking (such as guest name, contact information, dates, and booking preferences) on your behalf as your data processor. We do not process guest payment card details; those are handled directly by regulated payment providers.

Technical and usage information. IP address, device information, browser type and version, referring URL, pages visited, time spent, cookie identifiers, and information about how you interact with our dashboard, features used, and error logs.

Communication data. The content of emails, chat messages, and support tickets you send us, and recordings or transcripts of scheduled calls where you have consented.

4. How we use your personal information

We use your personal information to:

  • Deliver our services, including AI visibility checks, ongoing monitoring, channel management, MCP server setup, and payment orchestration
  • Onboard business customers, including identity verification, KYC/KYB, and sanctions screening as required for regulated services
  • Facilitate agent-driven bookings and payments, where Bluerails orchestrates the interaction between AI agents, your business, and regulated payment partners. Bluerails does not custody funds or hold guest payment card data.
  • Communicate with you about your account, service updates, changes to our terms, and support inquiries
  • Improve our services through analytics, error monitoring, and user feedback
  • Comply with legal and regulatory obligations, including anti-money laundering (AML), counter-terrorism financing (CTF), tax, and record-keeping requirements
  • Prevent fraud, misuse, and security incidents
  • Send marketing communications, with your consent and only where lawful
  • Support corporate transactions, such as financings and mergers, subject to confidentiality safeguards.

Legal bases (GDPR)

Where the GDPR applies, we rely on the following legal bases:

  • Performance of a contract (GDPR Art. 6(1)(b)) for delivering our services
  • Legitimate interests (GDPR Art. 6(1)(f)) for improving our services, preventing fraud, and business operations
  • Compliance with a legal obligation (GDPR Art. 6(1)(c)) for AML, CTF, tax, and regulatory reporting
  • Consent (GDPR Art. 6(1)(a)) for marketing communications and optional analytics cookies

5. When Bluerails acts as a data processor

If you are a business customer and you use Bluerails to process personal data of your guests, end users, or other data subjects (for example, when facilitating an AI-driven booking or payment), Bluerails acts as a data processor and you are the data controller.

In that case, we will enter into a separate data processing agreement (DPA) with you, compliant with Article 28 of the GDPR, and we will process your data subjects' personal information only on your documented instructions.

6. How we share your personal information

We do not sell your personal information. We share it only in the limited circumstances described below.

With our service providers and regulated partners. We work with regulated financial partners and technology vendors to deliver our services. These include:

  • Regulated stablecoin issuers (for example, Circle Europe SAS, AllUnity)
  • Regulated payment institutions and banking partners (for example, Ebury)
  • Regulated crypto-asset service providers where required (for example, BVNK)
  • KYC/KYB, sanctions-screening, and Travel Rule compliance vendors
  • Cloud infrastructure and hosting providers
  • Analytics, error monitoring, and support tooling providers

Each provider processes personal information only on our instructions and under contractual data-protection obligations.

With AI systems and directories. Where you have subscribed to a plan that requires it, we make your business's public information (rates, availability, amenities, and similar) available to AI agents, search engines, and business directories through structured protocols such as MCP and Schema.org. Personal information of your guests is not shared through these channels.

With regulatory authorities. We disclose personal information to regulatory and government authorities where required by law, including:

  • BaFin (Bundesanstalt für Finanzdienstleistungsaufsicht) in Germany
  • The Bank of Canada, under the Retail Payment Activities Act
  • FINTRAC, under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA)
  • National data protection authorities
  • Tax authorities and courts of competent jurisdiction

In corporate transactions. If we are involved in a merger, acquisition, financing, or sale of all or part of our business, personal information may be transferred to the acquiring party, subject to appropriate confidentiality and data-protection safeguards.

7. International transfers

Bluerails is headquartered in Germany, and we may transfer personal information outside the European Economic Area or the United Kingdom to deliver our services. Where we do so, we rely on appropriate safeguards under GDPR Chapter V, including:

  • Adequacy decisions issued by the European Commission or the UK Government
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • The UK International Data Transfer Addendum, where the UK GDPR applies

You can request a copy of the applicable safeguards by writing to privacy@bluerails.com.

8. How long we keep your personal information

We keep personal information only as long as necessary for the purposes for which it was collected, and to comply with legal, tax, and regulatory obligations. Typical retention periods:

  • Business customer contact and account information: for the duration of your account plus a further six years, in line with the German Commercial Code (HGB § 257) and Fiscal Code (AO § 147)
  • Transaction and payment records: at least ten years, in line with German commercial and tax law
  • KYC/KYB records: at least five years after the end of the business relationship, as required under German AML law (GwG) and Canadian PCMLTFA
  • Marketing consents and preferences: until you withdraw consent
  • Website analytics data: up to 26 months, or as configured in your consent preferences

At the end of the applicable retention period, we securely delete or anonymize the data.

9. Your rights

Under the GDPR and other applicable data protection laws, you have the following rights in respect of your personal information:

  • Right of access (GDPR Art. 15): request a copy of the personal information we hold about you
  • Right to rectification (GDPR Art. 16): ask us to correct inaccurate or incomplete information
  • Right to erasure (GDPR Art. 17): ask us to delete your personal information, subject to legal retention obligations
  • Right to restriction of processing (GDPR Art. 18): ask us to restrict how we process your data in certain circumstances
  • Right to data portability (GDPR Art. 20): request your data in a structured, commonly used, machine-readable format
  • Right to object (GDPR Art. 21): object to processing based on legitimate interests, or to direct marketing
  • Right to withdraw consent (GDPR Art. 7(3)): where processing is based on consent, withdraw it at any time
  • Right to lodge a complaint: complain to your local data protection authority. In Germany, this is the Berliner Beauftragte für Datenschutz und Informationsfreiheit. In Canada, this is the Office of the Privacy Commissioner of Canada.

To exercise any of these rights, write to privacy@bluerails.com. We will respond within one month.

10. Security

We implement technical and organizational measures to protect your personal information against unauthorized access, loss, alteration, or disclosure. These include:

  • Encryption of data in transit (TLS 1.2 or higher) and at rest
  • Access controls and role-based permissions
  • Multi-factor authentication for internal system access
  • Regular security reviews and testing
  • Contractual data-protection obligations for all service providers
  • Employee training on data protection and information security

No system is perfectly secure, and we cannot guarantee that unauthorized third parties will never defeat our safeguards. If a data breach affects your personal information, we will notify the relevant supervisory authorities and, where required, you, in accordance with GDPR Art. 33 and 34.

11. Cookies and tracking technologies

Our website uses cookies and similar technologies to operate the site, understand how visitors use it, and, where you consent, support marketing. You can manage your cookie preferences at any time through the cookie banner or your browser settings. Disabling certain cookies may affect the functionality of our website.

12. Automated decision-making

We do not make decisions based solely on automated processing (including profiling) that produce legal effects concerning you or similarly significantly affect you, unless we have your explicit consent, the decision is necessary for a contract with you, or it is authorised by law.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (where we have your email address) or by prominent notice on our website, at least thirty (30) days before the changes take effect. The most recent version is always available at bluerails.com/privacy.

14. How to contact us

For any question about this Privacy Policy or your personal information:

Email: privacy@bluerails.com
Postal address: Bluerails GmbH, Neue Schönhauser Straße 2, 10178 Berlin, Germany

If we cannot resolve your concern, you may lodge a complaint with the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin data protection authority) or another data protection authority with jurisdiction in your country.

Back to home page
  • Startseite
  • Globale Auszahlungen
  • On/Off-Ramp
  • Über uns
  • Blog
twitterlinkedin
  • Datenschutzerklärung
  • AGB
  • Impressum
©2026 Bluerails.