Legal

Privacy Policy

Last updated:

This privacy policy explains how Bothan Jura Retreat (“we”, “us”) collects, uses and protects your personal data when you visit bothanjuraretreat.co.uk or book a stay with us.

We aim to use only the personal data we need to run a small holiday-let business, to keep it secure, and to be straightforward about what we do.

Who we are

Bothan Jura Retreat is a partnership, equally owned and managed by Pi & Lynton Davidson, trading from Knockrome, Isle of Jura, PA60 7XZ.

We are the data controller for personal data collected through this website and our booking enquiries. We are registered with the UK Information Commissioner’s Office (application number C1996444; registration number to follow once issued).

Contact for data and privacy queries: hello@bothanjuraretreat.co.uk.

What personal data we collect

When you contact us or enquire about a stay

  • Your name
  • Your email address
  • Your phone number (if you choose to share it)
  • The dates and property you’re asking about
  • Anything else you tell us in your message

When you make a booking

When you book directly on this site, we collect the details needed to arrange your stay: guest names, contact details, dates, and any notes you provide. Payment is processed by Stripe — your card details go directly to Stripe and never touch our servers; we see only the payment outcome and amount. The booking record is managed in Lodgify, our booking-platform provider, which stores the reservation details on our behalf.

When you visit the website

We use cookies and similar technologies for analytics if you accept the cookie banner. Without your consent we don’t set analytics cookies and we don’t track behavioural data. The full list is on the Cookies page.

We also use a first-party performance tool (Vercel Analytics) that aggregates anonymous data without setting cookies — this runs regardless of consent because it doesn’t identify individual users.

How we use your data and our lawful basis

PurposeLawful basis (UK GDPR)
Replying to your enquiries and arranging your stayContract — taking steps before entering into a booking contract with you
Processing bookings, payments and refunds via Stripe and LodgifyContract — performance of the booking contract
Sending booking confirmations, arrival information, and follow-up about your stayContract / Legitimate interest — running the business and keeping you informed
Understanding how the website is used (analytics)Consent — only after you accept the analytics cookie category
Detecting abuse, errors, and AI crawler activityLegitimate interest — keeping the site secure and visible in AI search
Meeting our legal obligations (tax, accounting, short-term-let licensing)Legal obligation

Who we share your data with

We only share data with service providers we need to run the business. These are:

  • Stripe — payment processing for direct bookings. Receives your card details and billing information directly; we never see full card numbers. Stripe privacy policy.
  • Lodgify — booking and availability platform. Stores reservation records and guest details for bookings. Lodgify privacy policy.
  • Sanity — content management system. Stores the editorial content of the site. Doesn’t process booking or guest data. Sanity privacy policy.
  • Vercel — website hosting and analytics. Sees server logs (page views, user agents, IP addresses anonymised at edge). Vercel privacy policy.
  • Google (Analytics 4 + Search Console) — only if you accept analytics cookies. Aggregate site-usage data; we don’t share booking or guest data with Google. Google privacy policy.
  • Microsoft Clarity — only if you accept analytics cookies. Anonymous heatmaps and session replays; sensitive form fields are masked by default. Microsoft privacy statement.
  • Airbnb and Booking.com — only if you click through to one of those platforms from links on the site. From that point Airbnb / Booking’s own privacy policies apply.
  • Our accountant / HMRC — for tax and book-keeping purposes, where legally required.

We never sell your personal data. We never use it for advertising or behavioural retargeting.

International transfers

Some of the providers above are based outside the UK (notably the US). Where we transfer personal data outside the UK we rely on safeguards required under UK GDPR — typically the UK’s International Data Transfer Agreement (IDTA), the EU Standard Contractual Clauses, or an adequacy regulation where one applies. Each of the providers above has published documentation describing the safeguards they use.

How long we keep your data

  • Booking enquiries that don’t convert — kept for up to 12 months in case you come back, then deleted.
  • Booking records — kept for 6 years after the stay ends, in line with HMRC record-keeping requirements.
  • Email correspondence — kept while it’s relevant to the booking or business relationship, then deleted on a rolling basis.
  • Analytics data (if you consented) — Google Analytics retains user-level data for up to 14 months; Microsoft Clarity for up to 13 months.
  • Server logs — Vercel retains for up to 30 days for operational and security purposes.

Your rights

Under UK GDPR you have the right to:

  • Be told what data we hold about you (subject access request)
  • Have inaccurate data corrected
  • Have data deleted, where we don’t need it any more (right to erasure)
  • Restrict or object to how we use your data
  • Receive your data in a portable format
  • Withdraw consent for analytics cookies at any time — use the “Update preferences” button on the Cookies page

To exercise any of these rights, email us at hello@bothanjuraretreat.co.uk. We’ll respond within one calendar month, as required by law.

If you’re not satisfied with our response, you have the right to complain to the Information Commissioner’s Office (ICO):

We’d always prefer the chance to put things right ourselves first — please contact us before going to the ICO if you can.

Security

We take reasonable technical and organisational measures to protect your personal data: HTTPS site-wide, card payments handled entirely by Stripe (PCI-DSS Level 1), secure passwords on all admin accounts, two-factor authentication where available, and minimal data collection. No internet-based service can be 100% secure, but we work with reputable providers and review our practices periodically.

Children

This website is not aimed at children. We don’t knowingly collect personal data from anyone under 13. If a parent or guardian becomes aware that a child has provided us with personal data without consent, please contact us and we’ll delete it.

Changes to this policy

We may update this policy from time to time — most often when we add or change a service we use. The “Last updated” date at the top tells you when. Material changes will also be flagged via the cookie banner so you have a chance to review.