Privacy policy
This is a translation for your convenience. The German version is legally binding.
This website is deliberately simple. It sets no cookies, uses no advertising services and no third-party analytics and embeds no third-party content — no map, no video, no social media button, no contact form. Fonts, images and floor plans are stored on the same server as the website. We count how many visitors come and which pages they read with our own cookie-free statistics, also on our own server (section 3.9). That is why you do not see a consent banner here: there is nothing to consent to.
Even so, this policy tells you exactly what data arises when you visit the website, make an enquiry, book and stay with us — and what happens to it.
1. Controller
We are the controller within the meaning of the General Data Protection Regulation (GDPR). A business of our size is not required to appoint a data protection officer; please send all questions to the address above.
2. Principles and legal bases
We collect only what we need and keep it only as long as we need it or are required to keep it. Nothing is sold, and nothing is passed on for third-party advertising.
We rely on four legal bases, and each item in section 3 states which one applies: contract (Art 6(1)(b) GDPR) — everything needed to turn your enquiry into a booking and your booking into a stay. Legal obligation (point (c)) — what we must collect and keep by law, such as the guest register and invoices. Legitimate interest (point (f)) — the secure operation of the website and its visitor statistics. Consent (point (a)) — not needed anywhere at present; should it ever be, we would ask you beforehand.
3. What data we process
3.1 Visiting this website
When a page is requested, the server records access data in log files: IP address, date and time, the file requested, the amount of data transferred, and browser and operating system. Without this information the server cannot send you the page. The legal basis is our legitimate interest in secure operation (point (f)). We do not analyse these logs and do not combine them with other data; the visitor statistics are produced separately (3.9).
3.2 Enquiries by email or phone
The contact buttons on this website open your own email program or your phone — there is no form that sends anything to us. Whatever you then write to us or tell us on the phone, we process in order to answer your enquiry and make you an offer (point (b)). This includes your name, your contact details, the period you are interested in and anything else you tell us.
3.3 Booking
The “Book” button and the search on the home page take you to our own booking page book.arlberg-mountain-resort.com; as soon as you open the calendar of the search, your browser asks that page for the available dates (dates and number of guests, on our own server). It is part of our administration software (3.10); what you enter there — name, address, contact details, dates, number of guests — we process in order to complete your booking (point (b)).
If you pay there by card, you enter your card details directly with our payment service provider Stripe (Stripe Payments Europe Ltd., Dublin, Ireland); its privacy policy applies to that data. We neither see nor store your full card number.
If you have written to us, the route may be a different one: we then send you a personal offer as a link to our own administration software (3.10). There you read the offer and confirm the booking. The link is valid for your offer only; the data processed is the same as for any booking — name, address, period, number of guests.
3.4 Your stay
For the accommodation contract we need your name, address, contact details, travel period and the number of guests (point (b)). In addition, there is information we are obliged to collect whether we want to or not (point (c)): the guest register under the Austrian Registration Act, which every accommodation in Austria keeps, and the report of the visitor tax to the municipality.
Before you arrive, we send you a message with a link that lets you enter your registration details from home. That link leads to our registration service provider feratel media technologies AG, where the electronic guest register is kept. If you would rather not, you register with us on arrival — there is no disadvantage in that.
Anything else you tell us — an intolerance, a baby cot, a late arrival, an order for bread rolls — we note only in order to arrange your stay accordingly, and no longer than necessary.
3.5 Invoices and payments
Invoices contain your name, your address, the service and the amount; tax law requires both the invoice and its retention (point (c)). If you pay by card, the card data is processed by the payment terminal of our payment service provider — we neither see nor store your full card number. If you pay by bank transfer, your bank details are recorded in our accounts.
3.6 Video surveillance in the publicly accessible areas
Cameras are in use in the publicly accessible areas of the house. They protect guests and property against theft, damage and unauthorised entry; this is our legitimate interest (point (f)). There is no recording in the apartments, in the SPA areas or anywhere else where you are on your own — and only images are recorded, no sound.
The recordings overwrite themselves and are deleted after seven days at the latest. They are only viewed if there is a reason — damage, a break-in — and passed on only to the police, a court or an insurer, as far as that reason requires. Only the management has access to the recordings. A notice at the front door points out the surveillance before you enter the house.
3.7 The Wi-Fi in the house
You do not need to log in to the Wi-Fi with your name or email address — you receive the password at check-in, nothing more. We keep no list of who was connected when and with which device, and we do not see which websites you visit.
3.8 The access cards
The locking system records which card opened which door and when. We do not note which card we issued to which guest — so there is no name in this record. In an emergency, an individual entry could nevertheless be linked to an apartment, and thus to a stay, via the booking; we therefore treat these records like the rest of your data.
They are only viewed if there is a reason — a lost card, damage, a door that was left open. We do not analyse them to see when someone comes and goes. We do not keep a separate archive of them; whatever the device stores, it overwrites itself.
3.9 Visitor statistics
To see which pages are read and how many visitors find their way to a booking, we count page views with the software Umami. It runs on our own server; nothing is transferred to a third-party company. Umami sets no cookies and stores nothing in your browser.
It records the page viewed and its title, the page you came from, the time, browser, operating system, device type, screen size, language and the country derived from the IP address. The IP address itself is not stored. A click on “Book” is counted as a separate event, together with the page it was clicked on.
So that several page views count as one visit, the software forms an identifier from the IP address, browser information and a secret value that changes every day. You are not recognised across days, and we do not attribute the figures to any person. We only evaluate them in aggregate. The legal basis is our legitimate interest in designing the website according to our guests’ needs (point (f)); you may object at any time (section 9).
3.10 Our administration software
Bookings, offers, invoices and our correspondence with you are kept in our own software at amr.elpaservices.com — on the same server of ours as this website (section 6). The data does not leave the European Union, and we do not pass it to any outside provider for analysis.
Only those who work with it in the house have access, each with their own user account. The software records who changed what and when — so that mistakes remain traceable, not to watch anyone. Messages we send you go out through our own mailbox and stay in the outbox for as long as we need them for the matter at hand; no third-party dispatch service is involved.
4. Cookies and local storage
This website sets no cookies and stores nothing in your browser — neither for its operation nor for the season you can switch between on the home page. That is why there is no consent banner. When you pay by card on our booking page, Stripe (3.3) may set its own cookies; what is set there is described in its policy.
5. Fonts, images and third-party content
All fonts, photos and floor plans are stored on the same server as the website. Nothing is loaded from Google Fonts, an image service or a content delivery network, and no map, no video and no tracking pixel of a third-party provider is embedded. So no outside company learns that you are viewing this website.
In some places we link to third-party websites, for example ski schools, mountain railways or the bus timetable. These are ordinary links: nothing is loaded and nothing is transmitted unless you click on them. The operators of those websites are responsible for their content and data protection.
6. Hosting
The website runs on our own server, which we rent from STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany; our visitor statistics (3.9) and our booking software also run there. The host provides the data centre and the hardware and in doing so processes data solely on our behalf and according to our instructions — it is a processor within the meaning of Art 28 GDPR. The servers are located in Germany; your data is neither transferred to nor processed in any country outside the European Union.
7. Disclosure of data
Your data is only given to those who need it: our tax advisers for the accounts, our bank and our payment service provider for payment, the registration service from 3.4 for registration, the municipality for the visitor tax and authorities where we are legally obliged to. No one else. Nothing is passed on for advertising, and nothing is sold.
Not to the cleaners either: the schedule our cleaning company receives lists the apartment, the date and the hours — no guest name.
8. Retention period
Server log files: 14 days, then they are deleted. Visitor statistics: aggregated figures without any personal reference, for as long as we need them to compare over the years. Enquiries that do not lead to a booking: for as long as the conversation lasts, after which we delete them. Camera recordings: seven days. Invoices and accounts: seven years, as required by tax law. Guest register entries: seven years, as required by the Registration Act. After that, the data is deleted.
9. Your rights
You have the right to access the data we hold about you, to rectification if something is wrong, to erasure, to restriction of processing, to data portability and to object to processing based on our legitimate interest. An informal email or letter to the address in section 1 is sufficient; we will reply within one month.
If you believe that we are not processing your data lawfully, you can lodge a complaint with the Austrian Data Protection Authority: Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
10. Data security
This website is delivered encrypted (HTTPS) — nobody can read what passes between your device and the server on the way. We keep your documents in the house locked away, our computers are password-protected, and only those who need access to guest data for their work have it.
11. No automated decision-making
There is no procedure that makes decisions about you without a human being involved — neither for the booking nor for the price. We do not create profiles.
12. Changes to this policy
Should this website later embed further services — a map, a video, a contact form — we will change this policy beforehand, not afterwards. The version published here is authoritative.
Contact
Arlberg Mountain Resort
Pettneu am Arlberg 222b, A-6574 Pettneu am Arlberg, Austria
Phone: +49 172 7205618
Email: info@arlberg-mountain-resort.com
As of: 9 October 2026