Privacy Policy
Last updated: 2026-08-31
Who we are
Resort Buggy is operated by NORTHDAN SOFT SRL (CUI RO44282833), registered office Iuliu Maniu 19C, Aiud, Alba, Romania. Contact: [email protected].
Which data this policy covers
This policy covers the data we decide the purposes for: what we collect from visitors to this website, from people who contact us or book a demo, and from the staff of the properties we work with.
Guest data inside the app belongs to the property. The property decides what is collected and why, and we process it on the property's instructions under our Data Processing Agreement. The sections below describe how we handle it on their behalf. A guest who wants their data corrected or deleted should ask the property; if you write to us instead, we will pass your request to them.
What data we collect
From resort/club staff (admins, drivers): name, email (admin), access codes, IP, browser info, and a telephone number where the property switches on Hold phone numbers so its front desk can call. Only that property's administrators can read a number, and it is erased when the record is deleted or the property turns the setting off. The property's managers see counts and averages per named staff member, derived from the operational records the service holds — jobs done, checks completed, rides taken, declined or let pass, and minutes stood at doors.
From drivers, where the property checks its vehicles: the answers a driver gives about a vehicle at the start and end of a shift, any note they type with an answer, the photographs they take of the vehicle, and the odometer readings they enter. These are held under the driver's name. A shift that ends without their own end check — a flat phone, the front desk freeing the buggy, a colleague taking it over — is counted against that driver and shown to the property; a manager completing the check afterwards accounts for the vehicle and does not remove the count. A fault a driver reports about a vehicle — what is wrong, anything they typed, and any photograph — is held under their name and shown to the property's engineers and managers.
From guests: name/room identifier (provided by the resort), access code, email address where the resort supplies one so we can send a pre-arrival message, pickup/dropoff selections, GPS location while the app is active, the location at the moment a ride is called, on codes the resort marks Require location, checked against the property outline plus the resort's allowed distance, special requests and any free text entered with a ride or booking request, chat messages and any photos sent in chat, push notification token (if subscribed), and a telephone number where the resort switches on Hold phone numbers, erased at checkout and readable by that resort's administrators only.
When a manager reports a problem or asks us for a number from inside the console: what she wrote, her name, the screen she was on, the dates she had chosen, which build of the app she was running, her browser and language, and whether the browser was online. A problem report also carries what the app had just been doing: the last calls it made to our server — time, method, path, outcome, how long each took, and our own reference for it — and the last lines the app wrote in the browser. It carries no request or response contents, no headers, no access code and nothing from the sign-in screens.
From the property organization: property details, map data, operational metrics.
How we use it
- Operating the service
- Aggregate statistics that identify no property and no individual
- Push notifications related to active orders
- Customer support
Why we are allowed to use it
For our customers and the people we talk to about the product, we rely on our legitimate interest in running and marketing a business service, and on the contract we have with the property. Where we use a cookie or tag that is not necessary for the site to work, we rely on your consent, which you can change at any time from the cookie settings link in the footer.
For guest data inside the app, the property chooses the legal basis and we act on its instructions. Statistics that identify no property and no individual are used to operate and improve the service, as set out in our Terms.
What we don't do
- Sell data to third parties
- Share data with advertisers
- Track guests across other apps or websites
- Use guest data for marketing
Your rights
You can ask us for a copy of your data, correct it, delete it, take it elsewhere, or object to what we do with it. Where we rely on consent, you can withdraw it. Email [email protected] and we will answer within one month.
If our answer does not satisfy you, you can complain to a data protection authority — ours is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), and you may also complain to the authority where you live or work.
Data retention
Departed guests: 90 days after a guest's checkout date we delete the guest's name, contact details, special requests and messages, along with the guest record itself. We do not delete the ride. A ride record — its times, its pick-up and drop-off points, its duration and its outcome — is retained as operational history and, after deletion, is attached to nobody. The same happens immediately when a property removes a guest from its console.
Guest chat and guest names on villa QR codes: once a villa's stay has been closed for 30 days, that stay's chat messages are deleted, the guest name is reset to the villa name and the device's access code stops working.
Ride history: retained for as long as the property's account is active, minus the guest identity described above. A property downloads its data from its own console at any time, and can ask us to delete it at any time; everything is deleted or returned when the agreement ends.
A guest with no checkout date on file never reaches the 90-day rule, because their access has no end date. Properties can see this count in their console.
Enquiries and demo bookings: kept while we are in contact with you and for our own business records afterwards; deleted on request.
Vehicle checks: a check and its photographs are kept for as long as the property's account is active, under the name of the driver who made them. Deleting a driver deletes their checks and the photographs with them. The odometer readings those checks produced stay on the vehicle, attached to nobody, because they are what the vehicle's distance is counted from.
Problem reports and requests sent from the console: kept while the property's account is active, so a manager can see what became of what she sent. They are deleted with the property's data when the agreement ends.
Access codes: until deleted or expired. Backups: 30 days.
Third parties we use
- Hosting: Hetzner Cloud (EU)
- Maps: Esri (satellite imagery tiles), CARTO (label tiles), OpenStreetMap Nominatim (admin address search) — full list in our DPA
- Email: Resend (transactional)
- Application delivery and anti-spam: Cloudflare
- Support-report triage: Anthropic — reads a problem report sent from a property console, and nothing else in the service
- Demo scheduling: Cal.com — loads only on the Book a Demo page and receives the name and email you submit when booking, plus the campaign (UTM) tags from the link that first brought you to the site (Cal.com's privacy policy)
- Hetzner is in the EU. Cloudflare, Resend, Esri, Anthropic and Cal.com are in the United States, and CARTO in Spain and the United States. Where personal data reaches a service outside the EEA, the transfer runs under the EU Standard Contractual Clauses. Each service that handles data we process for a property, with its purpose and location, is listed in our DPA.
Security
TLS in transit, encryption at rest, multi-tenant isolation, access controls. See our Security page.
Changes to this policy
We post changes here with an updated "last updated" date. Material changes are emailed to customers.