MojPorat logoMojPorat

Privacy Notice

Last updated: 2026-08-17

Moolah Media, trading as MojPorat, is the data controller for personal data processed through MojPorat's website and owner accounts. For guest data that owners enter into their own account, the owner is the controller and we act as processor on their behalf.

1. Data we collect and why

  • Account data (name, email, login credentials, language): to create and secure your account and provide the service. Legal basis: performance of a contract.
  • Property and business data (objects, units, prices, tax settings, expenses, team members): to operate the features you use. Legal basis: performance of a contract.
  • Guest and reservation data entered by owners (guest names, dates of birth, identity document numbers, nationality, contact details, stay dates): to produce reservations, tourist-tax figures and eVisitor registrations on the owner's instruction. Legal basis: the owner's legal obligation and contract; we process it as their processor.
  • Support messages: to answer you. Legal basis: legitimate interests.
  • Usage, device and log data (IP address, browser, pages and actions, error reports): to keep the service secure, diagnose problems and improve the product. Legal basis: legitimate interests.
  • Marketing communications: only where you have opted in. Legal basis: consent, withdrawable at any time.

Card and billing data is collected and processed by Paddle as Merchant of Record — we never see or store full card details.

2. Who we share data with

  • Hosting, database and email infrastructure providers operating the platform on our instruction.
  • Paddle.com, our Merchant of Record, for sale of subscriptions, payments, invoicing and tax compliance.
  • Systems you connect yourself: eVisitor / the Croatian tourist board, booking channels such as Booking.com or Airbnb, and your own payment account for guest card deposits.
  • AI providers used to draft guest replies, processing only the message text needed to produce a draft.
  • Professional advisers (legal, accounting) and authorities where required by law.

3. International transfers

Data is primarily processed in the EU. Where a provider processes data outside the EEA, transfers rely on an adequacy decision or on Standard Contractual Clauses with appropriate safeguards.

4. Retention

Account and reservation data is kept for as long as your account is active and, after closure, for 30 days for export, then deleted or anonymised — except where longer retention is required by law (for example accounting and tax records, typically kept for the statutory period). Log data is kept for up to 12 months.

5. Your rights

Under the GDPR you may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests. You may withdraw consent at any time. Contact us at alex@moolahmedia.co and we will respond within one month. You can also complain to your supervisory authority — in Croatia, AZOP (Agencija za zaštitu osobnih podataka).

6. Security

We apply appropriate technical and organisational measures: encryption in transit, encrypted storage of integration credentials, row-level access control so each account only reaches its own data, role-based team permissions and audited administrative access.

7. Cookies

We use strictly necessary cookies and local storage for sign-in sessions, language choice and offline calendar access. We do not set advertising cookies on this site. Owners may enable their own analytics or pixel tracking (for example Meta Pixel or GA4) on their booking page or embedded widget — that tracking is configured and controlled by the owner, who is responsible for obtaining guest consent where required. You can clear or block cookies in your browser settings.