Privacy Policy
Last updated: July 2026
This privacy policy explains how Lounger collects, uses, and protects your personal data when you use our beach booking platform. We process your data in accordance with the EU General Data Protection Regulation (GDPR).
Data Controller
The controller responsible for data processing on this platform is the Lounger team. For any questions about data protection, or to request access to or deletion of your data, you can reach us at info@lounger.it.
What Data We Collect
We only collect data that is necessary to provide our services:
- Account data: your name, email address, and password (stored only as a secure hash) when you create an account.
- Booking data: the selected beach, date, spots, and additional services, plus your name, email address, and optional phone number for guest bookings.
- Payment data: payments are processed by Stripe. Your full card details are never stored on our servers.
- Technical data: IP address, browser type, and access times in server logs, kept for security and troubleshooting purposes.
Payment Processing (Stripe)
All payments are handled by Stripe as our payment processor. Stripe processes your payment details under its own privacy policy and is certified to the highest industry security standard (PCI DSS Level 1). We only receive a payment confirmation and the data needed to match the payment to your booking.
Maps and Hosting
To display beach locations, we embed Google Maps and use Google Places data (Google Ireland Limited). When map content is loaded, your IP address is transmitted to Google. Please refer to Google's privacy policy for details.
Our platform is hosted on servers operated by Hetzner Online GmbH in Germany. All data is stored within the EU.
Legal Bases
We process your data on the following legal bases under Art. 6 GDPR: performance of a contract (handling your bookings, Art. 6(1)(b)), our legitimate interests (platform security and fraud prevention, Art. 6(1)(f)), and compliance with legal obligations such as commercial record-keeping duties (Art. 6(1)(c)).
Data Retention
We retain your account data for as long as your account exists. Booking and payment records are kept for up to 10 years to comply with statutory retention obligations. Server logs are deleted after 30 days at the latest. You can request deletion of your account at any time.
Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you.
- Rectification and erasure: have inaccurate data corrected or your data deleted.
- Data portability: receive your data in a structured, commonly used, machine-readable format.
- Objection and restriction: object to or restrict certain processing of your data.
- Complaint: lodge a complaint with a data protection supervisory authority.
Cookies
We use a single, strictly necessary session cookie to keep you signed in. We do not use any tracking, analytics, or advertising cookies. Because no non-essential cookies are set, no cookie consent banner is required.
Contact for Data Requests
To exercise any of your rights or to ask questions about this privacy policy, contact us at info@lounger.it
