Skip to content

Privacy policy

How Sunlit Villas uses personal information when you enquire, book, stay, or create an account. Last updated 15 September 2026. Our Terms & Conditions and Cancellation Policy apply alongside it.

1. Who we are

Sunlit Villas is a trading name of Sunlit Keys Ltd, a company registered in England and Wales (company number 15818391) with its registered office at 9 Hartshill Avenue, Oakengates, Telford, TF2 6AR, United Kingdom. We arrange holiday rentals of privately-owned villas in Cyprus, acting as booking agent for the property owners.

Sunlit Keys Ltd is the data controller. The UK General Data Protection Regulation and the Data Protection Act 2018 govern how we handle personal data. Because we offer our services to guests in the European Union, the EU General Data Protection Regulation (EU 2016/679) also applies to their data, and the rights below are the same under both.

Questions about this policy, or requests to exercise your rights, go to office@sunlitvillas.com.

2. What we collect, and when

An enquiry
Your name, email address, the message you write, and any dates, party size or villa you mention. The concierge and villa-listing forms also take a phone number if you give one.
A booking
The lead guest's name, email, phone number and postal address, the number of guests (adults, children and infants), your dates, any message to us, your acceptance of the terms, and whether you ticked the box for occasional emails from us.
A payment
Handled by Stripe, on Stripe's systems. Card numbers never reach our servers. We keep the amount, the date, the outcome (paid, refunded, failed), the invoice number, and Stripe's reference for the payment so we can reconcile and refund it.
An account
Your email and name, and a password if you set one, stored only as a one-way hash. If you add a passkey we store its public key and a name for the device, never a private key. If you turn on an authenticator app we store the shared secret it needs, and recovery codes as hashes. If you sign in with Google or Apple we store the identifier and email address they give us, nothing else from those accounts.
A review
Your rating and text, linked to your completed booking. On the site your name appears abbreviated to first name and last initial.
Correspondence
Emails we send you about a booking or enquiry, and messages you send us, are kept against your record so anyone on the team can pick up where a colleague left off.
Technical data
Your IP address, used to limit repeated submissions and to check that a form was sent by a person. Error reports if something breaks on a page, configured not to include personal data. Page views and a handful of anonymous events (a villa viewed, a price shown, a booking started), collected without cookies and without identifying you.

3. Why we use it, and on what basis

To perform the contract with you — taking and confirming a booking, collecting the deposit and balance, sending receipts, reminders and arrival details, handling changes, cancellations and the return of the security deposit, and passing the details the owner needs to host you.

In our legitimate interests — answering enquiries; keeping the site secure and free of abuse (rate limits, the bot check, fraud screening on payments); understanding how the site is used so we can improve it; keeping records of what was agreed in case of a dispute; and inviting you to review a stay you have completed.

With your consent — sending you occasional emails about our villas and offers, only if you ticked the box when booking or enquiring. You can withdraw that consent at any time using the link in any such email or by writing to us. Emails about your own booking are not marketing and continue regardless.

To meet legal obligations — keeping accounting and tax records of payments and refunds, and responding to lawful requests from authorities.

4. Who we share it with

We do not sell personal data, and we share it only with the organisations below, each of which processes it under a contract with us or as an independent controller of the part it handles.

The property owner
The owner or their management company receives the lead guest's name, contact details, party size and dates for the booking, so they can prepare the villa and reach you during your stay. They use it to host you and for no other purpose of ours.
Stripe
Our payment provider. Stripe receives your name, billing address and payment details to take the payment, screen it for fraud and process any refund. Stripe is an independent controller of the data it holds and publishes its own privacy policy.
Resend
Delivers our email. It sees the address and content of each message we send you.
Vercel
Hosts the website and provides the cookieless analytics. Requests to the site pass through Vercel's network.
Neon
Hosts our database, in Frankfurt, Germany.
Cloudflare
Stores villa photographs, and provides the check that a form was submitted by a person, which sees your IP address and browser characteristics.
Sentry
Receives error reports from the site so we can fix faults. Configured not to send personal data; a report may include the page you were on and a technical identifier for the request.
Google and Apple
If you choose to sign in with Google or Apple, that provider knows you signed in to our site. Villa pages may show a Google map, which is loaded from Google and subject to Google's privacy policy.
Holiday-rental calendars
To keep availability accurate we exchange calendar feeds with the platforms owners list on. What we publish contains only blocked date ranges — never a guest's name or details.

We may also disclose personal data where the law requires it, or to establish or defend a legal claim.

5. Where it is kept

We are based in the United Kingdom. Our database and file storage are in the European Union, which the UK recognises as providing adequate protection. Some of the providers above process data in the United States; those transfers rely on the UK extension to the EU–US Data Privacy Framework where the provider is certified under it, and otherwise on the UK International Data Transfer Agreement or Addendum in our contract with the provider, together with the provider's own safeguards. For guests in the EU, the equivalent EU adequacy decisions and standard contractual clauses apply.

6. How long we keep it

Bookings and payments
For as long as UK law requires a company's accounting records to be kept — currently six years from the end of the financial year of the booking — because the payment records are part of our accounts.
Unpaid bookings
A booking started but not paid for is cancelled automatically after 24 hours and kept only as a cancelled record with the rest of your booking history.
Enquiries and messages
For three years after our last contact with you, so that a returning guest is recognised, then deleted.
Accounts
Until you ask us to close the account. Sign-in sessions expire after 30 days; sign-in links after 15 minutes; email-confirmation links after 24 hours.
Reviews
For as long as the villa is listed, unless you ask for yours to be removed.
Error reports
Deleted by Sentry after 90 days.
Analytics
Held by Vercel in aggregate, with no identifier that links to you.

7. Cookies

The site sets no advertising or tracking cookies, and its analytics do not use cookies, which is why you were not asked to accept any. The cookies it does set are strictly necessary:

vp_session
Keeps you signed in to your account. Set only when you sign in; lasts 30 days or until you sign out.
vp_pending
Holds the state of a sign-in that is part-way through a second step. Short-lived.
Stripe
The payment form is provided by Stripe inside the page and may set Stripe's own cookies for fraud prevention, described in Stripe's privacy policy.

8. Your rights

Under the GDPR you may ask us to: give you a copy of the personal data we hold about you; correct anything inaccurate; delete it, where we have no continuing reason to keep it (we must keep booking and payment records for the period in section 6); restrict how we use it; provide it in a portable form; and stop using it for marketing, or for any purpose based on our legitimate interests where your situation warrants it. Where we rely on your consent you may withdraw it at any time.

Write to office@sunlitvillas.com. We may ask you to confirm your identity — usually by replying from the email address on the booking — and we will respond within one month.

You also have the right to complain to a supervisory authority. Ours is the UK Information Commissioner's Office. If you live in the European Union you may instead complain to the data protection authority in your own country, or to the Commissioner for Personal Data Protection of the Republic of Cyprus, where the villas are.

9. Security

Every connection to the site is encrypted. Passwords are stored as one-way hashes, and staff and partner accounts require a second sign-in step. Access to guest data is limited to the people who need it to manage bookings, and property owners see only the bookings for their own villas. Payment details are entered directly into Stripe and never pass through our systems.

10. Children

Bookings may only be made by adults. We record the number of children and infants in a party so the villa can be prepared, and nothing else about them.

11. Automated decisions

We make no decisions about you by automated means that have legal or similarly significant effects. The bot check on our forms and Stripe's fraud screening may block a submission or a payment automatically; if that happens to you in error, contact us and a person will look at it.

12. Changes to this policy

When this policy changes we update the date at the top and, for changes that affect how we use data you have already given us, tell you by email. The current version is always at this address.