Who we are
Spaya ("we", "us", "our") is a spa day pass marketplace operating at getspaya.com, based in Lisbon, Portugal. We are the data controller responsible for your personal data under the General Data Protection Regulation (GDPR) and applicable Portuguese data protection law.
Contact: hello@spaya.com
Who this policy applies to
This Privacy Policy applies to all users of the Spaya platform, including:
- Guests — individuals browsing, booking and using spa day passes through Spaya
- Hotel & Spa Partners — businesses and their staff using the Spaya partner portal
By using Spaya, you confirm that you are at least 16 years of age. Users under 16 may not create an account or make bookings on the platform.
What data we collect
3.1 Data you provide directly
- Full name — required to create an account and issue vouchers
- Email address — required for account creation, booking confirmations and voucher delivery
- Phone number — optional, used for booking-related communications
3.2 Data we collect automatically
- Geolocation data — approximate location collected when you use location-based features (e.g. “spas near me”), with your explicit consent
- Device and browser data — device type, operating system, browser version, IP address
- Usage data — pages visited, search queries, booking history, time spent on platform
- Cookies and tracking data — see Section 7 (Cookies) for full details
Why we use your data (legal basis)
4.1 Performance of a contract (Art. 6(1)(b) GDPR)
- Processing your booking and issuing QR vouchers
- Sending booking confirmation and voucher to your email
- Communicating with you about your booking
- Enabling hotel partners to verify your voucher at the door
4.2 Legitimate interests (Art. 6(1)(f) GDPR)
- Improving the platform and user experience
- Fraud detection and platform security
- Analytics to understand how users interact with Spaya
- Communicating platform updates relevant to your bookings
4.3 Consent (Art. 6(1)(a) GDPR)
- Sending marketing emails and newsletters — only if you opt in
- Collecting and using your geolocation — only when explicitly requested
- Non-essential cookies and tracking — only after you accept via our cookie banner
You may withdraw your consent at any time by contacting us at hello@spaya.com or adjusting your account settings.
Who we share your data with
We do not sell your personal data. We share it only with:
5.1 Hotel and spa partners
When you make a booking, the relevant hotel or spa partner receives your name and booking details to verify your voucher. Partners are contractually required to handle your data in compliance with GDPR.
5.2 Service providers (data processors)
- Stripe — payment processing (your payment data is handled directly by Stripe and never stored on our servers)
- Resend — transactional email delivery (booking confirmations, vouchers)
- Railway / Render — cloud hosting and infrastructure
- Google Analytics — anonymised usage analytics
All service providers are bound by data processing agreements and may only use your data to provide services to Spaya.
5.3 Legal obligations
We may disclose your data if required by law, court order, or competent authority in Portugal or the EU.
How long we keep your data
- Account data — retained for as long as your account is active, plus 2 years after account deletion
- Booking records — retained for 5 years for legal and tax compliance purposes
- Marketing data — retained until you unsubscribe or withdraw consent
- Analytics data — retained in anonymised form indefinitely; identifiable data deleted after 26 months
- Geolocation data — not stored permanently; used only in real-time to show nearby spas
Cookies
7.1 What are cookies
Cookies are small text files stored on your device when you visit Spaya. We use the following types:
7.2 Essential cookies
Required for the platform to function. Cannot be disabled.
- Session cookies — keep you logged in during your visit
- Security cookies — protect against fraud and unauthorised access
- Booking flow cookies — maintain your booking state during checkout
7.3 Analytics cookies
Used to understand how users interact with the platform. Require your consent.
- Google Analytics — tracks page views, session duration, user behaviour (anonymised IP)
7.4 Preference cookies
Remember your settings and preferences (language, location, filters). Require your consent.
7.5 Managing cookies
When you first visit Spaya, you will see a cookie consent banner. You can accept all, reject non-essential, or customise your preferences. You can change your cookie settings at any time via the cookie settings link in the footer. You can also control cookies through your browser settings. Note that disabling essential cookies may affect platform functionality.
Your rights under GDPR
As a data subject in the EU/EEA, you have the following rights:
- Right of access (Art. 15) — request a copy of all personal data we hold about you
- Right to rectification (Art. 16) — request correction of inaccurate or incomplete data
- Right to erasure (Art. 17) — request deletion of your data (“right to be forgotten”)
- Right to restriction (Art. 18) — request that we limit processing of your data
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format
- Right to object (Art. 21) — object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent — withdraw consent at any time without affecting prior processing
To exercise any of these rights, contact us at hello@spaya.com. We will respond within 30 days.
If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Portuguese data protection authority: Comissão Nacional de Proteção de Dados (CNPD) at www.cnpd.pt.
Data security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encrypted data transmission (HTTPS/TLS)
- Payment data processed exclusively by Stripe (PCI-DSS compliant)
- Access controls limiting who can access personal data within our team
- Regular security reviews and updates
No system is 100% secure. In the event of a data breach that poses a risk to your rights, we will notify you and the CNPD within 72 hours as required by GDPR.
International data transfers
Spaya operates within the EU/EEA. Some of our service providers (e.g. Stripe, Google Analytics) may process data outside the EEA. In such cases, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.
Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a prominent notice on the platform at least 14 days before the change takes effect. The current version is always available at getspaya.com/privacy.
Contact
For any privacy-related questions or to exercise your rights:
- Email — hello@spaya.com
- Website — getspaya.com
- Address — Lisbon, Portugal