Skip to content

Heram Al Noor

Privacy Policy

Last updated Aug 24, 2026

This policy describes what Heram Al Noor ("we") collects on this website, why, and what happens to it. The website is operated in Texas, United States, by Heram Al Noor and its owner/operators. It uses service providers for hosting, security, and transactional communications.

1. What we collect, and when

The inquiry form. When you send an inquiry we collect exactly the fields on the form: your name, email address, optional phone number, optional party size, optional preferred arrival and departure dates and a flexible-dates flag, the type of gathering you are interested in, your message, and, if you arrived from a listing page, which page and listing that was, along with any marketing campaign tags (UTM parameters) present in the address you used.

The booking request form. When you request dates we collect your name, email address, optional phone number, the dates and the stay or rooms you chose, how many adults, children, and infants are coming and how many pets, any message you add, and the fact that you accepted the booking agreement, with the date and the wording that was in force at the time. We take no payment and collect no card details.

Your IP address, protected. We never store your raw IP address. When our abuse-correlation key is configured (a dedicated secret separate from every other key in the system), the IP is stored only as a one-way keyed correlation value (an HMAC) that is designed not to be usable to reconstruct your IP address; it serves only to correlate abusive submissions and to rate-limit the form, and rotating the key intentionally breaks correlation with older submissions. When that key is not configured, no IP-derived value is stored at all. In no configuration is a raw or reversible IP stored.

Spam defense. The form carries a hidden honeypot field, a minimum time-on-form check, and a Cloudflare Turnstile challenge. Turnstile is provided by Cloudflare and processes the challenge under Cloudflare's own terms; it is the only third-party service loaded on our pages. Cloudflare's privacy practices are described at https://www.cloudflare.com/privacypolicy/.

Duplicate-submit protection. For up to 30 minutes after you submit, a bounded copy of the confirmation response is retained so an accidental double-click cannot create two inquiries.

What we do not collect. No account can be created by visitors; there are no public logins in this version of the site. We take no payments and hold no payment card data. We run no analytics, advertising, or social-media trackers.

2. Cookies and local storage

  • A session cookie and a CSRF security token cookie, which Laravel requires for the site and its forms to function (essential; session lifetime 120 minutes; marked secure in production).
  • Your light/dark theme choice, stored only in your browser's local storage under the key haln-theme; it never leaves your device.
  • Cloudflare Turnstile may set its own cookies on the inquiry page as part of abuse prevention.

There are no advertising, analytics, or cross-site tracking cookies. Because we do not sell personal data or use targeted advertising, no opt-out controls for those practices are needed.

3. Email we send

  • A notification of your inquiry to the property owner, sent through our transactional mail provider selected for production. If the provider is unavailable, the notification is written to our private server logs instead so the inquiry is not lost; that fallback is recorded and alarmed.
  • A confirmation to the address you gave.
  • Our provider reports delivery and bounce events back to us through a signed webhook; we record those events (delivery status, bounce reason) against your inquiry so we know whether the owner actually received it.

We do not send marketing email and we do not share your address with anyone for their own independent marketing use.

4. Staff access and internal records

  • Inquiries are visible to a small set of authenticated staff accounts protected by mandatory two-factor authentication; role-based permissions limit who can view or manage them.
  • Staff can export inquiries, rates, events, and reservations as CSV files for operations; every export is recorded in an audit log (who exported what, when).
  • Reservations are created by staff from your correspondence, or from a booking request you send on this site; the site takes booking requests but no payments.
  • A read-only availability calendar can be shared with the owner's calendar apps through a private tokenized link; the calendar contains occupancy windows only, never guest names or contact details, and links can be revoked at any time.

5. Media

Photographs on this site are uploaded only by staff. If you appear in a photograph from a gathering and want it removed, contact us at the address below and we will review promptly. Uploaded images are re-encoded and served publicly as page images.

6. Retention and deletion

  • Inquiries marked as spam are permanently deleted after 30 days.
  • Closed inquiries are permanently deleted after 24 months.
  • Both windows are enforced automatically by a scheduled purge task, and both are owner-configurable; the periods stated here are the current documented defaults. Server logs and database or media backups may retain copies for a limited additional period under operational and legal-retention practices.

Your requests. You may ask us to access, correct, or delete the personal data in your inquiry by contacting us at the address below. We will verify the request against the email address on the inquiry and respond within the time required by applicable law.

7. Processors and transfers

We share personal data only with service providers that operate the site on our behalf:

  • Hosting and infrastructure providers that operate the site.
  • The transactional email provider selected for production.
  • Cloudflare Turnstile for abuse prevention when enabled.

Data is processed in the United States. We do not sell personal data, we do not share it for targeted advertising, and we have no data-broker relationships.

8. Security, honestly stated

Staff logins require two-factor authentication; raw inquirer IP addresses are never stored, and at most a one-way keyed correlation code is kept for abuse prevention (see Section 1); secrets are kept out of code and logs by policy; exports are audited; and the site sends security headers including a restrictive content security policy. No security is perfect: if we learn of a breach affecting your personal data we will notify affected people and authorities as required by applicable law, including Texas breach-notification requirements.

9. Children

This website is a general-audience site for adults planning stays and gatherings. It is not directed to children under 13 and we do not knowingly collect personal information from children under 13 (COPPA). If you believe a child has submitted the form, contact us and we will delete the submission.

10. Your Texas and U.S. privacy rights

Texas residents have rights under the Texas Data Privacy and Security Act (TDPSA), including the rights to know whether personal data is being processed, to access it, to correct it, to delete it, and to opt out of its sale or use in targeted advertising. We do not sell personal data or use targeted advertising. To exercise any right, contact us at the address below; if we decline a request you may appeal by replying to our decision, and Texas residents may also contact the Texas Attorney General.

Residents of other states may contact us with the same types of requests, and we will handle them under applicable law and our documented practices.

11. Changes

We may update this policy as the site, our providers, or the law change. The date at the top of this page reflects the latest revision, and material changes will be posted here rather than communicated silently. Please review this page from time to time; continued use of the site after a change takes effect means the updated policy applies.

12. Contact

Reach us using the email address or phone number shown in the site footer. For requests about your personal data, write from the email address you used on your inquiry so we can verify the request, and tell us whether you want access, correction, or deletion. We respond within the time required by applicable law, and Section 10 describes your options if you disagree with our decision.