Privacy Policy
1. Who We Are
LuxStay is a Closed User Group (CUG) hotel booking platform operated in the United Kingdom. This policy explains how we collect, use, and protect your personal data.
2. Data We Collect
When you create an account, we collect your email address and name (provided via Google Sign-In). When you make a booking, we collect the information necessary to complete the reservation, including guest names and payment details.
We also collect anonymous usage data through PostHog (analytics) and Microsoft Clarity (session recordings) to improve the service. This data is not linked to your personal identity.
3. How We Use Your Data
Your email address and name are used to create your member account, send booking confirmations (via EmailJS), and communicate important service updates. We do not send marketing emails unless you explicitly opt in.
Booking information is shared with our distribution partner (LiteAPI) and the hotel to fulfil your reservation.
4. Cookies and Tracking
We use essential cookies to maintain your login session. We use PostHog for product analytics and Microsoft Clarity for understanding how users interact with the site. Both tools use cookies. You can opt out of non-essential tracking using your browser settings.
5. Third-Party Services
We share data with the following services as necessary to operate the platform: Google Identity Services (authentication), LiteAPI (hotel booking fulfilment), PostHog (analytics), Microsoft Clarity (session analytics), and EmailJS (booking confirmation emails).
Each of these services has its own privacy policy governing how they handle data.
6. Data Retention
Account data is retained for as long as your account is active. Booking records are retained for 7 years in accordance with UK accounting requirements. You can request deletion of your account and personal data at any time.
7. Your Rights
Under UK GDPR, you have the right to access your personal data, request correction of inaccurate data, request deletion of your data, object to processing, and request data portability. To exercise any of these rights, contact us at luxstaymembers@gmail.com.
8. Data Security
All data is transmitted over HTTPS with TLS encryption. Payment processing is handled by a PCI DSS-compliant gateway. We do not store payment card details on our servers.
9. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated to members via email.
10. Contact
For privacy-related enquiries, contact us at luxstaymembers@gmail.com.
Last updated: March 2026