Privacy
Privacy policy
Last updated 12 September 2026. This covers this website, our concierge desks, our telephone line, and the travel and celebration services we arrange.
The short version
We collect what we need to arrange your travel and nothing more. We share it with the suppliers who have to deliver your trip, and with the technology providers who run our systems. We do not sell your information and we do not sell or share it for advertising. We never ask for card, bank or government-identification numbers in a chat, a form or an email. You can ask us what we hold, correct it, or have it deleted.
1. Who is responsible
Gwynevere-Arthur Royal Escapes, a Georgia company, is the controller of the personal information described here. Contact us on +1 (727) 266-1264, 9am–7pm Eastern, or through the request form, and mark it “privacy”.
2. What we collect
| Information | Examples |
|---|---|
| Who you are | Name, email, telephone, the names and ages of people travelling with you |
| What you want | Dates, destinations, occasion, party size, budget band, preferences, the notes you write us |
| Travel documents | Passport details, visa and entry documentation, frequent-traveller numbers — only where a supplier or a government actually requires them, and only once you send them to us securely |
| Care information | Dietary needs, allergies, accessibility and mobility needs, and anything else you choose to tell us so that you are looked after |
| Conversations | Your messages with our concierge desks, and telephone messages left on our line including their transcription |
| Payment information | Amounts, dates and references. Card details are entered directly with our payment processor and are never stored by us |
| Vendor applications | Business name, contact details, specialties, regions, insurance status and references you give us |
| Technical | IP address, browser type and pages visited, used to keep the site working and secure |
Dietary, allergy, medical and accessibility information is sensitive. We collect it only because you have chosen to tell us so that your trip is safe and comfortable, we pass it only to the suppliers who must act on it, and we do not use it for anything else.
3. Why we use it, and our lawful bases
| Purpose | Lawful basis (GDPR / UK GDPR) |
|---|---|
| Answering your enquiry and preparing options | Steps taken at your request prior to a contract |
| Arranging, booking and coordinating your travel or event | Performance of our contract with you |
| Passing dietary, allergy, accessibility and medical needs to suppliers | Your explicit consent, and protection of vital interests where safety requires it |
| Taking and reconciling payments; holding client funds | Contract, and legal obligation |
| Preventing fraud and verifying supplier banking | Our legitimate interests, and yours |
| Keeping accounting and tax records | Legal obligation |
| Sending you our own occasional updates | Your consent — withdrawable at any time, in one click |
| Vetting vendor and contractor applications | Steps prior to a contract, and our legitimate interests |
4. The concierge desks, plainly
Our concierge desks are automated. When you write to one, your message and the reply are processed by a third-party artificial-intelligence provider under contract to us, stored in our request queue, and read by a Royal Advisor so your request can be acted on. We do not permit that provider to use your conversation to train its models.
The desks make no decisions about you — no pricing, no approval, no refusal. Every decision with a consequence is made by a person. If you would rather not use a desk at all, telephone us or use the request form and a person will handle it from the start.
Please do not type card numbers, bank details, government identification numbers or passwords into a chat. We do not need them there, and we will never ask for them there.
5. Who we share it with
- Suppliers who must deliver your trip — the property, airline, cruise line, charter operator, driver, venue, caterer, photographer, stylist and so on. They receive only what they need. Passenger names and passport details go to carriers; a dietary need goes to the caterer.
- Our technology providers — website hosting, our database, our telephone system, our payment processor, our email provider, and the AI provider described above. Each is bound by contract to protect your information and to use it only for us.
- Professional advisers — our accountant, insurer, and lawyers where necessary.
- Authorities — where the law genuinely requires it, including border and immigration requirements.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not pass your details to other travel companies to market to you.
6. International transfers
We arrange travel worldwide, so your information will be sent to suppliers in the country you are travelling to, and our providers are largely in the United States. Where information leaves the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) or another lawful transfer mechanism, together with the safeguards in our provider contracts. Where you have asked us to book in a particular country, the transfer to the suppliers there is also necessary to perform that contract.
7. How long we keep it
| What | How long |
|---|---|
| Enquiries that do not become bookings | 24 months, then deleted |
| Booking and event files | 7 years after travel, for tax, insurance and liability reasons |
| Concierge conversations and telephone messages | 24 months, or with the booking file if a booking follows |
| Financial and client-account records | 7 years, as required |
| Vendor applications that are declined | 12 months |
| Marketing consent records | Until you withdraw, then a suppression record so we do not contact you again |
8. How we protect it
Access is limited to the people who need it. Every company account requires multi-factor authentication. Credentials are held in a password manager and never in a document, an email or a chat. Traveller information is not accessed on shared or public computers, or over public wi-fi without a VPN. Our request queue is built so that the public website can file a request into it and cannot read anything back out of it. Card data is held by our payment processor and never by us.
No system is perfect. If a breach ever affects your information, we will tell you and the relevant regulator within the time the law requires, and we will tell you what we are doing about it.
9. Your rights
Wherever you live, you may ask us to:
- tell you what we hold about you, and give you a copy
- correct anything wrong
- delete it, where we are not required to keep it
- restrict or object to a particular use
- send it to you or another provider in a portable format
- withdraw a consent you gave, including for marketing
If you are in the EEA, the UK or Switzerland these are your GDPR rights, and you may also complain to your national data protection authority.
If you are in California you have the right to know, delete, correct, and to opt out of sale or sharing — we do not sell or share, so there is nothing to opt out of — and the right not to be discriminated against for exercising any of them. An authorised agent may act for you with written proof.
To exercise any right, telephone +1 (727) 266-1264 or write through the request form marked “privacy”. We respond within 30 days (45 for California requests, extendable once where the law allows). We may need to verify who you are first, and we will not charge you for a reasonable request.
10. Cookies and analytics
This site uses only the cookies and local storage needed to make it work — keeping you signed in to the advisor desk, and remembering a conversation in progress. We do not run advertising cookies and we do not let third parties track you across other websites. If we later add analytics, we will ask your consent first where the law requires it and update this page.
11. Children
This site is for adults. We do not knowingly collect information directly from anyone under 16. We do hold children's names, ages and care needs when a parent or guardian gives them to us so that a family can travel — that comes from you, not from the child. If you believe a child has sent us information directly, tell us and we will delete it.
12. Changes
When we change this policy we update the date at the top. If a change materially affects how we use information we already hold about you, we will tell you directly rather than rely on you noticing.
13. Contact
Gwynevere-Arthur Royal Escapes · Georgia, United States · +1 (727) 266-1264 · 9am–7pm Eastern, seven days a week · request form