Last updated: August 2026. This is plain-language and aims to tell you what actually happens with your information. The legalese is preserved where it has to be.
What we collect
When you book a room, parking pass, or event: first and last name, email, phone, mailing address, license plate (parking only), names of additional guests in your party, payment information (handled by Stripe — see "Processors" below), and any optional notes you add.
When you submit a contact or inquiry form: name, email, phone, and whatever details you include in the message.
When you visit the site: standard server logs (IP address, browser, referrer, pages visited, timestamps), plus analytics events via Google Analytics 4 and Google Ads, and a Meta (Facebook) Pixel for advertising attribution.
We do not collect data about you from data brokers. We don't fingerprint your device beyond standard browser metadata.
How we use it
Booking and inquiry data is used to: deliver the service you requested (confirm the reservation, send the parking pass PDF, route you to the right valet lane), follow up about your stay, and maintain accurate hotel records. Analytics data is used to: understand which pages drive bookings, improve the booking flow, and measure marketing campaign performance.
We do not sell your personal information. We do not share booking data with third-party marketers.
Third-party processors
The data above is stored or processed by:
- Stripe — payment processing. We never see your card number.
- Supabase — database hosting for booking records, on our own infrastructure.
- Resend — outbound email delivery (confirmations, receipts).
- Vercel — website hosting and serverless functions.
- Google Analytics 4 — anonymous-ish traffic analytics.
- Google Ads — conversion tracking for paid ads.
- Meta (Facebook) Pixel — conversion tracking for Meta ads. You can opt out via the cookie banner.
- Apple Wallet / Google Wallet — optional digital pass delivery.
Each of those providers has its own privacy policy. We've chosen them because they're considered industry-standard and operate under SOC 2, GDPR, and CCPA frameworks.
The World of Blue mobile app
If you use our mobile app, here is what it handles beyond the website:
- Account & profile — your name, email, and sign-in method (email, or Sign in with Apple / Google).
- Your reservation — when you link a booking by confirmation code or email, the app shows reservation details mirrored from the hotel's property-management system.
- Front-desk messaging — messages you send to our staff through the app.
- Mobile check-in — if you check in through the app, we collect the details you submit, including a photo of your ID taken with your camera (camera access is asked for first), and a payment card handled by Stripe for the room and the incidentals hold. We never see your card number.
- Digital room key — room keys are issued to your device through SALTO's mobile-key system and presented at the door over Bluetooth/NFC. The key credential lives on your device and is revoked at check-out.
- App analytics — usage events (screens visited, feature taps) via PostHog, to understand what's working.
App data is stored in Supabase on our own infrastructure, alongside the website's booking records. You can delete your app account — and the data listed above — at any time: see Account Deletion for the in-app path, the email fallback, and exactly what is deleted versus retained.
Your rights
California residents (CCPA/CPRA) can request a copy of the personal information we hold about you, request that we delete it, or opt out of any "sale" of personal information (we don't sell — but you have the formal right). Email privacy@theworldofblue.com with "CCPA Request" in the subject line; we respond within 45 days.
EU/UK residents (GDPR) have the right to access, rectify, delete, restrict processing, or port your personal data, plus the right to object to processing for marketing purposes. Same email, "GDPR Request" in the subject; we respond within 30 days.
Anyone can ask us to delete their information at any time, even if you're not in a jurisdiction with a formal right.
Cookies & tracking
Strictly-necessary cookies (booking session state, fraud prevention) are set automatically and can't be disabled.
Marketing cookies (Meta Pixel, ad attribution) only fire after you accept the consent banner. You can change your choice at any time via the "Cookie Preferences" link in the footer.
Retention
Booking records are kept for 7 years for accounting and tax compliance. Inquiry records are kept for 3 years. Analytics data is retained per Google's standard retention windows (14 months by default).
A parking pass and its code are part of the booking record it belongs to, and are retained on the same 7-year schedule. A pass stops being valid after the date it was issued for, but the record is not deleted at that point — we keep it for accounting, chargeback, and tax purposes. You can ask us to delete it sooner using the contact details below, and we will unless we are required to keep it.
Contact
Privacy questions or requests: privacy@theworldofblue.com · (201) 896-0500.
This policy is provided for transparency. It is not a substitute for legal advice; we recommend you contact counsel if you need to understand how the law applies to your situation. World of Blue reserves the right to update this policy; material changes will be highlighted on this page.
