
Legal
Privacy Policy
How we collect, use and protect your personal information.
Who we are and what this policy covers
Pure Concierge Services (“we”, “us”, “our”) arranges hotels, villas, charter boats, event and sports tickets, flights and travel, and bespoke trips for clients in Ibiza, the United Kingdom and worldwide. This policy explains what personal information we collect through this website and when we deal with you directly, why we collect it, who we share it with, and what your rights are.
We are the “data controller” for the information described here, which means we decide how and why it is used. We follow the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).
If you have any question about this policy or your information, email hello@pureconciergeservices.com. We have not appointed a Data Protection Officer; that address reaches the person who looks after data protection for us.
This policy applies to visitors to this website, people who send us an enquiry, our clients, and other people named in a booking we arrange (for example, other members of a travelling group).
The short version
- We collect only what we need to answer your enquiry and arrange your booking.
- We never sell your information, and we don’t send marketing emails or messages unless you’ve agreed to them.
- We share it only with the suppliers and service providers needed to do what you’ve asked us to do.
- We delete enquiry records after 12 months without contact, and keep client records for 6 years (for tax and legal reasons).
- You can ask to see, correct or delete your information at any time.
What information we collect, and why
Information you give us through the website
When you use our enquiry form we collect:
- Your name and email address (both required) and, if you choose to give it, your phone number.
- Which services you are interested in, where you would like to go, how many people, your rough budget, and your travel dates (or that your dates are undecided).
- Anything else you write in the notes box.
Please don’t put sensitive details (such as health information or card numbers) in the form. We’ll ask for anything we genuinely need separately.
Information you give us in other ways
If you email us, message us on WhatsApp or call us, we keep the details you share and a record of our conversation so that we can help you and keep an accurate account of what was agreed.
When you book with us
To arrange a booking we may also need the full names of everyone travelling (as shown on their passport or ID), dates of birth, passport or ID details where a supplier or airline requires them, contact details, special requests (for example dietary needs, accessibility needs or a celebration), and records of what was booked and paid for.
Some of these, such as dietary or accessibility requirements, can reveal information about health or religious belief. The law treats that as “special category” information. We only ask for it when it is needed to arrange something for you, and we do so with your explicit consent, which you can withdraw at any time (although we may then be unable to arrange that part of your trip).
If you give us information about other people, such as your travelling companions, please make sure they know and are happy for you to do so, and show them this policy.
This website does not take payments or store card details. If we ask you to pay for a booking, we will tell you how, and we will keep a record of the payment (but not your full card number).
Information we collect automatically
- Your IP address when you submit the enquiry form. We keep it for 30 days to spot and block spam and abuse.
- Our website host keeps standard technical logs (such as IP address, browser type and the pages requested) to keep the site secure and running.
- Your cookie choice, saved in your browser (see “Cookies and similar technologies” below).
- If you accept analytics cookies: how you use the site (the pages you view, how long you stay, the device and browser you use, roughly where in the world you are, and how you found us), collected by Google Analytics.
Information from other people
Sometimes we receive your details from someone else, for example a friend or colleague who is booking for a group, or from a supplier we are working with on your booking. We use it only for that booking.
Why we use your information, and our legal basis
- To reply to your enquiry and prepare costed options: taking steps at your request before a contract (UK GDPR Article 6(1)(b)).
- To arrange and manage your booking, including passing details to suppliers: performing our contract with you (Article 6(1)(b)).
- To keep a record of our dealings with you and follow up on your enquiry: our legitimate interest in running our business and responding to people who contact us (Article 6(1)(f)).
- To keep accounts, meet tax obligations and deal with legal claims: legal obligation and our legitimate interests (Article 6(1)(c) and (f)).
- To keep the website and our systems secure and to prevent spam and abuse: our legitimate interests (Article 6(1)(f)).
- To use special category information such as dietary or accessibility needs: your explicit consent (Article 9(2)(a)).
- To use non-essential cookies or similar technologies, if we ever use them: your consent (PECR regulation 6 and Article 6(1)(a)).
Where we rely on legitimate interests, we have weighed them against your rights and expectations. You can object at any time (see “Your rights” below).
What we don’t do
- We don’t sell or rent your personal information.
- We don’t make decisions about you by automated processing or profiling.
- We don’t send marketing emails or messages unless you have asked us to. If that changes we will ask for your consent first, and every message will include an easy way to opt out.
Who we share your information with
We only share what is needed, and only for the reasons below.
Suppliers and travel partners
To arrange your trip we pass the necessary details (for example names, dates, group size and requests) to the hotels, villa owners and agents, charter operators, ticket and hospitality providers, airlines, transfer companies and local partners involved. They use the information to provide the service and are responsible for it under their own privacy policies.
Companies that help us run the website and the business
These companies handle information on our behalf and only under our instructions:
- Supabase: the secure database, sign-in system and file storage behind this website. Our data is stored in London, UK.
- Vercel: hosts this website. Our site runs from London, UK.
- Resend: sends the emails our website generates, such as the confirmation we email you after an enquiry. Those emails contain the details you submitted.
- Google Workspace: our business email.
- Google Analytics (Google): measures how visitors use the site, but only if you accept analytics cookies. Google receives your IP address and browser details when it loads, and handles the information for us under its data processing terms.
- Meta (WhatsApp): if you contact us on WhatsApp.
Others
We may share information with our professional advisers (such as accountants, lawyers and insurers), and with authorities such as HMRC, the police or the courts where the law requires it or to protect our legal rights. If our business is ever sold or reorganised, your information may be passed to the new owner, who must use it in line with this policy.
Links to other websites
This website links to other sites (such as WhatsApp). We are not responsible for how they use your information, so please read their privacy policies.
Sending information outside the UK
Some of the companies above are based in, or can access information from, other countries (for example the United States), and many of the suppliers we work with are abroad (for example in Spain and elsewhere in Europe and beyond). Whenever your information leaves the UK, we make sure it is protected by one of the safeguards the law allows: the destination country is covered by UK “adequacy” regulations (this includes the countries of the European Economic Area), or the recipient is bound by approved contract terms (the UK International Data Transfer Agreement, or the UK Addendum to the EU standard contractual clauses), or a US recipient is certified under the UK–US data bridge.
Where none of those applies, for example a villa owner in a country without an adequacy decision, we send only what is necessary to carry out the booking you asked for, which UK GDPR permits (Article 49(1)(b)). If you would like detail about the safeguard for a particular transfer, contact us.
How long we keep it, and keeping it safe
How long we keep your information
We keep personal information only for as long as we need it for the reasons above, and our website deletes old records automatically on a monthly schedule. The periods are:
- Enquiries and contact records for people who don’t become clients: deleted 12 months after our last contact with you.
- Client records (bookings, correspondence and payment records): kept for 6 years after our last activity with you, for tax, accounting and legal-claims purposes, then deleted.
- Spam or abusive enquiries: deleted after 30 days.
- IP addresses used for spam protection on the enquiry form: deleted after 30 days.
- Copies of the emails our website sends: deleted after 12 months.
- Security records of sign-in attempts to our admin area (our team only): deleted after 90 days.
- Website analytics information (only if you accept analytics cookies): kept for 14 months, then deleted automatically by Google Analytics.
Emails and messages we exchange with you directly are kept for the same periods as the records they relate to. If you ask us to delete your information sooner, we will, unless the law requires us to keep it (for example accounting records). Your cookie choice stays in your browser until you clear it.
Keeping your information safe
- All traffic to this website is encrypted (HTTPS).
- Our systems can only be reached by named members of our team, who must sign in with a password and a second step (an authenticator app).
- Our database uses access rules so that the public can read only published website content, never enquiries or client records.
- We use well-known, reputable providers for hosting, database and email.
No system is completely secure. If a data breach is likely to put your rights and freedoms at risk, we will report it to the Information Commissioner’s Office within 72 hours and, where required, tell you without undue delay.
Cookies and similar technologies
Cookies are small files that a website saves on your device. “Similar technologies” includes your browser’s local storage. Under PECR we need your consent for anything that isn’t strictly necessary to provide the service you asked for.
What this website uses
- Your cookie choice: a note called “cookie-consent” saved in your browser’s local storage so that we remember whether you accepted or declined. It is strictly necessary for the cookie banner to work, stays on your device until you clear it, and is not sent to us.
- Analytics cookies (Google Analytics): these count visits and show which pages are popular, so we can improve the site. They are only set if you choose Accept on our cookie banner. The cookies are named “_ga” and “_ga_” followed by letters and numbers, and last up to two years.
- Advertising cookies: we don’t use any, and we tell Google not to use analytics information for advertising.
- Our admin area: our team’s sign-in uses essential cookies. Visitors never receive them.
You can change your mind at any time using “Cookie preferences” in the footer of any page, and you can block or delete cookies in your browser’s settings (your browser’s help pages explain how). Blocking essential cookies may stop parts of the site working.
Our enquiry form is protected against spam by a hidden field and by limiting how often one connection can submit it. If we add a bot-check service in future, we will list it here.
Your rights, and how to complain
Under UK data protection law you have the right to:
- Be informed about how we use your information (this policy).
- Access a copy of the personal information we hold about you.
- Have inaccurate information corrected, or incomplete information completed.
- Have your information erased, in some circumstances.
- Restrict how we use your information, in some circumstances.
- Receive your information in a portable format, where we use it based on your consent or a contract.
- Object to us using your information on the basis of our legitimate interests, and to any direct marketing.
- Withdraw your consent at any time, where we rely on it (this won’t affect anything we did before).
- Not be subject to a decision based solely on automated processing. We don’t make any.
To use any of these rights, email hello@pureconciergeservices.com. We may need to check your identity first. We will reply within one month (this can be extended by up to two further months for complex requests, and we will tell you if so). There is no charge, unless a request is clearly unfounded or excessive.
Children
Our services are for adults. This website is not aimed at children and we don’t knowingly collect their information through it. If a booking includes children, the adult making the booking provides their details.
Complaints
If you are unhappy with how we have handled your information, please tell us first so that we can put it right. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator: ico.org.uk/make-a-complaint or telephone 0303 123 1113.
Changes to this policy
We may update this policy from time to time. The date at the top of the page shows when it last changed, and we will make any important change clear here.
Contact us
Pure Concierge Services · hello@pureconciergeservices.com · WhatsApp or phone +44 7947 559710
