Gizlilik politikası

How we process personal data under BiH data-protection law and GDPR where applicable.

Last updated: August 2026. This Privacy policy explains how Ture Rent Buy processes personal data in line with the Law on Personal Data Protection of Bosnia and Herzegovina and, where applicable, the EU General Data Protection Regulation (GDPR) for visitors or guests in the European Economic Area.

1. Controller

The controller of personal data is Ture Rent Buy (contact details on the Contact page: email, phone, WhatsApp). For privacy requests write to the same email with the subject “Personal data”.

2. What data we collect

  • Identity and contact: name, email, phone, address when needed for contracts.
  • Booking data: dates, guests, listing, extras, confirmation code, signatures, vouchers.
  • Payment data: method, amount, status, bank-slip files you upload; card details are handled by Monri, Stripe or PayPal — we do not store full card numbers.
  • Account data: login email, password hash, role, language, currency preference.
  • Communications: contact-form messages, admin replies, inquiries on listings.
  • Technical data: IP address, browser type, device, pages viewed, cookie identifiers, approximate location derived from IP.
  • Marketing / analytics: if Google Analytics or similar tools are enabled in settings, measurement IDs and related events.

3. Purposes and legal bases

  • Contract / pre-contract: create and manage bookings, payments, vouchers and contracts (BiH data-protection law; GDPR Art. 6(1)(b) where GDPR applies).
  • Legal obligation: accounting, tax and tourist-reporting duties (Art. 6(1)(c)).
  • Legitimate interests: securing the site, preventing fraud, improving service, defending legal claims (Art. 6(1)(f)), balanced against your rights.
  • Consent: optional marketing emails or non-essential cookies (Art. 6(1)(a)); you may withdraw at any time.

4. Who receives data

Data may be shared with: hosts/suppliers for your booking; payment providers (Monri, Stripe, PayPal); email/SMS providers; hosting and backup providers; professional advisers; and public authorities when required by law. We do not sell personal data.

5. International transfers

Some processors (e.g. Stripe, PayPal, cloud hosts) may process data outside BiH / the EEA. Where GDPR applies we rely on adequacy decisions or Standard Contractual Clauses and additional safeguards as needed.

6. Retention

  • Booking and payment records: typically up to 10 years for accounting and legal claims, or longer if a dispute is open.
  • Contact messages: up to 3 years after the last reply, unless needed longer for a claim.
  • Accounts: while active, then deleted or anonymised within a reasonable period after closure.
  • Server logs: usually up to 12 months.

7. Your rights

Under BiH law and, where applicable, GDPR you may request: access; rectification; erasure; restriction; data portability; objection to processing based on legitimate interests; and withdrawal of consent. You may lodge a complaint with the Personal Data Protection Agency of Bosnia and Herzegovina (AZLP) and, if you are in the EU/EEA, with your local supervisory authority.

8. Cookies

We use essential cookies for login, language, currency and security. Analytics or marketing cookies are used only if enabled and, where required, after consent. You can control cookies in your browser; blocking essential cookies may break checkout or login.

9. Security

We use access control, encrypted transport (HTTPS), hashed passwords and least-privilege admin roles. No method is perfectly secure; please use a strong unique password.

10. Children

The service is aimed at adults. We do not knowingly collect data from children under 16 without parental authority. Guest names of minors on a booking are processed only as needed to perform the stay.

11. Changes

We may update this policy. The current version is always on this page. For significant changes we will take reasonable steps to inform you (e.g. notice on the site or email).