Data protection

Privacy Policy

How Astervina collects, uses, shares, and protects the information readers give us.

Revised: 2 September 2026

1. What this notice covers

Astervina publishes hospitality reviews and passes reservation enquiries to properties. Guarding personal data and explaining our handling of it clearly is an obligation we hold across all reader touchpoints.

Below we explain the categories Astervina gathers, the purposes they serve, the parties they may reach, and the safeguards applied — whether you are reading rankings, creating a profile, or sending a stay enquiry.

2. Information we collect

To return accurate availability, verified assessments, and reliable enquiry confirmations, we handle several categories of record:

Who you are and how to reach you
Name, salutation, chosen language, residential region, the email address you authorise, and telephone contact points given at registration or enquiry.
Travel and room requirements
Check-in and check-out dates, room type and bedding choice, suite tier, dietary requirements, accessibility needs, and hotel loyalty references.
Billing verification records
The cardholder's name, masked card identifiers, billing location, and confirmation tokens issued by certified payment intermediaries. Complete card numbers never reach Astervina systems.
Device telemetry and technical metadata
IP address, browser version, operating system, referring pages, time zone, device identifiers, and interaction timestamps.

3. Legal grounds and operational purposes

Processing takes place only under an established lawful ground — contractual necessity, legitimate interest, legal obligation, or consent you have given. Those grounds support the following purposes:

Enquiry fulfilment
Relaying your dates and requirements to the property's reservations desk so it can answer with current availability.
Editorial personalisation
Adjusting the rankings and guides we surface to match the destinations and property styles you have shown interest in.
Fraud prevention and security
Keeping the infrastructure secure, verifying that requests are legitimate, and preventing unauthorised access to reader profiles.
Operational communication
Issuing reservation updates, confirmation vouchers, itinerary reminders, and essential service notifications.
Meeting legal obligations
Satisfying accounting disclosure, tax reporting, and other duties imposed by the jurisdictions in which we operate.

4. Disclosure and partners

We do not sell, rent, or lease personal identifiers to unconnected commercial parties. Transfers happen only under contractual safeguards, and only to the following categories of recipient:

The hotels themselves
Resorts receive the guest name, dates, and accommodation specifics strictly necessary to respond to a request or honour a reservation.
Certified payment gateways
Where payment is involved, encrypted billing details are routed to PCI-DSS validated processing partners.
Hosting and cloud services
Encrypted database backups sit with tier-1 hosting and content distribution providers to ensure availability.
Legal and regulatory authorities
Disclosure may follow a valid legal demand, court order, or regulatory mandate, or be necessary to protect someone's vital interests.

5. Digital identifiers and measurement

Cookies and browser storage let us recognise repeat visitors, remember currency and layout preferences, evaluate site performance, and preserve session integrity. You retain complete control through your browser, but switching off essential cookies degrades enquiry functionality.

6. Safeguards and how long we keep records

Layered administrative, technical, and physical controls protect records against unauthorised access, loss, alteration, or extraction. These include TLS 1.3 in transit, AES-256 at rest, segregated database clusters, and role-restricted credentials.

Records are held only as long as needed to complete an enquiry, resolve a question, satisfy audit requirements, or meet a statutory retention period. Once that period ends, records are permanently erased or irreversibly anonymised.

7. Your rights

Depending on where you live, and after identity verification, you can exercise these rights:

Access and inspection
Request a transferable copy of your stored records and verify our handling procedures.
Right to correction
Request prompt correction of profile information that is wrong, partial, or out of date.
Right to erasure
Ask for records to be deleted where no statutory or contractual basis for keeping them remains.
Restriction
Pause processing activity while a record's accuracy or our legitimate interest is under review.

Opt-out and your choices

How your personal information is gathered and used remains under your control. Subject to your location and the applicable legislation, you may exercise these opt-outs:

Sharing and sale of your data
You may opt out of the sale or sharing of your personal information with third parties where laws such as the CCPA/CPRA in California, or comparable legislation elsewhere, provide for it. While we do not sell personal information in the conventional sense, some data may be shared with trusted partners in order to provide or improve the service.
Cookie controls
Use your browser's settings, or the consent tool on this site, to manage or reject cookies and other tracking technologies.
Marketing communications
You can stop receiving promotional email or newsletters at any time by using the unsubscribe link in any message, or by contacting us directly.
Consent withdrawal
Any consent you have given may be withdrawn at any point. Doing so does not render unlawful the processing that occurred before withdrawal.

To exercise any of these rights, or to make an opt-out request, please contact us at [email protected] or use our contact form.

8. Updates to this document

Astervina may revise this notice to reflect regulatory developments or changes to the service. Material amendments appear on this page with a new effective date, and continued use of the site after publication indicates acceptance of the revised terms.