Montenegro Select
Privacy Policy
Last updated: August 17, 2026 · v2.0.0
Privacy Policy
1. Data controller
The controller of personal data collected through the Montenegro Select digital platform (montenegroselect.me, hereinafter: the "Platform") is the company Velocci D.O.O., Trg Magnolije, Zgrada 2B, Stan 4, Tivat, Montenegro, registration number (CRPS) 5-1312531/001, tax identification number (PIB) 03757137 (hereinafter: "we", "us" or "our").
For any questions regarding the protection of personal data you can contact us at hello@montenegroselect.me or by phone at +382 45 763 241.
For the processing of data relating to bookings, payment collection, cancellations and returns of funds, the controller is Velocci. For operational purposes directly connected with the performance of the booked service, the controller of personal data is the service provider with whom you booked (see section 4).
We are committed to protecting our customers' personal data by collecting only the necessary, basic data required to fulfil our obligations; by informing customers about how the collected data is used; and by enabling them to exercise the rights set out in section 6. We do not use your data for marketing campaigns without your consent. All customer data is strictly safeguarded and is accessible only to employees who need it to perform their work. All our employees and business partners are responsible for respecting the principles of privacy protection.
2. What data we collect
a) Booking data
When you submit a booking request or make a booking through the Platform, we collect: first and last name, e-mail address, telephone number, the number and composition of guests, special requests and notes you enter yourself, and details of the booked service (time slot, location, price).
b) Payment data
When you pay by card, you enter your card details (card number, CVV) exclusively into the protected fields of the certified payment processor AllSecure doo; the charge is processed by Hipotekarna banka AD Podgorica. Your card number is at no point stored on our systems, nor is it accessible to us. From the payment processor we receive and retain the transaction status, amount, currency, card type and masked (truncated) card number, the transaction authorisation code, and the billing address you enter when paying.
c) Data generated by use of the Platform
A session identifier during booking, a pseudonymous identifier used to remember your saved choices (favourite services, planner answers), your language setting, and — only with your consent — analytics data and visit-source data (e.g. campaign UTM parameters); details are in section 7 (Cookies). We record your IP address and browser details in exactly two cases: when you confirm acceptance of the terms of use (as evidence of acceptance and of the version of the accepted documents) and when you make a card payment, when the IP address is passed to the payment processor as part of the mandatory 3-D Secure check.
d) Communication
The content of communication you have with us (e-mail, forms on the site), including complaints and refund requests with supporting documentation.
e) Partner (operator) data
For users of the partner portal we collect business contact details, account data and data necessary for payouts and settlements, as well as technical error records from the portal (browser details and error content, without the IP address).
Providing the data under points a) and b) is a condition for concluding and performing the booking contract — without it, the booking and payment cannot be processed. All other data is provided voluntarily.
3. Purposes and legal bases of processing
| Purpose | Data | Legal basis |
|---|---|---|
| Processing bookings and requests, communication about the booking, execution of payments and refunds | 2a, 2b, 2d | Performance of a contract / steps prior to entering into a contract |
| Sending transaction and booking confirmations (e-mail) | 2a, 2b | Performance of a contract; card scheme and acquiring bank rules |
| Retention of transaction documentation and handling of transaction complaints | 2a, 2b, 2d | Legal obligations; contract with the acquiring bank (3-year retention period) |
| Prevention of fraud and abuse | 2a, 2b, 2c, 2d | Legitimate interest; protection of the payment system |
| Site operation: booking session, language, saved choices | 2c | Legitimate interest / necessity for providing the service you requested |
| Visit analytics and campaign measurement | 2c | Consent (cookie banner); until consent is given, this data is not collected |
| Operation of the partner portal (sign-in, error monitoring) | 2e | Performance of the contract with the partner; legitimate interest |
We do not use your data for automated individual decision-making that produces legal effects or similarly significantly affects you, nor do we sell it to third parties.
4. Who we share data with
- Service providers (partners): the partner with whom you book receives the booking details (first and last name, e-mail, telephone, time slot, number of guests, notes) — without any card data — for the purpose of performing the service. For that data, in the part relating to the performance of the service, the partner is an independent controller. The partner has no right to use that data for any other purpose, including marketing, without your express consent.
- AllSecure doo — card payment processor (PCI-DSS Level 1); processes card data on our behalf.
- Hipotekarna banka AD Podgorica — acquiring bank; processes transactions and, in the event of a transaction complaint, the related documentation.
- Technical processors (by category): application and database hosting providers, the transactional e-mail delivery service, interactive map display services and the technical error-monitoring service on the partner portal, as well as the visit analytics tool (Google Analytics — only with your consent). You can request the current list of specific processors at any time via the contacts in section 1.
- State authorities — where we are required to do so by law.
Platform data is primarily stored on servers in the European Union (Ireland). We conclude appropriate data processing agreements with all processors. Where particular data is exceptionally processed outside Montenegro or the EU/EEA, the transfer is based on appropriate safeguard mechanisms, including standard contractual clauses. You can request a copy of the applied safeguards via the contacts in section 1.
5. How long we keep data
- Transaction and booking documentation: at least 3 years from the date of authorisation of the transaction (obligation towards the acquiring bank), or longer where required by accounting and tax regulations.
- Complaints: complaint documentation is kept within the period set out in the previous point; the deadlines for submitting complaints are governed by the Terms of Use.
- Cookie consent record: 12 months, after which consent is requested again.
- On-device identifiers: within the categories and rules set out in section 7; preference identifiers expire at the latest 12 months after your last visit, or earlier if you delete them from your browser.
- Support communication: for as long as needed to resolve the request and evidence our handling of it, and at most within the statutory limitation periods.
6. Your rights
In accordance with the Personal Data Protection Act of Montenegro, and for persons in the EU/EEA also in accordance with the GDPR, you have the right to: access your data; rectification of inaccurate data; erasure; restriction of processing; objection to processing based on legitimate interest; data portability; and withdrawal of consent at any time (without affecting the lawfulness of processing before the withdrawal) — for cookies, you can withdraw consent in the manner described in section 7.
Requests should be submitted via the contacts in section 1. We will respond without undue delay. You also have the right to lodge a complaint with the supervisory authority: the Agency for Personal Data Protection and Free Access to Information of Montenegro (AZLP), www.azlp.me. If you are located in the EU/EEA, you may also lodge a complaint with the supervisory authority in the country of your habitual residence.
7. Cookies and similar technologies
On the Platform we use cookies and similar browser storage (e.g. localStorage). On your first visit, a banner is displayed on which you can accept or decline analytics and marketing cookies. Consent is valid for 12 months and you can change it at any time by deleting the site data from your browser, after which the banner is displayed again; a consent setting will also be available via a link in the site footer.
We use cookies in the following categories:
- Necessary — enable core functions: carrying an in-progress booking, protection against abuse during payment, the record of your cookie decision and partner sign-in to the business portal. We set these ourselves and they cannot be switched off, because without them the site, bookings and payments do not function.
- Preferences — remember your choices for a better experience: your selected language and a pseudonymous device identifier through which we store your favourite services and saved plans. They are not used for tracking beyond the Platform. We set these records on the basis of our legitimate interest in the site remembering your choices; you can remove them at any time by deleting the site data in your browser.
- Analytics — visit and site-usage statistics via the Google Analytics tool. It is enabled only with your consent; until consent is given, analytics cookies are not set.
- Marketing / attribution — remembering the source of your visit (e.g. advertising campaign parameters) to measure advertising effectiveness. The data is stored locally on your device and is used only with your consent.
- Third parties during payment — the payment processor AllSecure and the bank that issued your card (as part of the 3-D Secure check) may set their own cookies necessary for the secure execution of the card payment, in accordance with their own privacy policies.
- Maps — interactive map display services (Mapbox; Google Maps in the partner portal) may use their own storage in accordance with their own policies.
The specific names and lifetimes of individual cookies may change over time as the Platform develops; the categories, purposes and consent rules described in this section remain authoritative. Declining optional cookies does not affect your ability to browse the site or to make bookings and payments.
8. Security
We apply technical and organisational protection measures: data transmission is encrypted (TLS), card data is processed exclusively by a PCI-DSS certified processor with 3-D Secure support, and access to data is restricted to persons who need it for their work.
9. Minors
The Platform is not intended for persons under 18 years of age and we do not knowingly collect their data. Bookings for minor participants are made by an adult.
10. Changes to this Policy
We may amend this Policy from time to time; the current version is always published at „/privacy" with its publication date. We will announce material changes with a clear notice on the Platform before they enter into force.
