PRIVACY POLICY
Last updated: September 10, 2026
At COSTA GLOW (accessible from costaglow.com), the privacy of our visitors and clients is one of our main priorities. This Privacy Policy document outlines the types of information we collect, how we use it, how it is disclosed, and the strict security practices implemented to protect it in accordance with the European General Data Protection Regulation (GDPR).
1. INFORMATION WE COLLECT
When you interact with our website or purchase a Flexible Gold Pass, we may collect the following data:
- Personal Identification Information: Name, email address, phone number, and billing address.
- Transaction Data: Payment details (processed securely via Stripe), purchase history, and voucher issuance records.
- Log Files & Analytics: IP addresses, browser type, internet service provider (ISP), date/time stamps, and referring/exit pages to optimize website performance.
2. HOW WE USE YOUR INFORMATION
We use the collected information strictly to operate our business and provide a secure, luxury service, specifically to:
- Process your payment securely and issue your Flexible Gold Pass vouchers.
- Communicate with you regarding your bookings, itinerary customization, and customer support.
- Fulfill our accounting, tax, and legal obligations under Spanish and EU law.
- Protect our website against fraudulent transactions, unauthorized access, and cyber threats.
3. DATA DISCLOSURE TO THIRD PARTIES
We do not sell, rent, or trade your personal data to third parties. Your information is only disclosed to trusted partners necessary to execute our services:
- Payment Processors: Your payment data is securely transferred directly to Stripe to process transactions. COSTA GLOW does not store your full credit card details.
- Hosting & Concierge Partners: Once you redeem your voucher and personalize your itinerary, minimal logistical data (such as your name) is shared with authorized accommodation, private chauffeur, and wellness partners exclusively to coordinate your arrival and stay.
- Legal Compliance: We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., the Spanish Tax Agency / AEAT).
4. METHOD OF DISCLOSURE AND TRANSFER
Data is transferred electronically using secure, encrypted protocols. Because we utilize global service providers like Stripe for transaction infrastructure, your data may be processed in secure data centers monitored under recognized international data protection frameworks.
5. SECURITY PRACTICES & DATA SAFEGUARDS
We implement industry-standard security measures to safeguard your personal information from unauthorized access, alteration, disclosure, or destruction:
- Encryption: All data transmitted through our website is protected using secure SSL (Secure Sockets Layer) encryption technology.
- Tokenization: Payment details are fully tokenized by Stripe, ensuring sensitive financial information never touches our local servers.
- Access Control: Access to your personal identification data is strictly restricted to authorized administrators who require the information to manage your luxury itinerary.
6. YOUR DATA PROTECTION RIGHTS (GDPR)
Under the GDPR, you have the right to access, rectify, or request the deletion of your personal data stored by us. You also have the right to restrict or object to certain data processing methods. To exercise any of these rights, please contact our privacy manager at info@costaglow.com.
