Privacy policy
This policy explains what personal data we collect through this website, why, who we share it with, and your rights under the General Data Protection Regulation (EU) 2016/679 — GDPR.
Version: v1.2 · Last updated: 03.09.2026
1. Data controller
The controller that determines the purposes and means of processing your data through this website is the Romanian sole trader identified below, which operates the Cabana de Sub Deal property. No Data Protection Officer is appointed: the activity does not meet the conditions of Article 37 GDPR. Requests concerning your personal data should be sent directly to the contact details below.
CÎNDEA CORNEL „AGRO” PERSOANĂ FIZICĂ AUTORIZATĂ (sole trader, Romania)
- Tax ID (CUI)
- 27526490
- Registered address
- Avrămești, Arieșeni commune, Alba county, Romania
- Phone
- +40 750 448 891
2. Data we collect
Booking data
Full name, e-mail, phone, check-in / check-out dates, number of guests, accommodation type, optional add-ons (e.g. hot tub), preferred language, free-text notes, internal booking reference.
Contact form data
Name, e-mail, phone (optional), subject, message content, preferred language.
Payment metadata
We do NOT store card numbers. When online payment is enabled, Stripe processes the card and returns to us only: PaymentIntent ID, status, amount, currency, timestamp. Saved against the matching booking for reconciliation.
Automatic technical data (logs)
IP address, browser user-agent, accessed URL, timestamp, HTTP response code. Used for security (rate limiting, brute-force detection), application debugging and abuse protection. NOT treated as analytics data.
Analytics data (cookies)
Through Google Analytics 4 — only with your „Analytics” consent. IP anonymized via Consent Mode v2. See Cookie Policy for the exact list.
Tracking events
Conversion events (booking view, date selection, quote generated, lead submission) sent to Google Analytics 4, Meta Pixel / CAPI and TikTok Pixel / EAPI — only with the corresponding „Analytics” and/or „Marketing” consent. We include anonymous identifiers (_ga client_id, _fbp, _fbc, _ttp) when you consent.
Admin authentication data
Relevant only for property administrators (e-mail, bcrypt password hash, JWT sessions, login attempts history, password reset log). Does not apply to public visitors.
3. Processing purposes and legal basis
Booking processing
To receive your request, contact you for confirmation, issue legal fiscal documents, send stay information. Basis: GDPR art. 6(1)(b) — performance of contract / pre-contractual measures.
Online payment processing
Collecting deposit or full payment through Stripe. Basis: art. 6(1)(b).
Responding to contact messages
To answer your questions. Basis: art. 6(1)(f) — legitimate interest in communication initiated by you.
Audience analytics
To understand how the site is used and improve it. Basis: art. 6(1)(a) — explicit consent via the cookie banner.
Marketing and remarketing
To show you relevant ads on Meta and TikTok and measure campaign performance. Basis: art. 6(1)(a) — explicit consent.
Customer support
To answer post-booking requests and resolve incidents. Basis: art. 6(1)(b) or (f), as applicable.
Fraud prevention and security
reCAPTCHA Enterprise, rate limiting, admin brute-force detection, CSRF, HTML sanitization. Basis: art. 6(1)(f) — legitimate interest in keeping the service safe.
Legal obligations
Retention of fiscal data under applicable Romanian law. Basis: art. 6(1)(c).
Operational communications
For existing bookings we automatically send confirmation, a check-in reminder 1 day before arrival, and a review request 1 day after checkout. Channels used are e-mail (Resend) and — if a valid phone number is provided — WhatsApp (Meta Cloud API) through Meta-pre-approved templates. These messages are strictly operational (transactional), NOT marketing. Basis: art. 6(1)(b) — contract performance.
4. Who we share data with (sub-processors)
We use sub-processors under art. 28 GDPR. Each has its own DPA with us and adequate safeguards for transfers outside the EEA (Standard Contractual Clauses — SCCs). We do not sell your data.
| Processor | Role | Region | Policy |
|---|---|---|---|
| Stripe Payments Europe Ltd. | Online payments processor (Stripe Checkout, webhooks). | EU / US (SCCs) | View policy → |
| Google LLC — Analytics 4 | Audience measurement (web + server-side Measurement Protocol). IP anonymized. | EU / US (SCCs) | View policy → |
| Google LLC — reCAPTCHA Enterprise | Anti-bot protection on public forms (booking, contact). | EU / US (SCCs) | View policy → |
| Meta Platforms Ireland Ltd. | Meta Pixel (browser) + Conversions API (server) — remarketing and campaign measurement. | EU / US (SCCs) | View policy → |
| TikTok Technology Limited (Ireland) | TikTok Pixel (browser) + Events API (server) — TikTok measurement and remarketing. | EEA / US (SCCs) | View policy → |
| MongoDB, Inc. — Atlas | Primary database (bookings, admin users, application logs). | EU (SCCs pt. orice transfer extra) | View policy → |
| Resend (Resend, Inc.) | Transactional email delivery (booking confirmations, admin notifications, password reset). | US (SCCs) | View policy → |
| Cloudflare, Inc. | CDN, DDoS / WAF protection, TLS termination. | Global / SCCs | View policy → |
| Vercel Inc. | Frontend hosting (React SPA). | EU / US (SCCs) | View policy → |
| Render Services, Inc. | Backend hosting (FastAPI API). | EU / US (SCCs) | View policy → |
5. Retention periods
Booking data (fiscal)
5 years from the close of the financial year in which they were drawn up, under Article 25 of Romanian Accounting Law 82/1991.
Payment metadata
Stored with the booking for the same duration as above (accounting reconciliation).
Contact messages
12 months from the end of the exchange.
Technical logs
90 days.
Analytics cookies (_ga, _ga_*)
Up to 24 months (set by Google Analytics 4).
Marketing cookies (_fbp, _fbc)
Up to 90 days (set by Meta).
Marketing cookies (_ttp)
Up to 13 months (set by TikTok).
Revoked admin data
Password hashes and JWT sessions are invalidated immediately on logout / reset. Revoked JTIs are kept until the original token expiration.
6. Your rights (GDPR art. 15-22)
Right of access
To receive a copy of your personal data.
Right to rectification
To correct inaccurate or incomplete data.
Right to erasure („right to be forgotten”)
To request deletion, except where a legal obligation requires retention (e.g. fiscal records).
Right to restriction
To limit processing in certain situations.
Right to data portability
To receive your data in a structured, commonly used, machine-readable format.
Right to object
To processing based on legitimate interest or direct marketing.
Withdraw consent
For cookies anytime via „Cookie settings” in the footer. For other consent-based processing, via the e-mail listed in section 1.
Complaint to authority
Romanian DPA (ANSPDCP) — anspdcp.ro, anspdcp@dataprotection.ro, +40 318 059 211.
7. Security
Connections encrypted with TLS 1.2+. Admin passwords hashed with bcrypt (cost ≥ 12). Admin sessions use httpOnly Secure SameSite=None JWT cookies with server-side revocation on logout. Stateless HMAC-signed CSRF protection. Rate limiting via slowapi. reCAPTCHA Enterprise on public forms. All tracking scripts lazy-loaded only after explicit consent.
8. Automated decisions / profiling
We do not use automated decision-making or profiling with legal effects on you. reCAPTCHA Enterprise computes a bot risk score used only to accept / reject a form submission — not to profile the user.
9. International transfers
Some sub-processors operate servers outside the EEA (mainly the US). Transfers rely on Standard Contractual Clauses (SCCs) approved by the European Commission; vendors listed in section 4 are DPF-certified or equivalent.
10. Policy changes
We may update this policy. The current version is always shown here with the last update date. For material changes we will notify you via banner or e-mail.
11. Contact
To exercise your rights or for any question about personal data, write to contact@cabanadesubdeal.ro or call +40 750 448 891. We reply within one month of receiving the request, per Article 12(3) GDPR. You also have the right to lodge a complaint with the Romanian supervisory authority (ANSPDCP), Bd. Gen. Gheorghe Magheru 28-30, Bucharest.
CÎNDEA CORNEL „AGRO” PERSOANĂ FIZICĂ AUTORIZATĂ (sole trader, Romania)
- Tax ID (CUI)
- 27526490
- Registered address
- Avrămești, Arieșeni commune, Alba county, Romania
- Phone
- +40 750 448 891