Privacy
Privacy policy
What personal data we collect, why, who processes it and how we protect it. Your data is stored within the EEA.
Data controller
Salabókun ehf., Hlíðasmári 8, 201 Kópavogur, is the data controller for the personal data processed in the service.
What data is collected
Processors
We use the following service providers to run Salabókun. Each processes only the data its service requires.
Data location
- Core user data is stored within the EEA: database and file storage in Frankfurt.
- Two data flows leave the EEA under Standard Contractual Clauses (SCCs): the email service (United States), and card data (IP and card window) that the payment provider transfers as an independent controller to the United States, Brazil, Israel, South Africa and the Visa and Mastercard card networks.
- Identity verification by electronic ID (eID) runs on a processor whose infrastructure is in the United Kingdom (covered by the European Commission's adequacy decision) together with a content-delivery network. It processes kennitölur only on our written instructions under a data processing agreement (DPA).
- Each sub-processor operates under a data processing agreement (DPA); the email service's transfer to the United States is covered by the European Commission's Standard Contractual Clauses (SCCs) in that DPA. The payment provider is not our processor but an independent controller under data protection law, and its transfers outside the EEA rest on SCCs it maintains itself.
Deletion and retention
- You have the right to erasure under GDPR. On deletion, the reference to you in the audit log is removed without disturbing the log itself. Its metadata contains no personal data.
- Messages between guest and host are retained as long as necessary as evidence in case of a dispute.
- Accounting records (invoices, receipts and payout records) are kept for seven years as required by Icelandic bookkeeping law (Lög um bókhald). Other personal data is kept only as long as necessary for the purpose it was collected for, or until you exercise your right to erasure.
Security measures
Google Calendar
Hosts can choose to connect Google Calendar to a listing for two-way sync of bookings. The connection is optional and the OAuth tokens are encrypted at rest. We request only the scopes the sync needs:
calendar.events— to read and write booking events in the calendar you choose.calendar.calendarlist.readonly— to list your calendars so you can pick which one to sync.
We do not sell, share, transfer, or disclose your Google user data to any third party. The calendar events and the OAuth tokens from this connection are used only to provide the two-way sync you turned on; they are stored solely in our own EEA infrastructure (hosting and database in Frankfurt), are never used for advertising, sold to data brokers, or used to train AI or machine-learning models, and are deleted when you disconnect the calendar.
Salabókun's use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.Marketing email
We send only transactional email: confirmations, reminders and booking notifications. There is no marketing email and no marketing consent gate at launch.
Questions about privacy?
Get in touch and we'll answer as quickly as we can.