Privacy Policy
Effective 17 August 2026 · Last updated 17 August 2026
This Privacy Policy explains how Frinbe KlG processes personal data when you visit or use Frinbe, join an organization, manage accommodation, or request a reservation. It also describes your rights under the Swiss Federal Act on Data Protection and, where applicable, the GDPR.
At a glance
- Frinbe uses your data to operate accounts and memberships, process reservation requests, secure the platform, and communicate with you.
- Hotels and organizations receive only the information they need for their own role. Your organization does not receive your reservation history.
- Core hosting and storage are in Switzerland. Google and Microsoft may process sign-in data in the EEA and the United States.
- You can contact us at any time to exercise your data-protection rights or ask how a particular processing activity works.
1. Controller and contact
Frinbe KlG, CHE-263.712.857, c/o Angela Käppeli, Dorfstrasse 54, 6026 Rain, Switzerland, is the independent controller for the platform processing described in this Policy. Privacy requests can be sent to privacy@frinbe.com.
Hotels and other organizations independently decide how they use personal data for their own operations, including invitations, reservations, guest communication, and stays, and are responsible for that use. Their own privacy information may therefore also apply.
2. Data we process
Depending on how you use Frinbe, we process the following categories:
- Account and profile data, such as name, email address, language, account status, permissions, and a profile photo if provided.
- Authentication and security data, such as password hashes, email-verification status, sessions, IP address, user agent, request identifiers, and security events.
- Organization and professional data, such as organization membership, role, affiliation, property assignment, approvals, and invitation information.
- Hotel and property data, such as names, descriptions, contact information, addresses, images, availability, rates, and operating settings.
- Reservation data, such as the hotel, stay dates, number of adults and children, price, currency, confirmation number, status, and associated messages.
- Communications, such as support requests, reservation chat, email replies, message content, and delivery metadata.
- Files and lead information, such as uploaded images and their metadata, contact-form details, software used, room count, referral source, and message.
- Technical data needed to operate, secure, diagnose, and improve the service.
When you sign in with Google or Microsoft, we receive your name, email address, email-verification status, profile picture, provider account identifier, and authentication tokens needed to complete and maintain the sign-in. We use this information to create and sign in to your account and to show your profile picture in Frinbe. We request only basic sign-in scopes and no access to your other Google or Microsoft services.
Frinbe does not currently collect payment-card details, identity documents, or dates of birth. If a future feature requires age or date-of-birth information, we will request only what is necessary and explain the purpose at collection.
Fields identified as optional can be left blank. If you do not provide information required to create or secure an account, verify your eligibility, or submit a reservation request, we may be unable to provide that function. We explain any additional requirement when we collect the data.
3. Where data comes from
We receive data from you, organization administrators who invite or manage you, hotels involved in a reservation, and automatically from devices and service operation. If you sign in with a supported provider, we receive the sign-in data described above from that provider. Where an organization requires institutional login, we receive your email address from that organization's identity provider. We may also receive reservation updates from a hotel's property-management system or channel manager.
4. Purposes and legal grounds
- Creating accounts, managing memberships, and providing requested platform and reservation services to perform our contract or take requested pre-contract steps.
- Routing booking requests, messages, and confirmations to hotels and their authorized systems to perform the requested service.
- Displaying hotel locations through Google Maps based on our legitimate interest in making properties and offers easy to locate.
- Securing accounts, preventing abuse, diagnosing failures, supporting users, and improving reliability based on our legitimate interests.
- Complying with accounting, legal, regulatory, and dispute-handling duties.
- Sending Frinbe marketing only where you have voluntarily opted in and your email address is verified. You may withdraw at any time.
Under Swiss law, processing is also governed by the principles of lawfulness, proportionality, purpose limitation, transparency, and appropriate security.
5. Service providers and processing locations
- Infomaniak Network SA: hosting, databases, object storage, and email infrastructure. Processing and storage take place in Switzerland.
- Google LLC: social sign-in, basic profile information, and public maps that load automatically on relevant property and booking views. When a map loads, Google receives technical connection data, including your IP address, browser and device information, Frinbe's origin, and the requested hotel place, coordinates, or address. Google may associate the interaction with your Google account if you are signed in. Google's processing is described in its Privacy Policy. Relevant processing takes place in the EEA and the United States. Transfers are protected, as applicable, by the Swiss-U.S. Data Privacy Framework and approved standard contractual clauses.
- Microsoft Corporation: social sign-in, basic profile information, and institutional identity services. Relevant processing takes place in the EEA and the United States. Transfers are protected, as applicable, by the Swiss-U.S. Data Privacy Framework and approved standard contractual clauses.
Infomaniak processes the core infrastructure data for Frinbe under contractual and security obligations. Google and Microsoft also process information for their own sign-in, identity, and content delivery purposes under their terms and privacy notices. An organization or hotel may choose additional identity or reservation providers for its own operations; that organization or hotel is responsible for its selection and use of those providers.
6. Other recipients
We otherwise disclose data only as needed to:
- Frinbe personnel who need access to operate, secure, and support the service.
- The hotel or accommodation provider handling your request or stay, including authorized administrators of the hotel organization that owns the property.
- Your own organization and its authorized administrators, for your membership, affiliation, approvals, and property assignment. They do not receive your reservations and do not see where or when you stay.
- Your organization's identity provider, where the organization requires institutional login. The organization decides how its identity provider processes your data.
- A hotel's selected PMS, channel manager, or similar reservation provider when that integration is enabled.
- Professional advisers, authorities, or counterparties where legally required or necessary to establish, exercise, or defend claims.
7. International transfers
Core infrastructure is in Switzerland. As listed above, Google and Microsoft may process data in the EEA and the United States. Where a destination is not recognized as providing adequate protection, we rely as applicable on the Swiss-U.S. Data Privacy Framework, approved standard contractual clauses, or another safeguard permitted by law. You may request information about the safeguard used for a specific transfer at privacy@frinbe.com.
8. Retention
We keep personal data for as long as needed for the purpose it was collected for and as permitted by applicable law. How long that is depends on how long your account or service relationship lasts, what we must keep to meet legal obligations, and what we need to protect our legal position or the safety of people using Frinbe.
- Account, reservation, and related conversation data is retained for as long as your account exists, so that you can consult your own booking history, and afterward for as long as reasonably necessary.
- When an account is deleted, we delete or anonymize the associated data, except where we still need it to comply with legal, accounting, tax, reporting, or audit obligations, to establish, exercise, or defend legal claims within the applicable limitation periods, or to protect platform safety and prevent fraud or abuse.
- Residual copies may remain in our backup systems for a limited period after deletion.
- Accounting records and invoices are kept for the statutory period, currently ten years under Swiss law.
- Sales leads are no longer needed after 24 months and are then deleted.
- Unused invitations are retained until they are accepted, withdrawn, expire, or are otherwise no longer needed. Accepted invitation and membership evidence is retained for the relevant relationship and afterward only where needed for compliance, legal claims, fraud prevention, or security.
- Operational logs are no longer needed after 30 days, except where an active security investigation requires keeping them longer.
- Records of legal acknowledgements and consent are retained during the account relationship and afterward only for applicable limitation periods or compliance needs.
9. Cookies, maps, and diagnostics
Frinbe uses storage necessary for authentication, language, security, and interface preferences. Public Google Maps content loads automatically on relevant property and booking views. Google may use cookies or similar technologies under its Privacy Policy. You can block third-party Google content in your browser; the map will then be unavailable, but booking remains available. We use minimized error reporting to identify failures and do not use browser session identifiers or advertising trackers for this purpose.
10. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent without affecting earlier lawful processing. Contact privacy@frinbe.com, where possible from the email address associated with your data. You do not need a Frinbe account to make a request. We may take proportionate steps to verify your identity. Access requests are generally free of charge and are normally answered within 30 days, subject to lawful exceptions.
Where applicable, you may lodge a complaint with the competent data-protection supervisory authority.
Frinbe does not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
11. Age, security, and changes
Frinbe is intended for adults and for minors who use it with the consent of their parent or legal guardian. We do not collect dates of birth and therefore do not verify age. A parent or legal guardian who believes a minor has provided us with personal data can ask us to delete it at privacy@frinbe.com.
A reservation may include children travelling with an adult. In that case we collect only the number of children, not their names, ages, or other details about them, and the adult making the booking provides that number.
We use organizational and technical safeguards appropriate to the risk, but no internet service can guarantee absolute security. We may update this Policy as services or law change and will give appropriate notice of material changes. Future features are reviewed before they begin collecting new data or using data for a materially new purpose.