Blueprint Hotels

Privacy Policy

Effective from June 2026. Last updated June 2026.

Provisional draft — being finalised with legal counsel. This describes how Blueprint Travel Collective Pty Ltd ("Blueprint") handles personal information collected through blueprint-hotels.com.au.

1. Who we are

Blueprint Travel Collective Pty Ltd (ABN 74 685 366 241), an Australian company, operates Blueprint Hotels — a B2B hotel booking platform for travel agencies. Our registered address and contact email are at the foot of this page.

2. What information we collect

We collect three categories of personal information:

3. How we use it

We use personal information only for the purposes for which it was collected:

We do not sell, rent, or trade personal information to third parties.

4. Who we share it with

We share the minimum personal information needed with these categories of service provider:

We may also disclose information where required by law (court order, regulator request) or to protect our rights and the safety of Guests.

5. Where we store information

Primary data is stored in Australia (AWS ap-southeast-2, Sydney). Some sub-processors (Stripe, Resend, TBO) may process data outside Australia. By using the Platform you consent to cross-border transfers for these purposes.

6. How long we keep it

7. Security

We use industry-standard security measures including TLS encryption in transit, password hashing (bcrypt), parameterised database queries to prevent injection, server -side authorisation on every page that exposes private data, and rate limiting on authentication endpoints. We do not store unencrypted card details on our servers.

No system is 100% secure. If a data breach occurs we will notify affected Agencies and (where applicable) the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme.

8. Your rights

Under the Australian Privacy Principles you may request:

If you are based in the United Kingdom or the European Union, you have additional rights under UK GDPR / EU GDPR including data portability and the right to lodge a complaint with your local supervisory authority (e.g. the ICO in the UK).

All requests: email bookings@blueprint-hotels.com.au. We respond within 30 days.

9. Cookies

We use a small number of strictly necessary cookies (authentication session, CSRF protection) and may set anonymous analytics cookies in the future. We do not use third-party advertising cookies.

10. Children

Blueprint Hotels is a B2B platform and is not intended for use by individuals under 18. We do not knowingly collect personal information from children.

11. Changes to this policy

We may update this Policy from time to time. Material changes will be notified to registered Agencies by email at least 14 days before they take effect.

12. Contact

Privacy enquiries and requests: bookings@blueprint-hotels.com.au
Blueprint Travel Collective Pty Ltd · QLD 4209, Australia.

Information about complaints and OAIC: oaic.gov.au.