Legal

Privacy Policy

Spaya — getspaya.com · Last updated: July 2026

01

Who we are

Spaya ("we", "us", "our") is a spa day pass marketplace operating at getspaya.com, based in Lisbon, Portugal. We are the data controller responsible for your personal data under the General Data Protection Regulation (GDPR) and applicable Portuguese data protection law.

Contact: hello@spaya.com

02

Who this policy applies to

This Privacy Policy applies to all users of the Spaya platform, including:

  • Guestsindividuals browsing, booking and using spa day passes through Spaya
  • Hotel & Spa Partnersbusinesses and their staff using the Spaya partner portal

By using Spaya, you confirm that you are at least 16 years of age. Users under 16 may not create an account or make bookings on the platform.

03

What data we collect

3.1 Data you provide directly

  • Full namerequired to create an account and issue vouchers
  • Email addressrequired for account creation, booking confirmations and voucher delivery
  • Phone numberoptional, used for booking-related communications

3.2 Data we collect automatically

  • Geolocation dataapproximate location collected when you use location-based features (e.g. “spas near me”), with your explicit consent
  • Device and browser datadevice type, operating system, browser version, IP address
  • Usage datapages visited, search queries, booking history, time spent on platform
  • Cookies and tracking datasee Section 7 (Cookies) for full details
04

Why we use your data (legal basis)

4.1 Performance of a contract (Art. 6(1)(b) GDPR)

  • Processing your booking and issuing QR vouchers
  • Sending booking confirmation and voucher to your email
  • Communicating with you about your booking
  • Enabling hotel partners to verify your voucher at the door

4.2 Legitimate interests (Art. 6(1)(f) GDPR)

  • Improving the platform and user experience
  • Fraud detection and platform security
  • Analytics to understand how users interact with Spaya
  • Communicating platform updates relevant to your bookings

4.3 Consent (Art. 6(1)(a) GDPR)

  • Sending marketing emails and newsletters — only if you opt in
  • Collecting and using your geolocation — only when explicitly requested
  • Non-essential cookies and tracking — only after you accept via our cookie banner

You may withdraw your consent at any time by contacting us at hello@spaya.com or adjusting your account settings.

05

Who we share your data with

We do not sell your personal data. We share it only with:

5.1 Hotel and spa partners

When you make a booking, the relevant hotel or spa partner receives your name and booking details to verify your voucher. Partners are contractually required to handle your data in compliance with GDPR.

5.2 Service providers (data processors)

  • Stripepayment processing (your payment data is handled directly by Stripe and never stored on our servers)
  • Resendtransactional email delivery (booking confirmations, vouchers)
  • Railway / Rendercloud hosting and infrastructure
  • Google Analyticsanonymised usage analytics

All service providers are bound by data processing agreements and may only use your data to provide services to Spaya.

5.3 Legal obligations

We may disclose your data if required by law, court order, or competent authority in Portugal or the EU.

06

How long we keep your data

  • Account dataretained for as long as your account is active, plus 2 years after account deletion
  • Booking recordsretained for 5 years for legal and tax compliance purposes
  • Marketing dataretained until you unsubscribe or withdraw consent
  • Analytics dataretained in anonymised form indefinitely; identifiable data deleted after 26 months
  • Geolocation datanot stored permanently; used only in real-time to show nearby spas
07

Cookies

7.1 What are cookies

Cookies are small text files stored on your device when you visit Spaya. We use the following types:

7.2 Essential cookies

Required for the platform to function. Cannot be disabled.

  • Session cookieskeep you logged in during your visit
  • Security cookiesprotect against fraud and unauthorised access
  • Booking flow cookiesmaintain your booking state during checkout

7.3 Analytics cookies

Used to understand how users interact with the platform. Require your consent.

  • Google Analyticstracks page views, session duration, user behaviour (anonymised IP)

7.4 Preference cookies

Remember your settings and preferences (language, location, filters). Require your consent.

7.5 Managing cookies

When you first visit Spaya, you will see a cookie consent banner. You can accept all, reject non-essential, or customise your preferences. You can change your cookie settings at any time via the cookie settings link in the footer. You can also control cookies through your browser settings. Note that disabling essential cookies may affect platform functionality.

08

Your rights under GDPR

As a data subject in the EU/EEA, you have the following rights:

  • Right of access (Art. 15)request a copy of all personal data we hold about you
  • Right to rectification (Art. 16)request correction of inaccurate or incomplete data
  • Right to erasure (Art. 17)request deletion of your data (“right to be forgotten”)
  • Right to restriction (Art. 18)request that we limit processing of your data
  • Right to data portability (Art. 20)receive your data in a structured, machine-readable format
  • Right to object (Art. 21)object to processing based on legitimate interests or for direct marketing
  • Right to withdraw consentwithdraw consent at any time without affecting prior processing

To exercise any of these rights, contact us at hello@spaya.com. We will respond within 30 days.

If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Portuguese data protection authority: Comissão Nacional de Proteção de Dados (CNPD) at www.cnpd.pt.

09

Data security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encrypted data transmission (HTTPS/TLS)
  • Payment data processed exclusively by Stripe (PCI-DSS compliant)
  • Access controls limiting who can access personal data within our team
  • Regular security reviews and updates

No system is 100% secure. In the event of a data breach that poses a risk to your rights, we will notify you and the CNPD within 72 hours as required by GDPR.

10

International data transfers

Spaya operates within the EU/EEA. Some of our service providers (e.g. Stripe, Google Analytics) may process data outside the EEA. In such cases, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.

11

Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a prominent notice on the platform at least 14 days before the change takes effect. The current version is always available at getspaya.com/privacy.

12

Contact

For any privacy-related questions or to exercise your rights:

  • Emailhello@spaya.com
  • Websitegetspaya.com
  • AddressLisbon, Portugal