Privacy Notice
Last updated: 2026-08-17
This is a translation. The Croatian version is legally binding. See the Croatian original.
Moolah Media, trading as MojPorat, is the controller for personal data processed through the MojPorat website and host accounts. For guest data that a host enters into their own account, the host is the controller and we act as processor on their behalf.
1. What data we collect and why
- Account data (name, email, login credentials, language): to open and secure your account and provide the service. Legal basis: performance of a contract.
- Property and business data (properties, units, prices, tax settings, expenses, team members): to operate the features you use. Legal basis: performance of a contract.
- Guest and reservation data entered by the host (guest name, date of birth, ID number, nationality, contact details, stay dates): to create reservations, calculate tourist tax and register guests with eVisitor at the host's instruction. Legal basis: legal obligation and the host's contract; we process it as their processor.
- Support messages: so we can reply to you. Legal basis: legitimate interest.
- Usage, device and log data (IP address, browser, pages and actions, error reports): for service security, troubleshooting and product improvement. Legal basis: legitimate interest.
- Marketing messages: only if you've opted in. Legal basis: consent, which you can withdraw at any time.
Card and billing data is collected and processed by Paddle as the Merchant of Record — we never see or store full card details.
2. Who we share data with
- Hosting, database and email infrastructure providers who maintain the platform on our instructions.
- Paddle.com, our Merchant of Record, for subscription sales, payments, invoicing and tax obligations.
- Systems you connect yourself: eVisitor or the local tourist board, sales channels such as Booking.com and Airbnb, and your own account for charging guests' card deposits.
- AI service providers to draft replies to guests, processing only the message text needed to create the draft.
- Professional advisers (legal, accounting) and competent authorities when required by law.
3. International transfers
Data is primarily processed within the European Union. When a provider processes data outside the EEA, the transfer relies on an adequacy decision or on standard contractual clauses with appropriate safeguards.
4. Data retention
We keep account and reservation data while your account is active and for a further 30 days after closure for export, after which we delete or anonymise it — except where longer retention is required by law (for example accounting and tax records, kept for the legally required period). System logs are kept for up to 12 months.
5. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict processing, port your data, and object to processing based on legitimate interest. You can withdraw consent at any time. Contact us at alex@moolahmedia.co and we will respond within one month. You can also lodge a complaint with a supervisory authority — in Croatia this is AZOP (the Croatian Personal Data Protection Agency).
6. Security
We apply appropriate technical and organisational measures: encryption in transit, encrypted storage of integration credentials, row-level access control so each account sees only its own data, role-based team permissions, and logged administrative access.
7. Cookies
We use only essential cookies and local storage for sign-in, language selection and offline calendar operation. We do not set advertising cookies on this site. Hosts may enable their own analytics or pixels (for example Meta Pixel or GA4) on their booking page or embedded widget — such tracking is set and controlled by the host, who is responsible for obtaining guest consent where required. You can delete or block cookies in your browser settings.