Privacy Policy
Last updated: 29 September 2026
The short version
- We collect what the service needs to work, and nothing for advertising.
- We do not sell personal data, and we do not use analytics or ad trackers.
- Businesses that use RezPartner control their clients' data. We handle it only on their instructions.
- We use only the cookies that keep you signed in and protect forms.
- You can ask to see, correct or delete your data at support@rezpartner.com.
1. Who we are and our two roles
RezPartner ("we", "us") provides software that travel and experience businesses ("vendors") use to manage inventory, send proposals, issue invoices and itineraries, and run a storefront. This policy explains how we handle personal data. We handle it in two roles:
- As controller, for data about the people who use our service: account holders, their teams, people we invite, and visitors to our own pages. We decide how this data is used.
- As processor, for data that vendors put into their workspaces about their own clients, and for booking requests that visitors send to a vendor's storefront. The vendor is the controller of that data. We use it only to provide the service to that vendor.
We follow the Barbados Data Protection Act, 2019. Where other laws such as the EU or UK GDPR apply to you, we respect the rights they give you.
2. What we collect
| Data | What it includes | Where it comes from |
|---|---|---|
| Account | Email address, password (stored only as a one-way hash), company name, your role in each workspace, and when you confirmed your email. | You, when you sign up or accept an invitation. |
| Sessions | For each signed-in device: the browser and system (from the user agent), the IP address, and the sign-in time. You can see these in your account settings. | Your browser, when you sign in. |
| Invitations | The email address invited, who sent the invitation, and when. | The workspace member who sends it. |
| Workspace content | Business details, inventory, images, prices, proposals, invoices and itineraries. | Vendors and their teams. |
| Vendors' client data | Client names, email addresses, phone numbers, notes, trip details, and clients' answers to proposals. | Vendors, and clients who answer a proposal. |
| Booking requests | Name, email, phone (optional), number of guests, preferred date, and the item or option chosen. | Visitors to a vendor's storefront. |
| Technical logs | IP address, date and time, the page requested, and errors. | Your browser, on every request. |
We do not ask for payment card details, passport numbers or other sensitive data. Please do not put sensitive data (for example health details) in notes unless you need to and you have a lawful basis.
3. How we use it
- To create and secure your account, and to keep you signed in.
- To send the emails the service needs: email confirmation, password resets, email-change confirmations, invitations and important notices about the service or these policies.
- To run the features you use, such as proposals, invoices and storefronts.
- To find and stop abuse, fix errors and keep the service reliable.
- To meet legal obligations.
We do not send marketing email unless you agree to it. We do not sell personal data, we do not use it for advertising, and we do not make automated decisions about people that have legal or similar effects.
4. Legal bases
- Contract: to provide the service you signed up for.
- Legitimate interests: to keep the service secure and working, and to answer your messages.
- Legal obligation: when the law requires us to keep or disclose data.
- Consent: where we ask for it. You can withdraw consent at any time.
For vendors' client data, the vendor chooses the legal basis, and we act on the vendor's instructions.
5. Who we share it with
We share personal data only with:
- The workspace team. Everyone in a vendor's workspace can see that workspace's data.
- People a vendor shares a link with. A proposal, itinerary or invoice link shows its contents to whoever opens it. Storefront listings are public.
- Service providers that process data for us, under contracts that limit how they use it:
| Provider | What it does | Location |
|---|---|---|
| DigitalOcean | Hosts the service: servers, the database and uploaded files. | United States (New York) |
| Resend | Sends the service's emails. | United States |
| Google Fonts | Supplies the fonts the pages use. Your browser requests them from Google, which receives your IP address. | Global |
| YouTube (Google) | Shows video thumbnails and plays videos that a vendor adds to an item. We use YouTube's privacy-enhanced mode, and your browser contacts YouTube only on pages with a video. | Global |
- Authorities, when the law requires it or to protect the rights and safety of people or the service.
- A successor, if the service is sold or transferred. We will tell you before your data comes under a different privacy policy.
We will update this list before we add a new provider that handles personal data.
6. Cookies
We use only cookies that the service needs to work:
- A session cookie that keeps you signed in and protects forms from forgery.
- A "keep me signed in" cookie, if you choose it. It lasts up to 14 days.
We do not use analytics, advertising or tracking cookies. Because these cookies are needed for the service, we do not ask for consent to them. If you block them, you cannot sign in.
7. Where data is stored
Our servers and our email provider are in the United States. If you are outside the United States, your data is transferred there. We rely on our providers' contractual commitments to protect it to the standard that the laws above require.
8. How long we keep it
| Data | How long |
|---|---|
| Account and workspace data | While the account is open. Deleted within 30 days after it is closed. |
| Sign-in sessions | Expire after 14 days, or when you sign out or end them in settings. |
| Email links | Confirmation links work for 3 days, password reset links for 1 hour, and invitations for 7 days. |
| Web server logs (these include IP addresses) | 14 days. |
| Application logs (these do not include IP addresses) | Kept for a limited time, then deleted automatically. |
| Vendors' client data | As long as the vendor's account is open, or until the vendor asks us to delete it. |
We keep data for longer only when the law requires it.
9. Security
- All traffic uses HTTPS.
- Passwords are stored only as bcrypt hashes. Nobody at RezPartner can read them.
- Links in our emails contain one-time codes. We store only a hash of each code, and each code expires.
- You can see every signed-in device and end any session.
- Each vendor's data is kept separate, and only its workspace members can reach it.
No system is completely secure. If a breach affects your personal data, we will tell you and the authorities as the law requires.
10. Your rights
You can ask us to:
- give you a copy of the personal data we hold about you;
- correct data that is wrong;
- delete your data;
- limit or stop some uses of it;
- give you your data in a format you can move to another service.
Email support@rezpartner.com from the address on your account. We will answer within one month. You can change your email and password yourself in your account settings.
11. If you are a vendor's client
If a travel or experience business sent you a proposal, itinerary or invoice through RezPartner, or you sent a booking request on its storefront, that business controls your data. Please contact the business first. If you contact us, we will pass your request to the business and help it respond.
12. Children
The service is for businesses, and account holders must be 18 or older. We do not knowingly collect data from children. A vendor may record details of a child who is part of a trip; that vendor is responsible for having a lawful basis and a parent's or guardian's permission.
13. Changes
If we change this policy in an important way, we will email account holders at least 30 days before the change takes effect. The date at the top shows the latest version. See also our Terms of Service.
14. Contact and complaints
Privacy questions and requests: support@rezpartner.com.
If you are not happy with our answer, you can complain to the Data Protection Commissioner of Barbados, or to the data protection authority where you live.