Privacy Policy
Last updated: March 31, 2026
1. Introduction
Serene Nook (“we”, “us”, or “our”) operates theserenenook.com. This Privacy Policy explains how we collect, use, and protect your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable EU law.
2. Information We Collect
Personal data you provide:
- Name and email address
- Phone number (optional)
- Booking details (dates, number of guests)
- Payment information (processed securely by Stripe — we never store card details)
Data collected automatically:
- IP address and browser type
- Device and session information
- Essential cookies (see Cookie Policy below)
3. How We Use Your Data
- To process and manage your booking
- To communicate with you about your reservation
- To comply with legal obligations
- To improve our website and services
- For security and fraud prevention
4. Legal Basis for Processing
We process your data on the following legal grounds:
- Contract: Processing is necessary to fulfil your booking
- Legal obligation: Where required by law
- Legitimate interests: Security and service improvement
- Consent: For non-essential cookies (which you can withdraw at any time)
5. Data Sharing
We do not sell or rent your personal data. We share data only with trusted service providers acting as data processors:
- Supabase — database hosting
- Stripe — payment processing
- Resend — transactional email delivery
- Vercel — website hosting
We may also disclose data to legal authorities if required by applicable law.
6. International Data Transfers
Some service providers may process your data outside the EU/EEA. Where this occurs, we ensure appropriate safeguards are in place (Standard Contractual Clauses or equivalent) in accordance with GDPR.
7. Data Retention
We retain personal data only as long as necessary for the purposes described, or as required by law. Booking records are retained for a minimum of 5 years for accounting and tax compliance.
8. Your Rights (GDPR)
Under GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data (“right to be forgotten”)
- Restrict or object to processing
- Data portability — receive your data in a machine-readable format
- Withdraw consent for cookies at any time
- Lodge a complaint with a supervisory authority (in Greece: Hellenic Data Protection Authority — dpa.gr)
To exercise your rights, contact: aeskantar@hotmail.com
9. Security
We use industry-standard security measures including HTTPS/HSTS encryption, secure authentication cookies (httpOnly, sameSite=strict), and access-controlled data storage to protect your personal data.
10. Cookie Policy
We use only essential cookies:
- Cookie consent: Remembers your cookie preference (localStorage)
- Admin session: Secure, httpOnly authentication cookie for the admin dashboard only
We do not use tracking, advertising, or analytics cookies. You may accept or decline via the banner shown on your first visit.
11. Children's Privacy
Our website is not directed at children under 16. We do not knowingly collect personal data from children.
12. Changes to This Policy
We may update this Privacy Policy at any time. Changes will be posted on this page with an updated date. Continued use of the Site after changes constitutes acceptance.
13. Contact
For questions or to exercise your rights:
Serene NookIoniou Pelagous 8, Chania, Crete 73100, Greece
aeskantar@hotmail.com