Data protection

Privacy Policy

How Tavurina collects, uses, shares, and protects the information readers give us.

Last revised: 2 September 2026

1. Scope and application

Tavurina publishes hospitality reviews and passes reservation enquiries to properties. Guarding personal data and explaining our handling of it clearly is an obligation we hold across all reader touchpoints.

Below we explain the categories Tavurina gathers, the purposes they serve, the parties they may reach, and the safeguards applied — whether you are reading rankings, creating a profile, or sending a stay enquiry.

2. Categories of information gathered

The following categories are collected so that we can provide accurate availability, verified editorial assessments, and reliable confirmations:

Personal identity and contact information
Name, salutation, chosen language, residential region, the email address you authorise, and telephone contact points given at registration or enquiry.
Stay preferences and requirements
Dates of travel, room configuration and category, bedding selection, dietary and accessibility requests, and loyalty programme identifiers.
Billing and payment confirmation records
Cardholder name, truncated card indicators, billing address, and transaction confirmation tokens handled by accredited payment processors. Full card numbers are never stored on Tavurina servers.
Device telemetry and technical metadata
IP address, browser version, operating system, referring pages, time zone, device identifiers, and interaction timestamps.

3. Legal grounds and operational purposes

Processing takes place only under an established lawful ground — contractual necessity, legitimate interest, legal obligation, or consent you have given. Those grounds support the following purposes:

Passing on your request
Transmitting itinerary details to the partner resort so a room hold and arrival preparations can be arranged.
Tailoring what you see
Presenting hospitality rankings and reviews aligned with the regions and property categories you browse.
Security and verification
Defending the platform's infrastructure, checking that submissions are genuine, and protecting profiles from unauthorised access.
Operational communication
Issuing reservation updates, confirmation vouchers, itinerary reminders, and essential service notifications.
Meeting legal obligations
Satisfying accounting disclosure, tax reporting, and other duties imposed by the jurisdictions in which we operate.

4. Who receives your information

There is no sale, rental, or leasing of personal identifiers to unrelated commercial entities. Disclosures occur strictly under contractual protection to the parties below:

The hotels themselves
Resorts receive the guest name, dates, and accommodation specifics strictly necessary to respond to a request or honour a reservation.
Payment processors
Where payment is involved, encrypted billing details are routed to PCI-DSS validated processing partners.
Infrastructure providers
Encrypted database backups sit with tier-1 hosting and content distribution providers to ensure availability.
Legal and regulatory authorities
Information may be released where a lawful subpoena, court order, or official mandate requires it, or to protect vital interests.

5. Cookies and analytics

Digital identifiers and local storage support returning-visitor recognition, preference retention, performance measurement, and session continuity. Control rests with you via browser configuration; blocking essential cookies will impair some features.

6. Safeguards and how long we keep records

We apply multi-layered administrative, technological, and physical defences — TLS 1.3 transport encryption, AES-256 storage encryption, separated database clusters, and access limited by role — to guard against unauthorised access, loss, or alteration.

Retention lasts no longer than the enquiry, any related correspondence, audit obligations, or a statutory holding period demand. At expiry, records are erased permanently or anonymised irrevocably.

7. Rights and choices available to you

Subject to verification of your identity and the law in your jurisdiction, you may exercise the following:

Access and inspection
Receive a copy of the data we hold about you, in a portable form, along with an explanation of its use.
Rectification
Have inaccurate, incomplete, or outdated details corrected without undue delay.
Erasure
Ask for records to be deleted where no statutory or contractual basis for keeping them remains.
Restriction
Restrict our use of your data during any dispute over accuracy or over our grounds for processing.

Choices you can exercise

Control over the collection and use of your personal information rests with you. Where local law provides for it, the following choices apply:

Sharing and sale of your data
Under the CCPA/CPRA and equivalent statutes elsewhere, you may refuse the sale or sharing of your personal information with third parties. Although we do not sell personal information in the traditional sense, limited data may reach trusted partners so that we can provide or improve our services.
Cookies and tracking
Cookies and similar tracking tools can be managed or declined via your browser configuration or the consent controls published on this website.
Promotional email
Promotional email and newsletters can be discontinued through the unsubscribe link in any message or by contacting us directly.
Withdrawing consent
Where you previously consented to processing, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it.

Write to [email protected], or use the contact form on this site, to exercise any right or lodge an opt-out request.

8. Updates to this document

This notice may be refined periodically in line with legal or architectural change. Any material modification is reflected on this page with an updated date, and further use of the service constitutes acknowledgement.