Porto Break
Privacy Policy
The data used for your booking, why it is used and how you can exercise your rights.
On this page
1. Data controller
GuestSpaTur Habitação e Turismo, Lda., tax identification number 518401057, with its registered office at Rua Régulo Magauanha, 102, 4000-413 Porto, Portugal, is the controller of personal data collected through the PortoBreak portal. For privacy questions or to exercise your rights, contact [email protected] and identify your request as a data protection matter.
2. Data we process
The booking form asks for your name, email address and country. You can also provide your telephone number, address, tax identification number and comments. We process dates, property details, the number of adults, children and infants, amounts, references, and booking and payment statuses.
If you create an account, we process profile data, a hash of your password and the information needed for email verification and account recovery. We also process support communications, IP addresses, browser information and technical logs associated with the use and security of the service.
Additional guest identification details may be requested at check-in to meet legal accommodation requirements. Avoid including health information or other sensitive data in the comments field; contact the team if you need to explain a specific requirement.
2.1. Usage statistics and traffic sources
The portal maintains aggregate page-request counts by hour, page, search category, device, estimated connection country or referring domain. These use no analytics cookies, visitor or session identifiers, or browser fingerprinting. They cannot follow an individual or measure unique visitors.
Only with permission for “Usage statistics”, our own analytics uses random pseudonymous visitor and session identifiers. These measure pages and properties viewed, referring domains and permitted campaign parameters, search dates and guest numbers, booking steps and estimated active time. An internal reference may link the session to a completed booking to count conversions, without copying personal booking information or payment data into analytics.
Device, browser, operating system and language categories are recorded. Country is used only when estimated by a trusted proxy from the IP address: it is not nationality or an exact location, and remains unknown without a reliable source. Active time is an estimate which may be incomplete, not an exact stopwatch.
The analytics module does not store raw IP addresses, the full User-Agent, free-text searches, personal form contents, payment data, tokens or URLs containing sensitive parameters. We neither infer nor collect gender or age ranges; those fields remain unknown. These limits do not change the separate records needed for bookings and security described above.
3. Purposes and legal bases
Processing needed for your booking does not depend on a general marketing consent.
- Preparing requests and managing bookings, payments, cancellations, accounts and support: taking steps at your request before entering into a contract and performing the contract.
- Invoicing, tax obligations, guest records and responses to authorities: compliance with applicable legal obligations.
- Protecting accounts, preventing misuse, resolving incidents and defending rights: legitimate interests in the security and protection of the service, balanced against individuals' rights.
- Remembering language, loading external maps and measuring usage with pseudonymous identifiers: consent, requested separately for each purpose and which you can withdraw using ‘Manage cookies’, without affecting the lawfulness of earlier processing. You can search and book without allowing them. Aggregate counts without cookies or identifiers do not create visitor profiles. Any promotional communications require a separate choice.
4. Required data and decisions
Fields marked as required are needed to prepare the booking and send confirmation. Without that information, it may not be possible to complete the request. Creating an account is not required to book.
Availability and prices are calculated from the dates and guests you enter. You can contact the team to clarify a result or request a review of a situation. Payment checks carried out by Stripe are described in its privacy policy.
5. Who receives your data
Data needed to operate the service is accessible to the team managing bookings and stays. Internal notifications may include booking details so the team can follow up and support guests.
We use providers of hosting, maintenance, email and payment processing services. Stripe processes the data needed for payment and fraud prevention. Where necessary, data may be disclosed to accountants, advisers and authorities in the course of their respective duties and legal obligations.
6. External services and international transfers
OpenStreetMap maps are loaded only after you allow the external maps category. When enabled, your browser sends your IP address, browser information and technical request data to the map service. You can withdraw this permission using ‘Manage cookies’ in the footer. Property images may be served from szeroapp.com, a domain used to operate the portal, which receives the technical data needed to deliver the images. Fonts and the map library are hosted by the portal, without requests to Google Fonts or unpkg.
Payment takes place on Stripe's hosted checkout, which has its own privacy information. Using international service providers may involve processing data outside the European Economic Area. Transfers are subject to GDPR requirements, including an applicable adequacy decision or appropriate safeguards, as relevant. You can request information about the relevant recipients, countries and safeguards through the privacy contact. Stripe's policy describes the mechanisms used by that provider.
7. Data retention
Retention periods are determined by the purpose and applicable obligations: managing bookings and outstanding requests; maintaining the account while needed for the service; statutory retention periods for tax and accommodation records; and the periods needed to resolve complaints or defend legal rights.
Requests for erasure are assessed against these criteria. Where the law requires certain documents to be retained, deleting an account does not mean those documents can be deleted immediately. You can request the specific periods or criteria applicable to your data. Cookie lifetimes are listed in the Cookie Policy.
The reference retention periods are 90 days for analytics events and sessions and 180 days for aggregate counts without visitor or session identifiers. The random visitor identifier and last-activity date become eligible for cleanup after 180 days of inactivity. Automatic cleanup periodically deletes records exceeding these periods while the portal is in use; if the portal is inactive, cleanup resumes on its next use. Withdrawing consent stops new events linked to visitors and sessions and deletes analytics cookies; earlier data remains subject to this cleanup and your rights. Cookie lifetimes are separate.
8. Your rights
Subject to the conditions and limits of the GDPR, you can request access, rectification, erasure, restriction and portability of your data, and object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time.
Send your request to [email protected]. We may ask for the information strictly necessary to confirm your identity and protect your data. We normally reply within one month; any legally permitted extension will be communicated with the reasons for it.
You can lodge a complaint with the Portuguese Data Protection Authority (CNPD), without affecting other administrative or judicial remedies.
9. Security and updates
Keep your password and booking access links secure. Do not share references, documents or personal links publicly. Contact the team if you suspect unauthorised access.
This policy may be updated when the service or applicable obligations change. The published date and version identify the current text.