Staging Environment — synthetic data only

Guest access

Privacy notice

How Villa Elita Hotel & Resort handles booking and account information.

This notice describes the personal information we collect for reservations and authenticated guest or staff portals. It is intended for demo and pre-production review and is not a substitute for a DPO-approved privacy policy.

Who we are

Villa Elita Hotel & Resort (short name: Villa Elita) operates hospitality services in Sudipen, La Union, Philippines.

What we collect for bookings

  • Name, email, and optional phone number you provide for a reservation.
  • Stay dates, room selection, guest count, and related booking preferences.
  • Privacy acknowledgement and optional marketing consent choices.
  • Technical request metadata needed to secure the booking API (for example request ids).

Authentication

The production target uses local Villa Elita accounts secured by encrypted, server-side Laravel sessions in PostgreSQL. The browser receives a Secure, HttpOnly session cookie and CSRF protection; it does not receive access or refresh tokens. Retired external identity-provider authentication paths cannot be re-enabled through runtime configuration.

Optional “Continue with Google” or “Continue with Facebook” sign-in is disabled until Villa Elita approves the providers, privacy terms, exact callbacks, and deployed security tests. When enabled, accounts are tied to the provider and provider user identifier, never merged into an existing account from an email match alone. Provider access tokens are not persisted by Villa Elita or exposed to browser storage. Staff sign-in never uses personal social login.

Booking contact email and phone are collected separately for reservations and are not treated as proof that two social logins are the same person. Guests can link or unlink an enabled provider only through a reauthenticated Villa Elita session, and signing out ends the Villa Elita session without signing the guest out of Google or Facebook. This pre-production notice still requires DPO and business-owner approval before production use.

When a guest first uses an approved social provider, Villa Elita creates a local guest account from the provider identity, display name, and only an email the provider authoritatively verifies. Social providers are not treated as a reliable source of telephone numbers. A guest may therefore be asked to add a telephone in the local account profile; it is encrypted at rest and can be used for guest and reservation contact.

How we use information

  • To create and manage room reservations and related operational workflows.
  • To communicate about a booking when contact details are provided.
  • To protect accounts and APIs (session cookies, CSRF, rate limits, audit events).

Payments

Live payment processing depends on a production payment service provider that has not been selected yet. Demo environments may use clearly marked fake payments with synthetic data only.

Retention and rights

Retention schedules, lawful bases, and formal data-subject request workflows require owner/DPO approval. Elevated privacy export and erasure APIs remain blocked until those decisions and implementations are complete.

Contact

Questions about this notice: Contact Villa Elita.