Privacy Policy

How LakeBooking collects, uses, shares and protects your personal data, and the rights you have over it under the GDPR.

Privacy Policy

Last updated: 22.08.2026

This policy explains what personal data LakeBooking collects, why, who it is shared with, how long it is kept, and what you can do about it. It describes what the platform actually does. If you find something here that does not match your experience of the service, please tell us at contact@lakebooking.com.

1. Who we are

LakeBooking S.R.L. is the data controller for the processing described here.

  • Registered office: Strada Dr. Leonte Anastasievici, Nr. 9, Camera 2, Etaj 1, Ap. 2, Sector 5, Bucharest, Romania
  • CUI: 55420249
  • Trade Register: J2026049620005
  • Email for privacy matters: contact@lakebooking.com

We have not appointed a Data Protection Officer. You can raise any privacy question at the address above.

2. What this policy covers

lakebooking.com and the LakeBooking booking service. It covers anglers who book, hosts who list a lake, and visitors who only browse.

Lake hosts decide things about their own venue and their own customers that we do not control. Where a host uses your booking details for their own purposes at the venue, they act as a controller in their own right for that use.

We only collect what a given feature needs. Fields marked optional can be left empty, and the platform works without them.

Account and authentication

  • Data: name, email address, username, password (stored only as a hash, never in readable form), and optionally a phone number, short bio, profile photo, address, country, county, city, postcode, language, currency and time zone.
  • Also recorded: whether your email is verified, whether you have two-factor authentication enabled, when you accepted the Terms and which published version, and the sign-in sessions on your account (IP address, browser user agent, last activity) so you can see and end them.
  • Why: to create and run your account, sign you in, keep the account secure, and show prices, dates and messages in the right language and currency.
  • Legal basis: performance of a contract with you (art. 6(1)(b)). Keeping the account secure also rests on our legitimate interest in preventing unauthorised access (art. 6(1)(f)).

Signing in with Google or Facebook

Covered separately in section 4.

Finding lakes near you

  • Data: an approximate country, worked out from your IP address, on your first visit. If you have granted your browser's location permission to this site, also your device's coordinates.
  • Why: to pick a sensible default language, currency and search area, and to centre search results on where you are.
  • Legal basis: our legitimate interest in showing you relevant results and the right language on a first visit (art. 6(1)(f)) for the country estimate; your consent (art. 6(1)(a)) for the precise device location, which your browser asks for separately and which you can revoke at any time in your browser's site settings.
  • What happens to it: the country estimate is kept in a first-party cookie on your device. Device coordinates are used to centre the search and are sent to our own servers to run it. Neither is stored on your account, and neither is shared with an advertiser. If you pan the map or run a search, the coordinates appear in the page address, which is what makes a set of results shareable as a link.
  • We never ask for location on page load. Without your permission the site falls back to the country estimate, and everything works.

Bookings

  • Data: the lake, package, swims, dates, number of anglers, guests and rods, the price, the contact name, email and phone you enter for the booking, and any note you add for the host.
  • Why: to make, confirm, change and cancel the reservation, and to let you and the host contact each other about it.
  • Legal basis: performance of a contract with you (art. 6(1)(b)).

Payments

  • Data: the amount, the currency and an identifier for the payment. Your card number, expiry and security code are entered directly into Stripe's own payment form and never reach LakeBooking's servers. We store Stripe's payment identifier so we can match a payment to a booking and issue a refund.
  • Why: to take the online service fee and to refund it where the booking rules require.
  • Legal basis: performance of a contract with you (art. 6(1)(b)). Stripe's fraud prevention rests on Stripe's own and our legitimate interest (art. 6(1)(f)).

Invoicing and accounting

  • Data: your billing identity and address (which may be a company name, CUI and VAT number), the invoice amounts, and the invoice PDF.
  • Why: to issue the fiscal invoice for the service fee we retain, and to keep the accounting records Romanian law requires.
  • Legal basis: compliance with a legal obligation (art. 6(1)(c)).

Messages and support

  • Data: the content of messages you send to a host or to platform support, and anything you write in the contact or feedback forms (including your name and email).
  • Why: to deliver your message and to answer you.
  • Legal basis: performance of a contract for host and booking conversations (art. 6(1)(b)); our legitimate interest in answering enquiries and improving the service for general contact and feedback (art. 6(1)(f)).

Reviews

  • Data: your rating, the text you write, any photos you attach, and your display name and profile photo shown alongside.
  • Why: to publish honest reviews of lakes, which is the point of the feature.
  • Legal basis: performance of a contract (art. 6(1)(b)), since reviewing a completed stay is part of the service. Reviews are public by design; you are told so before you submit one.

Catch reports

  • Data: the species, weight, length, bait, rig, the time of the catch, the photos you upload, the position you pin on the lake map, and any notes you write.
  • Why: to keep your own catch log, to build the lake's activity view, and (where you choose it) to appear in the lake's public catch feed.
  • Legal basis: performance of a contract (art. 6(1)(b)).
  • You choose who sees each catch when you file it: everyone, or only you. Notes are never shown publicly, whatever you choose, and you can change or delete a catch afterwards. Location metadata is removed from photos when they are uploaded (see section 9).

Photos and other uploads

  • Data: the image files themselves, plus any caption or alt text.
  • Why: to show your profile photo, your catch photos and your lake's gallery.
  • Legal basis: performance of a contract (art. 6(1)(b)).
  • We strip embedded metadata (EXIF, IPTC, XMP) from every uploaded image before it is stored, which removes GPS coordinates, capture timestamps and device identifiers your camera or phone may have written into the file.

Hosting a lake

  • Data: everything about the listing (which is business information, not personal data), plus your identity as the operator, your seller tax details and, if you choose to apply for the verified badge, identity documents.
  • Why: to run the listing, to pay out correctly and to check that a host is who they say they are.
  • Legal basis: performance of a contract (art. 6(1)(b)); compliance with a legal obligation for the tax and reporting data (art. 6(1)(c)); our legitimate interest in verifying hosts and protecting anglers from fraudulent listings (art. 6(1)(f)).

Host verification documents

  • Data: an identity document for an individual host, or a company registration certificate for a business.
  • Why: to confirm a host can take bookings for the lake they list.
  • Legal basis: our legitimate interest, and yours as an angler, in a marketplace where hosts are real and verified (art. 6(1)(f)). Uploading a document is optional; it unlocks the verified badge and is not required to take bookings.
  • How they are handled: stored on a private, non-public storage bucket. They are never included in any public page or API response, never reachable by URL, and can only be opened by a platform administrator through an authenticated route. Only administrators reviewing a verification request access them.

Seller tax data (DAC7)

  • Data: the seller's identity, tax identification number, address and the consideration paid over the reporting year.
  • Why: the EU rules on reporting by digital platform operators (Council Directive 2021/514, "DAC7"), implemented in Romania, oblige us to collect and report this for hosts who earn through the platform.
  • Legal basis: compliance with a legal obligation (art. 6(1)(c)).

Newsletter and marketing email

  • Data: your email address, the language you subscribed in, the date and IP address of your subscription and of your confirmation, and which version of the wording you agreed to.
  • Why: to send the newsletter and optional product updates you asked for.
  • Legal basis: your consent (art. 6(1)(a)). You can withdraw it at any time from the unsubscribe link in any such email, or from your account's notification settings, without affecting anything else.

Referrals and the affiliate programme

  • Data: the referral code you arrived through, and which signups and bookings are attributed to an affiliate.
  • Why: to credit the person who recommended us.
  • Legal basis: your consent for the cookie that remembers the code (art. 5(3) ePrivacy and art. 6(1)(a)); performance of the affiliate contract for the attribution itself (art. 6(1)(b)). If you decline marketing cookies, no referral is recorded.

Security, abuse prevention and platform operation

  • Data: IP addresses in server request logs and rate-limit counters, sign-in sessions, and technical error reports.
  • Why: to stop brute-force attempts, spam and abuse, and to find and fix faults.
  • Legal basis: our legitimate interest in a secure and working service (art. 6(1)(f)).
  • Error reports are sent to our monitoring provider with personal data attachment switched off. We do not log message bodies, form contents, passwords, payment details or authentication tokens.

Platform administration

Platform administrators can, for support and fault reproduction, temporarily view the platform as a given user. Every such session is recorded with who did it, to which account and when, and payment, credential and account-deletion actions are blocked while it is happening.

4. Signing in with Google or Facebook

You can create an account or sign in with Google or with Facebook instead of a password. If you do:

  • What we ask the provider for. From Google: your OpenID identifier, basic profile and email address (openid, profile, email). From Facebook: your email address, name and profile picture. We have narrowed the Facebook request to exactly those fields, so information Facebook would otherwise return by default (such as gender and your profile link) is not sent to us at all.
  • What we keep. The provider's identifier for you, the email address, the name and the profile picture URL. The name and picture are a display snapshot refreshed when you sign in; they do not overwrite anything you set on your LakeBooking profile.
  • What we do not keep. We do not store the access token or refresh token the provider issues, and we do not call the provider's APIs afterwards. The connection is used to prove it is you, and nothing more. Authorisation codes, tokens and provider payloads are never written to our logs, our redirects or any message sent back to your browser.
  • Linking to an existing account. If your provider email matches an existing LakeBooking account, we connect the two automatically only when both sides are verified: the provider states the email is verified, and the LakeBooking account has already verified the same address. Otherwise we ask you to sign in with your password first and connect the account from your security settings. This is deliberate: it prevents someone registering an account with your address and waiting for your sign-in to attach to it.
  • If the provider stops sharing your email, we cannot match or create an account and the sign-in fails with an explanation.
  • If you disconnect the provider from your security settings, we delete the stored connection. We refuse only when it is your last way in (no password and no other provider), so you cannot lock yourself out.
  • If you revoke LakeBooking's access from Google or Facebook, that provider will no longer sign you in. Your LakeBooking account and its data are unaffected; use your password or another provider.
  • If you delete your LakeBooking account, the provider connection stops signing you into a live account. Signing in with it during the recovery window offers your account back rather than creating a new one; after the retention window it is erased with the rest.
  • Two-factor authentication. Google and Facebook run their own multi-factor checks, which we rely on for these sign-ins. LakeBooking's own two-factor authentication continues to protect password sign-in.
  • Browser-managed sign-in. On browsers that support it, your browser itself may offer to sign you in with the Google account you are already signed into in that browser, in a prompt the browser draws (no Google code runs on our page). Nothing reaches us until you choose an account. If you do, the browser hands us a signed identity token containing the data listed above and a one-time code we issued; we verify it and keep only what "What we keep" says, never the token itself. Dismissing the prompt sends us nothing. Requires legal review

Google and Facebook process your use of their sign-in service under their own privacy policies (Google, Meta).

Requires legal review Whether LakeBooking and the sign-in providers are independent controllers or joint controllers for the sign-in step, and what that means for this section's wording, is a legal classification we have flagged rather than asserted.

5. Who we share your data with

We share personal data only with the parties below, only for the purposes stated, and only to the extent each one needs. We do not sell personal data, and we do not share it for advertising.

RecipientWhat they receiveWhy
The lake hostYour name, email and phone from the booking, your dates, party size and any note you wroteSo they can identify you at the venue and manage the reservation
StripeThe payment amount and currency, a booking reference, and the card details you enter directly into their formTo take the service fee, prevent fraud and process refunds
MailgunRecipient email address and the content of the emailTo deliver account, booking and newsletter email
GoogleYour IP address and cookie data when a map loads (only after you allow it), plus the sign-in data in section 4Interactive maps and Google sign-in
Meta (Facebook)The sign-in data in section 4Facebook sign-in
AlgoliaYour search query and IP address when you use the location searchTo return search results
SentryTechnical error reports, with personal data attachment switched offTo find and fix faults
VercelWebsite requests, including IP addressHosting and delivering the website
Laravel CloudAPI requests, including IP addressHosting the application and its database
Cloudflare R2Uploaded filesStoring photos, documents and invoice PDFs
AI translation providers (Google Gemini, Groq, Anthropic)Listing text submitted for translation, and published testimonial quotesTo translate content between the site's languages
Romanian tax authorities (ANAF)Host seller and income dataThe DAC7 reporting obligation
Professional advisers, and authorities where legally requiredOnly what is necessaryAccounting, legal advice, and answering a lawful request

We also share data where we are legally obliged to, or where it is necessary to establish, exercise or defend a legal claim.

Note on invoicing. LakeBooking does not currently transmit invoices to the ANAF RO e-Factura system. An earlier version of this policy said it did. If that changes, this policy will be updated before it happens.

6. Where your data is processed

Our hosting is in the European Union: the website is served from Frankfurt, and the application and database are hosted in the EU.

Some of the providers above are established outside the European Economic Area, or may process data outside it, notably Stripe, Google, Meta, Algolia, Sentry, Vercel, Cloudflare and the AI translation providers. Where that happens, transfers rely on the mechanisms in Chapter V of the GDPR, which for these providers is ordinarily the European Commission's Standard Contractual Clauses, an adequacy decision, or the EU-US Data Privacy Framework where the provider is certified.

Requires legal review The exact transfer mechanism relied on for each provider, and confirmation of each provider's current certification status, are being verified. We have stated the factual position (which providers may process data outside the EEA) rather than asserting coverage we have not confirmed.

7. How long we keep your data

WhatHow long
Account dataWhile your account exists. Deleting your account deactivates it immediately and it is permanently erased 6 months later (see section 8)
BookingsKept after account deletion, with your account link removed, because they are the host's own business record
Invoices and accounting records10 years, as Romanian financial and accounting law requires
Payment identifiersWith the booking they belong to
Host verification documentsErased when your account is erased. A shorter, automatic deletion after review is built and awaiting the retention period being fixed (see below)
Seller tax data (DAC7)As long as the reporting obligation requires
MessagesWhile the conversation exists, and erased with the account
Reviews and catch reportsUntil you delete them, or until your account is erased
Uploaded photosUntil you delete them, or until your account is erased
Newsletter subscriptionUntil you unsubscribe. The record that you subscribed and unsubscribed is kept as evidence of your consent, and erased if you also delete your account
Sign-in sessions30 days of inactivity, or until you end them
Read notifications90 days
Payment webhook records30 days
Consent recordsWhile your account exists, as evidence of consent, then erased with it

Requires legal review The retention period for host verification documents has not been set. Keeping an identity document indefinitely is not defensible under the storage limitation principle, and the automatic deletion is already implemented, but the correct period depends on obligations (anti-money-laundering record keeping, DAC7 due diligence, the window in which a verification decision must remain defensible) that need a legal decision rather than an engineering one. Until it is set, documents are erased when the account is erased.

8. Deleting your account

You can delete your account yourself, from Account then Security, whether you signed up with a password, with Google or with Facebook. You will be asked to confirm your password; if you signed up with a provider and have never set one, set one first from the forgot-password flow.

What happens:

  • Your account is deactivated immediately. You are signed out everywhere, all your sessions and API tokens are revoked, and you can no longer sign in.
  • Any lakes you own are taken down with it.
  • For 6 months the account is recoverable. If you try to sign in, or sign up again with the same address, or use the same Google or Facebook connection, we offer it back rather than refusing you.
  • After that window it is permanently erased: the account, your profile photo, catch reports and their photos, reviews, notifications, favourites, pending invitations, verification documents and their files, newsletter subscription and consent records.
  • Bookings and invoices survive, with your account link removed. We are required to keep the invoices for 10 years, and the bookings are the host's own record of business they did. They are not ours to erase on request.

We refuse a deletion that would strand someone else: while you have an upcoming booking, or while anglers hold upcoming bookings at a lake you own. Cancel or complete those first.

9. Photos and location

Photos taken on a phone or camera commonly carry hidden metadata, including the exact GPS coordinates where the photo was taken. We remove that metadata from every image at upload, before it is stored, for profile photos, catch photos, lake galleries and testimonial photos alike.

The position shown for a catch is the one you pin on the lake map yourself, not one read from your photo, and you choose whether it is published.

10. Automated decision-making

We do not make decisions about you solely by automated means that produce legal effects or similarly significantly affect you. We do not profile you for advertising.

Automation in the platform is limited to running the service: availability and price calculations, booking expiry, fraud checks performed by Stripe on payments, and machine translation of listing text. None of these decides anything about you as a person.

11. Cookies and similar technologies

Set out in the Cookie Policy. In short: strictly necessary cookies run automatically; everything else runs only if you allow it, and you can change or withdraw that at any time from Cookie settings in the footer.

12. Children

The service is not intended for people under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will delete it.

13. Your rights

You have the right to:

  • Access your data, and get a copy of it. You can download a machine-readable copy yourself, at any time, from Account then Security then Download my data.
  • Rectify data that is wrong or incomplete. Most of it is editable directly in your account.
  • Erase your data. Section 8 explains what this covers and what we must keep.
  • Restrict processing while a dispute about accuracy or our grounds is resolved.
  • Object to processing based on our legitimate interests, on grounds relating to your situation. We stop unless we can show compelling legitimate grounds that override yours, or the processing is for legal claims.
  • Portability for data you gave us that we process on consent or on a contract, in a structured, commonly used, machine-readable format. This is the same download as above.
  • Withdraw consent at any time, where we rely on consent (marketing email, the newsletter, and non-essential cookies). Withdrawing does not affect what was lawful before you withdrew.
  • Complain to a supervisory authority. In Romania this is ANSPDCP, www.dataprotection.ro. You may also complain in the country where you live or work.

These rights are not unconditional, and some do not apply to some data. We cannot, for instance, erase an issued invoice, and we cannot restrict processing that a legal obligation requires. Where we cannot do what you ask, we will say so and explain why.

To exercise a right, use the controls in your account where they exist, or write to contact@lakebooking.com. We answer within one month, and will tell you if we need longer (which the GDPR allows for complex requests). We may need to confirm your identity first.

14. Security

We protect your data with, among other measures: passwords stored only as hashes, optional two-factor authentication, encrypted connections, session cookies that scripts cannot read, cross-site request forgery protection, rate limiting on sign-in and other sensitive actions, private storage for verification documents, unguessable names for non-public files, strict access rules on every API endpoint, and audit records for administrator impersonation.

No system is perfectly secure. If a breach occurs that is likely to result in a high risk to you, we will tell you and the supervisory authority as the GDPR requires.

15. Changes to this policy

If we change this policy we update the date at the top. Where a change is significant, or where it affects processing you consented to, we will tell you and, where consent is involved, ask again.

16. Contact

contact@lakebooking.com, or write to LakeBooking S.R.L. at the registered office in section 1.

Cookies on LakeBooking

We use strictly necessary cookies to sign you in and process payments securely. Optional ones (interactive maps and referral attribution) only run if you agree. Details in our Cookie Policy.