How your data is actually handled
Last updated: 14 September 2026, written against the actual code rather than a template for what a page like this is supposed to contain.
Fast answer: there is nothing to sign up for, no advertising, and measurement stays off unless you switch it on, which today does nothing anyway because no measurement account is wired up yet. One thing does reach a third party before any click, a partner's own product photo, and it gets a full explanation further down rather than a footnote.
Who is answerable for this
bestbeachesinmalta.com is run under the name Best Beaches In Malta, and that is the entity the GDPR treats as controller for anything on this page. Every route through this policy, a correction, a rights request, a plain question, ends at admin@whattodoinmalta.com.
What can actually reach us, category by category
| Category | What happens, and why it is allowed |
|---|---|
| Analytics | Off by default. Turns on only after an explicit accept on the banner, which is the legal basis for the whole category: consent, nothing else. Right now accepting does not even do that much, because this domain has no analytics account connected, so there is genuinely nothing for the accept to trigger. Step-by-step detail lives on the cookie policy. |
| Partner product photos | Every option shown inside a booking panel carries a picture pulled live from that partner's own server, not stored here. All 41 of those images currently come from Tiqets, and the request fires the moment the panel scrolls into view, before any click and regardless of your banner answer. Fetching an image is an ordinary web request, and an ordinary web request discloses who is asking: where you are connecting from, what browser you are using, and which page sent you. Their reply is free to set its own cookie in return, and nothing about the exchange comes back to us. A photo from Klook, KKday or WeGoTrip would work identically the day either carries one. |
| Two on-device values | Which beaches you have starred, and your banner answer. Both sit in your browser's local storage rather than in a cookie, both stay on your device, neither is ever transmitted to us. Basis: none needed, we never see it. |
| Email you send | Your address plus whatever you wrote, used only to answer you. Basis: our legitimate interest in replying to someone who wrote to us. Deleted once the thread is resolved. |
| Server request logs | Any web request tells the receiving server an IP address; ours keeps that briefly to serve pages and to catch abuse. Basis: the shared interest of us and our host in keeping the lights on. Nobody reads these to build a picture of a specific visitor. |
Everyone else who gets a look
- Google, and only if two separate things are both true at once: you accepted, and a measurement account exists for this domain. Miss either one and nothing is sent. Once both hold, IP addresses are shortened before being logged and advertising permissions are never switched on, because there is nothing here to advertise. Data crossing to Google, a US company, relies mainly on the EU-US Data Privacy Framework, backed by standard contractual clauses where that framework does not stretch.
- Travelpayouts sits between a marked link and the partner it points at. Clicking one routes you through them first so the click is credited to this site, then on to the partner immediately. Think of it as a waypoint rather than something embedded in these pages.
- Tiqets, Klook, KKday and WeGoTrip, whichever one a marked link actually leads to. Once you land there, their own policy takes over completely, and short of the product photograph already described nothing about that visit is shared with them ahead of time or reported back to us afterward. Full context on the affiliate disclosure.
- The company hosting this site, and whoever carries our email, doing only what it takes to serve these pages and deliver messages. Ask and we will name them.
None of the above amounts to a sale of data, and there is no advertising arm here for anyone to sell it to in the first place.
Retention, and getting rid of what little there is
An email thread lasts until its subject is closed, then it is removed. Server logs expire on our host's own schedule, not one we set. The two values in your browser persist until you clear your browsing data yourself, at any point, without needing our permission.
Your rights, and how far they actually reach
The GDPR gives you the right to ask what we hold on you, to have wrong details put right, to have the record erased, to have a specific use of it paused, or to receive a portable copy of it. Send any of those to admin@whattodoinmalta.com and expect an answer inside a month. Realistically, the honest reply is usually "an email thread and nothing else", because that is the whole of what tends to exist. Unsatisfied with the answer, you can escalate to Malta's Information and Data Protection Commissioner.
About younger visitors
This is written for adults planning a trip, not for children, even though a fair few of the beaches on it are chosen with a family day in mind. Nothing here is built to identify or collect from anyone under age, knowingly or otherwise.
Changing your answer
Every page carries a Cookie settings link in its footer that reopens the same choice, no matter what you picked before. A fresh decline is recorded instantly, and if measurement happened to be active in that moment, the refusal reaches it right away rather than waiting for the next page load. Clearing your browser's storage achieves the same reset, at the cost of also losing your starred beaches.
This page changing
Watch the date at the top. Anything that meaningfully alters what happens to your data gets a visible mention on the site itself, not a silent edit buried in a paragraph here.