Legal
Privacy Policy
Last updated: April 3, 2026
1. Introduction
The Privée Collection S.R.L. ("The Privée Collection", "we", "us", or "our") operates the website thepriveecollection.com and its associated mobile applications, platforms, and services (collectively, the "Platform"). This Privacy Policy describes how we collect, use, store, share, and protect your personal information when you access or use our Platform, engage our luxury vacation rental and property management services, or otherwise interact with us.
We are committed to safeguarding the privacy and confidentiality of our clients, property owners, guests, and website visitors. This policy complies with applicable data protection laws including, but not limited to, the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Dominican Republic Law No. 172-13 on the Protection of Personal Data, and other applicable international privacy frameworks.
By accessing or using our Platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please discontinue use of our Platform immediately.
2. Information We Collect
2.1 Information You Provide Directly
- Account registration data: full name, email address, phone number, date of birth, nationality, mailing address, and profile photograph
- Identity verification documents: government-issued photo identification (passport, driver's license), proof of address, and related biometric data processed through OCR technology
- Booking and reservation information: preferred dates, property preferences, number of guests, special requests, dietary requirements, and accessibility needs
- Payment information: credit/debit card numbers, billing address, and bank account details processed through our PCI-DSS compliant payment processor (Stripe)
- Guest preference profiles: dietary preferences, room preferences, activity interests, beverage preferences, amenity requirements, VIP status, language preferences, and prior stay notes
- Communication data: emails, messages, phone call records, live chat transcripts, and correspondence with our concierge team
- Property owner information: property details, ownership documentation, banking information for payout disbursements, tax identification numbers, and management agreement details
- Survey and feedback responses: satisfaction surveys, reviews, ratings, and testimonials
- Newsletter subscriptions: email address and communication preferences
2.2 Information Collected Automatically
- Device information: IP address, browser type and version, operating system, device identifiers, screen resolution, and hardware configuration
- Usage data: pages visited, click patterns, search queries, property views, time spent on pages, navigation paths, referring URLs, and exit pages
- Location data: approximate geographic location derived from IP address, GPS coordinates (with your consent), and timezone settings
- Cookie data: session cookies, persistent cookies, performance cookies, and analytics cookies (detailed in Section 9)
- Log data: server logs including access times, error reports, and system activity records
2.3 Information from Third Parties
- Social login providers: when you authenticate via Google Sign-In, we receive your name, email address, and profile photograph as authorized by your social account settings
- Payment processors: transaction confirmations, refund statuses, and fraud risk assessments from Stripe
- Channel partners: booking data from affiliated travel agencies, online travel agencies (OTAs), and referral partners
- Public databases: property ownership records, regulatory compliance data, and corporate registry information
- Background verification services: identity verification results and fraud screening outcomes for high-value reservations
3. How We Use Your Information
3.1 Service Delivery
- Processing and managing reservations, bookings, and property inquiries
- Facilitating payment transactions, invoicing, security deposits, and refunds
- Providing personalized concierge services, guest profiling, and tailored recommendations
- Managing property listings, availability calendars, and pricing configurations
- Coordinating housekeeping, maintenance, inspections, and property operations
- Generating and managing rental contracts, digital signatures, and legal documentation
3.2 Communication
- Sending booking confirmations, check-in instructions, and payment receipts
- Responding to inquiries, support requests, and concierge service communications
- Delivering transactional emails including reservation updates and status changes
- Sending marketing communications and newsletters (with your opt-in consent)
- Conducting post-stay satisfaction surveys and experience feedback collection
3.3 Platform Improvement & Analytics
- Analyzing usage patterns to improve website functionality, performance, and user experience
- Conducting A/B testing, user research, and feature development
- Generating aggregated, anonymized analytics reports for business intelligence
- Monitoring system performance, uptime, and technical health
3.4 Security & Legal Compliance
- Detecting, preventing, and investigating fraud, unauthorized access, and malicious activity
- Enforcing our Terms and Conditions and other contractual agreements
- Complying with applicable laws, regulations, legal processes, and governmental requests
- Maintaining audit trails and records as required by Dominican Republic law and international regulations
4. Legal Bases for Processing
We process your personal data under the following legal bases as defined by applicable data protection law:
- Contractual Necessity: Processing required to fulfill our booking agreements, management contracts, and service obligations to you
- Legitimate Interests: Processing necessary for our legitimate business interests including fraud prevention, platform security, service improvement, and direct marketing to existing clients, provided these interests are not overridden by your fundamental rights
- Consent: Processing based on your freely given, specific, informed, and unambiguous consent, such as marketing communications, cookie tracking, and optional profile enrichment
- Legal Obligation: Processing required to comply with applicable laws and regulations including tax reporting, anti-money laundering requirements, and law enforcement requests
- Vital Interests: Processing necessary to protect the vital interests of you or another natural person in emergency situations
5. Information Sharing & Disclosure
We do not sell, rent, or trade your personal information. We may share your data with the following categories of recipients, strictly on a need-to-know basis:
5.1 Service Providers
- Payment processors (Stripe) for secure transaction handling
- Cloud infrastructure providers for data storage and hosting
- Email service providers (Resend) for transactional and marketing communications
- SMS service providers (Twilio) for booking notifications and two-factor authentication
- AI/ML service providers (OpenAI) for OCR document processing and intelligent features, with data processing agreements in place
- Media storage providers (Cloudinary) for property image and media management
- Analytics platforms for anonymized usage analytics
5.2 Property Owners
When you book a property, we share necessary guest information (name, contact details, number of guests, dates, special requests) with the property owner or their authorized representative to facilitate your stay.
5.3 Legal & Regulatory
- Law enforcement agencies when required by valid legal process (court orders, subpoenas)
- Tax authorities as required by Dominican Republic fiscal law and international tax treaties
- Regulatory bodies for compliance with tourism, hospitality, and real estate regulations
- Legal counsel for the establishment, exercise, or defense of legal claims
5.4 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or asset sale, your personal data may be transferred to the successor entity, subject to the same privacy commitments described herein. We will notify you of any such transfer and any changes to this Privacy Policy.
6. International Data Transfers
The Privée Collection is headquartered in the Dominican Republic. Your personal data may be transferred to and processed in countries outside your country of residence, including the United States and countries within the European Economic Area. When we transfer data internationally, we implement appropriate safeguards including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data processing agreements with all third-party service providers
- Encryption of data in transit (TLS 1.3) and at rest (AES-256)
- Access controls and audit logging for cross-border data access
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law:
- Active account data: Retained for the duration of your account and for 3 years following account closure or last activity
- Booking and transaction records: Retained for 7 years to comply with fiscal and tax regulations in the Dominican Republic
- Identity verification documents: Retained for 5 years from the date of verification, encrypted with AES-256 encryption at rest
- Communication records: Retained for 3 years from the date of the communication
- Analytics data: Aggregated and anonymized after 24 months; raw data deleted after 13 months
- Marketing consent records: Retained for the duration of the consent plus 2 years following withdrawal
- Legal and compliance records: Retained as required by applicable law, typically 10 years
8. Data Security
We implement comprehensive technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:
Technical Measures
- AES-256 encryption for sensitive data at rest, including identity documents and OCR-processed text
- TLS 1.3 encryption for all data in transit between your device and our servers
- Secure password hashing using bcrypt with appropriate cost factors
- Two-factor authentication (TOTP) for administrator and property owner accounts
- JWT-based authentication with httpOnly, secure, and SameSite cookie attributes
- Rate limiting and brute-force protection on authentication endpoints
- Regular security audits and penetration testing
- Database access controls with principle of least privilege
- Automated vulnerability scanning and dependency monitoring
Organizational Measures
- Role-based access control (RBAC) with 7 distinct permission levels
- Employee security awareness training and confidentiality agreements
- Incident response procedures with 72-hour breach notification capability
- Vendor security assessment for all third-party service providers
- Regular review and update of security policies and procedures
While we implement robust security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to continuously improving our safeguards.
10. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete personal data
- Right to Erasure: Request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements
- Right to Restriction: Request restriction of processing of your personal data in certain circumstances
- Right to Data Portability: Request your personal data in a structured, commonly used, machine-readable format
- Right to Object: Object to processing of your personal data for direct marketing or based on legitimate interests
- Right to Withdraw Consent: Withdraw previously given consent at any time, without affecting the lawfulness of processing prior to withdrawal
- Right to Lodge a Complaint: File a complaint with a supervisory data protection authority in your jurisdiction
CCPA-Specific Rights (California Residents)
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information held by us and by our service providers
- Right to opt-out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising your CCPA rights
To exercise any of these rights, please contact us at privacy@thepriveecollection.com. We will respond to your request within 30 days, or as required by applicable law.
11. Children's Privacy
Our Platform is not intended for individuals under the age of 18. We do not knowingly collect, use, or disclose personal information from children under 18. If we become aware that we have inadvertently collected personal data from a child under 18, we will take immediate steps to delete such information. If you believe a child has provided us with personal data, please contact us at privacy@thepriveecollection.com.
12. Third-Party Links & Services
Our Platform may contain links to third-party websites, services, or applications that are not operated or controlled by The Privée Collection. This Privacy Policy does not apply to third-party services. We encourage you to review the privacy policies of any third-party service before providing your personal data. We are not responsible for the privacy practices, content, or security of third-party websites or services.
13. Changes to This Policy
We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by posting the updated policy on our Platform with a revised "Last Updated" date, and where required by law, by sending you direct notification via email. Your continued use of the Platform after any changes constitutes acceptance of the revised policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
The Privée Collection S.R.L.
Data Protection & Privacy
Casa de Campo Resort, La Romana 22000, Dominican Republic
Email: privacy@thepriveecollection.com
Phone: +1 (809) 523-8000
