Privacy Policy

We think it matters that you know which personal data we process and why. This policy describes — concisely and without legal jargon — how ZEN-Bungalows handles your data.

1. Who we are

ZEN-Bungalows is registered at Koperslager 19, 2631 RK Nootdorp, the Netherlands. VAT number NL826584093B01. For privacy questions you can reach us at momentvoorjezelf@zenbungalows.nl.

2. Which personal data we collect

When you book and stay with us, we typically process:

  • Name, email address and phone number (for booking and communication during your stay).
  • Country of residence (for our records and legal obligations).
  • Payment details (handled by our payment processor Stripe — we only see status and invoice data, never the full card number).
  • Identity document before arrival (required by local recreational-rental regulations — checked only and not stored longer than strictly necessary).
  • Notes or special requests you enter yourself in the reservation form.
  • Technical data about your visit to our site, such as IP address, browser type and pages visited — for security and performance.

3. Why we process data

Your data is used to:

  • Handle your booking and stay carefully — from confirmation to check-out.
  • Communicate with you about practical matters (arrival information, any changes).
  • Comply with legal obligations, such as tax retention and any tourist/accommodation tax.
  • Improve our service — for instance by resolving a recurring issue or optimising a form.
  • Prevent abuse and fraud, for example via Google reCAPTCHA to distinguish bots from real visitors.

4. Legal basis for processing

We process your data on one of these grounds only:

  • Performance of the contract — your booking is an agreement with us; name, contact and payment details are needed for it.
  • Legal obligation — such as tax administration and identity verification.
  • Legitimate interest — including security against abuse and improving our website.
  • Consent — only where you actively give it (e.g. marketing emails, if we ever offer them).

5. How long we keep your data

  • Booking and invoice data: 7 years (statutory tax retention period).
  • Identity document: up to a maximum of 24 hours after your check-out. The scan is then deleted.
  • Email correspondence about your stay: maximum 2 years after departure, for service-related lookup.
  • Marketing communication: until you unsubscribe — there is always an unsubscribe link in the email.
  • Technical website logs: maximum 90 days, then automatically deleted.

6. Whom we share data with

We share your data only with parties strictly necessary to deliver our services. We have data-processing agreements (DPAs) with all of them. Specifically:

  • Lodgify (Spain) — our property-management software where your booking is recorded and managed.
  • Stripe (Ireland) — the payment service that processes your payment.
  • Postmark (United States) — for sending transactional emails (confirmations, reminders). Transfer outside the EU takes place on the basis of Standard Contractual Clauses.
  • MessageBird (Netherlands) — for sending any SMS messages and WhatsApp communication.
  • Google reCAPTCHA — for detecting automated abuse attempts on our forms. Limited to the signals Google needs to distinguish bots.

We never sell your data to third parties and we don't share it for their own marketing.

7. Transfer outside the EU

Some processors (such as Postmark) are based outside the European Economic Area. For these transfers we use the Standard Contractual Clauses approved by the European Commission, supplemented with technical measures such as encryption. Transfer takes place only where necessary for the service.

8. Cookies

We place only functionally-necessary cookies — for instance to remember your booking session or to keep the site secure. We place no tracking or marketing cookies unless you give explicit consent later via a cookie banner.

9. Your rights

Under the GDPR you have the following rights:

  • Right of access — you can request which data we hold about you.
  • Right to correction — we'll correct inaccurate data on request.
  • Right to erasure — we delete your data unless a legal retention obligation applies.
  • Right to data portability — you can request your data in a common format.
  • Right to object — you can object to processing based on legitimate interest.
  • Right to file a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).

Send a request to momentvoorjezelf@zenbungalows.nl. We respond within four weeks.

10. Security

We secure your data with encryption in transit (TLS) and at rest, with access restricted to only the necessary staff, and with periodic review of our processors. Should a data breach occur despite all measures, we will inform you and — where applicable — the Dutch Data Protection Authority.

11. Changes to this policy

We may update this policy when our services change or when legislation requires it. The last-modified date appears at the bottom of this page. For significant changes we'll notify you — for instance by email if you have an active booking.

12. Contact

For privacy questions, requests or complaints concerning ZEN-Bungalows, contact momentvoorjezelf@zenbungalows.nl. We're happy to help.

In the event of any dispute arising from this policy, the Dutch version shall be binding. Last updated: 1 May 2026.