Privacy Policy
Last updated: [DATE]
1. Introduction
Book Local ("we," "our," or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, process, and protect your information when you use our accommodation booking platform.
2. Data Controller Information
3. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent: For marketing communications and analytics
- Contract: To provide our booking services
- Legal Obligation: To comply with tax and legal requirements
- Legitimate Interest: To improve our services and prevent fraud
4. Information We Collect
4.1 Personal Information You Provide
- Name and contact details (email, phone, address)
- Booking information (dates, preferences, special requirements)
- Payment information (processed securely by third-party providers)
- Communication history and support requests
- Property information (for accommodation providers)
4.2 Automatically Collected Information
- IP address and location data
- Browser type and device information
- Website usage and navigation patterns
- Cookies and similar tracking technologies
5. How We Use Your Information
We use your personal data for the following purposes:
- Processing and managing your bookings
- Communicating with you about your reservations
- Providing customer support
- Improving our services and website functionality
- Sending marketing communications (with your consent)
- Preventing fraud and ensuring security
- Complying with legal obligations
6. Data Sharing and Third Parties
We may share your information with:
- Property Owners: To facilitate your booking
- Service Providers:
- Email service providers (Mailgun)
- Analytics providers (Google Analytics)
- Payment processors
- Property management systems (Beds24)
- Legal Authorities: When required by law
7. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). We ensure appropriate safeguards are in place through:
- Standard Contractual Clauses
- Adequacy decisions by the European Commission
- Certification schemes and codes of conduct
8. Data Retention
We retain your personal data only for as long as necessary:
- Booking data: 7 years (for tax and legal compliance)
- Marketing data: Until you withdraw consent
- Website analytics: 26 months (Google Analytics retention)
- Support communications: 3 years
9. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data
- Portability: Receive your data in a structured format
- Restriction: Limit how we process your data
- Objection: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent at any time
Exercising Your Rights
To exercise any of these rights, please:
10. Cookie Policy
We use cookies to:
- Essential cookies: Enable basic website functionality
- Analytics cookies: Understand how visitors use our site
- Marketing cookies: Deliver relevant advertisements
You can manage your cookie preferences through our cookie consent banner or your browser settings.
11. Security Measures
We implement appropriate technical and organizational measures to protect your data:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication
- Staff training on data protection
12. Children's Privacy
Our services are not directed to children under 16. We do not knowingly collect personal information from children under 16.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by:
- Posting the updated policy on our website
- Sending you an email notification
- Displaying a prominent notice on our site
14. Contact Information
For any questions about this Privacy Policy or our data practices, please contact:
15. Supervisory Authority
You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with data protection laws. In the Faroe Islands, you can contact:
This Privacy Policy is effective as of [DATE] and was last updated on [DATE].