Summary: We collect only the minimum personal data necessary to process your booking. We run no advertising, no third-party analytics, and no tracking cookies. Your data is stored in the EU and is never sold.
The data controller responsible for your personal data is:
Contact email: available via reply to any booking email from this system.
This Privacy Policy is provided in compliance with the EU General Data Protection Regulation (GDPR) (Regulation 2016/679) and the Danish Data Protection Act (Databeskyttelsesloven).
| Data | Why we collect it | Source |
|---|---|---|
| Full name | To identify you as the booking guest and address communications to you | You provide it in the reservation form |
| Email address | To send your reservation reference, approval or rejection, payment link, and booking confirmation | You provide it in the reservation form |
| Check-in & check-out dates | To process and record your booking | You select them on the booking form |
| Number of guests | To confirm occupancy does not exceed the property limit | You select it on the booking form |
| Guest message (optional) | To understand any special requirements or context for your stay | Optionally provided by you |
| Nostr public key (npub) (optional) | To verify your identity as a confirmed guest for review purposes and to send encrypted Nostr notifications if you choose | Optionally provided by you |
| Bitcoin payment confirmation | To confirm payment has been received and record it for accounting purposes | Verified by us via the blockchain |
| IP address (temporary) | Security — rate limiting to prevent automated abuse of the booking system. Not logged long-term. | Automatically collected by the server |
| Review content (optional) | To display guest reviews on the site, subject to your consent | Optionally submitted by you |
We do not collect payment card details, passport numbers, national identification numbers, financial account details, or any special category personal data under GDPR Article 9.
We rely on the following lawful bases under GDPR Article 6:
| Data | Retention period | Reason |
|---|---|---|
| Booking records (name, email, dates, amount) | 5 years from check-out date | Danish bookkeeping law (Bogføringsloven) requires financial records to be kept for 5 years |
| Guest message | 1 year after check-out | In case of any post-stay dispute |
| Nostr public key | Duration of the booking record, or until you request deletion | Review verification |
| Published reviews | Until you request removal or we remove them | Guest information service |
| IP addresses (security logs) | 30 days maximum | Short-term security monitoring only |
We do not sell, rent, or trade your personal data. We share it only in the following limited circumstances:
Hostinger International Ltd. (EU/Lithuania) — our web and database hosting provider. Your data is stored on Hostinger's EU servers. Hostinger acts as a data processor under a data processing agreement. See Hostinger's privacy policy at hostinger.com/privacy-policy.
Property images may be served via Cloudinary Inc. (USA, covered by Standard Contractual Clauses). Cloudinary does not receive your personal data — it only serves image files to your browser.
If you are also booking through Airbnb (or if we synchronise our calendar with Airbnb), date availability information (not your personal details) is shared via iCal calendar feeds. No personal data about direct booking guests is transmitted to Airbnb.
If you are also booking through Booking.com (or if we synchronise our calendar with Booking.com), date availability information (not your personal details) is shared via iCal calendar feeds. No personal data about direct booking guests is transmitted to Booking.com.
We may disclose your data to competent authorities if required to do so by Danish law, a court order, or any applicable regulation.
We do not use Google Analytics, Meta Pixel, or any other third-party analytics or advertising tools. No advertising networks receive any data from this Site.
If you pay using a Lightning Network address, Lightning payments are generally more private than on-chain transactions and are not stored on the public Bitcoin blockchain.
Nostr is a decentralised, open social protocol. If you optionally connect your Nostr identity or submit a review via Nostr:
Providing your Nostr identity is entirely optional. You can use the Site and make bookings without it.
This Site does not use advertising cookies, tracking pixels, or third-party analytics cookies.
The Site uses sessionStorage (a browser storage mechanism) to maintain your admin login session within a single browser tab. This data is:
External services loaded by this Site (Google Fonts, Leaflet maps, CDN-hosted scripts) may set their own cookies or log your IP address in accordance with their own privacy policies. We use these services to deliver the Site's core functionality.
We do not display a cookie consent banner because we do not use tracking or advertising cookies that would require consent under ePrivacy rules. If you believe this assessment is incorrect, please contact us.
As a data subject under GDPR, you have the following rights. To exercise any of them, contact us by replying to any booking email.
Request a copy of all personal data we hold about you.
Ask us to correct inaccurate personal data.
Request deletion of your data, subject to our legal retention obligations (e.g. accounting records).
Ask us to restrict processing of your data in certain circumstances.
Receive your data in a structured, machine-readable format.
Object to processing based on legitimate interests.
Where processing is based on consent (e.g. Nostr key, reviews), withdraw it at any time.
Lodge a complaint with the Danish Data Protection Authority (Datatilsynet).
We will respond to your request within 30 days as required by GDPR. We will not charge a fee for reasonable requests.
Datatilsynet (Danish Data Protection Authority): datatilsynet.dk · Tel: +45 33 19 32 00
This Site is not directed at children under 18. We do not knowingly collect personal data from individuals under 18 years of age. If you believe a child has submitted personal data to us, please contact us and we will delete it promptly.
We take reasonable technical and organisational measures to protect your personal data, including:
No method of internet transmission or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
We may update this Privacy Policy periodically. The "Last updated" date at the top of this page will be changed accordingly. We will not reduce your rights under this Policy without providing prominent notice. Material changes will be communicated to guests with active bookings by email where possible.
To exercise your rights or raise a privacy concern, please contact us by replying to any booking email from this system. We aim to respond within 5 working days and will always respond within the 30-day GDPR deadline.
If you are not satisfied with our response, you may contact the Datatilsynet (Danish Data Protection Authority):