How information is handled
Privacy information
This draft explains how Gites.co.uk Ltd proposes to handle personal information across the ChezFrance service. It must be checked against the final production suppliers, contracts and legal analysis before publication.
Pre-launch information draft. This wording is published for operational and legal review and is not presented as having received final legal approval.
Who is responsible and whose information we use
Gites.co.uk Ltd is intended to be the controller for ChezFrance accounts, marketplace administration, security, support and first-party service measurement. An owner or agency will normally be a separate controller for its accommodation service and guest relationship. The final allocation of controller, joint-controller and processor roles must be legally reviewed before launch.
We use information supplied by guests, owners and agencies to create accounts, review and publish listings, distribute eligible promotional listing content through controlled sister-site placements, process booking requests, provide private booking access and operate optional tools such as messages, contracts, house guides, forms, calendars and team access.
Booking records can include names, email addresses, telephone numbers, stay dates, party size, agreed prices and terms, operational messages and transaction status. Guest identity and contact fields and one-time notification access tokens are stored using application encryption; passwords are not stored in readable form.
Information, sources and contexts
Guests provide identity and contact details, dates, party details, messages, form answers and booking choices. Owners, agencies and team members provide account and business contacts, roles, listing content, prices, calendars, rules, contracts, guides, payout onboarding status and support communications. The service also records timestamps, security and audit events, device or browser details and IP addresses where needed for sessions, terms evidence, intake, rate limiting or security.
Listing data can come directly from an owner or agency, from authorised team members, or from Gîtes catalogue imports. Imported source snapshots can include property descriptions, locations, facilities, rates, availability and image addresses. Payment status and transaction references come from Stripe; delivery status comes from Mailgun. Publicly loaded source images may cause the visitor’s browser to contact the image host until the image is stored locally.
Why we use information and proposed lawful bases
The proposed bases are: contract or steps requested before a contract for accounts, booking requests, provider decisions, payments and stay delivery; legal obligation for tax, accounting, regulatory and rights handling; legitimate interests for service security, fraud prevention, support, audit, listing quality and necessary marketplace administration; and consent for optional first-party browsing measurement and any future electronic marketing that requires it.
These bases, any legitimate-interests assessments, and whether ChezFrance ever acts as a processor for an owner or agency are launch decisions, not final conclusions in this draft. Refusing required booking or payment information may mean the relevant request or transaction cannot be completed. Optional tools and optional measurement can be declined without preventing an ordinary browse.
How each part of the marketplace uses information
Guests use public search and, when they make a request, a private booking area for approvals, payment, messages, documents, balances, guides and optional pre-arrival forms. Owners and agencies manage their listings, prices, availability, connected payment account, enquiries, bookings, team permissions and optional operational documents. Administrators can access records when necessary for publication, support, security, reconciliation and compliance.
Eligible property content may be displayed in a controlled promotional listing on Gîtes.co.uk that links back to the ChezFrance booking route. Public sister-site distribution does not include guest details, private messages or owner or agency telephone numbers, email addresses, payment links or external booking links. Information needed for a booking remains restricted to scoped guest access and authorised owner, agency or administrative access.
Payments, email, hosting and other recipients
The property owner or agency is the accommodation provider and merchant of record. Stripe processes card payments through that provider’s connected account. ChezFrance stores transaction references, webhook evidence and booking-ledger entries but not full card numbers or security codes. Stripe may carry out authentication, security and fraud screening under its own responsibilities.
Information may be disclosed on a need-to-know basis to the accommodation provider and its authorised team, Stripe, Mailgun for transactional delivery, [provider name awaiting launch review] as the intended production host, RunCloud for server administration, and professional advisers, insurers, auditors, public authorities or prospective business transferees where lawful. The processor and subprocessor register, production contracts and exact hosting identity remain subject to launch review.
International transfers
Some suppliers may process information outside the United Kingdom or European Economic Area. Before launch, ChezFrance must document the destination, the parties’ roles and the safeguard used for each transfer. Depending on the transfer, this may include a UK or EU adequacy decision, the UK extension to the EU-US Data Privacy Framework, standard contractual clauses with the UK Addendum, or another lawful safeguard.
Stripe publishes international-transfer information, including adequacy arrangements, the Data Privacy Framework and contractual clauses. That does not replace ChezFrance’s own supplier and transfer assessment. The position for Mailgun, [provider name awaiting launch review] and any support supplier must also be verified.
Retention and deletion
Essential sessions normally expire after 120 minutes of inactivity; a “keep me signed in” choice can retain a remember token for up to 400 days; and cookie choices are kept for 180 days. Consented first-party browsing attribution and funnel events are retained for 395 days and older records are pruned. Guest access links and payment windows expire according to their security purpose. Optional guest form answers can be assigned a deletion date from departure up to two years later.
Booking agreements, accepted terms, payments, refunds, invoices or ledger evidence, listing-source snapshots, security and administrator audit trails may need longer retention for contract, accounting, disputes, fraud prevention and legal claims. This draft does not invent a single deletion period for those records: the final category-by-category schedule, backup deletion cycle and statutory accounting period must be approved and then implemented before publication.
Your rights and complaints
Depending on the law and circumstances, you may ask for access, correction, deletion, restriction or portability, object to processing based on legitimate interests or direct marketing, and withdraw consent without affecting earlier lawful processing. Contact hello@chezfrance.com. We may need to confirm identity and determine whether ChezFrance or the accommodation provider is responsible for the request.
You can complain to the UK Information Commissioner’s Office at ico.org.uk or, where applicable, another competent European data-protection authority. A request may not require deletion of records that must be kept for legal obligations, security, accounting or the establishment, exercise or defence of legal claims.
Security, children and sensitive information
ChezFrance uses access controls, scoped guest links, password hashing, application encryption for selected identity and evidence fields, encrypted session payloads, rate limits, audit records and restricted administration. No internet service can promise absolute security. Please do not send card details, passwords, access tokens or unnecessary sensitive information in messages or forms.
The service is designed for adult guests and accommodation providers and is not directed to children. An adult may supply the age or needs of a child travelling in their party where necessary for the stay. The service does not intentionally request special-category information; if accessibility or health-related information is genuinely needed, collect only what is necessary and agree the lawful handling and deletion process.
Marketing, measurement and automated processing
Current account, booking, payment and service messages are transactional. ChezFrance does not currently describe a general email-marketing programme or third-party advertising trackers. Any future marketing list must have its own transparent sign-up, lawful basis and unsubscribe route rather than reusing booking contact details silently.
Optional first-party measurement is off until allowed in cookie choices. When allowed, ChezFrance records searches, property views and booking-funnel outcomes using opaque references and sanitised campaign or referring-host information, without raw IP addresses, contact details, full card data or raw Stripe identifiers. Automated checks also support availability, price calculation, request expiry, payment state, rate limiting and fraud prevention. Instant Book may progress an eligible booking automatically; otherwise the accommodation provider decides whether to approve it. Contact hello@chezfrance.com to question a significant outcome.
This page describes the current ChezFrance service. The dated booking agreement shown during a transaction records the terms and versions that apply to that request.