Your privacy matters

Privacy & Cookie Policy

This policy explains what information Crete Guestbook handles, why it is used, who may receive it, and the choices available to property owners and guests.

Last updated 31 July 2026

1. Who we are

Crete Guestbook provides digital guestbooks for accommodation owners and their guests. For platform account, website and service-administration data, Crete Guestbook acts as the data controller. A property owner may act as a separate controller for guest and stay information collected through their guestbook.

Privacy questions can be sent to hello@creteinfo.gr or +30 694 22 48 846.

2. Information we collect

  • Account information: name, username, email, phone number, encrypted authentication credentials, plan and account preferences.
  • Property information: property name, address, coordinates, contact channels, descriptions, images, house information and service settings.
  • Stay and guest information: guest contact details, stay dates, party size, requests and private feedback when those features are used.
  • Online check-in information: the information a guest submits is sent to the relevant property owner by email. Identification details are not intentionally retained in the Crete Guestbook database after transmission.
  • Technical and usage information: IP address, browser/device details, security events and approximate timestamps needed to operate and secure the service. When Google Analytics is enabled and consent requirements are met, Google may also process page visits, device information and referral data for audience measurement.
  • Billing information: subscription status and transaction references. Payment card details are handled by Stripe and are not stored by Crete Guestbook.

3. How and why we use information

  • Provide accounts, guestbooks, stays, requests, feedback and customer support.
  • Send operational emails, guestbook links, check-in confirmations and security notices.
  • Process subscriptions and keep billing records.
  • Prevent abuse, investigate incidents and protect users, guests and the platform.
  • Measure service performance through Google Analytics when enabled and lawfully permitted.
  • Comply with legal, tax, accounting and regulatory obligations.

Depending on the activity, processing is based on performance of a contract, legitimate interests in operating and securing the service, compliance with a legal obligation, or consent where the law requires it. Consent may be withdrawn at any time without affecting earlier lawful processing.

4. Property owners and guest information

Property owners decide what guest and stay information they request and how they use it. They are responsible for giving their guests any additional privacy information required for their own processing, using the information only for lawful hospitality purposes, and keeping their account access secure. Guests should contact the property owner first about property-specific records.

5. When information is shared

Information is shared only as reasonably necessary with:

  • The relevant property owner and authorised account users.
  • Hosting, database, email-delivery, security and support providers that process information for the platform.
  • Stripe when a paid subscription or payment feature is used.
  • Google Maps, Cloudflare Turnstile, map providers and embedded booking/service providers when their corresponding feature is enabled or opened.
  • Authorities or professional advisers when disclosure is legally required or needed to protect rights and safety.
  • A successor organisation if the service is reorganised, sold or transferred.

Crete Guestbook does not sell personal information.

6. International transfers

Some service providers may process information outside Greece or the European Economic Area. When this occurs, appropriate safeguards are used where required, such as an adequacy decision or approved contractual protections.

7. Retention and security

Information is retained only for as long as needed to provide the service, meet legal obligations, resolve disputes and protect the platform. Retention depends on the type of record and the status of the relevant account or stay. Data that is no longer required is deleted or anonymised, subject to routine backup expiry and legal retention requirements.

Administrative, technical and organisational safeguards are used to reduce the risk of unauthorised access, alteration or loss. No internet service can guarantee absolute security, so users must also use a strong password and protect their account access.

8. Your data-protection rights

Subject to the GDPR and applicable law, you may request access, correction, deletion, restriction, portability or objection to certain processing. You may also withdraw consent and lodge a complaint with a supervisory authority. Requests can be sent to hello@creteinfo.gr. We may need to verify your identity before acting on a request.

In Greece, the supervisory authority is the Hellenic Data Protection Authority. You can also read the European Data Protection Board guidance on individual rights.

9. Cookie Policy

Cookies are small files stored by a browser. The core public guestbook is designed to work without advertising cookies. It may use essential session and security storage, while local browser storage remembers choices such as acknowledgement of the cookie notice and app-install prompts.

CategoryPurposeWhen used
Strictly necessaryAuthentication, security, fraud prevention and core functionality.As needed to provide the requested service.
PreferencesRemember cookie-notice, language or app-install choices.When you save or dismiss a preference.
Third-party servicesMaps, security checks, payments and embedded booking widgets.When the related feature is enabled, displayed or used.
Analytics or advertisingAudience measurement or campaign attribution.Only when such an integration is enabled and a lawful basis exists.

You can delete or block cookies and site data in your browser settings. Blocking essential storage may prevent login or other requested features from working. Under EU rules, non-essential cookies require consent before they are placed; strictly necessary cookies do not. Learn more from the European Union online privacy guidance.

10. Children, external links and policy changes

The platform is intended for accommodation operators and adult travellers, not for children to create accounts independently. Guestbooks may link to external websites and services governed by their own privacy policies. This policy may be updated when the service, providers or legal duties change; the revised date will appear at the top of this page.

For the rules governing use of the platform, see our Terms & Conditions.