Privacy Policy

UK GDPR & Data Protection Act 2018

Data Controller

Mix and Match Stays Ltd is the data controller for personal data processed through the platform.

Registered office: c/o Aacsl Accountants Ltd, 1st Floor, North Westgate House, Harlow, Essex, CM20 1YS, United Kingdom.

Operations office: North Somerset, United Kingdom.

ICO registration number: ZC114008.

What Personal Data We Collect

  • Information you provide, such as name, email address, telephone number, booking details, and travel preferences.
  • Technical data such as IP address, browser type, device information, and pages visited.
  • Booking-related information needed to manage reservations.
  • Limited payment reference data — the last 4 digits and brand of the card used (e.g. •••• 1234, Visa), the Revolut transaction reference, and the 3-D Secure authentication result. Returned to us by Revolut after payment. We never see or store full card numbers, expiry dates, or CVVs.
  • Payment Data

    When you pay for a booking, your card is processed directly by our regulated payment provider, Revolut. Your full card number, expiry date, and security code (CVV) are entered into Revolut’s hosted payment form and never reach our servers. We cannot charge your card again without you re-entering it.

    After payment is authorised, Revolut returns a limited set of non-sensitive data which we store against your booking record:

  • the last 4 digits of the card used (e.g. •••• 1234)
  • the card brand (e.g. Visa, Mastercard)
  • the Revolut transaction reference, used to issue refunds
  • the 3-D Secure authentication result, evidencing Strong Customer Authentication under PSD2
  • the IP address and email used at the time of payment
  • This data is held under Article 6(1)(b) UK GDPR (performance of your booking contract, including refunds) and Article 6(1)(f) (our legitimate interest in defending against payment fraud and chargeback disputes).

    Payment reference data is retained for 6 years from the date of the booking, in line with HMRC tax record-keeping obligations and the card scheme chargeback dispute window. After this period the data is deleted or anonymised.

    Within Mix & Match Stays this data is accessible only to authorised staff in finance, support, or administration roles, each required to use multi-factor authentication, with access logged and audited. It may also be shared with Revolut (the original processor) and, in the event of a chargeback, with the relevant card scheme (Visa or Mastercard) and issuing bank as part of the dispute evidence.

    How We Use Your Data

  • To process and manage bookings.
  • To create and maintain user accounts.
  • To communicate about bookings and support requests.
  • To improve the website, app, and services.
  • To comply with legal and regulatory obligations.
  • To send optional marketing updates where consent has been given.
  • Legal Basis for Processing

    We rely on the following lawful bases under UK GDPR Article 6:

    Article 6(1)(b) — performance of a contract

    processing bookings, payments, refunds, and customer support.

    Article 6(1)(f) — legitimate interests

    fraud prevention, chargeback defence, platform security, service improvement, and basic analytics.

    Article 6(1)(c) — legal obligation

    tax record-keeping, regulatory reporting, and responding to lawful requests from authorities.

    Article 6(1)(a) — consent

    optional marketing communications and non-essential cookies. Consent can be withdrawn at any time.

    Who We Share Data With

    We share personal data only where necessary, and only with the following categories of recipient:

  • Accommodation providers and global hotel inventory partners to confirm and fulfil your booking.
  • Revolut as the regulated payment processor.
  • Hosting and infrastructure providers under appropriate technical and contractual safeguards.
  • Email and communications providers for booking confirmations and support replies.
  • Analytics and bot-protection services on a privacy-respecting basis.
  • Card schemes (Visa, Mastercard) and issuing banks, only in the event of a chargeback dispute and only to the extent required as evidence.
  • Regulators, tax authorities, and law enforcement where there is a legal obligation to disclose.
  • We do not sell personal data and do not share it for unrelated marketing purposes. Data Processing Addendums or equivalent contractual safeguards are in place with our key processors.

    International Transfers

    Where service providers operate outside the UK, we use appropriate safeguards such as Standard Contractual Clauses to protect personal data.

    Data Retention

    Personal data is kept only for as long as necessary for the purpose collected or to meet legal requirements, then securely deleted or anonymised. Indicative retention periods:

  • Booking and transactional records: 6 years from the date of booking, in line with HMRC tax record-keeping obligations.
  • Payment reference data (Revolut transaction reference, last 4 digits, card brand, 3-D Secure result, payment IP): 6 years, covering both tax obligations and the card scheme chargeback dispute window.
  • Account information: while the account is active, plus a reasonable period after closure to handle outstanding queries.
  • Marketing data: until consent is withdrawn or the contact becomes inactive.
  • Website logs and security records: typically up to 12 months.
  • Where data is retained beyond the original purpose, it is held only to the extent necessary to meet a specific legal or regulatory obligation.

    How We Protect Your Data

    We apply a layered set of safeguards proportionate to the sensitivity of the data we hold:

  • Encryption in transit (TLS 1.2 or above) on all connections to and from the platform.
  • Encryption at rest (AES-256) for our primary database.
  • Strict separation between Mix & Match Stays and the payment environment — full card numbers, expiry dates, and CVVs are entered into Revolut’s hosted form and never enter our systems.
  • Role-based access control: only staff who need data to perform their role can access it, with administrative actions logged to an audit trail.
  • Multi-factor authentication on staff and administrative accounts.
  • Continuous, encrypted database backups in line with our hosting provider’s standards.
  • Regular review of dependencies, libraries, and external service providers.
  • No system can be guaranteed completely secure, but we treat any suspected data incident seriously and will notify the Information Commissioner’s Office and affected users where required by law.

    Your Rights

    Users may request:

  • Access a copy of the data we hold about you
  • Correct any inaccuracies
  • Request deletion of your data
  • Restrict or object to processing
  • Data portability
  • Withdraw consent at any time (where processing is based on consent)
  • Requests should be sent to privacy@mixmatchstays.com. You may also complain to the Information Commissioner’s Office (ICO) at ico.org.uk . Note that requests to delete data within an active retention period — for example an open refund or chargeback window — may be lawfully refused under Article 17(3)(b) and (e) UK GDPR.

    Cookies

    We use cookies and similar technologies to improve your experience. For full details, please see our Cookie Policy.