On this page
How Coble handles your guests’ personal information on your behalf. It meets Article 28 of the UK GDPR, and is part of the terms for owners.
Who is who
You — the business using Coble — are the controller of your guests’ personal information. Coble is your processor. This agreement lasts as long as you use Coble, and until the information has been returned or deleted afterwards.
What is processed
- Whose: your guests and hirers, and the people on your team.
- What: names, email addresses, telephone numbers, party sizes, dates and times, notes, add-ons, booking and payment status, and reviews.
- Why: to take and manage bookings, send the emails about them, take payment through Stripe, and keep records — the service described in the terms.
Only on your instructions
Coble processes the information only to provide the service to you — the terms, and what you do in your panel, are your instructions — unless the law requires otherwise, in which case we will tell you first where the law allows.
Confidentiality
Anybody at Coble who can reach the information is bound to keep it confidential.
Security
Encryption in transit, passwords stored only as one-way hashes, two-step sign-in, access limited by role, each business’s information kept separate from every other’s, and card details held only by Stripe.
Sub-processors
You authorise Coble to use these providers, each under a contract that protects the information at least as well as this one. We will email you before adding or replacing one, so you can object.
- Hostinger International Ltd — Hosting the website and the database
- Brevo (Sendinblue SAS) — Sending confirmation and reminder emails
- Cloudflare, Inc. — Delivering the site securely
- Stripe — Taking payments, into your own Stripe account
Where a provider handles information outside the UK, the transfer is protected by UK adequacy regulations or the ICO’s International Data Transfer Agreement or Addendum.
Helping with guests’ rights
Your panel lets you find, export and erase a guest’s information. If a guest asks Coble directly, we will pass the request to you promptly and help you answer it.
If something goes wrong
We will tell you without undue delay — within 48 hours where we can — after becoming aware of a breach affecting your guests’ information, with what we know, so you can meet your own duty to report it. We will also help with any assessment you need to carry out.
How long, and at the end
Guests’ names and contact details are removed 24 months after their last stay, unless you choose another period; dates and amounts are kept as your accounting records. When you leave Coble your bookings can still be exported for 90 days; after that the personal information is deleted, unless the law requires it to be kept.
Showing that we comply
We will give you the information you reasonably need to show that this agreement is kept, and allow a reasonable audit on reasonable notice, no more than once a year unless there has been a breach.