Loading…
Loading…
TheSpaVista (“we”, “us”, “our”) is a spa discovery and listing platform operating at thespavista.com. This Privacy Policy explains what personal information we collect, why we collect it, how we use it, and your rights regarding your data. By using TheSpaVista, you agree to the practices described in this policy.
We collect only the minimum information needed to operate the platform:
a) Information you provide directly:
- Contact form: Your name, email address, and message when you contact us through our website.
- Spa enquiry chatbot: Your name, phone number, and the service you are interested in, submitted through the chat widget on spa listing pages.
- Review submissions: Your display name, star rating, and written review text.
- Spa listing submissions: Business name, address, contact details, photos, and owner information submitted by spa owners seeking to list their business.
b) Information collected automatically:
- Usage analytics: Page views, button clicks (WhatsApp, Call, Directions), and search queries — stored in aggregate, not linked to your identity.
- Device & browser data: Browser type, operating system, and approximate city-level location (derived from IP address) for analytics purposes.
- Cookies & local storage: Session preferences such as saved or recently viewed spas.
We use the information we collect for the following purposes:
- To operate the platform: Display spa listings, process reviews, and enable search and discovery features.
- To respond to enquiries: When you submit a contact form or chatbot enquiry, we use your name, email/phone to respond to you or forward your enquiry to the relevant spa.
- To improve our service: Aggregate analytics help us understand which spas and features are popular so we can improve the platform.
- To communicate with spa owners: We email spa owners when their listing is approved, rejected, or when their account is set up.
- To send transactional emails: Password reset emails for admin and spa owner accounts. We do not send marketing emails without explicit consent.
We do not sell, rent, or share your personal information with third parties for advertising purposes.
When you click "Book via WhatsApp" on a spa listing page, you are redirected to WhatsApp's platform. This action:
- Opens a pre-filled WhatsApp message directly to the spa's number.
- Takes you outside TheSpaVista's platform and into WhatsApp (operated by Meta Platforms, Inc.).
- Is governed by WhatsApp's own Privacy Policy.
TheSpaVista does not store, intercept, or have access to your WhatsApp conversation. All booking communication is directly between you and the spa. We only track that a "WhatsApp click" event occurred (without storing the content) for analytics purposes.
Our chat widget appears on free spa listing pages to help you send a booking enquiry. When you use the chatbot:
- Your name, phone number, and selected service are collected and stored securely on our servers.
- This information is forwarded to the spa owner and to TheSpaVista admin via email so the spa can follow up with you.
- Enquiry data is stored in our system and may be retained for up to 12 months for business communication records.
- You can request deletion of your enquiry data by emailing support@thespavista.com.
We use cookies and browser local storage for:
- Session management: Keeping admin and spa owner accounts logged in via secure HTTP-only cookies.
- Preferences: Remembering your recently viewed spas or preferred view (grid/list) on the search page.
- Analytics: We use privacy-respecting, self-hosted analytics that do not track you across other websites.
We do not use Google Analytics, Facebook Pixel, or any third-party advertising cookies. You can clear your browser cookies at any time without losing core platform functionality.
Your data is stored on secure servers hosted in India. We take reasonable precautions to protect your information:
- Encryption in transit: All data is transmitted over HTTPS (TLS encryption).
- Password hashing: Admin and spa owner passwords are hashed using bcrypt — we never store plain-text passwords.
- Access control: Only authorised TheSpaVista team members can access stored data.
- File-based storage: We use structured JSON file storage on our server — no third-party cloud database.
While we take security seriously, no system is 100% secure. We encourage you to use strong passwords and not share your login credentials.
TheSpaVista integrates with the following third-party services:
- Google Maps / Google Business: Embedded maps and directions links. Subject to Google's Privacy Policy.
- WhatsApp (Meta): Booking links that open WhatsApp. Subject to Meta's Privacy Policy.
- Hostinger (hosting): Our website and email are hosted on Hostinger's infrastructure. Subject to Hostinger's Privacy Policy.
- Google Fonts: We load fonts (Cormorant Garamond, Plus Jakarta Sans) from Google Fonts, which may log your IP address.
We are not responsible for the privacy practices of these third-party services.
You have the following rights regarding your personal data:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of your personal data (enquiry records, reviews, listing data).
- Objection: Object to our processing of your data for analytics purposes.
- Portability: Request your data in a machine-readable format.
To exercise any of these rights, email us at support@thespavista.com with the subject line "Data Request". We will respond within 30 days.
TheSpaVista is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has submitted personal information to us, please contact support@thespavista.com and we will promptly delete it.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make significant changes, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Your continued use of TheSpaVista after changes are posted constitutes your acceptance of the updated policy.
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
TheSpaVista
Email: support@thespavista.com
Website: https://thespavista.com
Location: Mumbai, Maharashtra, India
