Privacy Policy
Last updated: 3 May 2026
This Privacy Policy explains how we collect, use, share, and protect personal information in connection with the website luxuryintel.co and any related services (collectively, the "Services"). It also describes the rights you have in relation to your personal information.
In this policy, "we", "us", and "our" refer to the operator of luxuryintel.co. "You" refers to any individual who visits the Services or creates an account with us.
If you have any questions about this policy or our privacy practices, please contact us at support@luxuryintel.co.
1. Who We Are
luxuryintel.co is an independent luxury hotel intelligence platform that publishes editorial coverage, price tracking, and comparative information about luxury hotels and brands. We are the controller of the personal information we process about you for the purposes described in this policy.
We are based in Switzerland. Our Services are accessible globally and we comply with the UK General Data Protection Regulation ("UK GDPR"), the EU General Data Protection Regulation ("EU GDPR"), the Swiss Federal Act on Data Protection ("FADP"), and, where applicable, the California Consumer Privacy Act as amended by the CPRA ("CCPA").
2. Information We Collect
2.1 Information you provide to us
- Account information. When you register for an account, we collect your email address and a password (which we store in hashed form). You may also choose to provide a display name or other optional profile information.
- Subscription and payment information. If you purchase a subscription, you provide payment details directly to our payment processor, Stripe. We do not collect or store your full payment card number, security code, or banking credentials. We receive limited information from Stripe such as the last four digits of your card, the card brand, country, and a transaction reference.
- Communications. If you contact us by email or through any contact form, we collect the content of your message and any information you choose to include (such as your name and email address).
- User content (future). The Services do not currently allow users to post content. If we introduce features that let users submit reviews, comments, photos, or ratings in the future, we will update this policy and explain how that information is handled.
2.2 Information collected automatically
When you visit the Services, we and our service providers automatically collect certain information about your device and your interactions with the Services. This includes:
- Device and connection data, such as IP address, browser type and version, operating system, device type, screen size, language preferences, referring URL, and timestamps.
- Usage data, such as the pages you view, the searches you run, the hotels and brands you click on, the time spent on pages, and the navigation paths you take.
- Authentication and session data managed through Firebase Authentication, including session tokens and login timestamps.
We collect this information through cookies, similar technologies, and server logs. See section 7 for details.
2.3 Sensitive personal information
We do not knowingly collect any "special category" data under UK or EU GDPR (such as health, biometric, or political data), nor any "sensitive personal information" under the CCPA. Please do not submit such information to us.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Services and your account.
- Process subscription purchases, renewals, and refunds.
- Authenticate users and keep accounts secure.
- Communicate with you about your account, your subscription, and changes to the Services.
- Respond to your support requests and other communications.
- Understand how the Services are used so we can improve content, functionality, and performance.
- Detect, prevent, and investigate fraud, abuse, security incidents, and violations of our Terms and Conditions.
- Comply with legal obligations and enforce our legal rights.
- Send service announcements and marketing communications. When you provide your email address to create an account, we may send you up to four product-related emails over two weeks. You can opt out at any time using the link at the bottom of any such email.
4. Legal Bases for Processing (UK / EU / Swiss Users)
If you are in the United Kingdom, the European Economic Area, or Switzerland, we rely on the following legal bases to process your personal information:
- Performance of a contract. To provide you with an account, deliver the Services you have subscribed to, and process payments.
- Legitimate interests. To operate, secure, and improve the Services; to communicate with you about service-related matters; and to prevent fraud and abuse. We balance these interests against your rights and freedoms.
- Consent. Where required by law (for example, for non-essential cookies and marketing emails). You can withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Legal obligation. To comply with applicable laws, regulations, and lawful requests from authorities.
5. How We Share Your Information
We do not sell your personal information. We share it only as described below.
5.1 Service providers
We share personal information with trusted third parties that help us operate the Services. These providers act on our instructions under contracts that require them to protect your information. They include:
- Stripe (payment processing).
- Google Firebase (authentication, database, hosting).
- Google Analytics 4 (usage analytics).
- Cloudflare (content delivery, security, and performance analytics).
- Email service providers that we may use for transactional and marketing messages.
5.2 Legal and safety reasons
We may disclose information if we believe in good faith that disclosure is necessary to comply with a legal obligation, respond to a lawful request from a regulator or law enforcement authority, enforce our agreements, protect the rights, property, or safety of us, our users, or others, or investigate fraud or security issues.
5.3 Business transfers
If we are involved in a merger, acquisition, financing, reorganisation, or sale of assets, your information may be transferred as part of that transaction. We will notify you and, where required, seek your consent.
5.4 With your consent
We may share your information for any other purpose that we describe to you and for which you have given your consent.
5.5 Affiliate and referral links (future)
The Services do not currently include affiliate or referral links. If we introduce them in the future, we will disclose those relationships clearly and update this policy.
6. International Data Transfers
We are based in Switzerland and our service providers are located in several countries, including the United States and the European Economic Area. When we transfer personal information outside the UK, EEA, or Switzerland, we rely on appropriate safeguards, such as the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, the Swiss Data Protection Addendum, or transfers to jurisdictions recognised as providing an adequate level of protection.
You can request more information about the safeguards we use by contacting us at support@luxuryintel.co.
7. Cookies and Similar Technologies
We use cookies and similar technologies to operate the Services, remember your preferences, keep you signed in, understand how the Services are used, and improve performance. The cookies we use fall broadly into the following categories:
- Strictly necessary cookies. Required for the Services to function (for example, authentication and security).
- Functional cookies. Remember your choices and personalise your experience.
- Analytics cookies. Set by Google Analytics 4 and Cloudflare to help us understand aggregate usage patterns.
You can control cookies through your browser settings. Blocking or deleting some cookies may affect the functionality of the Services. Where required by law, we will ask for your consent before setting non-essential cookies.
8. Data Retention
We retain personal information only for as long as necessary for the purposes described in this policy. In practice:
- Account data is retained while your account is active and for a reasonable period after you close it, in case you wish to reactivate.
- Subscription and billing records are retained for the period required by tax, accounting, and other legal obligations (typically up to ten years).
- Server logs and analytics data are retained for shorter periods, generally between 14 months and 26 months depending on the provider.
- Support communications are retained for as long as needed to handle your enquiry and for a reasonable period afterwards.
When personal information is no longer needed, we delete it or anonymise it.
9. Data Security
We implement technical and organisational measures designed to protect personal information from unauthorised access, disclosure, alteration, and destruction. These include encrypted connections (TLS), encrypted storage of sensitive credentials, access controls, and the use of reputable infrastructure providers. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
If we become aware of a personal data breach that affects you, we will notify you and the relevant authorities as required by law.
10. Your Rights
Depending on where you are located, you may have the following rights in relation to your personal information.
10.1 UK, EEA, and Swiss users
- Access the personal information we hold about you.
- Rectification of inaccurate or incomplete information.
- Erasure of your personal information in certain circumstances.
- Restriction of processing in certain circumstances.
- Portability of information you have provided to us.
- Objection to processing based on our legitimate interests, and to direct marketing at any time.
- Withdrawal of consent where processing is based on consent.
You also have the right to lodge a complaint with a supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk). In Switzerland it is the Federal Data Protection and Information Commissioner (edoeb.admin.ch). EEA residents can contact their local supervisory authority.
10.2 California users
If you are a California resident, you have the right to know what personal information we collect, use, disclose, and sell or share; to request deletion or correction of your personal information; to opt out of the sale or sharing of personal information (we do not sell or share personal information for cross-context behavioural advertising); to limit the use of sensitive personal information (we do not collect sensitive personal information for purposes that would require this); and not to be discriminated against for exercising your rights.
10.3 How to exercise your rights
To exercise any of these rights, please email support@luxuryintel.co. We may need to verify your identity before acting on your request. We will respond within the timeframes required by applicable law.
11. Children's Privacy
The Services are not directed to children under 18 and we do not knowingly collect personal information from children under 18. If you believe a child has provided us with personal information, please contact us so we can delete it.
12. Third-Party Websites
The Services may link to third-party websites, such as official hotel websites or booking platforms. We are not responsible for the privacy practices of those websites, and we encourage you to read their privacy policies before providing them with personal information.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will revise the "Last updated" date at the top and, where appropriate, notify you by email or through a notice on the Services. Your continued use of the Services after the updated policy takes effect means you accept the changes.
14. Contact Us
If you have any questions, comments, or requests about this Privacy Policy or our privacy practices, please contact us at:
Email: support@luxuryintel.co