Cookie Policy
RIGHT HOTELS SAS · Hotelminder (mindermod.org)
1. What is a cookie
Hotelminder uses cookies and comparable identifiers on mindermod.org and on the authenticated dashboard. A cookie is a small text file placed by a website on the terminal equipment (computer, tablet, mobile phone) of a visitor when that visitor accesses the site, and read back from that terminal on subsequent visits. The legal definition applicable in France is set out at Article 32-II of the Loi n° 2004-575 du 21 juin 2004 pour la confiance dans l’économie numérique (“LCEN”), which extends beyond strictly-defined HTTP cookies to any local or session storage mechanism enabling access to information already stored on a user’s terminal or the storage of new information there. This Policy therefore covers HTTP cookies in the narrow sense, HTML5 local storage, HTML5 session storage, IndexedDB entries, service-worker registrations, and comparable pixel-based, fingerprint-based or SDK-based identifiers, insofar as any of them are used on Hotelminder surfaces.
2. Consent regime
The applicable consent regime is set by Article 82 of the Loi Informatique et Libertés (transposing Article 5(3) of Directive 2002/58/EC as modified) and refined by the delibération n° 2020-091 of the CNIL of 17 September 2020 on cookies and other trackers, together with the CNIL guidance of the same date on the practical modalities of gathering consent. In short: strictly necessary cookies (Category 1 below) do not require consent because they are indispensable to delivering the online service explicitly requested by the visitor; every other category requires the visitor’s prior, freely given, specific, informed and unambiguous consent, expressed through an affirmative act, before the cookie is deposited or read. Refusing consent must be as simple as giving it. The visitor may withdraw consent at any time with the same ease, and neither refusal nor withdrawal shall block access to the marketing pages of mindermod.org.
3. Consent interface
The first time you land on mindermod.org, the consent banner opens with the following controls: “Accept all”, “Refuse all” and “Manage preferences”. All three buttons are visually equivalent and none is highlighted or defaulted to “on”. In the granular preferences drawer, each non-essential category is presented separately (Preferences, Analytics, Marketing) with a toggle whose initial state is “off”. The consent decision is stored in the strictly-necessary cookie hm_cx together with the timestamp of the decision, so that we can honour the decision on the next visit without asking again for thirteen (13) months, in line with CNIL recommendation. A discreet cookie shortcut is available at the bottom of every page under the footer link “Cookie preferences”, so that a visitor can reopen the drawer and change the decision at any time.
4. Categories in use
Hotelminder classifies cookies according to four categories that mirror the categories recognised by the CNIL and by the European Data Protection Board’s Guidelines 5/2020 on consent. Cookies in Category 1 are deposited without consent; cookies in Categories 2, 3 and 4 are only deposited after affirmative consent.
- Category 1 — Strictly necessary. These cookies are indispensable for the service explicitly requested by the visitor, for example session state, CSRF protection and load-balancing.
- Category 2 — Preferences. These cookies remember non-essential choices made by the visitor, such as the currency display, the light/dark theme and the collapsed state of the shortlist filters.
- Category 3 — Analytics. These cookies allow us to measure how visitors use mindermod.org in aggregate, so that we can improve the shortlist and the editorial guides.
- Category 4 — Marketing. These cookies allow us and our partners to measure attribution and to display advisory-oriented editorial content on carefully selected professional platforms. As of the date of this Policy, Hotelminder does not deploy any Category 4 cookies; the row is retained in the interface so that consent can be gathered before any future deployment.
5. Detailed cookie table
The following table enumerates every cookie deposited by mindermod.org or by an in-page third party on the visitor’s terminal.
| Cookie name | Purpose | Provider | Retention | Category |
|---|---|---|---|---|
hm_sid | Session identifier for authenticated users | Hotelminder (first-party) | Session | 1 · Strictly necessary |
hm_csrf | Cross-site request forgery protection token | Hotelminder (first-party) | Session | 1 · Strictly necessary |
hm_cx | Cookie consent decision and timestamp | Hotelminder (first-party) | 13 months | 1 · Strictly necessary |
hm_lb | Load-balancing affinity to a specific application node | OVHcloud edge (first-party context) | 6 hours | 1 · Strictly necessary |
__cf_bm | Bot management and abuse mitigation | Cloudflare | 30 minutes | 1 · Strictly necessary |
hm_pref_theme | Remembers the light or dark display preference | Hotelminder (first-party) | 12 months | 2 · Preferences |
hm_pref_ccy | Remembers the preferred currency for price display | Hotelminder (first-party) | 12 months | 2 · Preferences |
hm_pref_filters | Remembers the last shortlist filter state | Hotelminder (first-party) | 6 months | 2 · Preferences |
_pk_id, _pk_ses | Aggregate audience measurement, anonymised at ingestion | Self-hosted Matomo on OVHcloud Roubaix | 13 months / 30 minutes | 3 · Analytics |
__stripe_mid, __stripe_sid | Fraud prevention on the checkout page | Stripe Payments Europe Ltd. | 12 months / 30 minutes | 1 · Strictly necessary on /checkout only |
pm_tx | Delivery tracking pixel for transactional emails (opt-out available) | Postmark (ActiveCampaign LLC) | Session-scoped pixel | 3 · Analytics |
6. Third-party cookies
Hotelminder minimises third-party cookies. Where a third-party cookie is unavoidable — for instance the Cloudflare bot management cookie on the edge, or the Stripe fraud prevention cookies on the checkout page — the cookie is disclosed in the table above, and the third party in question acts either as a strict processor of Hotelminder for the operation concerned or as an independent controller for its own security duties. In no case is a third-party cookie used to build cross-site advertising profiles about the visitor. The Postmark tracking pixel embedded in our transactional emails can be disabled by any recipient at any time by clicking on the “disable open tracking for future messages” link included at the foot of every email we send.
7. How to withdraw consent
You can withdraw a previously given consent at any time and free of charge, either through (i) the footer link “Cookie preferences” which reopens the granular preferences drawer, (ii) the shortcut inside your account settings if you are a subscribed hotelier, or (iii) the browser-native controls listed in the next paragraph. Withdrawal takes effect immediately for new page loads; already-persisted analytics data is retained for the duration set at Section 4 or purged on request under Section 10.
8. Browser controls
Every modern browser lets you configure whether cookies are accepted, refused, deleted on close, or purged manually. The relevant documentation is:
- Google Chrome — Settings → Privacy and security → Cookies and other site data.
- Mozilla Firefox — Preferences → Privacy & Security → Cookies and Site Data.
- Apple Safari (macOS & iOS) — Preferences → Privacy → Manage Website Data.
- Microsoft Edge — Settings → Cookies and site permissions → Manage and delete cookies and site data.
- Brave — Settings → Shields → Cookies.
- Opera — Settings → Advanced → Privacy & security → Site Settings → Cookies and site data.
Blocking strictly necessary cookies at the browser level prevents authentication, checkout and other essential features from operating; you may then experience errors on some pages.
9. Do-Not-Track and Global Privacy Control
Hotelminder honours the Global Privacy Control (GPC) signal as an unambiguous request to refuse all non-essential cookies, in line with the CNIL 2024 clarifications on browser-transmitted preferences. Where a GPC signal is detected on the first request, the consent banner is not displayed and the consent decision is stored as “refuse all” for thirteen (13) months or until the visitor explicitly changes it through our interface. The historical Do-Not-Track header is also read; because its meaning is no longer consistently interpreted across browsers, we treat it as a strong hint but continue to display the banner so that the visitor can confirm.
10. Analytics retention
Analytics data collected under Category 3 is retained for a maximum of thirteen (13) months in accordance with the CNIL recommendation on measurement cookies. At the end of that period, event-level data is either fully deleted or aggregated in a way that is definitively non-identifying (removal of IP, of user-agent details beyond browser family, of country beyond first-order region, and of any correlation identifier). Aggregated statistics may be retained beyond thirteen months for product benchmarking.
11. Sub-processors involved
The following sub-processors are involved in cookie-adjacent operations: Cloudflare (edge routing, bot management), OVHcloud Roubaix (self-hosted analytics), Stripe (checkout page fraud prevention), Postmark (transactional email delivery). Each is bound by an Article 28 RGPD contract and is disclosed in more detail at /legal/dpa. Additions to this list follow the fifteen (15) day objection window described in the DPA.
12. Legal basis and record of consent
Strictly-necessary cookies are placed on the basis of a legitimate interest under Article 82(2) of the Loi Informatique et Libertés, i.e. to allow or facilitate an electronic communication or to provide the online service explicitly requested. Non-essential cookies rely on consent under Article 6(1)(a) RGPD combined with Article 82(1) of the Loi Informatique et Libertés. The record of consent (positive, refusal, or granular selection) is kept in the hm_cx cookie and mirrored server-side for audit; this record is deleted on request from the visitor addressed to privacy@mindermod.org.
13. Aggregate telemetry not based on cookies
Hotelminder’s own web server logs an HTTP access line for every request. That access line contains the URL, the timestamp, the IP address (truncated after six months to /24 for IPv4 and /48 for IPv6), the user-agent, the response code and the byte size of the response. Those logs are not cookies and are not read from your device; they are captured server-side for security and troubleshooting under the legitimate interest legal basis, and are retained for six (6) months.
14. Changes to this Policy
We may amend this Cookie Policy from time to time to reflect changes in the applicable law, in CNIL guidance, in the technical composition of the site, or in the list of sub-processors. When we deploy a new non-essential cookie or expand the purpose of an existing one, the consent is reset and the banner is re-displayed so that the visitor is asked to confirm the new configuration. Editorial changes that do not affect the substance of the cookies in use are pushed silently; the updated date at the top of the page always reflects the most recent revision.
15. Complaint and remedies
You may lodge a complaint about our use of cookies with the CNIL, 3 Place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07, at cnil.fr. You may also exercise the right of access, rectification, erasure, restriction and objection under Articles 15 to 21 RGPD as explained in the Privacy Policy at /legal/privacy.
16. Contact
Questions about this Cookie Policy: privacy@mindermod.org. Data Protection Officer: Camille Dubois-Renard, dpo@mindermod.org. Registered office: RIGHT HOTELS SAS, 7 Allée Jacques Cartier, 93160 Noisy-Le-Grand, France. Regulator: CNIL, cnil.fr — déclaration n° 2224789. Hosting: OVHcloud Roubaix, France.