Legal · GDPR

Privacy policy

This policy explains what personal data we collect through this website, why, who we share it with, and your rights under the General Data Protection Regulation (EU) 2016/679 — GDPR.

Version: v1.2 · Last updated: 03.09.2026

1. Data controller

The controller that determines the purposes and means of processing your data through this website is the Romanian sole trader identified below, which operates the Cabana de Sub Deal property. No Data Protection Officer is appointed: the activity does not meet the conditions of Article 37 GDPR. Requests concerning your personal data should be sent directly to the contact details below.

CÎNDEA CORNEL „AGRO” PERSOANĂ FIZICĂ AUTORIZATĂ (sole trader, Romania)

Tax ID (CUI)
27526490
Registered address
Avrămești, Arieșeni commune, Alba county, Romania

2. Data we collect

  • Booking data

    Full name, e-mail, phone, check-in / check-out dates, number of guests, accommodation type, optional add-ons (e.g. hot tub), preferred language, free-text notes, internal booking reference.

  • Contact form data

    Name, e-mail, phone (optional), subject, message content, preferred language.

  • Payment metadata

    We do NOT store card numbers. When online payment is enabled, Stripe processes the card and returns to us only: PaymentIntent ID, status, amount, currency, timestamp. Saved against the matching booking for reconciliation.

  • Automatic technical data (logs)

    IP address, browser user-agent, accessed URL, timestamp, HTTP response code. Used for security (rate limiting, brute-force detection), application debugging and abuse protection. NOT treated as analytics data.

  • Analytics data (cookies)

    Through Google Analytics 4 — only with your „Analytics” consent. IP anonymized via Consent Mode v2. See Cookie Policy for the exact list.

  • Tracking events

    Conversion events (booking view, date selection, quote generated, lead submission) sent to Google Analytics 4, Meta Pixel / CAPI and TikTok Pixel / EAPI — only with the corresponding „Analytics” and/or „Marketing” consent. We include anonymous identifiers (_ga client_id, _fbp, _fbc, _ttp) when you consent.

  • Admin authentication data

    Relevant only for property administrators (e-mail, bcrypt password hash, JWT sessions, login attempts history, password reset log). Does not apply to public visitors.

3. Processing purposes and legal basis

  • Booking processing

    To receive your request, contact you for confirmation, issue legal fiscal documents, send stay information. Basis: GDPR art. 6(1)(b) — performance of contract / pre-contractual measures.

  • Online payment processing

    Collecting deposit or full payment through Stripe. Basis: art. 6(1)(b).

  • Responding to contact messages

    To answer your questions. Basis: art. 6(1)(f) — legitimate interest in communication initiated by you.

  • Audience analytics

    To understand how the site is used and improve it. Basis: art. 6(1)(a) — explicit consent via the cookie banner.

  • Marketing and remarketing

    To show you relevant ads on Meta and TikTok and measure campaign performance. Basis: art. 6(1)(a) — explicit consent.

  • Customer support

    To answer post-booking requests and resolve incidents. Basis: art. 6(1)(b) or (f), as applicable.

  • Fraud prevention and security

    reCAPTCHA Enterprise, rate limiting, admin brute-force detection, CSRF, HTML sanitization. Basis: art. 6(1)(f) — legitimate interest in keeping the service safe.

  • Legal obligations

    Retention of fiscal data under applicable Romanian law. Basis: art. 6(1)(c).

  • Operational communications

    For existing bookings we automatically send confirmation, a check-in reminder 1 day before arrival, and a review request 1 day after checkout. Channels used are e-mail (Resend) and — if a valid phone number is provided — WhatsApp (Meta Cloud API) through Meta-pre-approved templates. These messages are strictly operational (transactional), NOT marketing. Basis: art. 6(1)(b) — contract performance.

4. Who we share data with (sub-processors)

We use sub-processors under art. 28 GDPR. Each has its own DPA with us and adequate safeguards for transfers outside the EEA (Standard Contractual Clauses — SCCs). We do not sell your data.

ProcessorRoleRegionPolicy
Stripe Payments Europe Ltd.Online payments processor (Stripe Checkout, webhooks).EU / US (SCCs)View policy →
Google LLC — Analytics 4Audience measurement (web + server-side Measurement Protocol). IP anonymized.EU / US (SCCs)View policy →
Google LLC — reCAPTCHA EnterpriseAnti-bot protection on public forms (booking, contact).EU / US (SCCs)View policy →
Meta Platforms Ireland Ltd.Meta Pixel (browser) + Conversions API (server) — remarketing and campaign measurement.EU / US (SCCs)View policy →
TikTok Technology Limited (Ireland)TikTok Pixel (browser) + Events API (server) — TikTok measurement and remarketing.EEA / US (SCCs)View policy →
MongoDB, Inc. — AtlasPrimary database (bookings, admin users, application logs).EU (SCCs pt. orice transfer extra)View policy →
Resend (Resend, Inc.)Transactional email delivery (booking confirmations, admin notifications, password reset).US (SCCs)View policy →
Cloudflare, Inc.CDN, DDoS / WAF protection, TLS termination.Global / SCCsView policy →
Vercel Inc.Frontend hosting (React SPA).EU / US (SCCs)View policy →
Render Services, Inc.Backend hosting (FastAPI API).EU / US (SCCs)View policy →

5. Retention periods

  • Booking data (fiscal)

    5 years from the close of the financial year in which they were drawn up, under Article 25 of Romanian Accounting Law 82/1991.

  • Payment metadata

    Stored with the booking for the same duration as above (accounting reconciliation).

  • Contact messages

    12 months from the end of the exchange.

  • Technical logs

    90 days.

  • Analytics cookies (_ga, _ga_*)

    Up to 24 months (set by Google Analytics 4).

  • Marketing cookies (_fbp, _fbc)

    Up to 90 days (set by Meta).

  • Marketing cookies (_ttp)

    Up to 13 months (set by TikTok).

  • Revoked admin data

    Password hashes and JWT sessions are invalidated immediately on logout / reset. Revoked JTIs are kept until the original token expiration.

6. Your rights (GDPR art. 15-22)

  • Right of access

    To receive a copy of your personal data.

  • Right to rectification

    To correct inaccurate or incomplete data.

  • Right to erasure („right to be forgotten”)

    To request deletion, except where a legal obligation requires retention (e.g. fiscal records).

  • Right to restriction

    To limit processing in certain situations.

  • Right to data portability

    To receive your data in a structured, commonly used, machine-readable format.

  • Right to object

    To processing based on legitimate interest or direct marketing.

  • Withdraw consent

    For cookies anytime via „Cookie settings” in the footer. For other consent-based processing, via the e-mail listed in section 1.

  • Complaint to authority

    Romanian DPA (ANSPDCP) — anspdcp.ro, anspdcp@dataprotection.ro, +40 318 059 211.

7. Security

Connections encrypted with TLS 1.2+. Admin passwords hashed with bcrypt (cost ≥ 12). Admin sessions use httpOnly Secure SameSite=None JWT cookies with server-side revocation on logout. Stateless HMAC-signed CSRF protection. Rate limiting via slowapi. reCAPTCHA Enterprise on public forms. All tracking scripts lazy-loaded only after explicit consent.

8. Automated decisions / profiling

We do not use automated decision-making or profiling with legal effects on you. reCAPTCHA Enterprise computes a bot risk score used only to accept / reject a form submission — not to profile the user.

9. International transfers

Some sub-processors operate servers outside the EEA (mainly the US). Transfers rely on Standard Contractual Clauses (SCCs) approved by the European Commission; vendors listed in section 4 are DPF-certified or equivalent.

10. Policy changes

We may update this policy. The current version is always shown here with the last update date. For material changes we will notify you via banner or e-mail.

11. Contact

To exercise your rights or for any question about personal data, write to contact@cabanadesubdeal.ro or call +40 750 448 891. We reply within one month of receiving the request, per Article 12(3) GDPR. You also have the right to lodge a complaint with the Romanian supervisory authority (ANSPDCP), Bd. Gen. Gheorghe Magheru 28-30, Bucharest.

CÎNDEA CORNEL „AGRO” PERSOANĂ FIZICĂ AUTORIZATĂ (sole trader, Romania)

Tax ID (CUI)
27526490
Registered address
Avrămești, Arieșeni commune, Alba county, Romania