Privacy

Privacy Policy

Your data belongs to you. This policy explains in plain language how your personal data is collected, used, shared and protected when you use VillaGetaway.app.

Last updated: 20 May 2026KVKK compliantUK GDPR & EU GDPR compliantICO registered
Summary
  • • We do not sell your data.
  • • We process it only to provide and improve the service and to meet legal obligations.
  • • You can download, correct or delete it at any time.
  • • Your data is stored in UK and EU data centres, encrypted with AES-256.

VillaGetaway.app ("we", "the platform") is operated by BIL ENTERPRISES LTD (Company No. 16856290, England and Wales). The importance we place on your privacy shapes how our product is designed. For any questions, please use the contact channels below.

01

Data we collect

  • Account information: full name, email, phone, profile photo, date of birth (age verification).
  • Identity verification: passport / ID card image and selfie (only at the moment of verification, stored as a hash).
  • Booking information: dates, number of guests, messaging content, reviews.
  • Payment information: card details are held by our PCI-DSS Level 1 certified payment provider (Stripe); we do not store them. Only the last 4 digits and card brand are kept.
  • Location data: only if you grant permission in the app; used to find nearby properties.
  • Usage data: device, browser, IP address, language preferences and on-site interactions.
02

How we use your data

  • To manage your bookings, facilitate communication with hosts and forward concierge requests.
  • Account security, fraud prevention and identity verification (machine-learning assisted risk scoring).
  • Legal obligations: tax reporting, anti-money-laundering (AML), consumer rights.
  • Anonymous analytics and A/B testing to improve service quality.
  • Personalised recommendations and marketing communications with your explicit consent — withdrawable at any time.
03

Data sharing

  • With hosts: name, profile photo and contact details once a booking is confirmed. The address is only shared 48 hours before check-in.
  • With payment providers (Stripe) and verification providers (Onfido / Persona) strictly for processing purposes.
  • With legal authorities upon a court order or mandatory legal request.
  • We do not sell your data to advertisers or any third parties.
04

Data retention

  • Account data: kept while the account is active; deleted or anonymised within 30 days after closure.
  • Booking records: 10 years as required by tax legislation.
  • Messaging: 3 years after the booking (for dispute resolution).
  • Marketing preferences: until you withdraw your consent.
  • Identity verification images: deleted within 7 days of completing verification.
05

Security

  • All traffic is encrypted with TLS 1.3.
  • Sensitive data is encrypted at rest with AES-256.
  • Access is protected by layered Row Level Security (RLS) policies — only you can see your own data.
  • Two-factor authentication (2FA) is optional for all accounts and mandatory for hosts.
  • Independent penetration tests and SOC 2 Type II audits are carried out annually.
06

Your rights (KVKK & GDPR)

  • Access: download all of your data in a machine-readable format.
  • Rectification and erasure (right to be forgotten).
  • Object to processing and to automated decision-making.
  • Data portability — transfer to another platform.
  • Withdraw consent (does not affect past processing).
  • Complaints: KVKK Authority (Türkiye), the ICO (UK — Information Commissioner's Office) or the supervisory authority in your country.
07

Cookies & tracking technologies

  • Strictly necessary cookies: session, language, currency (no consent required).
  • Analytics cookies: anonymised usage metrics (with consent).
  • Marketing cookies: retargeting (with consent, withdrawable at any time).
  • You can manage your cookie preferences from the 'Cookie settings' link in the footer.
08

International data transfers

  • Your data is hosted in the United Kingdom and the EU (Frankfurt and Dublin data centres).
  • Our service providers (Supabase, Stripe, Cloudflare) operate in the EU, the UK and the US.
  • Transfers outside the UK / EU rely on Standard Contractual Clauses (SCC), the UK IDTA and equivalent safeguards.
09

Children's privacy

  • Our platform is not directed at people under 18; the minimum age to create an account is 18.
  • Names of children included as guests on a booking are used solely to notify the host.
  • If we discover that we have unknowingly collected data from a child, we will delete it within 72 hours.
10

Data breach notification

  • When a breach is detected, we notify the relevant authorities within 72 hours (GDPR Article 33).
  • In high-risk cases, affected users are informed directly by email.
  • To report suspicious activity: info@villagetaway.app
11

Data Controller

  • BIL ENTERPRISES LTD
  • Company No. 16856290 · Registered in England and Wales
  • Suite A Bank House, 81 Judes Road, TW20 0DF, Egham, United Kingdom
  • ICO Registration: pending
12

Contact & Data Protection Officer

  • Data Protection Officer (DPO): info@villagetaway.app
  • General privacy enquiries: info@villagetaway.app
  • Post: BIL ENTERPRISES LTD, Suite A Bank House, 81 Judes Road, TW20 0DF, Egham, United Kingdom
  • Response time: within 30 days at the latest (GDPR Article 12).
This policy may be updated from time to time. We notify you of material changes by email at least 30 days in advance and keep previous versions in our archive.
Version 2.1 · Published 20 May 2026