Legal
Privacy Policy
Last updated : 14 July 2026 — working draft, final version expected end of August 2026
This policy explains how St Barth Experience (“SBE”, “we”) processes your personal data when you visit stbarthexperience.com, create an account or book a service, in accordance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act (Loi Informatique et Libertés).
1. Data controller
The data controller is St Barth Experience, Gustavia, Saint-Barthélemy (97133) — contact@stbarthexperience.com. [Full legal identification to be completed.]
2. Data we collect
We only collect the data we need:
- Account data — name, email address, password (stored in hashed form), language and currency preferences;
- Booking data — the services booked, dates, number of participants, messages exchanged with the Provider, billing history;
- Payment data — processed directly by our payment provider Stripe; we never store your full card number;
- Technical data — IP address, browser type, pages viewed and server logs, used for security and to operate the service.
3. Purposes and legal bases
Your data is processed:
- to create and manage your account and your bookings (performance of a contract);
- to process payments and payouts and to prevent fraud (performance of a contract; legal obligation);
- to meet our accounting, tax and consumer-law obligations (legal obligation);
- to secure and improve the Platform (legitimate interest);
- to send you marketing communications, only if you have agreed to receive them (consent, withdrawable at any time).
4. Who receives your data
Your data is shared only with: the Provider concerned by your booking (name, party size, dates and any information needed to perform the service); our processors (hosting, email delivery, payment processing via Stripe), each bound by a data processing agreement; and public authorities where the law requires it.
We never sell your personal data.
5. International transfers
Our services are hosted in the European Union wherever possible. Where a processor is located outside the EU/EEA, the transfer is protected by an adequacy decision or by the European Commission's Standard Contractual Clauses.
6. How long we keep your data
Account data is kept for the life of your account and deleted or anonymised after three years of inactivity. Invoices and transaction records are kept for the statutory retention periods (up to ten years under French commercial and tax law). Server logs are kept for a maximum of twelve months.
7. Your rights
Under the GDPR and French law, you have the right to:
- access your data and obtain a copy;
- rectify inaccurate or incomplete data;
- request erasure of your data;
- restrict or object to certain processing, including marketing;
- receive your data in a portable format;
- withdraw your consent at any time;
- set directives on the fate of your data after your death.
8. Exercising your rights
To exercise these rights, write to contact@stbarthexperience.com; we respond within one month. You may also lodge a complaint with the CNIL, the French supervisory authority (cnil.fr).
9. Security
We apply appropriate technical and organisational measures: encrypted connections (TLS), hashed passwords, access controls, activity logs and the principle of least privilege for internal access.
10. Cookies
Cookies and similar technologies are described in our Cookie Policy.
11. Changes to this policy
We may update this policy from time to time. The date of the latest version appears at the top of this page; substantial changes are notified to registered users.