LuxMare Privé — Luxury stays, private shuttle, curated experiences
Language

LuxMare Privé

Privacy policy

PRIVACY POLICY LuxMare Privé — Personal data protection 1. INTRODUCTION LuxMare Privé (“we”) processes personal data with rigour, transparency and security measures aligned with a high corporate standard. This policy explains how we collect, use, retain and protect your information in accordance with Regulation (EU) 2016/679 (GDPR), Organic Law 3/2018 on data protection and digital rights (LOPDGDD), and other applicable sector rules. 2. DATA CONTROLLER Controller: LuxMare Privé. Privacy and rights requests: info@luxmareprive.es Website: https://www.luxmareprive.es 3. PURPOSES To handle enquiries and information requests. To manage user registration, authentication and the client area. To manage bookings, payments and the contractual relationship (including necessary operational communications). To comply with legal, accounting, tax and anti-fraud obligations. To improve security, performance and site experience on the basis of legitimate interest and data minimisation. To send marketing communications only where there is a proper legal basis (e.g. consent or legitimate interest as applicable), with opt-out where required. 4. CATEGORIES OF DATA Identity and contact data (name, email, phone, language). Account and authentication data (user identifier, role, technical session data). Booking-related data (dates, party composition as needed, preferences, payment references handled by the gateway). Contact form data (message, subject, reply-to address). Technical data (IP address, device type, aggregated security logs) where needed to deliver the service securely. We do not seek special-category data unless a law or specific contract requires it; in that case you will be informed separately. 5. LEGAL BASIS Pre-contractual and contractual steps and performance (bookings, user account). Legal obligation. Legitimate interests in security, service improvement and abuse prevention, balanced against your rights and freedoms. Consent where required for optional communications or technologies. 6. RETENTION Data are kept only as long as needed for the purposes above and for any statutory limitation or record-keeping periods. After the relationship ends, blocking and deletion apply as required by law, subject to legal retention duties. 7. RECIPIENTS AND PROCESSORS Infrastructure, payment gateway, email or authentication providers may act as processors under Article 28 GDPR with appropriate safeguards. We do not sell your personal data. 8. INTERNATIONAL TRANSFERS If a provider processes data outside the EEA, we apply GDPR mechanisms (standard contractual clauses, adequacy decisions or equivalent tools). 9. YOUR RIGHTS You may request access, rectification, erasure, objection, restriction, portability and, where applicable, withdraw consent by emailing info@luxmareprive.es with a reasonable proof of identity. You may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es). 10. SECURITY We apply technical and organisational measures proportionate to risk: encryption in transit (HTTPS), access controls, environment segregation, secure secret management and periodic configuration review. 11. CHILDREN Our services are not directed at children under 16. If you believe a child has provided data, please contact us so we can take appropriate steps. 12. GOOGLE SERVICES AND GMAIL API (LIMITED USE) LuxMare Privé may use Google’s Gmail API solely on our servers, using OAuth 2.0 credentials tied to a corporate mailbox under our control, with a technical scope limited to sending messages (e.g. the “gmail.send” scope or an equivalent authorised operational scope). Purpose: to send transactional emails related to requests received through the site (for example internal notifications or acknowledgements from the contact form), limited to the information needed for that communication. What we do not do with the Gmail API: we do not access site visitors’ mailboxes to read, index or sync their email; we do not request broad read permissions over Gmail for website users; we do not use Gmail content for targeted advertising or to resell data; we do not train third-party AI models on the content of those messages. Credentials: access and refresh tokens are stored only in a secure server environment and are not exposed in the user’s browser. We comply with the Google API Services User Data Policy: https://developers.google.com/terms/api-services-user-data-policy Our use of data obtained via Google APIs follows the Limited Use restrictions for Gmail data: use solely to provide or improve user-facing features that are clearly shown in our application’s interface; transfers only as permitted by that policy; no personalised advertising based on Gmail content; and no human-readable storage of Google account credentials except as allowed by Google. 13. CHANGES TO THIS POLICY We may update this policy to reflect legal or service changes. The current version will be published on this page with the “last updated” date. Last updated: April 2026.

For general information only — not a substitute for legal counsel tailored to your circumstances. Please keep the version in effect when you confirm your stay or enter into an agreement with LuxMare Privé.

Privacy policy | LuxMare Privé