Legal

Privacy Policy

Effective date: [DATE OF LAUNCH]

[LEGAL ENTITY NAME] ("Journey Saga", "we", "us") operates journeysaga.com and the booking platform on it. This policy explains what we collect when you browse the site, make a reservation, or stay with us, why we collect it, who else sees it, and what you can ask us to do with it. We are the data controller for that information. You can reach us at [PRIVACY EMAIL], by phone on (616) 788-1316, or by post at [REGISTERED ADDRESS].

What we collect

  • When you browse. Pages visited, approximate location, device and browser type, and referring site.
  • When you enquire or reserve. Your name, email address, phone number, the dates and property you are interested in, your group size, and anything you tell us in a message or special-requests field.
  • When you create an account. Your name, email address, date of birth, phone number, and an emergency contact name and number. Date of birth is collected because our terms require the lead guest to be at least 25, and because some properties and experiences carry their own age limits.
  • When you pay. Our payment processor collects your card details directly. We never receive or store your full card number. We keep the last four digits, the card brand, the amount, and whether the payment succeeded.
  • When you personalise your stay. Dietary requirements, allergies, the occasion, arrival time, accessibility needs, and your choices of chef, bartender, massage, yoga, music or decor. Dietary and accessibility details may reveal health information. Where GDPR applies this is a special category of personal data, and we rely on your explicit consent, given when you enter it. You can leave those fields blank, though we may then be unable to cater safely.
  • When you travel with a group. If the lead guest invites you to a reservation, we receive your name and email from them. If you accept, you see the shared itinerary, not the lead guest's payment details.
  • When you use a Journey Pass. The date, time and partner business where you redeemed a discount.
  • When you contact us. The contents of your emails, messages and support requests.

Why we use it, and on what legal basis

PurposeGDPR legal basis
Taking and fulfilling your reservationPerformance of a contract
Taking payment and issuing refundsPerformance of a contract
Scheduling hosts, cleaners, chefs and other providersPerformance of a contract
Catering to dietary, allergy and accessibility needsExplicit consent
Sending booking confirmations and service messagesPerformance of a contract
Answering enquiries and support requestsLegitimate interests
Preventing fraud, damage and misuse of the platformLegitimate interests
Keeping accounting, tax and insurance recordsLegal obligation
Marketing emails about future staysConsent, withdrawable at any time
Measuring how the site is usedConsent where required, otherwise legitimate interests
Monitoring errors and service faultsLegitimate interests

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months.

Who else sees it

  • Service providers we use to run the platform. Supabase (database and account hosting), Lovable (website hosting and basic visitor analytics), PostHog (product analytics), Sentry (error monitoring), Google Maps (the maps on our pages), [PAYMENT PROCESSOR] for payments, and [EMAIL PROVIDER] for transactional email. Each is bound to use your information only to provide that service to us.
  • The people hosting your stay. Your Journey Host, cleaning and maintenance staff, and any chef, bartender, massage therapist, yoga instructor, musician or decorator you book. They receive only what they need: usually your name, group size, dates, arrival time, and the dietary or accessibility details relevant to their service. They are independent businesses and are required to keep what they receive confidential.
  • The property owner where you are staying, who receives the dates and group size but not your contact details.
  • Adventure Guide partners, if you redeem a Journey Pass with them. They see that a valid pass was used, the guest name on it, and the date.
  • Others, where we must: our accountants and insurers, professional advisers, and law enforcement or regulators where the law requires it. If the business is ever sold or merged, guest records may transfer with it, and we will tell you before that happens.

Cookies, analytics and browser storage

Essential storage.

We store a small amount of data in your browser to keep you signed in, hold your reservation while you complete it, remember your cookie choice, and remember preferences such as a filter or a saved shortlist. The site cannot work without this, and it is not used to track you.

Basic visitor analytics.

Our host, Lovable, measures overall traffic, visitors, pages viewed, time on page, referring site, device type, and country derived from your browser's timezone rather than your IP address. It does not build a profile of you and does not follow you between visits.

Product analytics.

We use PostHog to understand how the booking flow is used, so we can see where people get stuck. It records pages viewed and interactions, never your name, email, phone number or date of birth. In the UK and the EEA, PostHog does not load at all until you accept the banner, and no cookie is set before you do.

Error monitoring.

We use Sentry to find out when something breaks. It records the error and the page it happened on, with personal data switched off and query strings removed so nothing identifying is sent. This runs on legitimate-interest grounds because it is service integrity, not tracking, and it does not depend on your analytics choice.

Your choice.

Visitors in the UK and the EEA are asked before any non-essential analytics runs, and declining is as easy as accepting. You can change your mind at any time using "Cookie preferences" in the footer. We do not use advertising or social media tracking pixels.

How long we keep it

RecordKept for
Enquiries that do not become bookings24 months
Reservation and stay records7 years after the stay, for tax and insurance
Payment records7 years, as required for accounting
Account detailsWhile your account is open, then 12 months
Dietary, allergy and accessibility notesUntil 12 months after the stay
Marketing consents and opt-outsUntil withdrawn, then a suppression record indefinitely
Support correspondence24 months

How we protect it

Information is held on servers operated by our hosting providers, protected by access controls and encryption in transit. Passwords are stored as one-way hashes and cannot be read by us or anyone else. Access to guest records is limited to staff and providers who need it for your stay, and access is removed when someone leaves. No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant regulator where the law requires it.

International transfers

We operate from the United States, and our service providers are mostly US-based. If you are in the UK, the EEA or Switzerland, your information will be transferred to the United States. Where that happens we rely on the European Commission's Standard Contractual Clauses, and the UK Addendum where applicable. You can ask us for a copy of those safeguards.

Your rights

  • If you are in the UK, EEA or Switzerland, you can ask us to give you a copy of your information, correct it, delete it, restrict or object to how we use it, or send it to another provider in a portable format. Where we rely on consent, you can withdraw it at any time without affecting what we did before. You can also complain to your national data protection authority, or to the Information Commissioner's Office in the UK.
  • If you are in California, you can ask us what personal information we have collected about you, where it came from, why we collected it and who we shared it with; ask us to delete it; ask us to correct it; and ask us to limit how we use sensitive personal information. We do not sell your information or share it for cross-context behavioural advertising, so there is nothing to opt out of. We will not treat you differently for exercising any of these rights.
  • If you are elsewhere in the United States, similar rights apply in Colorado, Connecticut, Virginia, Utah, Texas and a growing number of other states. We apply the same process wherever you are.

To exercise any right, email [PRIVACY EMAIL]. We will respond within 30 days, or 45 days in the United States, and will ask you to verify your identity before releasing information. You may use an authorised agent.

Children

The platform is not intended for children, and only someone aged 25 or over can make a reservation. We do not knowingly collect information from anyone under 16. Children may of course stay as part of a family group; where you give us a child's name, age or dietary needs for that purpose, we keep it only for the stay and delete it within 12 months. If you believe a child has given us information directly, email [PRIVACY EMAIL] and we will delete it.

Changes

We will update this policy as the platform changes. The effective date at the top shows when it last changed. If a change materially affects how we use your information, we will email account holders and show a notice on the site before it takes effect.

Contact

[LEGAL ENTITY NAME], [REGISTERED ADDRESS], [PRIVACY EMAIL], (616) 788-1316.