Casa Maria Goretti · 51 Triq San Frangisk, Bormla BML 9062, Malta · +356 7981 3563

Casa Maria Goretti

Privacy Policy

This notice explains what personal data Casa Maria Goretti collects, why we collect it, who we share it with, and the rights you have under GDPR and Maltese law.

Last updated: 29 May 2026

1. About this policy

This Privacy Policy explains what personal information Casa Maria Goretti (“we”, “us”, or “the Host”) collects when you use this website, make a booking, send us a message, or stay with us, and how that information is handled. It also explains your rights under the EU General Data Protection Regulation (GDPR) and Maltese law.

The Host is the data controller for this information. For all questions about this policy or to exercise your rights, please contact the address at the end.

2. What we collect

Depending on how you interact with us, we may collect:

  • Booking details: full name, email address, phone number, stay dates, number of guests, any message provided at booking, booking reference, and the timestamp at which you accepted these terms.
  • Payment metadata: the Stripe checkout session id and payment intent id, the amount paid, the currency, and the payment status. We never see or store full card numbers or CVV codes — those are entered directly into Stripe’s secure forms.
  • Identification at check-in: where required by Maltese law for guest registration, basic identity-document details may be recorded by the Host on paper or in a secure register; these are not stored on this website.
  • Contact-form submissions: name, email, subject, message, and the timestamp of the submission.
  • Technical data: IP address, browser type, and pages visited. Used only for security, rate-limiting, and basic operational diagnostics.

3. Lawful bases for processing

We process personal data under the following GDPR lawful bases:

  • Performance of a contract — to take, confirm, and deliver your booking and stay (Art. 6(1)(b)).
  • Legitimate interests — to operate the property safely, prevent double bookings, prevent fraud, and respond to enquiries (Art. 6(1)(f)).
  • Legal obligations — to comply with Maltese tax, accounting, anti-money-laundering, and guest-registration rules (Art. 6(1)(c)).
  • Consent — for any optional marketing communications you choose to receive (Art. 6(1)(a)). You can withdraw consent at any time.

4. Payments

All card payments are processed by Stripe Payments Europe Ltd, an EU-regulated payment service provider. You enter card details directly into Stripe’s hosted forms; those details never touch this website’s servers and are never stored by us.

We retain the Stripe checkout session id, payment intent id, amount, currency, and status against your booking record so that we can match payments to bookings and issue refunds where applicable.

5. Email communications

When your booking is confirmed, we send you a booking confirmation email and, before your stay, an arrival-instructions email with your access code and address. Cancellation confirmations are sent when a booking is cancelled.

These emails are operational (transactional) communications necessary to fulfil your booking and are sent via Resend, our transactional email provider. We do not send marketing emails without prior consent.

6. Contact form

Messages submitted through the contact page are sent to our admin inbox via Resend so that we can respond. We may retain the message for a reasonable period to maintain a record of correspondence, after which it is deleted.

To prevent abuse, the form is rate-limited and your IP address is briefly held in memory for that purpose only.

7. Cookies and analytics

The website does not set any marketing or cross-site tracking cookies. Only the cookies strictly necessary to operate the booking and admin areas are used — for example, the admin authentication session.

We do not currently use Google Analytics, Meta Pixel, or any third-party advertising trackers. If we add basic, privacy-respecting analytics in the future, this policy will be updated and a clear notice will be presented on first visit where required.

8. Third-party providers

We use a small number of carefully chosen providers to operate the booking. Each provides its own GDPR-compliant safeguards:

  • Stripe (Ireland) — payment processing and refunds.
  • Supabase (EU region) — secure database and authentication for the booking system.
  • Resend — transactional email delivery.
  • Vercel — website hosting and serverless function execution.
  • Cloudflare — DNS and email routing for our contact addresses.
  • Airbnb and Booking.com — calendar synchronisation via iCal where you have booked through those channels (no private APIs or guest profiles are accessed).

9. Data retention

Booking records are retained for the period required by Maltese tax and accounting law (currently a minimum of 10 years) and any longer period necessary to resolve disputes or comply with regulatory obligations.

Contact-form messages are retained only as long as needed to handle the enquiry and any follow-up, typically up to 12 months.

Operational technical data (IP-based rate-limiting state) is held only for minutes and is not associated with your booking record.

10. Security

We apply industry-standard technical and organisational measures to protect personal data, including encryption in transit (TLS), encryption at rest in our database provider, restricted access controls for the admin area, and Stripe-hosted payment forms so card data never reaches our systems.

No system is perfectly secure. If a breach affecting personal data occurs, we will notify the relevant supervisory authority and, where required, affected guests, without undue delay.

11. International transfers

Our primary infrastructure is located within the European Economic Area. Where a provider transfers personal data outside the EEA, that transfer is covered by an adequacy decision or by Standard Contractual Clauses, as required by GDPR.

12. Your rights

Under GDPR you have the right to:

  • Request a copy of the personal data we hold about you.
  • Request correction of inaccurate or incomplete data.
  • Request deletion of your data, where it is no longer needed and where we are not legally required to keep it.
  • Object to certain processing or request that it be restricted.
  • Request portability of the data you have provided to us.
  • Withdraw any consent you have given (this does not affect the lawfulness of past processing).
  • Lodge a complaint with the Office of the Information and Data Protection Commissioner (IDPC) in Malta or with the supervisory authority in your country of residence.

13. Children

The website and booking flow are not directed at children under 16, and we do not knowingly collect data from anyone under 16 making a booking. Bookings must be made by an adult who will be present during the stay.

14. Updates to this policy

We may update this policy to reflect changes in our practices or in the law. Material changes will be highlighted on the page; the “Last updated” date at the top will always reflect the current version.

15. Contact for privacy requests

To exercise any of the rights above, or to ask any question about how we handle your information, please email info@casamariagoretti.com with the words “Privacy request” in the subject line, or write to us at the address below. We will respond within one month and may need to verify your identity first.

Address for written correspondence

Casa Maria Goretti, 51 Triq San Frangisk, Bormla BML 9062, Malta. Phone: +356 7981 3563. Email: info@casamariagoretti.com.

Book Your Stay