Legal information

Privacy policy

What personal data we use when you visit haciendademare.ro or book with us, why, and what your rights are.

Last updated: 30 Sep 2026

01Who is responsible for your data

The data controller is MANAT MAGNUM S.R.L., Str. Drumul Pescarilor nr. 16A, Loc. Olimp, Mun. Mangalia, jud. Constanța, Romania, tax code (CUI) RO22203235, Trade Register no. J2019000978235. For any question about your data, write to us at contact@haciendademare.ro.

02What data we use

  • When you book on the site: your name, email address, phone number, country (optional), the number of adults and children, any notes you choose to write, the dates of your stay, the room type, the language you booked in and the time you accepted the terms. We keep them together with the booking details: its reference, price, payments and status.
  • When you pay: you enter your card details directly on the Stripe page; your full card number never reaches us. Our booking system receives from Stripe only the payment identifiers, the amount and whether the payment succeeded; in our Stripe account we also see the usual payment details (for example the card brand and last 4 digits).
  • When you book another way (Booking.com, Airbnb, phone, WhatsApp, email or with us in person): we enter in the same booking system your name, phone number, email (if we have it), the dates of your stay, the number of guests, the booking code from that platform, the amounts and our staff’s internal notes.
  • When you write to us: your email address and the content of your message.
  • When you visit the site: our hosting provider keeps technical logs for a short time (IP address, browser, the page requested and, in some situations, booking details), to run and secure the site. We use no traffic analytics and no advertising tools.

Please do not put sensitive data in the notes, for example about health, unless it is really needed for your stay.

03Why we use it and on what legal basis

  • To make and manage your booking and stay, contact you about them and receive payment: performance of a contract (Article 6(1)(b) of Regulation (EU) 2016/679, the GDPR).
  • To keep our accounts and meet other legal obligations: legal obligation (Article 6(1)(c) GDPR).
  • To answer messages and complaints and defend our rights: performance of a contract or our legitimate interest (Article 6(1)(b) and (f) GDPR).
  • To keep the site running safely and prevent abuse and fraud: our legitimate interest (Article 6(1)(f) GDPR).

Your name, email and phone number are needed for a booking; without them we cannot make it. We do not use your data for marketing, we do not sell it, and we do not profile you or make solely automated decisions that have legal or similarly significant effects on you.

04Who receives it

Only the members of our team who handle bookings see your data. It also reaches the providers below. Most of them process it only on our behalf; Stripe also uses it for its own purposes, under its own policy:

  • Vercel Inc. (USA): website hosting. The servers that process bookings are currently in the USA.
  • Neon (USA): the database that holds bookings, in a data centre in the USA (Northern Virginia).
  • Stripe: card payments, when online payment is active. Stripe also uses some data for its own purposes, such as fraud prevention and legal obligations; see the Stripe privacy policy.
  • Resend, Inc. (USA): sending automatic booking emails, when these are switched on.
  • The provider of our email service, where your messages arrive.

If you book through Booking.com or Airbnb, that platform sends us the data needed for the booking, and its own policy covers what it does with your data. We share data with public authorities only when the law requires it and, for accounting documents, with those who keep our accounts.

05Transfers outside the European Union

Vercel, Neon, Stripe and Resend may process data in the USA. These transfers rely on Commission Implementing Decision (EU) 2023/1795 on the EU-US Data Privacy Framework, for certified companies, or on standard contractual clauses approved by the European Commission. You can ask us for a copy of these safeguards by writing to contact@haciendademare.ro.

06How long we keep it

  • Bookings that were cancelled or never confirmed, with nothing paid: 12 months from the arrival date.
  • All other bookings (completed, confirmed or with any payment, even if refunded): 3 years from the departure date, the general limitation period under Romanian law (Article 2517 of the Civil Code), for any complaints or legal claims.
  • Emails you send us: as long as needed to reply to you and for any complaints.
  • Accounting documents (for example invoices and payment records): as long as the law requires, generally 10 years from the end of the financial year (Article 25 of the Romanian Accounting Law no. 82/1991).
  • Technical logs of the site: for a short time, at the hosting provider. Stripe keeps its own payment records, under its own policy.

When the periods for bookings end, our system automatically deletes the name, email, phone number, country, your notes, our staff’s notes (except those about payments and refunds) and any booking code from another platform. What remains is the booking reference, dates, room, number of guests, amounts, booking and payment status, the Stripe payment identifiers and the time you accepted the terms, as needed for our accounts and as proof of payment. The payments in our Stripe account (with the email and the card’s last 4 digits) are part of our payment records and are kept like the accounting documents above. At your request we delete your data sooner, except for what the law requires us to keep.

07Your rights

You can ask for access to your data, for its correction or erasure, for restriction of processing and for data portability, and you can object to processing based on our legitimate interest. Write to us at contact@haciendademare.ro; we reply within one month.

You can also complain to the Romanian data protection authority, Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, postal code 010336, Bucharest, Romania, anspdcp@dataprotection.ro, www.dataprotection.ro.

08Cookies

  • The site sets no cookies for visitors and stores nothing else in your browser (for example in localStorage). You choose the language through the page address.
  • Fonts, images and videos are served from our own site, with no requests to Google or other third parties.
  • The Stripe payment page (checkout.stripe.com) belongs to Stripe and may use its own cookies, under Stripe’s policy.
  • The admin area, used only by staff, has a single cookie, strictly necessary for sign-in (cdm_admin), valid for 14 days.

That is why we do not ask for your cookie consent. If we ever add analytics or advertising tools, we will ask for your consent first.

09Security

The connection to the site is encrypted (HTTPS), and only our staff can access the booking system, with an account and password. If we change this policy, we update the date at the top of the page.

See also: Terms and conditions