Privacy Policy
Effective from June 2026. Last updated June 2026.
Provisional draft — being finalised with legal counsel. This describes how Blueprint Travel Collective Pty Ltd ("Blueprint") handles personal information collected through blueprint-hotels.com.au.
1. Who we are
Blueprint Travel Collective Pty Ltd (ABN 74 685 366 241), an Australian company, operates Blueprint Hotels — a B2B hotel booking platform for travel agencies. Our registered address and contact email are at the foot of this page.
2. What information we collect
We collect three categories of personal information:
- Agency account information — legal name, trading name, ABN, contact email and phone, primary contact's first/last name, hashed password.
- Booking information — for each Guest booked by an Agency: title, first/last name, contact email and phone, room preferences, dates of stay, destination. We do not collect or store payment card details (these are handled directly by Stripe — see below).
- Technical information — IP address, browser type, device type, cookies for session management, log files of API requests and responses (used for support and supplier reconciliation).
3. How we use it
We use personal information only for the purposes for which it was collected:
- To process bookings with our hotel-supply partner (TBO Holidays) and the relevant Property;
- To send transactional emails (booking confirmations, branded vouchers, cancellation notices, password resets);
- To operate, secure, and improve the Platform;
- To respond to support enquiries;
- To send agency-facing product updates (Agencies may opt out at any time);
- To comply with our legal and tax obligations.
We do not sell, rent, or trade personal information to third parties.
4. Who we share it with
We share the minimum personal information needed with these categories of service provider:
- TBO Holidays — Supplier of hotel inventory. Guest names and contact details are passed to TBO to complete bookings with properties.
- Stripe — Payment processor. Card details are entered directly into Stripe's secure environment and never touch Blueprint servers. We hold only Stripe customer IDs and saved-card metadata (brand, last 4 digits, expiry month/year).
- Resend — Email delivery for transactional notifications. Email addresses and message content are transmitted via Resend.
- Neon (PostgreSQL) — Database hosting. Data is stored in AWS Asia Pacific (Sydney) region.
- Fly.io — Application hosting. Application logs may briefly contain request metadata.
We may also disclose information where required by law (court order, regulator request) or to protect our rights and the safety of Guests.
5. Where we store information
Primary data is stored in Australia (AWS ap-southeast-2, Sydney). Some sub-processors (Stripe, Resend, TBO) may process data outside Australia. By using the Platform you consent to cross-border transfers for these purposes.
6. How long we keep it
- Booking records — minimum 7 years (Australian tax record-keeping).
- Agency accounts — retained while the account is active and for 7 years after closure.
- Support correspondence — 3 years.
- Marketing subscribers — until unsubscribed; then we keep the email on a suppression list to honour the unsubscribe.
7. Security
We use industry-standard security measures including TLS encryption in transit, password hashing (bcrypt), parameterised database queries to prevent injection, server -side authorisation on every page that exposes private data, and rate limiting on authentication endpoints. We do not store unencrypted card details on our servers.
No system is 100% secure. If a data breach occurs we will notify affected Agencies and (where applicable) the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme.
8. Your rights
Under the Australian Privacy Principles you may request:
- Access to the personal information we hold about you;
- Correction of inaccurate or out-of-date information;
- Deletion of your account (subject to our minimum retention obligations under tax law);
- Export of your booking history in a portable format.
If you are based in the United Kingdom or the European Union, you have additional rights under UK GDPR / EU GDPR including data portability and the right to lodge a complaint with your local supervisory authority (e.g. the ICO in the UK).
All requests: email bookings@blueprint-hotels.com.au. We respond within 30 days.
9. Cookies
We use a small number of strictly necessary cookies (authentication session, CSRF protection) and may set anonymous analytics cookies in the future. We do not use third-party advertising cookies.
10. Children
Blueprint Hotels is a B2B platform and is not intended for use by individuals under 18. We do not knowingly collect personal information from children.
11. Changes to this policy
We may update this Policy from time to time. Material changes will be notified to registered Agencies by email at least 14 days before they take effect.
12. Contact
Privacy enquiries and requests: bookings@blueprint-hotels.com.au
Blueprint Travel Collective Pty Ltd · QLD 4209, Australia.
Information about complaints and OAIC: oaic.gov.au.
