Last updated: October 8, 2026
This privacy policy explains how IsleFare (“we”, “us”) collects and uses personal data when you visit this website, and the rights you have under the EU General Data Protection Regulation (GDPR) and the UK GDPR.
1. Who is responsible for your data
The data controller is: [Controller legal name], [postal address], email: [contact email].
2. What data we collect
- Technical data: when you visit, our hosting provider’s servers automatically process your IP address, browser type, the pages you request and the date and time, in server logs. We need this to deliver the website and keep it secure.
- Messages you send us: if you email us, we process your email address and the content of your message to reply.
- Cookies and similar technologies: see section 4.
We don’t sell your personal data, and we don’t run user accounts or comments on this website.
3. Why we use your data, and our legal basis
- Running and securing the website (server logs, security, caching): legitimate interests (Art. 6(1)(f) GDPR).
- Answering your messages: legitimate interests, or steps prior to a contract where relevant (Art. 6(1)(b)/(f)).
- Analytics and affiliate tracking cookies: your consent (Art. 6(1)(a) GDPR and the ePrivacy rules, including the UK PECR), where consent is required. You can withdraw consent at any time.
4. Cookies, analytics and affiliate tracking
Optional cookies (such as analytics) stay off until you click Accept in our cookie banner. You can review the cookies we use and change or withdraw your choice at any time in our Cookie Policy or via Cookie settings in the footer.
Strictly necessary cookies may be set to deliver the website (for example, by our hosting and caching setup). These don’t require consent.
Analytics: we may use Google Analytics (provided by Google Ireland Limited) to understand how visitors use the site, in aggregated form. Where required, this runs only with your consent.
Affiliate links: when you click an affiliate link (for example to Aviasales via Travelpayouts, or accommodation links via Stay22), you leave our website. The partner and the affiliate network may set cookies or use similar identifiers on their websites to record that you came from us, so that a commission can be attributed if you make a booking. We receive aggregated reports (for example, the number of clicks and bookings and the commission earned). We do not receive your name, payment details or booking details. Their own privacy policies apply to data they collect.
Embedded content: where we embed third-party content (for example, an accommodation map), the provider may process your IP address and set cookies. Where required, we load such content only with your consent.
5. Who we share data with
- Our hosting provider (Cloudways / DigitalOcean infrastructure) acts as our data processor.
- Analytics and affiliate partners, as described in section 4.
- Authorities, where we are legally required to share data.
6. International transfers
Some providers may process data outside the UK and the European Economic Area, including in the United States. Where this happens, transfers rely on an adequacy decision (such as the EU–US Data Privacy Framework, where the provider is certified) or on Standard Contractual Clauses.
7. How long we keep data
- Server logs: kept for a short period for security purposes, then deleted by our hosting provider.
- Emails: kept as long as needed to deal with your request, and then deleted unless we need them for legal reasons.
- Analytics data: kept according to the retention period set in our analytics account (we aim for no more than 14 months).
8. Your rights
Under the GDPR and UK GDPR you have the right to access your data, to correct it, to have it deleted, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting earlier processing. To exercise your rights, contact us at the email above.
You also have the right to complain to a data protection supervisory authority, in particular in the country where you live. In the UK, that’s the Information Commissioner’s Office (ICO, ico.org.uk). In the EU, it’s your national data protection authority.
9. Changes
We may update this policy. The date at the top shows when it was last changed.