Curated luxury resort guide overview
Security & Governance

Privacy Policy

Discover our comprehensive commitment to transparent data handling, rigorous reservation protection, and guest rights across all travel services.

Legal Standards & Transparency

Privacy Charter and Data Governance

Effective Date: 27/08/2026

1. Scope of Data Governance

Clostavia operates as an editorial and digital reservation directory dedicated to showcasing premier accommodations and luxury hospitality destinations. We maintain a firm obligation toward safeguarding individual personal records and upholding strict standards of transparency across all customer touchpoints.

This document outlines how Clostavia collects, organizes, uses, transfers, and safeguards your individual details when you navigate our catalog, review destination ratings, create guest profiles, or complete accommodation bookings.

2. Information Gathered Through Our Services

To deliver accurate lodging availability, verified reviews, and seamless booking confirmations, we collect several categories of user records:

Personal Identity and Contact Details

Full name, professional title, preferred language, residential region, authorized electronic communication address, and telephone contact channels provided during account registration or inquiry submissions.

Reservation Preferences & Stay Requirements

Dates of arrival and departure, room configurations, suite categories, bed selections, dietary preferences, special accessibility requests, and hotel loyalty membership references.

Billing and Payment Verification Records

Cardholder identity, truncated account indicators, billing location, and transaction confirmation tokens processed through accredited and certified payment processing intermediaries. Full card numbers are never stored on Clostavia core servers.

Technical Metadata and Device Telemetry

Internet Protocol address, browser version, operating system environment, referring URLs, regional time zone settings, device identifiers, and page interaction timestamps.

3. Lawful Grounds and Operational Purposes

Clostavia processes guest records strictly within established legal justifications, including contractual execution, legitimate business interests, statutory compliance, and explicit customer consent. The primary operational objectives include:

  • Booking Execution: Transmitting itinerary details directly to partner resort destinations to finalize room holds and arrival preparations.
  • Editorial Customization: Personalizing featured hospitality rankings and travel reviews aligned with preferred destinations and resort styles.
  • Security & Verification: Safeguarding digital infrastructure, verifying transaction legitimacy, and shielding users against unauthorized profile access.
  • Service Communication: Providing reservation updates, booking vouchers, itinerary reminders, and critical customer service notifications.
  • Regulatory Adherence: Fulfilling accounting disclosures, tax reporting rules, and legal mandates established by administrative jurisdictions.

4. Authorized Data Disclosures and Partner Integrations

We do not sell, rent, or lease personal identifiers to unaffiliated commercial entities. Data transfers occur strictly under contractual safeguards with designated third parties:

Partner Hospitality Properties

Selected resort destinations and luxury hotels receive guest names, arrival dates, and accommodation specifics strictly necessary to honor room reservations.

Accredited Payment Processors

Encrypted billing data is routed to certified financial gateways operating under modern PCI-DSS validation standards to complete checkout actions.

Infrastructure and Cloud Providers

Tier-1 data center facilities and content distribution networks host encrypted database backups to ensure platform uptime and disaster resilience.

Legal and Regulatory Authorities

Information may be disclosed where required by lawful subpoena, court order, or official mandate to safeguard vital individual interests.

5. Digital Identifiers and Analytics Preferences

Our portal utilizes digital cookies and local storage tokens to recognize returning visitors, preserve currency display preferences, evaluate website performance, and maintain active session integrity. Users retain total autonomy over cookie management through standard web browser configurations. Disabling essential cookies may impact certain reservation functionality.

6. Storage Safeguards and Retention Principles

We apply rigorous multi-layered administrative, technological, and physical defenses to insulate guest records against unauthorized access, loss, alteration, or unlawful extraction. Protective mechanisms encompass TLS 1.3 transport encryption, AES-256 data storage encryption, segregated database clusters, and role-restricted credential access.

Data is preserved only for the duration necessary to satisfy the booking itinerary, resolve customer inquiries, satisfy audit standards, or fulfill statutory retention schedules. Once the designated holding period expires, records are permanently erased or irrevocably anonymized.

7. Individual Rights and Choices

Guests maintain comprehensive control over their personal records under modern consumer data standards. Subject to jurisdictional verifications, you may exercise the following prerogatives:

Right of Access & Inspection

Obtain a portable copy of stored personal records and verify handling procedures.

Right to Rectification

Request prompt corrections for outdated, partial, or inaccurate profile information.

Right to Erasure

Request deletion of guest records when processing is no longer required by law.

Right to Restrict Processing

Limit processing activities while record accuracy or legitimate interests are audited.

Opt-Out and Your Choices

You have the right to control how your personal information is collected and used. Depending on your location and applicable laws, you may exercise the following opt-out choices:

  • Data Sharing and Sale: You may opt out of the sale or sharing of your personal information with third parties, where applicable under laws such as the CCPA/CPRA in California or similar legislation in other jurisdictions. While we do not sell personal information in the traditional sense, some data may be shared with trusted partners to provide or improve our services.
  • Cookies and Tracking: You can manage or refuse cookies and tracking technologies through your browser settings or by using the cookie consent tools provided on our website.
  • Marketing Communications: You can opt out of receiving promotional emails or newsletters by following the unsubscribe link in any communication or by contacting us directly.
  • Withdrawal of Consent: If you have previously provided consent to data processing, you may withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

To exercise any of these rights or make an opt-out request, please contact us at [email protected] or via our contact form.

8. Updates to this Document

Clostavia reserves the right to refine and update this charter periodically in accordance with regulatory updates or architectural revisions. Any material modifications will be reflected directly on this page with an updated effective date. Continued interaction with our portal following publication signifies acknowledgment of the amended provisions.