top of page

Data Protection Privacy Policy

​

​

I'm a paragraph. Click here to add your own text and edit me. It's easy

Mid Wales Caravan Holidays — Data Protection Policy

Last Updated: April 2026 | Location: United Kingdom

This policy explains how we collect, use, share, and protect your personal data, in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

​

1. Introduction

We are committed to protecting your privacy. This policy applies to all personal data collected through our website, bookings, payments, and communications. We act as the Data Controller — we decide how and why your data is used.

​

2. Definitions

​

  • Personal Data: Any information that identifies you directly or indirectly (name, address, email, phone, booking details, payment reference).

  • Processing: Collecting, storing, sharing, or using your data in any way.

  • Data Processor: A third party that processes data on our behalf (e.g. Wix, Stripe).

  • Data Subject: The individual whose personal data is held.

  • ​

  • ​

3. Data Protection Principles

We ensure all data is:

  • Used lawfully, fairly, and transparently

  • Collected only for clear, specified purposes

  • Limited to what is necessary

  • Kept accurate and up to date

  • Retained only as long as required

  • Protected against unauthorised access or loss

  • Fully accountable — we can demonstrate compliance

  • ​

4. Lawful Basis for Processing

We rely on these legal grounds:

  • Contractual Necessity: To process your booking, arrange your stay, and take payment.

  • Legal Obligation: To meet tax, accounting, and consumer laws.

  • Legitimate Interests: To run our business safely and improve our services — without overriding your privacy rights.

  • Consent: For marketing — always separate and optional.

5. Types of Data We Collect

​

  • Contact details: Name, email address, phone number, billing address

  • Booking details: Dates of stay, number of guests, caravan reference, special requirements

  • Payment reference details: Last 4 card digits, transaction ID, amount, billing address — we never store full card numbers or security codes

  • Communications: Emails, messages, and support queries

  • Technical data: IP address, device info, and usage data

  • via cookies

  • ​

6. PAYMENTS — Wix, Stripe & Payment Links

This section explains how your data is handled when paying via Wix Payments, Stripe card payments, or Stripe Payment Links.

6.1 Who Processes Your Payment Data

  • Wix hosts our booking forms and website; it passes your booking and contact details to Stripe to process payment.

  • Stripe handles all card payment processing — including when we send you a Stripe Payment Link.

  • Both Wix and Stripe are Data Processors acting on our behalf. We have accepted their Data Processing Agreements (DPAs) to ensure UK GDPR compliance.

6.2 What Data Is Shared

  • When you book or pay via a link: your name, email, billing address, and payment details are sent directly to Stripe from the secure payment page.

  • WE NEVER SEE, COLLECT, OR STORE YOUR FULL CARD NUMBER, EXPIRY DATE, OR CVV/CVC. This information is entered on Stripe’s secure system and never passes to our website or our records.

  • We only receive: last 4 digits of card, card brand, transaction ID, payment amount, date/time, and billing address (for verification and record-keeping).

6.3 Purpose of Processing Payment Data

Your payment data is processed solely to complete your booking payment, for fraud prevention, financial verification, and to comply with legal financial obligations. No separate consent is required — this processing is necessary to fulfil our rental contract with you.

6.4 International Data Transfers

Stripe and Wix may transfer and process data outside the UK (including in the USA). All transfers are protected by UK-approved Standard Contractual Clauses (SCCs) to ensure your data meets UK GDPR standards. By completing payment, you acknowledge this transfer — essential to provide payment services.

6.5 Payment Links

When we send a Stripe Payment Link:

  • You enter details on Stripe’s secure page — we never see your card details.

  • Links are used only for payment — not for marketing or unsolicited messages.

  • Paid links are archived; we do not keep active links open indefinitely.

  • Do not share your payment link or payment confirmation emails with others.

  • ​

7. How We Use Your Data

  • Process and manage your booking and stay

  • Arrange payment and issue receipts

  • Answer questions and provide customer support

  • Comply with tax, accounting, and legal requirements

  • Maintain security and prevent fraud

  • Send service updates (only about your booking — not marketing without separate consent)

  • Improve our website and services

  • ​

8. Data Sharing & Third Parties

We never sell or rent your personal data. We may share data only with:

  • Wix — website hosting and booking management

  • Stripe — secure payment processing

  • Regulatory authorities — where legally required

  • Emergency services / insurers — only in the event of an incident

All third parties are bound by strict data protection contracts and may only use your data as instructed.

​

9. Data Security

  • Payment pages are fully encrypted — card details go directly to Stripe and are never stored by us

  • We do not keep full card numbers, expiry dates, or security codes anywhere

  • All admin accounts protected by strong passwords and two‑factor authentication

  • Secure HTTPS connection across our website

  • Regular security reviews and updates

  • Staff trained in data protection and confidentiality

  • ​

10. Data Retention

  • Booking & contact details: Retained for 6 years after your stay ends — required for HMRC tax, accounting, and legal obligations. Thereafter securely deleted or anonymised.

  • Payment transaction records: Held by Stripe per financial regulations — we cannot fully erase them due to law, but we ensure they are not used for marketing or other purposes.

  • CCTV & security footage: Retained for no more than 30 days unless an incident requires longer retention.

  • Marketing preferences: Kept until you opt out.

  • ​

11. Your Rights

Under UK GDPR you have the right to:

  • Access — request a copy of all personal data we hold about you

  • Rectification — correct inaccurate or incomplete details

  • Erasure — request deletion where no legal obligation prevents retention

  • Restriction — limit how your data is processed

  • Data Portability — receive your data in a machine‑readable format

  • Objection — object to processing for marketing or legitimate interests

  • Withdraw Consent — change marketing preferences at any time

  • Note: If you request deletion, transaction records held by Stripe due to financial law may be retained — we will explain this clearly to you.

To exercise any right, contact us below. We respond within one calendar month.

​

12. Marketing & Communications

  • We never add you to marketing lists without your clear, separate consent.

  • Payment‑related emails and booking confirmations are not marketing — they are contractual and required.

  • You may opt out of marketing at any time — reply to any email or use the unsubscribe link.

  • ​

13. Cookies & Tracking

​

Our website uses cookies to improve functionality. You may manage preferences via your browser settings. We do not share tracking data with advertisers without consent.

14. Policy Updates

​

We may update this policy to reflect legal or business changes. The latest version will always be published on our website.

15. Contact & Complaints

​

For all data protection enquiries:

Mid Wales Caravan Holidays  Email: info@aberystwyth-caravan-holidays.co.uk Unit 5T, Glan Yr Afon, Industrial Estate, LLanbadarn Fawr, Aberystwyth SY23 3JQ  Phone: 077592341365

.

bottom of page