Interesting precedent. The platform is responsible not just for their own security practices, but also their users' security practices.
Interesting precedent. The platform is responsible not just for their own security practices, but also their users' security practices.
Well, not really. Booking didn't get fined over security practices. They got fined over not notifying of a breach of their users data within 72 hours.
So you're not really "responsible for users' security practices", you're "responsible for notifying users/authorities in time when you notice leaks/breaches". Seems rather different to me.
As someone booking a hotel on the site, I would expect booking.com to take responsibility for keeping my payment details secure (or, if they want to operate like a marketplace, make it clear that they're not taking responsibility, but in that case it looses a lot of value toe as an end user)
yeah I stopped using booking because of this. an hotel decided that the card used for reservation was the one to charge for my stay and charged it the day of arrival and I only discovered later when trying to reserve a rental car and I hit my card limit and couldn't.
that pissed me off in so many ways, first because the booking wasn't a upfront pay but hotel did it anyway, second because booking disclosed my cc details to a third party instead of being a neutral escrow, and third of course because it bite me in the ass at the worst possible moment, as my car broke down and I needed to cover a rental and repairs while sorting out the rest of the travel.
> The property will charge you: €xxx
> The date you'll be charged—and what happens if you cancel—depends on the booking conditions.
And then the booking conditions (set by the property):
> You'll be charged a prepayment of the total price at any time.
On top of that, anyone taking a large payment via CC will usually require payment on the same card used for the authorization hold. Accepting another card is risky as funds can be easily made unavailable before the transaction settles.
You just had wrong expectations - on cc charges, that booking would be a “neutral escrow” or be able/willing to help. I’ve been in a similar situation where they held the entire reservation amount, in the thousands, while having already taken payment, and it’s 100% up to the hotel. They just don’t give a shit.
This is yet another reason why CCs are a terrible idea. Having the funds in a checking account and not being able to use them because of credit limit shenanigans is infuriating.
again, you're over generalizing your personal experience. booking on arrival happened to me exactly once. but you're not listening and keep repeating points that don't really apply to the situation at hand.
Of course they don't always make this very clear to the consumer, and it seems to have gotten more muddled in the last few years. I think they're trying to nudge people more towards their own payment platform nowadays.
[1] https://www.businessinsider.in/this-is-why-booking-coms-agen...
That's why I've used Agoda every time I could (works well in Asia, spotty elsewhere), because they allow paypal payment. Hotel will still want your card for the deposit but you can just provide it on the first day.
This way you don't have to fight with a place that did overbooking or similar and still has your card on file.
If you as a consumer give your booking.com login information to someone and your information is subsequently stolen, Booking.com would not be responsible for your security practices.
Of course, as the leak would be traced to them as well. When it comes to GDPR you'd like to manage the expose and the liability associated with having the data. Normally it should that even the admin operators are not to be trusted with full account/payment/etc. details enmasse and very special care is taken to exports/reports.