Your data
Privacy policy
This policy explains what personal data Villa La Selva Bandung collects when you browse this site or book a stay, why we hold it, who we share it with, and the rights you have over it.
Last updated: August 16, 2026
Who is responsible for your data
Villa La Selva Bandung (“we”, “us”) is the data controller for the personal data described here. We operate the villa at Dago, Bandung, West Java, Indonesia, and the website https://laselva.id.
For any question about this policy, or to exercise the rights described below, write to stay@laselva.id.
What we collect
When you book a stay
You do not need an account to book. We ask for your name and at least one way to reach you — an email address or a phone number, your choice. Alongside that we store the booking itself: your reference number, the villa, your check-in and check-out dates, the price, deposit and any discount or coupon applied, the language you booked in, any note you send us, any add-ons you order, and the times you check in and out.
When you pay
Card and wallet payments are handled entirely by our payment provider on their own pages. We never see or store your card number, CVV or banking credentials. What we keep is the payment record: method, amount, status, our order reference and the provider’s transaction status and timestamps.
When you write to us
If you contact us by email, phone or WhatsApp, we keep that correspondence and the contact details it carries so we can answer you and handle your stay.
When you leave a review
Testimonials are published only with your agreement. We show the name you give us, optionally your city or country and the month of your stay, your rating and your words. Give us a first name or initials if you would rather not be identified — and tell us any time you want it taken down.
When you simply visit
Our web server records ordinary technical data for each request: your IP address, the time, the page requested, and your browser’s user-agent string. These logs exist to keep the site running and secure, not to profile you.
Why we hold it, and on what basis
Under the EU General Data Protection Regulation, every use of your data needs a lawful basis. Ours are:
- To take and honour your booking — confirming dates, collecting the deposit, sending you the details you need before arrival, and welcoming you on the day. Basis: performance of our contract with you.
- To take payment and prevent fraud — passing what our payment provider needs to process the transaction and reconcile it afterwards. Basis: performance of our contract, and our legitimate interest in being paid and in preventing fraudulent bookings.
- To keep our books — retaining booking and payment records for the period Indonesian tax and accounting law requires. Basis: compliance with a legal obligation.
- To keep the site working and secure — server logs, error diagnostics and abuse prevention. Basis: our legitimate interest in a site that stays up and is not attacked.
- To publish your testimonial — showing your review on this site. Basis: your consent, which you can withdraw at any time.
We do not sell your data, we do not use it for automated decision-making or profiling, and we do not send marketing email unless you ask us to.
Who else sees it
We share your data only with the service providers that make the booking work, and only with what each of them needs:
- Midtrans (PT Midtrans, Indonesia) — our payment gateway. At checkout we pass your name, email address, phone number, order reference and the amount due so it can process the payment.
- Our hosting and email providers — they store the database and deliver the booking emails we send you.
- Google — this site embeds a Google map of our location and loads its typefaces from Google’s servers, so your IP address reaches Google when a page loads. See the cookies section below.
- Booking platforms — if you booked through Airbnb or a similar site rather than with us directly, that platform’s own privacy policy governs what it holds; we receive your booking details from them.
We may also disclose data where the law compels us to, or where it is necessary to establish or defend a legal claim.
Where your data goes
We are based in Indonesia and your data is stored here. If you are in the European Economic Area or the United Kingdom, booking with us means your data is transferred outside it. Indonesia has not received an adequacy decision from the European Commission, so we rely on the derogation in Article 49(1)(b) of the GDPR: the transfer is necessary to perform the booking contract you asked us to enter into. Some of our providers also process data in other countries; where they do, they are bound by contractual safeguards.
How long we keep it
- Booking and payment records — ten years after your stay, the period Indonesian tax law requires us to keep accounting records.
- Bookings that were never confirmed — enquiries and holds that expire without payment are deleted within twelve months.
- Correspondence — two years after our last exchange, unless it relates to a booking we still have to keep.
- Published testimonials — until you ask us to remove them.
- Server logs — twelve months.
Cookies
We set one cookie of our own: a session cookie that remembers your progress through the booking form. It is strictly necessary for the site to work, it carries no identifier we can trace back to you, and it disappears when you close your browser. We run no analytics, advertising or tracking cookies.
The Google map on our home page and stay guide is served by Google and may set its own cookies once it loads. Loading a page also fetches our typefaces from Google’s font servers, which discloses your IP address to Google. If you would rather avoid this, your browser’s content-blocking settings can prevent those requests; the rest of the site works without them.
Your rights
If the GDPR applies to you, you have the right to ask us for a copy of the data we hold about you, to have it corrected, to have it deleted, to restrict or object to how we use it, and to receive it in a portable format. Where we rely on your consent, you may withdraw it at any time without affecting what we did beforehand.
Write to stay@laselva.id and we will respond within one month. We may need to verify your identity first. Note that we cannot delete records we are legally required to keep for tax purposes until that period runs out — but we will restrict them to that purpose alone.
If you are unhappy with how we have handled your data, you may complain to the data protection authority in your country of residence.
Security and children
The site is served over an encrypted connection, payment details never touch our servers, and access to the booking system is limited to our staff, who sign in with individual accounts. No system is perfectly secure, but we take these measures seriously and review them.
Our booking service is meant for adults. We do not knowingly collect data from children; if a child has given us data, write to us and we will delete it.
Changes to this policy
When we change how we handle your data we will update this page and move the date at the top. If the change is significant and we hold your contact details, we will tell you directly.