Privacy notice
Last updated 11 September 2026
Draft for review. Two things must be settled before this is published: whether an EU representative is required under Article 27 GDPR, and the cookies section, which has to be written from what the site actually loads rather than from what it loads today.
Who is responsible for your data
[COMPANY NAME], [REGISTERED ADDRESS], decides how and why your personal data is used on this site. Write to us at [CONTACT EMAIL].
[IF THE COMPANY IS ESTABLISHED OUTSIDE THE EUROPEAN UNION AND SELLS TO PEOPLE IN IT, ARTICLE 27 GDPR REQUIRES A REPRESENTATIVE INSIDE THE UNION, NAMED AND ADDRESSED HERE. A SEPARATE UK REPRESENTATIVE IS NEEDED FOR UK GUESTS.]
What we collect
| Your booking request | Which property, your dates, how many people are coming. Used to check availability and price the stay. |
|---|---|
| Contact details | Name, email, telephone. Used to confirm the booking, send payment details, and reach you before and during the stay. |
| Guest names | Where the owner or French law requires a guest list, the names of your party. Passed to the owner, not to anyone else. |
| Payment records | Amount, currency, date and the transfer reference. Not your bank credentials, which we never see. |
| Correspondence | What you write to us and what we write back, kept so that a question asked in March can still be answered in August. |
| If you own a property | What you send through the owners form: the property, where it is, its size, your name and contact details. Used to answer you and, if we go ahead, to run the listing. |
| Technical data | Ordinary server logs, kept briefly for security. [LIST ANY ANALYTICS OR ADVERTISING TOOLS YOU ACTUALLY INSTALL.] |
We do not ask for health data or any other special category of personal data. If a guest has a mobility need that affects which rooms work for them, tell us only what we need to answer the question.
Why we are allowed to use it
- To perform our contract with you, and to take steps before it: answering your request, confirming the property, taking payment, running the stay.
- Because the law requires it: accounting and tax records, tourist tax declarations, and any guest register the property must keep.
- Our legitimate interests: keeping the site secure, preventing fraud, and defending a claim. We use the least data that works.
- Your consent, only where we ask for it plainly — non-essential cookies, or emails about properties we have taken on. You can withdraw it whenever you like.
Who else sees it
- The owner of the property you book. They receive your name, dates, party size and telephone number, because they are the ones meeting you at the door.
- Our bank and payment providers.
- Our hosting and email providers, which act only on our instructions.
- Authorities, where the law requires it.
- Our advisers, if a dispute makes it necessary.
We do not sell your data and we do not pass it to anyone for their own marketing.
Data leaving Europe
[COMPLETE ACCORDING TO WHERE THE COMPANY AND ITS SUPPLIERS ARE ESTABLISHED. IF DATA FROM THE EEA OR THE UK IS PROCESSED IN THE UNITED STATES, NAME THE MECHANISM RELIED ON — STANDARD CONTRACTUAL CLAUSES, OR CERTIFICATION UNDER THE EU–US DATA PRIVACY FRAMEWORK — AND OFFER A COPY OF THE SAFEGUARDS ON REQUEST.]
How long we keep it
| Requests that did not become bookings | [12] months. |
|---|---|
| Completed stays | As long as tax and accounting law requires, and while a claim remains possible. |
| Security deposit records | [24] months after departure. |
| Server logs | [90] days. |
Your rights
If the GDPR or the UK GDPR applies to you, you can ask for a copy of your data, have it corrected or deleted, restrict or object to how we use it, or have it sent to another provider. Where we rely on consent, you can withdraw it.
Write to [CONTACT EMAIL]. We reply within one month, free of charge.
You can also complain to the data protection authority of your country — the CNIL in France, the ICO in the United Kingdom.
If you live in California, you have comparable rights of access, deletion and correction, and the right not to be treated differently for using them. We do not sell or share personal information as California law defines those words.
Cookies
[REWRITE THIS FROM WHAT THE SITE ACTUALLY LOADS, BEFORE PUBLISHING.]
As it stands the site sets no cookies of its own. It loads a typeface from Google Fonts and, on opening, asks an external service for reference exchange rates; both receive your IP address, as any web request does. Adding analytics or advertising tags means a consent banner for visitors in the European Union, and those tags must then be listed here with what they do and how long they last.
Security
The site is served over an encrypted connection and access to booking records is limited to the people who need it.
We never ask for card or bank details by email. Payment instructions come only from the address on your confirmation. If you receive bank details that differ from those, telephone us before sending anything — this is the most common fraud in this trade.
Changes
We may update this notice. The date at the top says when it last changed, and earlier versions are available on request.