Privacy Policy

Last updated: March 31, 2026

1. Introduction

Serene Nook (“we”, “us”, or “our”) operates theserenenook.com. This Privacy Policy explains how we collect, use, and protect your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable EU law.

2. Information We Collect

Personal data you provide:

  • Name and email address
  • Phone number (optional)
  • Booking details (dates, number of guests)
  • Payment information (processed securely by Stripe — we never store card details)

Data collected automatically:

  • IP address and browser type
  • Device and session information
  • Essential cookies (see Cookie Policy below)

3. How We Use Your Data

  • To process and manage your booking
  • To communicate with you about your reservation
  • To comply with legal obligations
  • To improve our website and services
  • For security and fraud prevention

4. Legal Basis for Processing

We process your data on the following legal grounds:

  • Contract: Processing is necessary to fulfil your booking
  • Legal obligation: Where required by law
  • Legitimate interests: Security and service improvement
  • Consent: For non-essential cookies (which you can withdraw at any time)

5. Data Sharing

We do not sell or rent your personal data. We share data only with trusted service providers acting as data processors:

  • Supabase — database hosting
  • Stripe — payment processing
  • Resend — transactional email delivery
  • Vercel — website hosting

We may also disclose data to legal authorities if required by applicable law.

6. International Data Transfers

Some service providers may process your data outside the EU/EEA. Where this occurs, we ensure appropriate safeguards are in place (Standard Contractual Clauses or equivalent) in accordance with GDPR.

7. Data Retention

We retain personal data only as long as necessary for the purposes described, or as required by law. Booking records are retained for a minimum of 5 years for accounting and tax compliance.

8. Your Rights (GDPR)

Under GDPR, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data (“right to be forgotten”)
  • Restrict or object to processing
  • Data portability — receive your data in a machine-readable format
  • Withdraw consent for cookies at any time
  • Lodge a complaint with a supervisory authority (in Greece: Hellenic Data Protection Authority — dpa.gr)

To exercise your rights, contact: aeskantar@hotmail.com

9. Security

We use industry-standard security measures including HTTPS/HSTS encryption, secure authentication cookies (httpOnly, sameSite=strict), and access-controlled data storage to protect your personal data.

10. Cookie Policy

We use only essential cookies:

  • Cookie consent: Remembers your cookie preference (localStorage)
  • Admin session: Secure, httpOnly authentication cookie for the admin dashboard only

We do not use tracking, advertising, or analytics cookies. You may accept or decline via the banner shown on your first visit.

11. Children's Privacy

Our website is not directed at children under 16. We do not knowingly collect personal data from children.

12. Changes to This Policy

We may update this Privacy Policy at any time. Changes will be posted on this page with an updated date. Continued use of the Site after changes constitutes acceptance.

13. Contact

For questions or to exercise your rights:

Serene Nook
Ioniou Pelagous 8, Chania, Crete 73100, Greece
aeskantar@hotmail.com