Reset Password

Privacy Policy

Privacy Policy

This Privacy Policy explains how Casasoft Ltd, trading as Rent A Boat (“we”, “us”, “our” or “the Platform”), collects and uses personal data when you visit rentaboat.com.mt, register an account, list a boat, make or receive a booking, contact us, or otherwise use our services.

We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”), the Maltese Data Protection Act (Cap. 586) and Subsidiary Legislation 586.01 (the Maltese implementation of the ePrivacy Directive). For the purposes of the GDPR, Casasoft Ltd is the data controller for personal data we collect through the Platform.

1. Who we are

Casasoft Ltd, trading as Rent A Boat
Company registration number: C49034
VAT number: MT19736837
Registered office: 113, Mdina Road, Qormi QRM 9016, Malta
Privacy enquiries: [email protected]
General enquiries: [email protected] · [email protected]

We have not formally appointed a Data Protection Officer under Article 37 GDPR because our processing activities do not meet the thresholds set in that Article. For all privacy enquiries, please write to [email protected].

2. Scope and key roles

This policy covers personal data we process as the operator of the Platform: data we collect on the website, in your account, during a booking, in messages routed through the Platform, in support enquiries, and from your interactions with our marketing.

The Platform is a marketplace. Boats are listed by independent third-party owners (each an “Owner”) and rented by users who book them (each a “Renter”). The rental contract is formed between the Renter and the Owner, not with us. From the moment a booking is confirmed, the Owner is an independent data controller with respect to the personal data they receive from the Renter for the purpose of performing the rental (for example, to verify a skipper licence at handover, communicate about the charter, or process a damage claim). Each Owner is responsible for their own compliance with the GDPR and Maltese data protection law in that capacity.

Where we process personal data on instructions from an Owner (for example, hosting their listing content), we act as a data processor for that Owner under Article 28 GDPR, and our written terms with Owners govern that role.

3. Personal data we collect

The data we collect depends on how you use the Platform.

3.1 When you create an account

  • Name, email address, password (stored hashed), phone number
  • Account type (Renter, Owner, or both) and language preference
  • Profile photo, if you choose to upload one
  • For Owners only: trading name, VAT number, billing address, payout details for our payment processor (see section 6)

3.2 When an Owner creates a listing

  • Boat details: type, model, year, capacity, equipment, location, photos, availability calendar
  • Price, security-deposit amount, cancellation policy chosen for the listing
  • Operator licences, insurance information and any qualifications the Owner chooses to publish

Owners must only upload data they are entitled to publish. Owners must not publish other people’s personal data (for example, photos of identifiable individuals) without a lawful basis.

3.3 When you book a boat or send messages through the Platform

  • Booking dates, party size, special requests
  • Messages exchanged between Renter and Owner via our messaging feature
  • Order reference, total price, currency (EUR), tax breakdown

3.4 Payment data

Card payments are processed by Stripe (Stripe Payments Europe Ltd, Ireland) directly. Card numbers, expiry dates and CVV codes are entered into Stripe’s secure fields and are not seen or stored by us. We receive only the payment status, the masked last four digits of the card, the card brand, the country of issue, the booking reference and the amount.

Security and damage deposits are not processed by the Platform. Owners collect any deposit directly from the Renter at handover (for example by cash or by their own card terminal). Any data exchanged in that context is between the Renter and the Owner.

3.5 When you contact support

  • Your name, contact details, the content of your enquiry, attachments you choose to send, and any related booking reference

3.6 Browsing data

  • IP address, approximate location derived from IP, device type, browser, operating system, referring URL
  • Pages viewed, search queries on the Platform, listings viewed and favourited
  • Cookie identifiers and similar identifiers (see section 8)
  • Server logs of API and page requests, including timestamps and HTTP status codes

3.7 Reviews and user-generated content

  • Reviews you write after a completed booking (rating, free-text comment, photos)
  • Replies from Owners to reviews

3.8 Sensitive data

We do not ask for special categories of personal data under Article 9 GDPR (for example, health, ethnicity or biometric data). Please do not include such data in messages, support tickets or reviews. If you do, we will only process it to handle the matter you raised and we may delete it once handled.

4. Lawful bases for processing

We rely on the following lawful bases under Article 6(1) GDPR.

Where we rely on legitimate interests under Article 6(1)(f), we have carried out a balancing test and you can ask us for a summary of it by writing to [email protected].

5. How renters and owners share data through the Platform

Because the Platform is a marketplace, Renter and Owner data is shared in a controlled way through the booking flow.

5.1 Before a booking is confirmed

An Owner can see the Renter’s public profile (first name, profile photo, public reviews) and the content of the booking enquiry. The Renter can see the Owner’s public listing details and trading name. Email addresses and phone numbers are not exchanged at this stage.

5.2 At booking confirmation

Once a booking is confirmed and paid, we share the Renter’s full name, email address and mobile number with the Owner so that they can coordinate the charter. We share the Owner’s contact details with the Renter for the same reason. From this moment the Owner is an independent data controller for the data we have shared with them and is responsible for handling it lawfully.

5.3 At handover

For bareboat charters and jet-ski rentals, the Owner verifies the Renter’s identity and any required skipper licence at handover by sight. The Platform does not collect, store or transmit any image of those documents.

5.4 After the charter

If a Renter posts a review, their first name, last initial and profile photo appear next to it on the listing. The full review text and rating are visible to anyone who can see the listing.

6. Recipients and sub-processors

We share personal data only with the recipients listed below. Where the recipient is a service provider acting on our instructions, we have a data-processing agreement in place under Article 28 GDPR.

WhatsApp click-to-chat: where we display a “chat on WhatsApp” button, clicking it opens WhatsApp on your device using a deep link. We do not embed any WhatsApp script on our pages and we do not pass personal data to WhatsApp from our site. Once you continue the conversation in WhatsApp, that exchange is governed by your separate relationship with WhatsApp Ireland Ltd.

We do not sell personal data, and we do not share it with third parties for their own marketing.

7. International transfers

The Platform is operated from Malta, and we prefer EU-based suppliers. Where personal data is transferred outside the European Economic Area – for example to Google or Meta processing in the United States – we rely on one or more of the following safeguards under Chapter V GDPR:

  • An adequacy decision adopted by the European Commission;
  • The European Commission’s Standard Contractual Clauses, supplemented where necessary by additional technical and organisational measures;
  • Certification of the recipient under the EU–US Data Privacy Framework where it applies.

You can request a copy of the relevant safeguard by writing to [email protected].

8. Cookies and similar technologies

Cookies are small text files stored on your device when you visit a website. They allow the Platform to remember you, keep you signed in, measure how the Platform is used and serve relevant marketing. We use cookies in line with Subsidiary Legislation 586.01 in Malta and Article 5(3) of the ePrivacy Directive.

When you first visit the Platform, our cookie banner asks for your consent to non-essential cookies. You can change your choice at any time using the “Cookie settings” link in our footer.

You can also block or delete cookies through your browser settings, but doing so may affect how the Platform works.

9. How long we keep your data

Where we no longer have a lawful basis to keep your data, we delete it or irreversibly anonymise it. We may keep anonymised statistics indefinitely.

10. Your rights

Under the GDPR you have the rights below in relation to your personal data.

Right of access (Article 15)
You can ask for a copy of the personal data we hold about you.
Right to rectification (Article 16)
You can ask us to correct inaccurate or incomplete data. Most fields can also be edited directly in your account.
Right to erasure (Article 17)
You can ask us to delete your data where one of the grounds in Article 17 applies. We may keep some data where another lawful basis requires it (for example, accounting records).
Right to restriction (Article 18)
You can ask us to limit our processing while we check a request you have made.
Right to data portability (Article 20)
For data we hold on the basis of your consent or to perform a contract with you, you can ask us to provide it in a structured, commonly used, machine-readable format.
Right to object (Article 21)
You can object to processing based on our legitimate interests, including profiling. You can object to direct marketing at any time and we will stop.
Rights in relation to automated decision-making (Article 22)
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing.
Right to withdraw consent
Where we rely on your consent, you can withdraw it at any time without affecting the lawfulness of earlier processing.

To exercise any of these rights, please write to [email protected] from the email address linked to your account, or include enough information for us to verify your identity. We will respond within one month under Article 12(3) GDPR. We may extend that period by up to two further months for complex or numerous requests, in which case we will tell you within the first month.

11. Closing your account

You can close your account from your profile settings or by writing to us. After you close your account we keep it in a deactivated state for 30 days so that you can reverse the closure if you change your mind. After that grace period we delete or anonymise your account data, except for the records we are required or entitled to keep under section 9 (in particular, accounting records, bookings already made, and dispute evidence). Reviews you have written remain published in pseudonymised form (first name and initial) so that the marketplace remains useful for other users.

12. Complaints to the IDPC

If you believe we have processed your personal data unlawfully, please contact us first at [email protected] so that we can try to resolve the matter quickly. You also have the right under Article 77 GDPR to lodge a complaint with a supervisory authority. The Maltese supervisory authority is:

Information and Data Protection Commissioner (IDPC)
Floriana, Malta
Website: idpc.org.mt
Email: [email protected]

If you live in another EU or EEA country, you may also lodge a complaint with the supervisory authority in your country of residence or workplace.

13. Children

The Platform is intended for adults. You must be at least 18 years old to register an account, list a boat or make a booking. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please write to [email protected] and we will delete it.

14. Security

We apply technical and organisational measures appropriate to the risk under Article 32 GDPR, including TLS encryption in transit, access controls on our systems, vetted suppliers, periodic backups, hashed passwords, and logging of administrative access. No system is perfectly secure; if we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the IDPC under Article 33 GDPR and, where required, you under Article 34 GDPR.

15. Changes to this policy

We may update this Privacy Policy from time to time. The version number, “last updated” date and effective date appear at the top of this page. For material changes we will give you reasonable advance notice by email to your registered address or by a prominent banner on the Platform.

This policy works alongside our Terms & Conditions. If anything in this policy is inconsistent with mandatory provisions of Maltese or EU law, those provisions prevail.

  • Advanced Search

    Guests
    Adults
    Ages 13 or above
    0
    Children
    Ages 2 to 12
    0
    Infants
    Under 2 years
    0
    Close
    More Search Options
  • Reset Password