The Royal Collection

Privacy policy (GDPR)

Last updated: July 2026

This is an informative draft. Have it reviewed by a lawyer before going live.

1. Controller

The data controller is The Royal Collection, contact: info@theroyalcollection.eu.

2. Data we process

Identification and contact data (name, e-mail, phone), booking and payment data, communication and technical data (cookies, IP).

3. Purpose & legal basis

Contract performance (booking and stay), legal obligations (accounting), legitimate interest (site security) and consent (newsletter).

4. Recipients

Stripe (payments), Supabase (database and auth), Resend (e-mails), Vercel (hosting). All process data under data-processing agreements.

5. Retention

Booking data 10 years (accounting law), newsletter until consent is withdrawn, technical logs up to 12 months.

6. Your rights

You have the right of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with the supervisory authority.

7. Third-country transfers

Some providers may process data in the USA under EU standard contractual clauses.

Privacy policy (GDPR) · The Royal Collection