UK GDPR & Data Protection Act 2018
Mix and Match Stays Ltd is the data controller for personal data processed through the platform.
Registered office: c/o Aacsl Accountants Ltd, 1st Floor, North Westgate House, Harlow, Essex, CM20 1YS, United Kingdom.
Operations office: North Somerset, United Kingdom.
ICO registration number: ZC114008.
When you pay for a booking, your card is processed directly by our regulated payment provider, Revolut. Your full card number, expiry date, and security code (CVV) are entered into Revolut’s hosted payment form and never reach our servers. We cannot charge your card again without you re-entering it.
After payment is authorised, Revolut returns a limited set of non-sensitive data which we store against your booking record:
This data is held under Article 6(1)(b) UK GDPR (performance of your booking contract, including refunds) and Article 6(1)(f) (our legitimate interest in defending against payment fraud and chargeback disputes).
Payment reference data is retained for 6 years from the date of the booking, in line with HMRC tax record-keeping obligations and the card scheme chargeback dispute window. After this period the data is deleted or anonymised.
Within Mix & Match Stays this data is accessible only to authorised staff in finance, support, or administration roles, each required to use multi-factor authentication, with access logged and audited. It may also be shared with Revolut (the original processor) and, in the event of a chargeback, with the relevant card scheme (Visa or Mastercard) and issuing bank as part of the dispute evidence.
We rely on the following lawful bases under UK GDPR Article 6:
Article 6(1)(b) — performance of a contract
processing bookings, payments, refunds, and customer support.
Article 6(1)(f) — legitimate interests
fraud prevention, chargeback defence, platform security, service improvement, and basic analytics.
Article 6(1)(c) — legal obligation
tax record-keeping, regulatory reporting, and responding to lawful requests from authorities.
Article 6(1)(a) — consent
optional marketing communications and non-essential cookies. Consent can be withdrawn at any time.
We share personal data only where necessary, and only with the following categories of recipient:
We do not sell personal data and do not share it for unrelated marketing purposes. Data Processing Addendums or equivalent contractual safeguards are in place with our key processors.
Where service providers operate outside the UK, we use appropriate safeguards such as Standard Contractual Clauses to protect personal data.
Personal data is kept only for as long as necessary for the purpose collected or to meet legal requirements, then securely deleted or anonymised. Indicative retention periods:
Where data is retained beyond the original purpose, it is held only to the extent necessary to meet a specific legal or regulatory obligation.
We apply a layered set of safeguards proportionate to the sensitivity of the data we hold:
No system can be guaranteed completely secure, but we treat any suspected data incident seriously and will notify the Information Commissioner’s Office and affected users where required by law.
Users may request:
Requests should be sent to privacy@mixmatchstays.com. You may also complain to the Information Commissioner’s Office (ICO) at ico.org.uk . Note that requests to delete data within an active retention period — for example an open refund or chargeback window — may be lawfully refused under Article 17(3)(b) and (e) UK GDPR.
We use cookies and similar technologies to improve your experience. For full details, please see our Cookie Policy.