Privacy Policy
How Valpurena collects, uses, shares, and protects the information readers give us.
Last updated: 2 September 2026
1. Scope and application
As an editorial catalogue and booking-enquiry directory for premier accommodation, Valpurena takes on a firm duty to protect individual records and to maintain transparency wherever readers interact with the service.
This document sets out what Valpurena collects, how it is organised and used, when it is transferred, and how it is protected when you browse the catalogue, read ratings, register a profile, or submit an accommodation request.
2. What we collect through the service
Delivering accurate lodging information, verified reviews, and dependable enquiry handling requires us to process the following categories:
- Who you are and how to reach you
- Full name, form of address, preferred language, region of residence, email address, and any telephone number you supply when registering or submitting an enquiry.
- Reservation preferences
- Arrival and departure dates, room and bed configuration, suite category, dietary notes, accessibility requests, and any loyalty membership reference.
- Billing verification records
- Cardholder identity, partial card indicators, billing address, and processor-issued confirmation tokens. At no point is a full card number retained on Valpurena infrastructure.
- Technical and device data
- IP address, browser version, operating system, referring pages, time zone, device identifiers, and interaction timestamps.
3. Legal grounds and operational purposes
Processing takes place only under an established lawful ground — contractual necessity, legitimate interest, legal obligation, or consent you have given. Those grounds support the following purposes:
- Handling enquiries
- Forwarding your stay details to the relevant property so it can respond on availability and prepare for arrival.
- Content customisation
- Shaping featured rankings and travel guidance around your preferred destinations and resort types.
- Protecting the service
- Safeguarding digital infrastructure, validating the legitimacy of transactions, and shielding users from unauthorised profile access.
- Operational communication
- Delivering enquiry acknowledgements, booking references, travel reminders, and critical service messages.
- Meeting legal obligations
- Meeting accounting, tax reporting, and record-keeping requirements set by the applicable administrative authorities.
4. Authorised disclosures
Personal identifiers are never sold, rented, or leased to unaffiliated businesses. Data moves only where a contract governs it, and only to these recipients:
- Hospitality partners
- Selected properties are given only the name, arrival dates, and room details required to answer an enquiry or hold a room.
- Payment processors
- Encrypted billing data passes to certified financial gateways operating to current PCI-DSS validation standards.
- Infrastructure providers
- Tier-1 data centres and content delivery networks hold encrypted backups so the service stays available and recoverable.
- Courts and regulators
- Information may be released where a lawful subpoena, court order, or official mandate requires it, or to protect vital interests.
5. Cookies, storage, and analytics
Cookies and browser storage let us recognise repeat visitors, remember currency and layout preferences, evaluate site performance, and preserve session integrity. You retain complete control through your browser, but switching off essential cookies degrades enquiry functionality.
6. Storage protection and retention
We apply multi-layered administrative, technological, and physical defences — TLS 1.3 transport encryption, AES-256 storage encryption, separated database clusters, and access limited by role — to guard against unauthorised access, loss, or alteration.
Records are held only as long as needed to complete an enquiry, resolve a question, satisfy audit requirements, or meet a statutory retention period. Once that period ends, records are permanently erased or irreversibly anonymised.
7. Rights and choices available to you
Depending on where you live, and after identity verification, you can exercise these rights:
- Access
- Request a transferable copy of your stored records and verify our handling procedures.
- Right to correction
- Have inaccurate, incomplete, or outdated details corrected without undue delay.
- Right to erasure
- Have your data removed once processing is no longer required by law or by the purpose it served.
- Restriction
- Pause processing activity while a record's accuracy or our legitimate interest is under review.
Opt-out and your choices
Control over the collection and use of your personal information rests with you. Where local law provides for it, the following choices apply:
- Sharing and sale of your data
- You may opt out of the sale or sharing of your personal information with third parties where laws such as the CCPA/CPRA in California, or comparable legislation elsewhere, provide for it. While we do not sell personal information in the conventional sense, some data may be shared with trusted partners in order to provide or improve the service.
- Cookies and tracking
- Use your browser's settings, or the consent tool on this site, to manage or reject cookies and other tracking technologies.
- Promotional email
- Opt out of promotional messages and newsletters using the unsubscribe link in any communication, or by writing to us.
- Consent withdrawal
- Any consent you have given may be withdrawn at any point. Doing so does not render unlawful the processing that occurred before withdrawal.
To exercise any of these rights, or to make an opt-out request, please contact us at [email protected] or use our contact form.
8. Revisions
This notice may be refined periodically in line with legal or architectural change. Any material modification is reflected on this page with an updated date, and further use of the service constitutes acknowledgement.