DestinationsGlobalArticlesAboutContact
Legal

Privacy Policy

Last updated 23 August 2026

This policy explains what we collect when you contact us, why we hold it, who else gets to see it, and how to have it removed. It covers gblreservations.com and the enquiries you send us through it.

The short version: we only hold what you type into a form, we do not track you around the internet, and nothing that measures or advertises runs unless you allow it first.

Who is responsible for your data

Global Reservations is a trading name of GBL Reservations LLC, a limited liability company formed in California, United States, at 2108 N Street, Suite N, Sacramento, CA 95816. We are the data controller for the information described here.

You can reach us about anything in this policy at concierge.gblreservations@gmail.com, or on WhatsApp at +54 9 381 565-7175.

What we collect

Only what you choose to send us. There is no account to create and nothing to sign up for in order to browse the site.

When you send an enquiry— from the contact page, from the “Start Planning” panel, or from any experience page — we receive: your first and last name, email address, country of residence, phone or WhatsApp number, the destination you are asking about, the number of guests, the purpose of the trip, whatever you write in the message box, how you heard about us, and whether you ticked the box asking to hear from us about trips and offers. We also record which page you sent it from, and — if you wrote from a specific villa, yacht, or venue — which one you were looking at, so that whoever replies knows what you meant.

When you ask about a destination we have not opened yet, we receive your name, email, the destination, and your message.

When you subscribe to our updates, we receive your email address and nothing else.

Cookies

The first time you arrive, a small card asks what you allow. Until you answer it, nothing that measures or advertises loads at all — not one script, not one pixel. Declining is one click and costs you nothing: the site works exactly the same.

If you answer, we store one cookie with your choice and the date, so we do not ask again on every page. It holds nothing else — no name, no identifier, nothing that says who you are. It lasts a year, and you can change your mind whenever you like from the Cookies link at the bottom of any page.

There are three groups, and you decide on the last two:

  • Strictly necessary. What the site needs to load and to send us your enquiry. That one cookie belongs to this group, which is why it is not optional.
  • Measurement. How many people visit and which pages they read — never who you are.
  • Advertising. Lets us show our trips to people like you on other sites.

What we do not collect

Stated plainly, because most sites do the opposite:

  • No trackers you have not allowed. Google Analytics, Tag Manager, the Meta pixel and any remarketing tag stay off unless you switch them on in the banner. Decline, and none of them ever loads.
  • No IP addresses, device fingerprints or browsing profiles are stored with your enquiry. We do not build a profile of you and we do not track you across other websites.
  • Nothing loads from third parties unless you allowed it. Every image, font, and script on these pages is served from our own domain, so no outside company sees you visiting us.

If we add a new kind of measurement, we will ask you again rather than assume the answer you gave before covers it, and this policy will be updated before it goes live — not after.

Why we use it, and on what legal basis

  • To answer you and plan your trip. Without your contact details and what you are asking for, we cannot quote or coordinate anything. Legal basis: taking steps at your request before entering into a contract, and performing that contract once you book.
  • To keep a record of enquiries and bookings. Legal basis: our legitimate interest in running the business, and, for confirmed bookings, our legal obligation to keep accounting records.
  • To send you news and offers. Only if you ticked the box or subscribed. Legal basis: your consent, which you can withdraw at any time.

Who else sees it

We do not sell your personal information, and we do not share it for anyone else's advertising. It is seen by:

  • Our team. Access to the enquiry system requires an individual account with a password and a separate access PIN, and each person only sees the sections they have been granted.
  • The suppliers needed to fulfil your booking — the villa, yacht, restaurant, driver, or venue. We share only what that supplier needs to hold the reservation, typically the guest name, the dates, the number of guests, and a contact number. We do this only once you ask us to arrange something.
  • The companies that run our infrastructure, acting on our instructions and nothing more: Supabase, which hosts the database; and Vercel, which hosts the website. If you email or message us, that conversation also sits with your email provider and ours, or with WhatsApp.

We may also disclose information if the law requires it, or to establish or defend a legal claim.

Where it is stored

Our database is hosted in the United States (Northern Virginia). If you write to us from the United Kingdom, the European Economic Area, or anywhere else outside the US, your information is transferred there. Those transfers are covered by the standard data protection clauses our providers enter into with us.

How long we keep it

  • Enquiries that did not lead to a booking: 5 years after our last contact with you.
  • Confirmed bookings: 7 years, because they are business records tied to payments.
  • Your subscription to our updates: until you unsubscribe.

You can ask us to delete your information sooner — see below.

Your rights

Wherever you live, you can write to us and ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. We will not treat you differently for asking.

If you are in the United Kingdom or the European Economic Area, you also have the right to restrict or object to how we use your information, to receive it in a portable format, and to withdraw consent for marketing at any time — withdrawing it does not affect what we sent before. If you believe we have handled your information badly, you can complain to your national data protection authority.

If you are a California resident, you have the right to know what we collect, to have it deleted, to correct it, and to opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information, so there is nothing to opt out of.

California law also asks us to say how we respond to “Do Not Track” signals from your browser. We do not track visitors at all — no analytics, no advertising tag, and no profile built from your visit — so there is nothing for that signal to switch off.

To exercise any of this, email concierge.gblreservations@gmail.com. We answer within 30 days. To stop marketing emails you can also use the unsubscribe link in any of them.

How we protect it

Everything travels over an encrypted connection. The database enforces row-level access rules, files shared with suppliers and clients are served through links that expire after a few minutes rather than from a public folder, and staff access needs both a password and a second access PIN. No system is perfect, but we do not keep what we do not need, which is the part that helps most.

Children

This site is meant for adults arranging travel. We do not knowingly collect information from anyone under 16. If a child has sent us something, write to us and we will delete it.

Changes to this policy

If we change how we handle your information, we will update this page and the date at the top. If the change is significant — for example, if we start using analytics — we will make it obvious on the site rather than quietly editing this text.

Questions

Write to concierge.gblreservations@gmail.com. If you would rather talk it through, the contact page reaches the same people.

Concierge WhatsApp