Legal

Privacy Policy

What we do with your personal data when you book a suite, buy a gift voucher, write to us or list your spa — under the GDPR and the LOPDGDD.

Last updated: 22 September 2026. This policy explains, in the terms of Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD), what personal data Spafindo processes, why, on what legal basis, who receives it, where it is stored and what you can ask us to do about it.

1. Who is responsible for your data

  • Controller: PRIVA SPA, S.L. (sociedad unipersonal), trading as "Spafindo".
  • NIF: B93940922.
  • Registered office: Cl. Inglaterra – Faro Calaburra, 71, 29649 Mijas (Málaga), Spain.
  • Privacy contact: info@spafindo.com.
  • Commercial Registry: Registro Mercantil de Málaga — Tomo, Folio and Hoja pending; the company was incorporated on 5 August 2026 and the entry is being processed.
  • Data protection officer: none appointed. Our processing does not require one under Article 37 GDPR (no large-scale monitoring and no large-scale special-category data); write to the address above with any privacy question.

When you book, the venue you choose also receives your booking details and uses them, as an independent controller, to prepare and deliver your session — see section 4.

2. What we collect, and from whom

We collect only what a booking platform needs. Almost all of it comes from you; the rest is generated by your use of the Platform.

  • Guests booking a session: name, email address, phone number (optional), the suite, date, time, session length, number of guests, the extras chosen, the price, the payment status and a Stripe payment reference, plus the language you booked in.
  • Gift vouchers: the buyer's name and email, the recipient's name and email, the personal message written on the voucher, the amount and the balance left on the code.
  • Account holders: email address, password (stored only as a cryptographic hash, never in readable form), name, your bookings, saved suites and reviews.
  • Reviews: your rating, your text and the first name shown with it, linked to the booking it came from.
  • Enquiries, waiting lists and occasion reminders: name, email, the message or preference you send us, the page you sent it from and — where present — the campaign that brought you (UTM campaign labels and the referring site, only after analytics consent).
  • Spa owners applying to list: contact name, email, phone, the venue's name, address, website and description, opening hours, prices and photographs, and the identity and bank data you give directly to Stripe for payouts (we see only whether onboarding is complete, never your documents).
  • Technical data: IP address, browser and device type, pages requested, timestamps and error logs, kept in our hosting and application logs for security and troubleshooting.
  • Cookies and similar technologies: described in the Cookie Policy. Google Analytics 4 loads only after analytics consent; no advertising tag is active. Google Maps is described in section 4.4 below.

Please don't send us health information. We do not ask for it and we have no field for it. The health guidance in our Terms is for you to act on yourself; you never need to disclose a condition to us or to a venue to book.

Providing your name, email and payment data is necessary to make a booking — without them the contract cannot be performed. Everything else is optional.

4. Who receives your data

4.1 The venue you book

The venue receives your name, email, phone number if you gave one, the date, time, session length, number of guests and the extras you chose — what it needs to prepare the suite and welcome you. It never receives your card data. The venue is an independent controller for that use and answers for it under its own privacy policy; ask the venue directly if you want to know more.

4.2 Our processors

These suppliers process data on our instructions only, under Article 28 GDPR contracts:

  • Supabase, Inc. (United States) — our database, sign-in system and photo storage. The data itself is held in Supabase's AWS region ap-southeast-2 (Sydney, Australia).
  • Vercel, Inc. (United States) — hosting, content delivery and the server functions that run the site; also short-lived request and error logs.
  • Stripe Payments Europe, Ltd. (Ireland), with Stripe, Inc. (United States) — card payments, refunds and partner payouts. Stripe is also an independent controller for fraud prevention and for the identity checks that payments law requires of it, under its own privacy policy.
  • Resend, Inc. (United States) — sending our transactional emails.
  • Google Ireland Ltd. (Google Analytics 4) — analytics, loaded only after you consent to analytics cookies. Google receives browser/session identifiers, the events described above and technical connection data under its Privacy Policy. Meta Pixel is not active.

We also disclose data to our accountants and legal advisers under professional confidentiality, and to public authorities, courts or the police where the law requires it. We never sell your personal data.

4.3 Transfers outside the EEA

Because of the providers above, your data is stored and processed outside the European Economic Area — in Australia (the database and file storage) and in the United States (hosting, email and part of the payment chain). Neither country benefits from a general adequacy decision for these providers, so the transfers rely on the European Commission's Standard Contractual Clauses together with the supplementary measures in each provider's data processing agreement — encryption in transit and at rest, access controls and a commitment to challenge unlawful government access. Where a US provider is certified under the EU-US Data Privacy Framework, that framework applies in addition. You can ask us for a copy of the safeguards at info@spafindo.com.

4.4 Google Maps

When enabled, Google Maps loads when you choose Show map in search results, or as you approach a listing's location section. Our maps use town coordinates; we do not provide Google with the venue's exact address or contact details, or request your device's precise location.

Loading a map connects your browser to Google. Google logs technical request data, including your IP address, the request URL and parameters, time, and browser and operating-system headers. Google's Privacy Policy applies to its handling of this data, including its retention and your privacy controls. This map service is separate from Google Analytics and does not activate our analytics or advertising tags.

5. How long we keep it

  • Bookings, payments and vouchers: for the life of the contract and then 6 years from the end of the corresponding financial year, as commercial and tax law requires (Art. 30 Código de Comercio, Art. 66 Ley General Tributaria). A voucher's own record is kept until it expires or is used up, and then for the same 6 years.
  • Your account: while it is open. After you ask us to close it, we erase or anonymise your personal data within 30 days, keeping only the booking and invoicing records the law above requires, which are blocked (Art. 32 LOPDGDD) and used for nothing else.
  • Reviews: while the listing is published; they stay visible with your first name after an account is closed, and we will remove or anonymise a review on request.
  • Enquiries, waiting lists and occasion reminders: up to 24 months from your last contact, or until you withdraw consent.
  • Spa applications that we do not approve: 12 months, so we can explain the decision, and then deleted.
  • Security and server logs: up to 30 days, longer only for an incident under investigation.
  • Backups: a daily backup kept for 30 days on a rolling basis in private, access-controlled storage; deletions you request work through the backups within that window.
  • Cookie choices: stored in your browser for up to 12 months, or until you change or clear them. The choice controls whether optional analytics may run.

6. How we protect it

Access to the database is restricted per user by row-level security, so one guest can never read another's bookings and one spa can never read another's. Traffic is encrypted with HTTPS, passwords are stored only as hashes, card numbers never reach our systems, administrative access is limited to the people who need it, and the database is backed up daily. If a breach ever put your rights at serious risk, we would notify the AEPD within 72 hours and tell you without undue delay.

7. Your rights

You can exercise all of the following free of charge by writing to info@spafindo.com. We answer within one month, extendable by two more for complex requests, and we will tell you if we need longer. We ask for proof of identity only where we have reasonable doubt about who is asking.

  • Access — a copy of the data we hold about you. Signed-in guests can also download it themselves from My bookings.
  • Rectification — correct anything inaccurate or incomplete.
  • Erasure — deletion of your data where we no longer need it. Bookings we must keep for tax and accounting are blocked instead of deleted.
  • Restriction — freeze a processing operation while a dispute about it is resolved.
  • Objection — object at any time to processing based on our legitimate interest, giving reasons connected to your situation.
  • Portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another controller.
  • Withdraw consent — at any time, without affecting what was lawful before. Cookie choices are changed from "Cookie settings" in the footer.

If you think we have not respected your rights, you may complain to us first — we would rather fix it — and in any case to the Spanish supervisory authority: Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es. You may also go to the courts.

8. Children

The Platform is for adults; you must be 18 or over to book or to hold an account. We do not knowingly collect data from children. If a minor's data reaches us, write to us and we will delete it.

9. Changes to this policy

We update this policy when our processing, our providers or the law changes. The date at the top always shows the current version, and a change that materially affects you is announced on the Platform before it takes effect.

Related: Cookies · Terms · Legal notice