Legal
Privacy Policy
Text Message (SMS) Consent
By booking and providing your phone number, you authorize Polu Resorts to send text messages with details regarding your reservation information and other offers. Message frequency varies. Message/data rates may apply. Consent is not a condition of purchase. Reply STOP to end. No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. You may opt in for SMS messages by selecting the check-box whenever you submit your phone number.
Apple Messages for Business
We offer Apple Messages for Business so you can chat with us through the Messages app on your Apple device. By booking or requesting information, you consent to receiving important messages about your inquiry, reservation, or account through this channel. Message frequency varies and message/data rates may apply. You may unsubscribe or stop messages at any time by sending the word "unsubscribe" in the conversation.
Conversations through Apple Messages for Business are started by you, and Apple does not share your phone number or Apple Account details with us unless you choose to provide contact information in the conversation. We may process the content of the messages you exchange with us, along with any information you choose to share, such as your name, email address, or reservation details, in order to respond to your inquiry and assist with your reservation or account. Apple's handling of your information is described in the Apple privacy policy.
Processing of Your Data Within the GauVendi Booking Solution
We use a booking solution from GauVendi GmbH (Feuerwehrstr. 10, Frankfurt, Germany) on our website, which allows you to make a room booking according to your personal needs and allows us to view and manage the necessary information about your booking.
The following data are processed:
- Number of persons
- Arrival and departure date
- Booked room features and rooms
- Booked additional services
- Booking country
- Other data relevant to the reservation and cancellation
- Your first and last name, email, phone number, government issued ID information, and the information of additional guests on your reservation.
The legal basis for processing is Art. 6 para. 1 lit. b) GDPR, the fulfillment of the booking contract concluded with you, as well as Art. 6 para. 1 lit. f) GDPR, our interest in the optimal provision of additional options during booking and maintaining business relationships. Additionally, we use a feature that allows us to display regional additional offers tailored to your location directly during booking. For this purpose, your IP address, which we obtain through your visit to our website, is used in shortened, anonymized form to obtain a rough estimate of your geolocation and offer you suitable regional additional options.
Guest Data in Our Property Management System (Mews)
We use Mews (Mews Systems B.V., Wibautstraat 137D, 1097DN Amsterdam, the Netherlands) as our property management system and the primary database for guest and reservation information. Mews processes this information as our data processor, on our instructions and under a Data Processing Agreement.
The information we hold in Mews may include:
- Your first and last name and contact details, including email address and phone number
- Government issued ID information and details of additional guests on your reservation
- Reservation details, such as arrival and departure dates, room and rate, and additional services
- Payment information used to guarantee and settle your stay
- Stay history, preferences, and communications relating to your booking
Guest and reservation data in Mews is hosted on Microsoft Azure cloud infrastructure and is encrypted in transit and at rest. Mews maintains independent security and privacy certifications, including SOC 2 Type 2, ISO/IEC 27001:2022, and PCI DSS v4.0.1, and processes personal data in accordance with the GDPR and the CCPA. You can review Mews' privacy practices in the Mews privacy policy and its security posture in the Mews Trust Center.
You may exercise your data protection rights, including requests to access, correct, or delete your personal information, by contacting us at [email protected]. We will coordinate with Mews and our other providers to fulfill valid requests.
Guest Operations Platform (SuiteOp)
We use SuiteOp (SuiteOp Inc.) as a guest operations and experience platform. SuiteOp processes guest information as our data processor, on our instructions, to automate check-in and check-out, verify guest identity, communicate with you before and during your stay, and support in-stay purchases and upsells.
Depending on the services active at your property, SuiteOp may process:
- Contact information, including your name, email address, and phone number
- Stay details, such as reservation dates and the property address
- Payment information and records of purchases and upsells, processed through Stripe
- Identity verification data, where identity verification is required for your booking, including a copy of a government issued ID or passport and a self-taken photo. This may involve biometric data and AI-assisted matching of your photo against your ID to confirm your identity.
- Environmental sensor readings, where a property is equipped with monitoring devices, such as noise levels measured in decibels, temperature, humidity, and CO2. These devices measure conditions only and do not record audio or video.
SuiteOp hosts data in the United States on AWS and Bubble.io infrastructure (both SOC 2 Type II certified), encrypts personal data at rest and in transit, and commits to notifying us of any personal data breach without undue delay. Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland, SuiteOp relies on the European Commission's Standard Contractual Clauses.
To deliver these services, SuiteOp engages sub-processors, including cloud hosting, identity verification, payment, and communication providers. The current list is maintained in the SuiteOp Data Processing Agreement. You may exercise your data protection rights, including access, correction, or deletion, by contacting us at [email protected].
Guest Messaging Platform (Canary Technologies)
We use Canary Technologies (Canary Technologies, Co., 275 Sacramento Street, Floor 3, San Francisco, CA 94111) as our guest messaging and communication platform. Canary powers our messaging with you before, during, and after your stay, including the text messages described above, web chat, digital check-in, and guest service requests.
Through Canary's messaging tools, we may process:
- Your name, email address, phone number, and mailing address
- The content of the messages you exchange with us and related service requests
- Reservation and stay details needed to assist you
- Device and usage information, such as IP address and browser or device type
Canary stores and processes this information primarily in the United States, as our service provider under a Data Processing Agreement. Canary maintains PCI DSS v4 and AICPA SOC (SOC 2) certifications and applies administrative, technical, and physical safeguards to protect the data. Where a payment is collected through a messaging conversation, card details are handled through the PCI DSS compliant payment tools described in the Payments and Secure Transactions section below. You can review Canary's practices in the Canary Technologies privacy policy, and you may exercise your data protection rights by contacting us at [email protected].
Payments and Secure Transactions (Canary Technologies)
We use Canary Technologies (Canary Technologies, Co., 275 Sacramento Street, Floor 3, San Francisco, CA 94111) to process payments and secure transactions and, where enabled at your property, to support contactless check-in, digital authorizations, and upsells. Canary processes this information as our service provider under a Data Processing Agreement.
Through Canary, we may process:
- Your name, email address, phone number, and billing address
- Credit or debit card details and account security codes used to authorize and settle your stay
- Your signature and reservation details on digital authorization and registration forms
- Names of additional guests you provide during the transaction
- IP address, device, and location information, which Canary uses for fraud detection and prevention
Canary stores and processes this information primarily in the United States. Canary maintains PCI DSS v4 and AICPA SOC (SOC 2) certifications and applies administrative, technical, and physical safeguards to protect the data. Where personal data is transferred internationally, Canary relies on the European Commission's Standard Contractual Clauses. You can review Canary's practices in the Canary Technologies privacy policy, and you may exercise your data protection rights by contacting us at [email protected].
Payment Processing and Identity Verification (Stripe)
We use Stripe (Stripe, Inc. and its affiliates) to process payments and, where identity verification is required, to confirm your identity through Stripe Identity. For these services Stripe acts as our service provider, and it also acts as an independent controller for its own fraud prevention and legal compliance purposes, such as anti-money laundering obligations. Stripe's handling of the data it controls is governed by the Stripe privacy policy.
Through Stripe, we may process:
- Your name, email address, and billing address
- Payment method details, such as your card or bank account information, and transaction history
- Device and location data, such as IP address, used to help prevent fraud
- Identity verification data, where verification is required, including images of your government issued ID or passport, a photo or live selfie, and details such as your name and date of birth
Where you use Stripe Identity, Stripe uses biometric technology to compare your selfie against your ID document to confirm that they match. You may separately consent to Stripe using your biometric data to improve its verification technology, and you can withdraw that consent at any time. Stripe retains biometric data for no longer than one year, or until you withdraw your consent, whichever is earlier.
Stripe is certified as a PCI DSS Level 1 service provider, the most stringent certification level in the payments industry, and encrypts payment data in transit and at rest. Stripe processes data in the United States and other countries, and relies on the European Commission's Standard Contractual Clauses and the EU-U.S. Data Privacy Framework for international transfers. Payment and compliance records may be retained for several years to meet legal and anti-fraud obligations. You may exercise your data protection rights by contacting us at [email protected] or Stripe's privacy team at [email protected].
Insurance and Payment Processing
When booking a property via Polu Resorts (including thru Airbnb, VRBO, and other online travel agencies) you consent to your personal information being shared with parties that facilitate insurance services and payment processing. Examples of these systems (including but not limited to): Truvi, property damage insurance product for vacation rentals, Canary Technologies, our payment processing system, and other tools used to mitigate risk and/or provide services to you and property owners.
Cookies, Analytics, and Tracking
Our website uses cookies and similar technologies to operate the site, to remember your preferences, and to understand how visitors use the site so we can improve it. You can control or refuse cookies through your browser settings, though some parts of the site may not function properly without them.
We use the following tag management and analytics services:
- Google Tag Manager. A tag management service from Google that we use to load and manage the measurement tags on our site, including those listed below. Google Tag Manager itself does not collect personal information, but it controls when the other tags run.
- Google Analytics. A web analytics service from Google that helps us measure traffic and how the site is used. It uses cookies and similar identifiers to collect information such as your device and browser type, the pages you view, referring pages, approximate location derived from your IP address, and your interactions with the site. This information is processed by Google, including in the United States. You can opt out using the Google Analytics Opt-out Browser Add-on.
- Microsoft Clarity. A product analytics service from Microsoft that helps us understand how visitors use our site through aggregated metrics and session replays, which are recordings of page interactions such as clicks, scrolling, and mouse movement. Clarity is configured to mask text and sensitive input by default, so the information you type is not captured. Microsoft's handling of this data is described in the Microsoft Privacy Statement.
These services do not require you to provide contact details, but they may collect online identifiers and usage data as described above. We use this information only to understand and improve the performance of our website.
Your Privacy Rights in the EEA, UK, and Switzerland (GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation and comparable laws. Subject to certain conditions, you have the right to:
- Access the personal data we hold about you and receive a copy of it
- Request correction of inaccurate or incomplete data
- Request erasure of your data
- Restrict or object to our processing of your data, including processing for direct marketing
- Receive your data in a portable, machine readable format
- Withdraw your consent at any time, where we rely on consent
- Lodge a complaint with your local data protection authority
We process your personal data to perform our contract with you, such as managing your reservation and stay, to meet our legal obligations, with your consent, such as for optional marketing messages, and for our legitimate interests in operating and improving our services. Where your data is transferred outside your region, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
To exercise any of these rights, contact us at [email protected]. We may need to verify your identity before responding.
California Privacy Rights
If you are a California resident, you have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. Subject to certain conditions, you have the right to:
- Know what personal information we collect, use, and disclose, and to access that information
- Request deletion of your personal information
- Request correction of inaccurate personal information
- Opt out of the sale or sharing of your personal information
- Limit the use and disclosure of sensitive personal information
- Not receive discriminatory treatment for exercising your rights
We do not sell your personal information for money. Some of the analytics and advertising technologies described in this policy may be considered a sale or sharing of personal information under California law. You can opt out of these technologies through your browser settings, the opt-out tools linked above, and, where required, by using an opt-out preference signal such as Global Privacy Control.
To exercise your California rights, contact us at [email protected]. You may make an authorized request up to twice in a twelve month period, and we may need to verify your identity before responding.
For any privacy questions, contact [email protected].