Legal · GDPR Compliant

Privacy Policy

Last updated: July 2026  ·  Applies to: All visitors and guests who use this website

Summary: We collect only the minimum personal data necessary to process your booking. We run no advertising, no third-party analytics, and no tracking cookies. Your data is stored in the EU and is never sold.

Contents

  1. Who We Are (Data Controller)
  2. What Data We Collect & Why
  3. Lawful Basis for Processing
  4. How Long We Keep Your Data
  5. Who We Share Your Data With
  6. Bitcoin & Blockchain Data
  7. Nostr Protocol
  8. Cookies & Tracking
  9. Your Rights Under GDPR
  10. Children's Privacy
  11. Security
  12. Changes to This Policy
  13. Contact & Complaints

1. Who We Are (Data Controller)

The data controller responsible for your personal data is:

The Bitcoin Shepherd

Contact email: available via reply to any booking email from this system.

This Privacy Policy is provided in compliance with the EU General Data Protection Regulation (GDPR) (Regulation 2016/679) and the Danish Data Protection Act (Databeskyttelsesloven).

2. What Data We Collect & Why

DataWhy we collect itSource
Full nameTo identify you as the booking guest and address communications to youYou provide it in the reservation form
Email addressTo send your reservation reference, approval or rejection, payment link, and booking confirmationYou provide it in the reservation form
Check-in & check-out datesTo process and record your bookingYou select them on the booking form
Number of guestsTo confirm occupancy does not exceed the property limitYou select it on the booking form
Guest message (optional)To understand any special requirements or context for your stayOptionally provided by you
Nostr public key (npub) (optional)To verify your identity as a confirmed guest for review purposes and to send encrypted Nostr notifications if you chooseOptionally provided by you
Bitcoin payment confirmationTo confirm payment has been received and record it for accounting purposesVerified by us via the blockchain
IP address (temporary)Security — rate limiting to prevent automated abuse of the booking system. Not logged long-term.Automatically collected by the server
Review content (optional)To display guest reviews on the site, subject to your consentOptionally submitted by you

We do not collect payment card details, passport numbers, national identification numbers, financial account details, or any special category personal data under GDPR Article 9.

3. Lawful Basis for Processing

We rely on the following lawful bases under GDPR Article 6:

4. How Long We Keep Your Data

DataRetention periodReason
Booking records (name, email, dates, amount)5 years from check-out dateDanish bookkeeping law (Bogføringsloven) requires financial records to be kept for 5 years
Guest message1 year after check-outIn case of any post-stay dispute
Nostr public keyDuration of the booking record, or until you request deletionReview verification
Published reviewsUntil you request removal or we remove themGuest information service
IP addresses (security logs)30 days maximumShort-term security monitoring only

5. Who We Share Your Data With

We do not sell, rent, or trade your personal data. We share it only in the following limited circumstances:

5.1 Hosting Provider

Hostinger International Ltd. (EU/Lithuania) — our web and database hosting provider. Your data is stored on Hostinger's EU servers. Hostinger acts as a data processor under a data processing agreement. See Hostinger's privacy policy at hostinger.com/privacy-policy.

5.2 Cloudinary (if you interact with property images)

Property images may be served via Cloudinary Inc. (USA, covered by Standard Contractual Clauses). Cloudinary does not receive your personal data — it only serves image files to your browser.

5.3 Airbnb (iCal sync)

If you are also booking through Airbnb (or if we synchronise our calendar with Airbnb), date availability information (not your personal details) is shared via iCal calendar feeds. No personal data about direct booking guests is transmitted to Airbnb.

5.4 Booking.com (iCal sync)

If you are also booking through Booking.com (or if we synchronise our calendar with Booking.com), date availability information (not your personal details) is shared via iCal calendar feeds. No personal data about direct booking guests is transmitted to Booking.com.

5.5 Legal Requirements

We may disclose your data to competent authorities if required to do so by Danish law, a court order, or any applicable regulation.

5.6 No Other Sharing

We do not use Google Analytics, Meta Pixel, or any other third-party analytics or advertising tools. No advertising networks receive any data from this Site.

6. Bitcoin & Blockchain Data

If you pay using a Lightning Network address, Lightning payments are generally more private than on-chain transactions and are not stored on the public Bitcoin blockchain.

7. Nostr Protocol

Nostr is a decentralised, open social protocol. If you optionally connect your Nostr identity or submit a review via Nostr:

Providing your Nostr identity is entirely optional. You can use the Site and make bookings without it.

8. Cookies & Tracking

This Site does not use advertising cookies, tracking pixels, or third-party analytics cookies.

The Site uses sessionStorage (a browser storage mechanism) to maintain your admin login session within a single browser tab. This data is:

External services loaded by this Site (Google Fonts, Leaflet maps, CDN-hosted scripts) may set their own cookies or log your IP address in accordance with their own privacy policies. We use these services to deliver the Site's core functionality.

We do not display a cookie consent banner because we do not use tracking or advertising cookies that would require consent under ePrivacy rules. If you believe this assessment is incorrect, please contact us.

9. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights. To exercise any of them, contact us by replying to any booking email.

Right of Access

Request a copy of all personal data we hold about you.

Right to Rectification

Ask us to correct inaccurate personal data.

Right to Erasure

Request deletion of your data, subject to our legal retention obligations (e.g. accounting records).

Right to Restriction

Ask us to restrict processing of your data in certain circumstances.

Right to Data Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests.

Right to Withdraw Consent

Where processing is based on consent (e.g. Nostr key, reviews), withdraw it at any time.

Right to Complain

Lodge a complaint with the Danish Data Protection Authority (Datatilsynet).

We will respond to your request within 30 days as required by GDPR. We will not charge a fee for reasonable requests.

Datatilsynet (Danish Data Protection Authority): datatilsynet.dk · Tel: +45 33 19 32 00

10. Children's Privacy

This Site is not directed at children under 18. We do not knowingly collect personal data from individuals under 18 years of age. If you believe a child has submitted personal data to us, please contact us and we will delete it promptly.

11. Security

We take reasonable technical and organisational measures to protect your personal data, including:

No method of internet transmission or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

12. Changes to This Policy

We may update this Privacy Policy periodically. The "Last updated" date at the top of this page will be changed accordingly. We will not reduce your rights under this Policy without providing prominent notice. Material changes will be communicated to guests with active bookings by email where possible.

13. Contact & Complaints

To exercise your rights or raise a privacy concern, please contact us by replying to any booking email from this system. We aim to respond within 5 working days and will always respond within the 30-day GDPR deadline.

If you are not satisfied with our response, you may contact the Datatilsynet (Danish Data Protection Authority):