Legal

Privacy policy

What we collect when you book, why we need it, and how to get it back or have it removed.

Last updated 1 September 2026

1Who we are

Merill Stays is the data controller for the information described here. Write to [email protected] with any question about your data — it reaches a person, not a queue.

2What we collect, and why

When you book: your name, email address, phone number, country, arrival time, any notes you write us, and your stay dates and guest numbers. We need these to hold the dates, let you in, and reach you if something changes. The lawful basis is performance of our contract with you.

Payment details: we never see or store your card. Stripe processes the payment and returns only a payment reference and the amount.

When you browse: standard server logs — IP address, timestamp, page requested — kept for security and troubleshooting. We do not run advertising trackers, and we do not sell or share anything for advertising.

Email delivery records: we keep a copy of the confirmation emails we send you, so we can prove what was sent and resend it if it goes missing.

3Who we share it with

Stripe, to take payment. Our email provider, to deliver your confirmation. Our hosting and database providers, who store the data on our behalf under contract.

Maltese law requires accommodation providers to report certain guest details to the authorities; where that applies we provide only what is legally required.

That is the complete list. We do not sell your data, and we do not pass it to advertisers or data brokers.

4How long we keep it

Booking records, including the guest details attached to them, are kept for six years after the stay — the period Maltese tax and accounting law requires.

Server logs are kept for 30 days. Marketing consent, if you give it, is kept until you withdraw it.

5Marketing

We send you the emails needed to run your booking: confirmation, arrival details, and anything about a change you have asked for. Those are not marketing and you cannot opt out of them while you have a live booking.

We only send anything else if you have asked us to, and every such email has a working unsubscribe link.

6Your rights

Under the GDPR you can ask for a copy of your data, ask us to correct it, ask us to delete it, object to processing, or ask for it in a portable format. Email us and we will respond within 30 days at the latest, usually much sooner.

Deletion has one limit: we cannot delete a booking record we are legally required to retain. We can delete everything else, and we will tell you exactly what we have kept and why.

If you are unhappy with how we have handled your data you can complain to the Office of the Information and Data Protection Commissioner in Malta.

7Cookies

This site sets no analytics or advertising cookies, so there is no consent banner to dismiss.

The only cookie we set is a session cookie on the admin area, used to keep our own team signed in. Stripe sets its own cookies on its payment page, which is subject to Stripe's privacy policy.

8Security

Data is transmitted over TLS and stored in an access-controlled database. Admin access is limited to named members of our team and protected by individual credentials.

If a breach affecting your data ever occurred, we would notify the supervisory authority within 72 hours and tell you directly where the risk to you was high.