|
Privacy Policy for the Holiday Availability Calendar website, service and mobile app.
This policy explains what personal data we collect, how we use it, and the rights you have. It applies to our websites, the Holiday Availability Calendar service, and the HAC Manager mobile app. Last updated: 16 August 2026.
WHO WE ARE
The Holiday Availability Calendar provides tariff and availability calendar services for holiday rental properties. We are the data controller for the personal data described in this policy. You can contact us at any time using the contact form on our website.
WHAT DATA WE COLLECT
Account data: the name, email address and account details you provide when you register or subscribe. Property and booking data: the properties, availability, tariffs, booking dates and any guest details you choose to enter. Payment data: when you subscribe, payment is handled by our payment provider (Stripe); we do not store your full card details on our systems. Technical data: standard server logs, including IP address and browser information, kept for security and to operate the service. Cookies: see our Cookie Policy for details.
HOW WE USE YOUR DATA
We use your data to provide and operate the calendar and booking service, to display availability and tariffs as you configure them, to take payment for subscriptions, to send you service and account notifications (such as renewal reminders), and to keep the service secure. We do not sell your data, and we do not pass it to any third party except as needed to run the service (for example, our payment provider) or where required by law.
THE HAC MANAGER MOBILE APP
The HAC Manager app connects to your existing Holiday Availability Calendar account using an API key. Your API key and secret are stored securely on your own device using the operating system's secure storage (the iOS Keychain), and are sent only to your own calendar server over an encrypted (HTTPS) connection. The app does not include third-party advertising or tracking, and does not collect analytics about you.
LEGAL BASIS (GDPR)
Where the UK GDPR and EU GDPR apply, we process your data on the basis of the contract we have with you (to provide the service you have signed up for), our legitimate interests (to operate and secure the service), and, where relevant, your consent (for example, non-essential cookies). Data is processed in accordance with applicable data protection law.
DATA RETENTION
We keep your account data for as long as your account is active. If an account is not renewed, the information continues to display for 30 days after the expiry date. After this period, if renewal is still outstanding, the account and all associated data are permanently deleted and cannot be retrieved. We keep regular backups for recovery purposes.
YOUR RIGHTS
You have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, and to receive a copy in a portable format. To exercise any of these rights, contact us using the form on our website. If you are in the UK you may also complain to the Information Commissioner's Office (ICO); if you are in France you may complain to the Commission Nationale de l'Informatique et des Libertes (CNIL).
SECURITY
We take reasonable technical and organisational measures to protect your data, including encrypted connections and access controls. However, no online service can be guaranteed to be completely secure, and you provide data at your own risk.
CHANGES TO THIS POLICY
We may update this policy from time to time. The latest version will always be available on this page, with the date it was last updated shown at the top.