Privacy Policy
1. Controller
LuxeStyle LLC, the operating subsidiary of LuxeTivities LLC. Contact: legal@luxetivities.com.
2. What we collect
Account data (name, email, membership number); booking data (dates, party size, requests, notes, amounts, payment method and status); concierge chat messages (processed by our AI provider, Anthropic, to generate automated replies, and readable by our human concierge team); identity verification status and method — for in-app verification, pass/fail signals from Stripe Identity (we do not store your ID document or selfie; Stripe processes and retains those under its own policy); for in-person verification, only the fact, date, and verifying staff member are recorded — we do not photograph or copy your ID; insurance documents you choose to upload; technical logs (IP address, device data) collected by our hosting providers for security.
3. Why we process it (legal basis)
To provide the service and fulfil bookings (contract, GDPR Art. 6(1)(b)); to verify identity and prevent fraud (legitimate interests, Art. 6(1)(f), and legal obligation where applicable); to meet tax and accounting obligations (legal obligation, Art. 6(1)(c)); to send service communications (contract); marketing only with your consent (Art. 6(1)(a)), which you may withdraw at any time.
4. Processors and recipients
We use these processors: Supabase (database, authentication, file storage), Vercel (hosting), Stripe (payments and identity verification), Anthropic (automated concierge responses — chat content is sent to Anthropic’s API to generate replies), and Google Mail & Voice (email/SMS provider). Payments made via Cash App or Zelle are processed by those services under their own terms. Suppliers receive the booking details needed to fulfil your Experience (e.g., your name and party size). We do not sell personal data.
5. International transfers
Our processors may store data in the United States and other countries. Where GDPR applies, transfers rely on Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework as implemented by each processor.
6. Retention
Account and chat data: for the life of your membership and 12 months after closure. Booking and payment records: 7 years for tax/accounting compliance. Uploaded insurance documents: deleted 90 days after the related booking completes. Logs: 30–90 days.
7. Your rights
Where GDPR or similar laws apply, you may access, correct, export, restrict, object to, or delete your personal data, and lodge a complaint with your supervisory authority. In-app: use “Download my data” and “Delete my account” on the Member page. Deletion removes your profile, bookings, messages, and uploaded documents from our systems; financial records we must keep by law, and records held independently by payment processors, are retained for the mandated period.
8. Security
Data is encrypted in transit and at rest by our providers; access is restricted by row-level security so members can only access their own records; identity documents never touch our servers; insurance uploads live in a private bucket accessible only to you and our vetted staff.
9. Children
The service is for adults. We do not knowingly process data of anyone under 18.
10. Changes
We will notify you of material changes in the app or by email before they take effect.