Privacy & Cookie Policy
Last updated: 20 August 2026
The short version. We don't sell anything, we don't run a mailing list, and we don't build a profile of you. If you use the contact form we get your name, email and message so we can reply. If you click through to Booking.com we log that a click happened, along with a shortened piece of your IP address that can't identify you. That's essentially the whole of it.
This policy explains what personal data Isle of Man Stays collects when you visit isleofmanstays.co.uk, why we collect it, how long we keep it, who else sees it, and what you can require us to do about it.
1. Who is responsible for your data
Isle of Man Stays is an independent travel guide and affiliate publisher. The operator of this site is the data controller — the person who decides what is collected and why.
For anything to do with data protection, write to hello@isleofmanstays.co.uk.
To be completed before launch. The operator's legal or trading name, and a postal address for formal notices. These are deliberately left blank rather than filled with a plausible-looking company name and registration number — an invented one on a legal page would be a false statement of identity.
We are a very small operation and are not required to appoint a Data Protection Officer. Your questions come straight to the person who runs the site.
2. Which law applies — honestly
This is less straightforward than most privacy policies pretend, so here is the actual position rather than a comfortable one.
This site is written about the Isle of Man, but it is not run from there. It is operated by one person based in South Africa, and read mostly by people in the United Kingdom and Europe. Those three facts, not the subject matter, are what decide which law governs your data.
So, in order of how firmly each one applies:
- South African law — the Protection of Personal Information Act (POPIA). This one is certain. POPIA applies to whoever is responsible for the data wherever they are domiciled, and that is South Africa.
- UK GDPR — very probably. The UK's rules reach organisations outside the UK that offer services to people in it. A .co.uk site aimed at British travellers is squarely that, so we treat the UK regime as binding.
- EU GDPR — arguably, if you are in the EU. Weaker as a legal matter, but we apply the same standard to you regardless, so the question shouldn't matter to you in practice.
Isle of Man law almost certainly does not govern this site, even though the site is about the Island. Its regime reaches controllers established there, or using equipment there, or targeting people who are on the Island — and none of those describe us. The Island is a self-governing Crown Dependency with its own data protection law and its own Information Commissioner, but we are not registered with them and it would be misleading to imply otherwise. We mention it because readers reasonably assume it applies.
Rather than pick one regime and hope, this policy is written to the highest common standard. Every right in section 8 is yours whichever regime turns out to bite, and section 9 gives you a complaint route in each direction.
3. What we collect
a) When you write to us
The contact form asks for your name, email address, a subject line and your message. The same applies if you email us directly.
That message is sent to our inbox as an email. It is not written to any database, we do not add you to any mailing list, and we do not use your address for anything except replying to you.
b) When you click a link to Booking.com
Affiliate links pass through our own redirect before forwarding you on. This is how we tell which pages are actually useful. Each click records:
- which link or banner it was, and which page it was on;
- a truncated IP address — only the first three parts, for example
82.131.45instead of your full address. That identifies a rough network of up to a few hundred devices, not you; - a device class — desktop, mobile, tablet or bot — not your full browser user-agent string;
- a one-way hash combining the truncated prefix, the device class and the date. It exists purely to stop one person's repeated clicks being counted several times, it cannot be reversed, and it changes every day so it can't follow you between visits.
We do not record your full IP address, your name or your email against a click, and the redirect places no cookie on your device. Traffic we identify as automated is discarded before anything is written down.
One caveat we would rather state than hide: because the site sits behind a content delivery network, the address we see is sometimes the network's rather than yours. That makes our click figures approximate — which is fine, because they are only ever used in aggregate.
c) Your cookie choice
When you answer the cookie banner we store your answer in a cookie so we don't ask again on every page. Details are in the cookie section below.
d) Server logs
Our hosting provider keeps short-lived technical logs of requests to the site — IP address, time, page requested, browser — as every web server does. These are used to keep the site running and to investigate abuse or faults, and they age out automatically. We don't mine them and we don't connect them to anything else.
e) What we do NOT collect
It is worth being specific, because many sites of this kind do all of these and say so only in the small print. We do not:
- run a newsletter or hold a subscriber list;
- operate analytics of any kind at present — no Google Analytics, no measurement library of any sort is loaded on this site today;
- run advertising trackers. There is provision in the code for a Meta (Facebook) pixel, but it is not switched on, and it could only ever run after you had granted marketing consent;
- sell, rent or share your data with anyone for their own marketing;
- collect special category data — health, ethnicity, religion, political opinions, sexuality — or knowingly collect anything from children.
4. Why we are allowed to hold it
Data protection law requires a lawful basis for each use. Ours are:
| What | Why | Lawful basis |
|---|---|---|
| Your contact-form message | To read it and reply to you | Legitimate interests — you wrote to us and expect an answer. (Where your message is a step towards something contractual, that basis instead.) |
| Affiliate click log | To see which pages are useful, and to reconcile the commission we are owed | Legitimate interests — running and funding the site. The data is deliberately truncated so the impact on you is minimal. |
| Cookie consent record | To remember your answer and prove we asked | Legal obligation / legitimate interests — and the cookie itself is strictly necessary |
| Server logs | Security, fault-finding, keeping the site up | Legitimate interests — operating a website securely |
| Any non-essential cookie or tracker | Only if we ever turn one on | Your consent, which you may withdraw at any time |
Where we rely on legitimate interests we have weighed them against your rights and concluded they don't override yours — largely because we collect so little. You can object at any time (section 8), and for the click log you can ask us to stop entirely.
5. Who else sees it
We use a small number of service providers, who process data on our instructions only and may not use it for their own purposes:
- Our hosting provider — serves the site and holds the short-lived server logs.
- Supabase — the database holding the property listings, the articles, and the anonymised click log.
- Resend — delivers your contact-form message to our inbox as an email.
- CJ Affiliate — the affiliate network that records that a click came from us, so Booking.com can attribute a booking. CJ and Booking.com act as controllers in their own right for what they collect once you follow a link.
Once you click through to Booking.com you are on their site, under their privacy policy, not ours. They will set their own cookies and collect their own data, and we have no control over or visibility into any of it. If that matters to you, read their policy before booking.
Beyond that, we disclose personal data only where we are legally obliged to — for instance a valid order from a court or a regulator.
6. Data leaving your country
Our providers operate internationally, and the person who runs this site is based outside the UK, the EU and the Isle of Man. So your data will in practice be accessed from, and stored in, more than one country.
Concretely, that means two journeys. Your data sits with our hosting, database and email providers, whose servers are principally in the United States and Europe; and it is accessible to the person who runs the site, in South Africa. Where a destination has no adequacy decision, we rely on our providers' standard contractual clauses and equivalent safeguards.
Given how little we hold — a message you chose to send us, and a partial IP address — the practical exposure is small. But you are entitled to know it happens rather than discover it later, which is why it is stated plainly here instead of being buried.
A point of confusion worth heading off: the Isle of Man itself holds a European Commission adequacy decision. That is about data sent to the Island, which is not something this site does, so it offers you no protection here and we are not relying on it.
7. How long we keep it
| What | How long |
|---|---|
| Contact-form emails | While we deal with your enquiry, and up to 24 months afterwards in case you follow up. Ask us and we'll delete it sooner. |
| Affiliate click records | Up to 25 months, so we can compare a season against the one before, then deleted |
| Your cookie choice | 6 months, then we ask you again |
| Server logs | Short-term only, per our hosting provider's standard retention |
8. Your rights
Whichever regime applies to you, we will honour all of the following. You have the right to:
- Be told what we hold about you and why — this page, and anything further you ask.
- Get a copy of your personal data (a subject access request).
- Have it corrected if it is wrong or incomplete.
- Have it deleted where there is no good reason for us to keep it.
- Restrict what we do with it while a dispute about it is resolved.
- Object to processing based on legitimate interests, including the click log.
- Portability — receive data you gave us in a machine-readable form.
- Withdraw consent at any time, where we relied on it. Withdrawing doesn't undo what was lawful beforehand.
- Not be subject to automated decision-making that significantly affects you. We do none.
Ask at hello@isleofmanstays.co.uk. It is free, and we will answer within one month. We may need to check you are who you say you are before handing over personal data — that protects you, not us.
One honest limitation: if you only ever clicked an affiliate link, we most likely cannot find “your” records, because we never held anything that identifies you — a truncated IP prefix and a daily hash don't single you out. That is a feature of the design rather than an evasion, and we'll explain it rather than stall you.
9. Complaining
Please come to us first — most things are a misunderstanding we can fix the same day. But you never have to, and you can go straight to a regulator.
If you are in the United Kingdom — the Information Commissioner's Office, ico.org.uk. For most of our readers this is the right door.
If you are elsewhere in Europe — your own national data protection authority.
Against the operator directly — because the site is run from South Africa, you can also complain to the South African Information Regulator, which supervises us under POPIA.
The Isle of Man has its own Information Commissioner (inforights.im), but as explained in section 2 this site almost certainly falls outside their remit — so a complaint there would likely be referred elsewhere. We would rather tell you that than send you down a dead end.
10. Do you have to give us anything?
No. You can read every page, every property and every guide on this site without telling us anything at all. The only data you actively hand over is what you type into the contact form, and that is entirely your choice — the only consequence of not doing so is that we can't reply to you.
11. Keeping it safe
The site is served over HTTPS throughout. Our database sits behind row-level security so the public site can read published content and nothing else. Administrative access needs a separate login and is restricted to the site's operator. We deliberately collect as little as possible, which is the most reliable security measure available — data you never held cannot leak.
No system is perfectly secure. If a breach ever occurs that is likely to put your rights at risk, we will report it to the relevant authority and tell you, as the law requires.
12. Children
This site is meant for adults planning a trip. We don't knowingly collect data from children. If you believe a child has sent us personal data, tell us and we will delete it.
13. Cookies
A cookie is a small file a site stores on your device. We use very few, and we ask before setting anything that isn't essential.
Asking your permission is a legal requirement, not a courtesy. Under the UK's PECR rules and the EU's ePrivacy rules, we must have your consent before setting any cookie that isn't strictly necessary — and since that is where nearly all our readers are, that is the standard we work to. (Isle of Man law happens never to have adopted the European cookie-consent rules. That changes nothing here: it doesn't govern this site, and we wouldn't use it as an excuse if it did.)
a) Strictly necessary — no consent needed
| Cookie | Purpose | Lasts |
|---|---|---|
cookie_consent | Remembers your answer to this banner, so you aren't asked on every page | 6 months |
sb-…-auth-token | Keeps a site administrator logged in. Never set for ordinary visitors. | Session / short-lived |
b) Analytics cookies
None are currently in use. The banner offers an analytics category because we may add measurement later, and if we do it will be governed by that choice — but as things stand no analytics library is loaded on this site and no analytics cookie is set. We would rather tell you that than leave you assuming the worst.
c) Marketing cookies
None are currently in use either. The code contains a consent-gated Meta (Facebook) pixel, but it is not configured and does not run. If we ever enable it, it will load only after you have granted marketing consent, and this section will be updated to name the cookies it sets before that happens.
Separately, Booking.com sets its own cookies once you arrive on their site after clicking one of our links. Those are theirs, governed by their privacy policy, and outside our control.
d) Changing your mind
Use the Cookie settings link in the footer to change your choices at any time. You can also block or delete cookies in your browser settings — though blocking the strictly necessary ones means the banner will keep asking, because the cookie recording your answer is the very thing being blocked.
We honour the same choice everywhere on the site, and withdrawing consent is exactly as easy as giving it.
14. Changes to this policy
If what we collect changes, this page changes with it, and the date at the top tells you when. If a change is significant — a new tracker, a new purpose — we will re-ask for consent rather than quietly rely on the answer you gave to a different question.
15. Contact
Anything at all about this policy, or about data we hold: hello@isleofmanstays.co.uk, or the contact form. We would genuinely rather hear from you than have you wondering.