Privacy and data

Personal data, cookies, security

Only what the booking service needs: your account email and login credentials; the lead guest's name, email, phone, country, special requests and the details of the stay; the result and reference of your payment (never your full card number); the emails we exchange with you; and limited technical data needed to run the site securely.

To fulfil a reservation we share the details needed for your stay with the property and with the supply partner through which the accommodation is offered. We also use processors acting on our instructions: cloud hosting and database providers, our payment service provider and an email delivery provider. Many properties are outside the EEA, so booking one means those details are transferred to that country. We do not sell personal data.

Under the GDPR you can request access to your data and its correction, deletion, restriction or portability, object to certain processing, and withdraw consent where processing relies on it. Email info@stayatspa.com to exercise these rights. You can also complain to the Estonian Data Protection Inspectorate (aki.ee) or to the authority where you live.

We use cookies and similar storage to run the site - for example to keep you signed in and to carry your search through to checkout - and, only with your consent, for optional purposes. Our Cookie policy lists them and explains how to manage your choices.

Bookings are identified by a non-guessable reference rather than a sequential number, and every attempt to view or cancel one is re-checked on our servers against a verified identity - either your signed-in account or a one-time code sent to the booking email. Payment details are handled by our payment provider, not by us.

All topics

Still need help?

Write to us with your booking number and what you need - we read every message.

Email us