Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Elloha is a French booking and online sales platform for hotels, guesthouses, campsites, activities and restaurants, offering a booking engine, channel manager and payment. When its booking widget is embedded, it sets cookies for session handling, cart and conversion attribution and processes guest booking data within the European Union. Under the GDPR and the ePrivacy Directive, its non essential cookies require prior consent.
Elloha is a software as a service platform, based in France, that helps tourism and hospitality businesses sell online. It provides a booking engine, a channel manager that distributes availability to marketplaces, online payment and a website builder. Hotels, guesthouses, campsites, activity providers and restaurants embed its booking widget to take reservations directly.
When the Elloha booking widget loads it sets cookies for session handling, to keep a booking cart and to attribute conversions. To process a reservation it handles guest data such as name, contact details, stay dates and payment information. Some cookies are persistent identifiers used for analytics and attribution of the booking.
The analytics and attribution cookies are not strictly necessary, so storing them is governed by Article 5(3) of the ePrivacy Directive and requires consent, while a cookie strictly needed to hold a booking in progress may be exempt. The guest booking data is personal data under the GDPR, processed for the reservation contract.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Block the Elloha non essential cookies until the guest accepts them through a Consent Management Platform, while a cookie strictly necessary to complete a reservation the guest started may load. Log consent, make refusal as easy as acceptance, and avoid setting analytics identifiers before opt in.
Elloha is a French company and processes booking data within the European Union, so a standard configuration does not involve a transfer to a third country. If you enable payment or analytics partners that process data outside the EEA, apply the appropriate Chapter V safeguards and document them.
List the Elloha cookies and domains in your cookie policy and gate the non essential ones behind consent. Sign a data processing agreement, define retention for booking data, and confirm that the configuration keeps data in the EU. Inform guests about the booking process and review the integration when Elloha updates its widget.
Websites using Elloha must obtain user consent under GDPR regulations.
DPIA considerations
Elloha sets cookies and processes guest data such as name, contact details, stay dates and payment information. Key DPIA considerations: (1) analytics and attribution cookies are not strictly necessary identifiers requiring consent; (2) a cookie strictly needed for a booking in progress may be exempt; (3) booking data is processed in the EU, which lowers transfer risk; (4) appropriate retention must be set. A full DPIA is generally not required for a standard booking engine.
Sample consent text
We use Elloha to manage our online bookings. The Elloha widget sets cookies, processes your booking and payment data and keeps the data within the European Union. You can withdraw your consent to non essential cookies at any time through our cookie settings.
Third-party domains contacted
elloha.combooking.elloha.comcdn.elloha.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| elloha_session | Functional | Session | Maintains the booking session and keeps the reservation cart during a visit. |
| _elloha_attr | Analytics / Attribution | 1 year | Persistent identifier used to measure traffic and attribute completed bookings. |
Elloha uses cookies for user preferences — inform visitors with a consent banner.
Elloha sets cookies for session handling, to keep a booking cart and to attribute conversions. A cookie strictly needed to hold a booking in progress may be essential, but the analytics and attribution cookies are not strictly necessary and require consent.
Yes for the non essential cookies. The analytics and attribution cookies Elloha sets need prior consent under the GDPR and the ePrivacy Directive, so they should not load until the guest accepts. A cookie strictly necessary to complete a reservation can rely on a different basis.
Consent under Article 6(1)(a) GDPR covers the analytics and attribution cookies, while processing the reservation the guest requested relies on contract under Article 6(1)(b). Booking data should be kept only as long as needed for the stay, accounting and legal obligations.
In a standard configuration, Elloha processes data within the European Union and does not transfer it to a third country. If you connect payment or analytics partners that process data outside the EEA, those transfers must rely on Standard Contractual Clauses or another Chapter V safeguard.
A DPIA is usually not mandatory for a standard booking engine, but it is advisable if you handle large volumes of guest data or special categories. Documenting the booking processing, the cookies, the retention and the EU data location supports accountability.
Add Elloha through a CMP that blocks non essential cookies until consent, keep any essential booking cookie separate, and confirm the configuration keeps data in the EU. Sign a data processing agreement, set retention for booking data, and disclose cookies and recipients.
Other booking and channel management platforms include Cloudbeds, Mews, SiteMinder and Amenitiz, some of which are also EU based. All set booking and analytics cookies and process guest data, so consent gating and clear retention remain the priority, with EU hosting an advantage for transfer compliance.
Describe the Elloha cookies, their purpose and duration, list the Elloha domains, and confirm that booking data is processed in the European Union. Explain the reservation process and retention in your privacy notice and keep both aligned with the integration.