When you visit villasoleil.id or contact us via WhatsApp/email, we may collect:
Booking details: name, email, phone, dates, group size, special requests.
Communication content: WhatsApp messages, emails you send to us.
Payment information: handled by our bank or payment processor (we do not store full card numbers on our servers).
Website analytics: anonymized via Google Analytics 4 and Microsoft Clarity — page views, click events, scroll depth, country (IP truncated). No personally identifiable information.
Cookies: first-party for session tracking; third-party (Clarity, GA4) for analytics. See section 5.
2. How we use it
To respond to your inquiry and arrange your stay.
To process payment.
To coordinate services (driver, chef, spa) you request during stay.
To follow up after your visit (one feedback request only — no marketing spam).
To improve the website and our content (aggregated analytics).
3. Who we share with
We share data only with:
Service providers you book through us (drivers, chefs, etc.) — they receive your name and contact only.
Airbnb if you booked through them (their privacy policy applies).
Indonesian authorities if legally required.
We do not sell your data, ever.
4. Data retention
Booking communications retained for 2 years after your last interaction (Indonesian tax/business records). Analytics data retained 14 months in GA4 then deleted. Marketing list (if you opted in): until you unsubscribe.
5. Cookies
We use:
Essential cookies: session storage to track if you've seen popups; no consent needed.
Analytics cookies: Google Analytics 4 (anonymized IP, _ga, _gid) and Microsoft Clarity (_clck, _clsk) — used to understand site usage.
You can opt out by enabling Do Not Track in your browser or using a cookie blocker. We honor DNT signals.
6. Your rights
Under Indonesian Law No. 27/2022 on Personal Data Protection (UU PDP) and GDPR (for EU visitors), you have the right to:
Access — see what data we hold about you
Correction — fix incorrect data
Deletion — request removal (subject to legal retention requirements)
Portability — receive your data in a portable format
Withdraw consent — opt out of marketing or analytics
The site uses TLS 1.2/1.3, HSTS preload, and Cloudflare protection. Data on our servers is access-restricted. No system is 100% secure but we take reasonable measures.
8. Children
The website is for adults arranging stays. We do not knowingly collect data from children under 13.
9. Changes
We may update this policy. Material changes will be noted at the top with a new "Last updated" date. Continued use of the site after changes constitutes acceptance.