Travel to Montenegro
Draft — pending legal reviewLast updated:

Privacy Policy

This policy explains how we process your personal data when you use Travel to Montenegro Booking. It complements the general privacy notice of the travel guide.

This page is a working draft that has not yet been reviewed by a lawyer. Highlighted values in brackets are still missing and will be completed by the operator. If anything is unclear, contact us before you book.

1. Data controller

The controller is [NAZIV PRAVNOG LICA], [ADRESA SJEDIŠTA], PIB [PIB]. Contact for data protection: [E-MAIL ZA ZAŠTITU PODATAKA]. Our representative in the EU under Article 27 GDPR: [PREDSTAVNIK U EU (čl. 27 GDPR)].

We process data in accordance with the Montenegrin personal data protection law and, where it applies to you, the EU General Data Protection Regulation (GDPR, 2016/679).

2. What data we process

  • Account data: name, e-mail, phone number, password (stored only as a secure hash by our login system), language.
  • Booking and inquiry data: listing, dates, number of guests, messages and special requests, price breakdown, status of the request.
  • Host data: business name and type, tax ID, bank details for payouts, listing content and photos.
  • Reviews you write after a completed stay.
  • Technical data: IP address, browser type, pages requested and error logs, kept for security and to keep the service running.

3. Why we process it (legal bases)

  • To create your account and to forward your request or inquiry to the host and manage the booking — performance of a contract (Art. 6(1)(b) GDPR).
  • To send service messages about your request (e.g. confirmation, cancellation) — performance of a contract.
  • To prevent fraud and abuse, secure the platform and moderate reviews — our legitimate interest (Art. 6(1)(f)).
  • To meet legal obligations such as accounting and responding to lawful requests of authorities (Art. 6(1)(c)).
  • Newsletters and marketing only with your consent, which you can withdraw at any time (Art. 6(1)(a)).

4. Sharing with the host

When you send a booking request or inquiry, we share your name, contact details, dates, number of guests and message with the host of that listing. The host needs this to confirm and provide the service and becomes a separate controller for that data. By law, the host also collects identity data on arrival to register you with the authorities and to charge tourist tax — this happens directly between you and the host, not through the platform.

5. Service providers (processors)

We use carefully selected providers that process data only on our instructions:

  • Hosting and storage: [HOSTING PROVAJDER I LOKACIJA SERVERA] — servers running the application, database and file storage (MinIO, self-hosted).
  • Login and accounts: Keycloak, an open-source identity system that we run on our own servers.
  • Cloudflare, Inc. — content delivery network, protection against attacks and DNS; processes IP addresses and technical request data.
  • Resend — sending transactional e-mails (when e-mail notifications are enabled).
  • AI translation providers (Anthropic, DeepSeek) — used only to translate hosts' listing texts; guests' personal data is not sent to them.

6. Transfers outside Montenegro and the EU

Some providers (for example Cloudflare and Resend) are based in the United States. Transfers are based on the EU Standard Contractual Clauses or the EU–US Data Privacy Framework where the provider is certified.

7. How long we keep data

  • Account data: while your account exists; deleted within 30 days after you ask us to delete it, unless we must keep some data by law.
  • Booking records: [ROK ČUVANJA — npr. 5 godina] after the end of the stay, for accounting, dispute and legal purposes.
  • Unanswered or declined requests and inquiries: [ROK — npr. 12 mjeseci].
  • Technical logs: up to [ROK — npr. 90 dana].

8. Your rights

You have the right to access your data, to have it corrected or deleted, to restrict or object to processing, to data portability and to withdraw consent at any time. Write to [E-MAIL ZA ZAŠTITU PODATAKA]; we reply within one month.

You can also lodge a complaint with the Montenegrin Agency for Personal Data Protection and Free Access to Information (AZLP, azlp.me) or, if you live in the EU, with the data protection authority of your country.

9. Cookies and local storage

The booking site uses only what it needs to work: keeping you logged in, remembering your language and your search. We do not use advertising or cross-site tracking cookies on the booking site. If we add analytics that require consent, we will ask for it first.

10. Security

Connections are encrypted (HTTPS), access to data is restricted to people who need it, and hosts see only the requests for their own listings.

Need help?

Questions about a listing, a request or your stay? Write to us — we'll help you reach the host.

We answer in Montenegrin and English.