Tavira · Algarve · Portugal
Privacy Policy
Your privacy matters to us. This page explains what personal data we collect, why, and how we protect it.
Who We Are
Casa Bispo is a licensed holiday rental (AL 6708) located in Tavira, Algarve, Portugal, operated by Marcus Thim UNIP LDA. For any privacy-related questions, contact us at [email protected].
What Data We Collect
When you make a booking or enquiry through our website, we collect:
- Contact information: name, email address, phone number (if provided)
- Booking details: check-in/check-out dates, number of guests, messages
- Payment information: processed securely by Stripe. We do not store your card details.
- Feedback: ratings and comments submitted via our feedback form
- Analytics data: anonymised usage data via Google Analytics (GA4), including pages visited, referral source, and device type
Why We Collect It — Legal Basis
Under Article 6 of the GDPR, we rely on the following legal bases for processing your personal data:
- Performance of a contract (Art. 6(1)(b)) — processing booking details, payments, confirmations, payment reminders, and check-in information is necessary to fulfil your reservation.
- Legal obligation (Art. 6(1)(c)) — retaining booking records and, where applicable, reporting guest stays to comply with Portuguese tax and tourism regulations.
- Consent (Art. 6(1)(a)) — analytics cookies are only set when you click “Accept” on our cookie banner. You can withdraw consent at any time by clearing your browser storage or by emailing us.
- Legitimate interests (Art. 6(1)(f)) — improving our service based on feedback you voluntarily submit, provided those interests do not override your rights.
Third-Party Services (Processors)
We use trusted third-party services to operate our booking system. Each processes personal data on our behalf under a Data Processing Agreement:
- Stripe (stripe.com) — payment processing. Your card details are handled directly by Stripe and never touch our servers.
- Resend (resend.com) — transactional email delivery (booking confirmations, payment reminders).
- Vercel (vercel.com) — website hosting and serverless functions.
- Upstash Redis via Vercel KV (upstash.com) — encrypted key-value storage for booking records, enquiries, and feedback.
- Google Analytics 4 — website usage analytics. Only loaded after you accept our cookie banner; runs in Google’s Consent Mode otherwise (no personal identifiers stored).
- Google Ads (ads.google.com) — advertising measurement. Records which ad led to a booking. Email and phone provided at checkout are hashed in your browser (SHA-256) before being sent, so Google never sees the raw values.
- Microsoft Clarity (clarity.microsoft.com) — session recordings and heatmaps to help us improve site usability. Only loaded after you accept our cookie banner. Sensitive form fields (name, email) are masked before recording.
- Cloudflare (cloudflare.com) — DNS, content delivery, and bot protection.
Each provider has their own privacy policy and processes data in accordance with GDPR.
Data Retention
- Booking records: retained for the duration required by Portuguese tax law (typically 5 years)
- Enquiry data: retained for up to 12 months, then deleted
- Feedback: retained indefinitely unless you request deletion
- Analytics data: Google Analytics retains data according to their retention settings (default 14 months)
Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the right to:
- Access your personal data we hold
- Correct inaccurate or incomplete data
- Delete your data (subject to legal retention requirements)
- Object to processing of your data for marketing purposes
- Data portability — receive a copy of your data in a structured format
To exercise any of these rights, email [email protected]. We will respond within 30 days.
Cookies & Local Storage
We keep our use of cookies and browser storage to a minimum:
- No server-side session cookies. The public site does not set its own session cookies. We only use browser
localStorageto remember your cookie-consent choice, andsessionStorageto avoid counting a confirmed booking twice in our analytics. - Analytics cookies (Google Analytics 4 & Google Ads): only set after you click “Accept” on our cookie banner. Until then GA4 runs in Google’s Consent Mode — no personal identifiers are stored. You can additionally opt out of Google Analytics entirely at tools.google.com/dlpage/gaoptout.
- Microsoft Clarity cookies: only set after you accept the cookie banner. Used for anonymised session recordings and heatmaps. Sensitive form fields (name, email) are masked before recording, so they never reach Microsoft’s servers.
- Payment cookies: Stripe may set cookies on its own checkout page for fraud detection. Those are governed by Stripe’s privacy policy.
To withdraw consent, clear your browser storage for casabispo.com or decline when the banner appears on your next visit.
Supervisory Authority
If you believe we have mishandled your personal data, you have the right to lodge a complaint with the Portuguese data-protection authority:
Comissão Nacional de Proteção de Dados (CNPD)
Av. D. Carlos I, 134, 1º, 1200-651 Lisboa, Portugal
www.cnpd.pt
Contact
For any questions about this privacy policy or your personal data, please contact us.
Email: [email protected]
Phone / WhatsApp: +47 930 38 391
Last updated: April 2026