Last updated: 2/10/2026
Albanian Coast ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.
1. Information We Collect
Personal Information
When you create an account or make a booking, we may collect:
- Name and contact information (email, phone number)
- Account credentials (username, password)
- Booking details and preferences
- Payment information (processed by third-party payment providers)
Automatically Collected Information
When you visit our website, we automatically collect:
- IP address (anonymized)
- Browser type and version
- Device information
- Pages visited and time spent
- Referring/exit pages
- Approximate geographic location
2. Legal Basis for Processing (GDPR)
We process your personal data under the following legal bases:
- Consent: Analytics cookies and marketing communications (you can withdraw consent at any time)
- Contract Performance: Processing bookings and providing services you requested
- Legitimate Interests: Website security, fraud prevention, and service improvement
- Legal Obligation: Complying with tax and financial regulations
3. How We Use Your Information
We use collected information to:
- Process and manage your bookings
- Communicate about your reservations
- Improve our website and services
- Provide customer support
- Send important updates about our services
- Analyze website usage and trends (with your consent)
- Prevent fraud and ensure security
4. Cookie Usage
We use cookies and similar tracking technologies. You can manage your preferences:
- Essential Cookies: Required for website functionality (cannot be disabled)
- Analytics Cookies: Help us understand usage patterns (optional, requires consent)
Manage your cookie preferences at any time on our Cookie Settings page.
5. Google Analytics
With your consent, we use Google Analytics to collect anonymous information about website usage. We have configured Google Analytics to:
- Anonymize IP addresses
- Not share data with other Google services
- Use secure cookie flags
- Respect your consent preferences
You can opt out using Google's opt-out browser add-on.
6. Your GDPR Rights
If you are in the European Union, you have the following rights:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data ("right to be forgotten")
- Right to Restriction: Limit how we use your data
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent for analytics and marketing at any time
To exercise any of these rights, you can:
We will respond to all requests within 30 days as required by GDPR.
7. Data Retention
We retain your data for the following periods:
- Account Data: Until you request deletion or account closure
- Booking Data: 7 years (for tax and legal requirements)
- Analytics Data: 26 months maximum (Google Analytics default)
- Cookie Consent: 12 months or until you change preferences
8. Data Sharing and Third Parties
We do not sell your personal data. We may share data with:
- Service Providers: Payment processors, hosting services, email providers
- Business Partners: Hotels, restaurants, and other businesses you book with
- Analytics Services: Google Analytics (with your consent and IP anonymization)
- Legal Requirements: When required by law or to protect our rights
9. International Data Transfers
Your data may be transferred to and processed in countries outside the European Union. We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the EU Commission
- Adequacy decisions for data transfers to approved countries
- Privacy Shield framework compliance (where applicable)
10. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption of data in transit (HTTPS/TLS)
- Secure password hashing
- Regular security assessments
- Access controls and authentication
- Regular backups
11. Children's Privacy
Our services are not intended for children under 16. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we may provide additional notice via email.
13. Contact Us & Data Protection Officer
For questions about this Privacy Policy, to exercise your rights, or to contact our Data Protection Officer:
14. Supervisory Authority
If you are in the EU and believe we have not addressed your concerns adequately, you have the right to lodge a complaint with your local data protection supervisory authority.