Privacy policy.

What we collect, why, how long we keep it and what you can ask of us. Written to be read, not to be ticked.

In short

Visitor figures without cookies

We count visits on our own server. No cookie, nothing stored in your browser, no third party. Your IP address is never stored — it is salted and hashed purely to tell one visit from another, and the salt changes every day, so yesterday's figures cannot be linked to today's. Respects Do Not Track.

Google and Meta only if you say yes

Google Analytics, Google Ads and the Meta pixel set cookies and send data to Google and to Meta. They are switched off until you explicitly agree in the box at the foot of the page. If you decline, no cookie is set and nothing is sent.

If you said yes, it is also recorded when you send an enquiry, so that we can see which page and which language actually lead to a trip. What is sent is the shape of the trip: language, package, the page the enquiry came from, the number of nights, the number of golfers and companions, the room type, and the price rounded to the nearest thousand kronor.

Your name, your email address, your telephone number, your message and your departure date are never sent to Google or Meta. Those stay with us.

What a booking needs

If you book a trip, the airline and the golf clubs need passport numbers, dates of birth and golf IDs. That is why we ask — and not for anything else.

Your own page — My trip

With your booking number and the key from the quote email you sign in to My trip and see your booking, your documents and your payment. That is also where you fill in passport details, date of birth and golf ID yourself, rather than emailing them.

What you enter stays on the web server only until our booking system collects it — usually a few minutes, at most until the next time we open the system. The server copy is deleted in that same call.

Your passport number is never shown again once you have saved it. The page shows only the last four digits, so you can see which passport we already have. Anyone who got hold of your key would reach a status page, not your passport details.

Legal basis: performance of the contract — without these details, flights and tee times cannot be booked.

Data controller

Meridian Fairways ApS, [REGISTRATION NUMBER], [POSTAL ADDRESS], Mauritius.

Email hello@meridianfairways.com, telephone +41 76 628 88 69.

Which law applies

We are established in Mauritius and are therefore subject to the Data Protection Act 2017, which rests in all essentials on the same principles as the European data protection regulation.

Because we sell trips to you who live in the EU and EEA — this site exists in Swedish, German and French, and prices are shown in euros and kronor — we are also subject to the GDPR, under Article 3(2). Both regimes apply, then, and where they differ we follow whichever gives you the stronger protection.

Your information is processed in Mauritius. Mauritius has no adequacy decision from the European Commission. Your giving the information directly to us is not in itself a third-country transfer within the meaning of the Regulation — we are the recipient and are already bound by the GDPR — but you should know where the information sits, and it sits here.

When you visit the site

Every page view sends one line to our own server. The line holds the time, which page you read, its language, which domain you came from (the domain only, never the full address), whether the screen is a phone, a tablet or a computer, and your time zone — for example Europe/Stockholm. The time zone is used instead of looking your IP address up in a geography database.

Your IP address is not stored. It is combined with a salt that changes every day and hashed to twelve characters, purely so that two page views can be counted as one visit. The hash cannot be turned back into an IP address, and yesterday’s hashes cannot be matched to today’s.

We use no cookies for this and store nothing in your browser. If you have Do Not Track switched on, nothing at all is sent.

Legal basis: legitimate interest — knowing how many people read the site and which pages work. The data is pseudonymised and cannot be tied to you as a person.

Kept: 14 months, one log file per month.

Google Analytics and Google Ads

If you agree, we load Google Analytics (measurement ID G-PGQ3KEWHXV) and Google Ads. They set cookies in your browser and send information about your visit to Google Ireland Limited, which also processes it in the United States.

Before you agree, everything is off: ad storage, ad user data, ad personalisation and analytics storage are all set to denied. No cookie is set. If you choose No thanks, it stays that way.

If you agree, Google can recognise your browser between visits and, if you are signed in to a Google account, connect the visit to that account. Collection goes to Google’s European servers and IP anonymisation is on.

Legal basis: your consent. You can withdraw it at any time by clearing site data for meridianfairways.com in your browser — the question then comes back.

Kept: according to the property's setting in Google, at most 14 months.

The Meta pixel

If you agree, we also load the Meta pixel — the one that measures advertising on Facebook and Instagram. It sets cookies in your browser and sends information about your visit to Meta Platforms Ireland Limited, which also processes it in the United States.

The pixel is not on the page at all until you have said yes. It is the same box and the same answer that govern Google’s tags — one yes covers both, one no covers both. If you choose No thanks, the pixel’s file is never fetched, and Meta is never told you were here.

If you agree, Meta can recognise your browser between visits and, if you are signed in to Facebook or Instagram, connect the visit to your account.

We send Meta the same limited information as Google: the shape of the trip — language, package, number of nights, size of the party, room type and the price rounded to the nearest thousand. Never your name, your email address, your telephone number or your message.

Legal basis: your consent. You withdraw it the same way as for Google — clear site data for meridianfairways.com and the question comes back.

Kept: under Meta’s own terms for data sources; we keep none of it ourselves.

When you send an enquiry

The form sends what you filled in to our own server: name, e-mail address, telephone number if you gave one, which package or which combination of your own you chose, departure and return, number of nights, how many are playing golf and how many are coming along, room type, language, currency and any message.

The enquiry is stored in a file above the web root — unreachable from the web — and collected from there into our booking system, which runs on our own machine and is not reachable from the internet.

You get a confirmation by e-mail. It is sent through our e-mail provider Postmark, a service of ActiveCampaign, LLC, USA, which processes your e-mail address and the content of the message on our behalf.

Legal basis: steps taken at your request before a possible contract.

Kept: 24 months from the last contact, if no booking comes of it.

When you book

To book flights, hotel and tee times we need more about each traveller: title, name exactly as it stands in the passport, passport number and expiry, nationality, date of birth and — for those playing — golf ID and handicap. A frequent flyer number too, if you want it used.

We ask only the people who actually play for a golf ID, and only one person in the party for contact details, because the airline wants one contact per booking.

The information is passed to those who deliver the trip: the airline, the hotel, the golf clubs, the transport company and the excursion operators. Most of them are in Mauritius, as we are; the airline may be anywhere along the way. Without passing it on there is no booking — it is necessary to perform the contract you have entered into with us.

We pass on only what each recipient needs: the golf club gets a name and a golf ID, not your passport number; the airline gets the passport details, not your handicap.

Payment details are handled by the bank. We neither receive nor store card numbers.

Legal basis: performance of a contract. For the accounts: legal obligation.

Kept: travel documents 24 months after you return, records covered by the accounting act seven years.

The app

Our app for iPhone and Android shows the same booking as My trip, and the day-by-day plan as well. You sign in with the same booking number and key. The app has no accounts and no passwords, and you cannot sign in with Google or Facebook.

There is no measurement in the app at all: no Google Analytics, no Meta pixel, no advertising tools and no third-party libraries that collect anything about you. The consent box is for the website and is not needed in the app.

The app keeps you signed in, unlike the website. On My trip the key is erased when you close the tab, because that page may be opened on a borrowed computer in a hotel lobby. A telephone is personal, so the app keeps the key in the phone’s secure storage instead — the Keychain on iPhone, the Keystore on Android — where it is protected by the phone’s own lock. Signing out erases it, and everything saved on the phone with it.

The app keeps your trip on the phone so that you can read it with no signal: the status, the payment plan, the day-by-day itinerary and any documents you have opened.

Passport numbers, dates of birth and passport expiry dates are never kept on the phone. The server never sends them back — only the last four digits of the passport number — and the app strips those fields out as well before anything is saved.

If you say yes to notifications, the app registers a notification token with Expo (USA), the service that builds the app, which in turn hands the notification to Apple or Google. A token is a postbox to your particular installation of the app. It does not contain your name, it cannot read anything on the phone, and here it is held against your booking number and nothing else.

We send six kinds of notification and no others: that the quote is ready, that we have answered you, that a document exists, that the trip is confirmed, that a payment falls due within the week, and that a time in the itinerary has changed. Never marketing. If you switch notifications off in the app, or sign out, your token is deleted here.

Payment happens on Stripe’s own page in the phone’s browser. The app never receives your card number.

Legal basis: performance of the contract for the booking and the itinerary; your consent for notifications.

Kept: on the phone until you sign out or delete the app. Your notification token is deleted here when you switch notifications off, when you sign out, or when Apple or Google tell us the installation no longer exists.

What is stored in your browser

We set no cookies of our own. Three values are stored locally in your browser and are never sent to us:

mft-lang — which language you chose. mft-cur — which currency prices are shown in. mft-consent — whether you said yes or no to Google and Meta.

If you say yes, Google sets cookies of its own, among them _ga, and Meta sets its own, among them _fbp.

Your rights

You have the right to know what data we hold about you and to get a copy of it, to have incorrect data corrected, to have data erased once we no longer need it, to object to processing that rests on legitimate interest, to ask for restriction, and to receive the data you gave us in a machine-readable format.

Write to hello@meridianfairways.com. We answer within one month.

If you are not happy with how we handle your data you can complain to the supervisory authority in the country where you live — in Sweden that is Integritetsskyddsmyndigheten (IMY) — or to the Data Protection Commissioner in Mauritius.

Changes

If we change anything in this policy we update the date below. Changes that affect what we do with information already collected, we tell you about directly.

Last changed 11 August 2026.