Privacy Policy
How Vespirona collects, uses, shares, and protects the information readers give us.
Updated: 2 September 2026
1. Scope of this notice
As an editorial catalogue and booking-enquiry directory for premier accommodation, Vespirona takes on a firm duty to protect individual records and to maintain transparency wherever readers interact with the service.
This document sets out what Vespirona collects, how it is organised and used, when it is transferred, and how it is protected when you browse the catalogue, read ratings, register a profile, or submit an accommodation request.
2. Information we collect
The following categories are collected so that we can provide accurate availability, verified editorial assessments, and reliable confirmations:
- Identity and contact details
- Your name, title, language preference, country or region, email contact, and telephone details provided during profile creation or enquiry submission.
- Stay preferences and requirements
- Dates of travel, room configuration and category, bedding selection, dietary and accessibility requests, and loyalty programme identifiers.
- Payment verification data
- Cardholder identity, partial card indicators, billing address, and processor-issued confirmation tokens. At no point is a full card number retained on Vespirona infrastructure.
- Technical metadata
- Internet protocol address, browser and operating system version, referring URLs, regional time zone, device identifiers, and page interaction times.
3. Why we process, and on what basis
We rely on contractual performance, legitimate interests, statutory compliance, or explicit consent as our lawful grounds. Within those, records serve these purposes:
- Enquiry fulfilment
- Forwarding your stay details to the relevant property so it can respond on availability and prepare for arrival.
- Content customisation
- Adjusting the rankings and guides we surface to match the destinations and property styles you have shown interest in.
- Security and verification
- Defending the platform's infrastructure, checking that submissions are genuine, and protecting profiles from unauthorised access.
- Service messages
- Delivering enquiry acknowledgements, booking references, travel reminders, and critical service messages.
- Statutory adherence
- Satisfying accounting disclosure, tax reporting, and other duties imposed by the jurisdictions in which we operate.
4. Who receives your information
We do not sell, rent, or lease personal identifiers to unconnected commercial parties. Transfers happen only under contractual safeguards, and only to the following categories of recipient:
- The hotels themselves
- Selected properties are given only the name, arrival dates, and room details required to answer an enquiry or hold a room.
- Certified payment gateways
- Where payment is involved, encrypted billing details are routed to PCI-DSS validated processing partners.
- Infrastructure providers
- Encrypted database backups sit with tier-1 hosting and content distribution providers to ensure availability.
- Authorities where the law requires
- Information may be released where a lawful subpoena, court order, or official mandate requires it, or to protect vital interests.
5. Cookies, storage, and analytics
Digital identifiers and local storage support returning-visitor recognition, preference retention, performance measurement, and session continuity. Control rests with you via browser configuration; blocking essential cookies will impair some features.
6. Safeguards and how long we keep records
We apply multi-layered administrative, technological, and physical defences — TLS 1.3 transport encryption, AES-256 storage encryption, separated database clusters, and access limited by role — to guard against unauthorised access, loss, or alteration.
Records are held only as long as needed to complete an enquiry, resolve a question, satisfy audit requirements, or meet a statutory retention period. Once that period ends, records are permanently erased or irreversibly anonymised.
7. Your rights
Where your jurisdiction provides them, and once we have verified who you are, the following rights are available:
- Access and inspection
- Request a transferable copy of your stored records and verify our handling procedures.
- Right to correction
- Ask us to fix any record that is inaccurate, incomplete, or no longer current.
- Erasure
- Ask for records to be deleted where no statutory or contractual basis for keeping them remains.
- Limiting processing
- Limit how we process your data while accuracy or a legitimate interest is being examined.
Your opt-out options
How your personal information is gathered and used remains under your control. Subject to your location and the applicable legislation, you may exercise these opt-outs:
- Data sharing and sale
- Under the CCPA/CPRA and equivalent statutes elsewhere, you may refuse the sale or sharing of your personal information with third parties. Although we do not sell personal information in the traditional sense, limited data may reach trusted partners so that we can provide or improve our services.
- Cookie controls
- Use your browser's settings, or the consent tool on this site, to manage or reject cookies and other tracking technologies.
- Marketing messages
- You can stop receiving promotional email or newsletters at any time by using the unsubscribe link in any message, or by contacting us directly.
- Consent withdrawal
- Where you previously consented to processing, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it.
To exercise any of these rights, or to make an opt-out request, please contact us at [email protected] or use our contact form.
8. Changes to this notice
This notice may be refined periodically in line with legal or architectural change. Any material modification is reflected on this page with an updated date, and further use of the service constitutes acknowledgement.