Privacy Policy

Effective 16 April 2026 · Last updated 16 April 2026

UU PDP 27/2022 GDPR (EU) CCPA (California) APPI (Japan)

Contents

  1. 1. Introduction & Controller
  2. 2. Personal Data We Collect
  3. 3. Legal Bases for Processing
  4. 4. How We Use Your Data
  5. 5. Sharing & Disclosure
  6. 6. International Transfers
  7. 7. Data Retention
  8. 8. Security
  9. 9. Cookies & Tracking
  10. 10. Your Rights (UU PDP / GDPR)
  11. 11. Children's Privacy
  12. 12. Automated Decisions
  13. 13. Indonesia UU PDP Addendum
  14. 14. EEA/UK GDPR Addendum
  15. 15. California Addendum (CCPA)
  16. 16. Changes to This Policy
  17. 17. Contact & DPO

1. Introduction & Data Controller

The Luxury Bali ("Platform", "we", "us", "our") is operated by The Luxury Leisure Group — a private limited company registered in Indonesia. This Privacy Policy explains how we collect, use, store, and protect your personal data when you access or use our platform, website, mobile experiences, and related services (collectively, the "Services").

This policy complies with:

Data Controller: The Luxury Leisure Group, Bali, Indonesia. Contact: privacy@theluxurybali.com.

2. Personal Data We Collect

2.1 Data you provide directly

CategoryExamplesPurpose
IdentifiersFull name, email, phone, countryAccount, booking, contact
Booking dataDates, guest count, special requestsProcess reservations
Payment data*Card data handled by Xendit/Stripe (PCI-DSS); we store only last 4 digits + masked refPayment, refund, fraud prevention
Host dataBusiness name, address, NPWP, NIB, bank details for payoutsHost onboarding, tax compliance
ContentMessages, reviews, photos you uploadService delivery, platform listings
Identity docs**Passport scan, KTP (if hosting)KYC, fraud prevention, legal compliance

* We never store your full credit card number or CVV. Payment processing is delegated to PCI-DSS Level 1 certified providers (Xendit, Stripe).
** Identity documents are encrypted at rest and retained only as long as required by Indonesian tax/AML law.

2.2 Data collected automatically

2.3 Data from third parties

3. Legal Bases for Processing (GDPR Art. 6 / UU PDP Art. 20)

Processing ActivityLegal Basis
Booking fulfilment, paymentsContract performance
Account management, supportContract performance
Marketing emails (after opt-in)Consent
Analytics cookies (optional)Consent
Fraud detection, AML/KYCLegal obligation + legitimate interest
Platform improvementLegitimate interest
Defence of legal claimsLegitimate interest

4. How We Use Your Data

We do not sell your personal data to third parties.

5. Sharing & Disclosure

5.1 Property hosts

When you book, we share your name, contact details, arrival date, guest count, and any special requests with the host fulfilling your reservation. Hosts are contractually bound to use this data only for your stay and to delete it after 90 days post-departure.

5.2 Service providers (sub-processors)

ProviderPurposeLocation
Vercel Inc.Platform hosting, CDNUSA, Singapore
SupabaseDatabase, authenticationSingapore (ap-southeast-1)
XenditPayment processing (Indonesia)Indonesia, Singapore
Stripe (optional)International card paymentsUSA, Ireland
ResendTransactional emailUSA
Twilio / Meta WhatsApp BusinessMessagingUSA, Ireland
Google Analytics 4Usage analytics (with consent)USA
Meta PixelAdvertising (with consent)USA, Ireland
Anthropic (Claude API)AI concierge (messages processed; no storage beyond session)USA
SentryError monitoringUSA

All sub-processors are bound by Data Processing Agreements meeting GDPR Art. 28 standards.

5.3 Legal

We may disclose personal data when required by law, court order, or to protect the rights, property, or safety of our users, staff, or the public.

6. International Data Transfers

Your data may be processed in Indonesia (primary), Singapore, the United States, and the European Union. For transfers from the EEA/UK, we rely on the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework.

For transfers from Indonesia under UU PDP Art. 56, we ensure the receiving country has an adequate level of protection, or we implement contractual safeguards with sub-processors.

7. Data Retention

Data CategoryRetention PeriodReason
Booking records10 years post-stayIndonesian tax law (PER-02/PJ/2019)
Host financial records10 yearsAccounting law
Enquiry (no booking)12 monthsRemarketing + dispute handling
Support tickets3 yearsQuality assurance
Account dataDuration of account + 24 months after deletionFraud prevention window
KYC documents5 years post-relationshipAML Act
Marketing consent records3 years after withdrawalProof of compliance
Analytics (aggregated)Indefinite (anonymised)Platform improvement

8. Security

9. Cookies & Similar Technologies

We use four categories of cookies:

CategoryPurposeOpt-in required?
Strictly NecessarySession, CSRF, loginNo (essential)
PreferencesCurrency, language, dark modeNo (essential)
AnalyticsGA4 aggregated usageYes
MarketingMeta Pixel, remarketingYes

On first visit, you see our cookie consent banner with granular controls. You can change preferences anytime via the "Cookie Preferences" link in our footer. Setting your browser Do Not Track header will be honoured for analytics and marketing cookies.

10. Your Rights

You have these rights over your personal data, exercisable at any time by emailing privacy@theluxurybali.com. We respond within 30 days (GDPR) or 72 hours for urgent requests (UU PDP Art. 7).

11. Children's Privacy

Our Service is intended for users aged 18 and above. We do not knowingly collect personal data from individuals under 18. If we become aware we have inadvertently collected data from a minor, we will delete it promptly. Bookings that include minors as guests are made by the adult booker; we collect only name and age band (e.g. "child 0–12").

12. Automated Decision-Making

We do not subject users to purely automated decisions with legal or similarly significant effect (GDPR Art. 22 / UU PDP Art. 10). Fraud scoring is reviewed by a human before any account or booking is declined. AI-assisted villa recommendations are advisory only — you make the final choice.

13. Indonesia (UU PDP) Addendum

Under UU PDP 27/2022, you have the rights listed in Article 5–15. To exercise them, contact our Data Protection Officer (see Section 17). If we cannot resolve your concern, you may lodge a complaint with:

Lembaga Pengawas Pelindungan Data Pribadi (data protection supervisory authority under the Ministry of Communication and Information Technology — kominfo.go.id).

14. EEA/UK (GDPR) Addendum

Our EU representative (GDPR Art. 27), if required, will be appointed upon reaching the threshold. For now, direct all enquiries to dpo@theluxurybali.com. You may lodge a complaint with your local data protection authority (e.g. the CNIL in France, ICO in the UK, or the authority where you live).

15. California (CCPA / CPRA) Addendum

California residents have the right to know what personal information we collect, request deletion, and opt out of "sale" or "sharing" of personal information. We do not sell personal information. Contact privacy@theluxurybali.com with subject "CCPA Request" to exercise your rights.

16. Changes to This Policy

We may update this policy to reflect legal, technical, or business changes. Material changes will be communicated via email to active users and via a banner on the Platform at least 30 days before taking effect. Continued use after that date signifies acceptance.

17. Contact & Data Protection Officer

Data Protection Officer: dpo@theluxurybali.com
Privacy enquiries: privacy@theluxurybali.com
Postal: The Luxury Leisure Group, c/o The Luxury Bali, Seminyak, Badung, Bali 80361, Indonesia

For urgent data breach notifications, please mark your email subject "URGENT — Data Breach".