Privacy Policy

Last updated: 2/10/2026

Albanian Coast ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.

1. Information We Collect

Personal Information

When you create an account or make a booking, we may collect:

  • Name and contact information (email, phone number)
  • Account credentials (username, password)
  • Booking details and preferences
  • Payment information (processed by third-party payment providers)

Automatically Collected Information

When you visit our website, we automatically collect:

  • IP address (anonymized)
  • Browser type and version
  • Device information
  • Pages visited and time spent
  • Referring/exit pages
  • Approximate geographic location

2. Legal Basis for Processing (GDPR)

We process your personal data under the following legal bases:

  • Consent: Analytics cookies and marketing communications (you can withdraw consent at any time)
  • Contract Performance: Processing bookings and providing services you requested
  • Legitimate Interests: Website security, fraud prevention, and service improvement
  • Legal Obligation: Complying with tax and financial regulations

3. How We Use Your Information

We use collected information to:

  • Process and manage your bookings
  • Communicate about your reservations
  • Improve our website and services
  • Provide customer support
  • Send important updates about our services
  • Analyze website usage and trends (with your consent)
  • Prevent fraud and ensure security

4. Cookie Usage

We use cookies and similar tracking technologies. You can manage your preferences:

  • Essential Cookies: Required for website functionality (cannot be disabled)
  • Analytics Cookies: Help us understand usage patterns (optional, requires consent)

Manage your cookie preferences at any time on our Cookie Settings page.

5. Google Analytics

With your consent, we use Google Analytics to collect anonymous information about website usage. We have configured Google Analytics to:

  • Anonymize IP addresses
  • Not share data with other Google services
  • Use secure cookie flags
  • Respect your consent preferences

You can opt out using Google's opt-out browser add-on.

6. Your GDPR Rights

If you are in the European Union, you have the following rights:

  • Right of Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to Restriction: Limit how we use your data
  • Right to Data Portability: Receive your data in a machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent for analytics and marketing at any time

To exercise any of these rights, you can:

We will respond to all requests within 30 days as required by GDPR.

7. Data Retention

We retain your data for the following periods:

  • Account Data: Until you request deletion or account closure
  • Booking Data: 7 years (for tax and legal requirements)
  • Analytics Data: 26 months maximum (Google Analytics default)
  • Cookie Consent: 12 months or until you change preferences

8. Data Sharing and Third Parties

We do not sell your personal data. We may share data with:

  • Service Providers: Payment processors, hosting services, email providers
  • Business Partners: Hotels, restaurants, and other businesses you book with
  • Analytics Services: Google Analytics (with your consent and IP anonymization)
  • Legal Requirements: When required by law or to protect our rights

9. International Data Transfers

Your data may be transferred to and processed in countries outside the European Union. We ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the EU Commission
  • Adequacy decisions for data transfers to approved countries
  • Privacy Shield framework compliance (where applicable)

10. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption of data in transit (HTTPS/TLS)
  • Secure password hashing
  • Regular security assessments
  • Access controls and authentication
  • Regular backups

11. Children's Privacy

Our services are not intended for children under 16. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we may provide additional notice via email.

13. Contact Us & Data Protection Officer

For questions about this Privacy Policy, to exercise your rights, or to contact our Data Protection Officer:

Email: [email protected]

Subject: GDPR Request / Privacy Inquiry

14. Supervisory Authority

If you are in the EU and believe we have not addressed your concerns adequately, you have the right to lodge a complaint with your local data protection supervisory authority.