Privacy

Privacy policy

What personal data we collect, why, who processes it and how we protect it. Your data is stored within the EEA.

Last updated · July 2026Data stored within the EEA
1

Data controller

Salabókun ehf., Hlíðasmári 8, 201 Kópavogur, is the data controller for the personal data processed in the service.

2

What data is collected

Category
Who
Note
Email, name, language, notification settings
All users
Stored on the user profile.
Kennitala
Hosts (required), guests (on first booking)
Encrypted at rest, never written to system logs, sent only for identity verification.
Identity confirmation (eID), bank account, VAT status
Hosts
Identity is verified with Icelandic electronic ID (rafræn skilríki); bank account and VAT status are entered in host onboarding and stored with us.
Card data
Guests
Never touches our servers. Handled in a PCI-certified payment gateway.
Messages and attachments
Guest ↔ host
Retained indefinitely as evidence.
Reviews and booking history
All
Reviews appear publicly on the venue and profile.
Calendar tokens (OAuth)
Hosts
Encrypted at rest with a dedicated key, least privilege.
IP address and card window
Guests
Leaves the EEA only when a card is entered; the payment provider receives it as an independent controller and the transfer is covered by SCCs.
System and audit logs
All
Metadata without personal data, no kennitölur.
3

Processors

We use the following service providers to run Salabókun. Each processes only the data its service requires.

Payment providerOutside EEA
Card payments and settlement; an independent controller, not our processor, and moves card data outside the EEA under SCCs
CalendarOutside EEA
Calendar sync, only if the host connects
Email serviceOutside EEA
Transactional email
Maps serviceOutside EEA
Maps and geographic search
Electronic IDOutside EEA
eID login and verification of kennitölur on our instructions under a DPA; runs outside the EEA (United Kingdom, under the EU adequacy decision)
Accounting systemEEA
Invoices and bookkeeping
HostingEEA
Web hosting, pinned to Frankfurt
DatabaseEEA
Database in Frankfurt, backups and PITR
Auth layerEEA
Sign-in and password hashing (argon2id/bcrypt)
4

Data location

  • Core user data is stored within the EEA: database and file storage in Frankfurt.
  • Two data flows leave the EEA under Standard Contractual Clauses (SCCs): the email service (United States), and card data (IP and card window) that the payment provider transfers as an independent controller to the United States, Brazil, Israel, South Africa and the Visa and Mastercard card networks.
  • Identity verification by electronic ID (eID) runs on a processor whose infrastructure is in the United Kingdom (covered by the European Commission's adequacy decision) together with a content-delivery network. It processes kennitölur only on our written instructions under a data processing agreement (DPA).
  • Each sub-processor operates under a data processing agreement (DPA); the email service's transfer to the United States is covered by the European Commission's Standard Contractual Clauses (SCCs) in that DPA. The payment provider is not our processor but an independent controller under data protection law, and its transfers outside the EEA rest on SCCs it maintains itself.
5

Deletion and retention

  • You have the right to erasure under GDPR. On deletion, the reference to you in the audit log is removed without disturbing the log itself. Its metadata contains no personal data.
  • Messages between guest and host are retained as long as necessary as evidence in case of a dispute.
  • Accounting records (invoices, receipts and payout records) are kept for seven years as required by Icelandic bookkeeping law (Lög um bókhald). Other personal data is kept only as long as necessary for the purpose it was collected for, or until you exercise your right to erasure.
6

Security measures

Kennitölur and calendar tokens encrypted at rest.
Card data never touches our servers. It's handled in a PCI-certified payment gateway.
Signature verification on webhooks.
CSRF protection, rate limiting and schema validation on input.
7

Google Calendar

Hosts can choose to connect Google Calendar to a listing for two-way sync of bookings. The connection is optional and the OAuth tokens are encrypted at rest. We request only the scopes the sync needs:

  • calendar.events to read and write booking events in the calendar you choose.
  • calendar.calendarlist.readonly to list your calendars so you can pick which one to sync.

We do not sell, share, transfer, or disclose your Google user data to any third party. The calendar events and the OAuth tokens from this connection are used only to provide the two-way sync you turned on; they are stored solely in our own EEA infrastructure (hosting and database in Frankfurt), are never used for advertising, sold to data brokers, or used to train AI or machine-learning models, and are deleted when you disconnect the calendar.

Salabókun's use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.
8

Marketing email

We send only transactional email: confirmations, reminders and booking notifications. There is no marketing email and no marketing consent gate at launch.

Questions about privacy?

Get in touch and we'll answer as quickly as we can.

Get in touch
Privacy policy | Salabókun