Privacy Policy
How we collect, use, share, and protect personal data across our websites, bookings, and services.
Effective date: August 25, 2026
This Privacy Policy explains how OmniVillas LLC, a United States limited liability company with its principal place of business at 548 Market St, San Francisco, CA 94104, United States (“OmniVillas”, “we”, “us”), collects, uses, shares, and protects personal data. You can reach us about anything in this policy at hello@omnivillas.com.
It applies to all OmniVillas-operated websites and services: omnivillas.com, book.omnivillas.com, the branded booking sites we operate for individual properties or collections (including Fare Oaoa and Anapa), the guest check-in portal, the owner portal, and our guest, owner, and service-provider communications. It applies wherever you are: we run one privacy program designed to meet the EU/UK GDPR and the French Data Protection Act (Loi Informatique et Libertés, which applies in French Polynesia), alongside applicable US law.
OmniVillas is the data controller for the processing described here. For certain stay data, the owner of the property you stay at receives limited information as an independent party to your accommodation contract (see “Who we share data with”).
What we collect
Identity and contact data. Name, email address, phone number, postal address, language preference, and (for property owners and service providers) business details, tax identifiers, and payout account details.
Booking and stay data. Reservation details (property, dates, party size, price, currency), payment plan and transaction history, special requests, house-rule acknowledgments, signed rental agreements, security-deposit status, damage reports and related evidence, and support conversations.
Payment data. Payments are processed by our payment processor (Stripe). We receive tokenized card references, card brand and last four digits, and transaction outcomes. We do not store full card numbers on our systems.
Identity-verification data. Where verification is required at check-in, our verification provider (Stripe Identity) processes your identity document and, where applicable, a selfie, and returns the verification outcome to us. We receive the outcome and limited extracted details, not a copy of your document, unless the law requires otherwise.
Fraud-prevention and security signals. IP address, device and browser characteristics, approximate geolocation, and risk scores from our fraud-prevention providers (including MaxMind minFraud and IPQualityScore), together with booking-pattern signals. We use these to protect guests, owners, and ourselves from fraud and abuse.
Communications. Emails, messages sent through booking platforms, WhatsApp and SMS messages where you have opted in, and chat conversations on our sites, including with our AI concierge assistant. AI-generated messages are labeled as such. Please do not share card numbers or identity documents in chat.
Website data. Pages visited, referrers, and analytics events, as described in our Cookie Policy. Where consent is required for non-essential cookies or analytics, we ask for it.
Why we process data, and on what legal basis
- To provide the service you asked for (performance of a contract): operating bookings, payments, check-in, stays, owner statements and payouts, and service-provider engagements.
- To meet legal obligations: tax and accounting records, tourist-tax (taxe de séjour) collection and remittance, and responding to lawful requests from authorities.
- For our legitimate interests, balanced against your rights: preventing fraud and abuse, securing our systems, defending legal claims, improving our services, and sending service communications about your existing bookings and relationships.
- With your consent, which you can withdraw at any time: marketing communications, optional SMS and WhatsApp notifications, and non-essential cookies. Withdrawing consent does not affect processing already performed, or processing we conduct on another legal basis.
We do not sell personal data, and we do not use it for third-party advertising.
SMS notifications
Guests (optional). If you opt in, OmniVillas sends SMS text messages about your stay, including booking and payment confirmations, check-in reminders, and arrival information. Consent is given only when you select the separate, optional consent box during online check-in. That box is unchecked by default; providing your mobile number alone does not opt you in. Consent is optional and is not a condition of booking or completing check-in.
Contractors and staff. OmniVillas sends SMS text messages to contractors and staff about property tasks assigned to them, including task offers, reminders, and reassignment notices. Consent is given only when you select the separate, optional consent box in your OmniVillas account. That box is unchecked by default; providing your mobile number alone does not opt you in. Consent is optional and is not a condition of receiving work or using OmniVillas.
For all SMS: message frequency varies; message and data rates may apply; reply STOP to opt out at any time, or HELP for help. We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes. Mobile numbers and SMS opt-in status are used only to send the messages described above.
WhatsApp messaging likewise requires your opt-in and can be stopped at any time by telling us or blocking the number.
Who we share data with
We share personal data only as needed to run the services, with:
- Property owners: limited stay information about bookings at their property (dates, party size, financials of the stay). Guest contact details are redacted from owners by default unless disclosure is needed for the stay or legally required.
- Payment and financial providers: Stripe (payments, identity verification), Airwallex (payouts), Xero (accounting).
- Operations platforms: Guesty (property-management system), Supabase (database and storage), Amazon Web Services (hosting and email delivery), Twilio (SMS/WhatsApp delivery), Meta (WhatsApp Business).
- Fraud-prevention providers: MaxMind, IPQualityScore.
- Booking platforms: where your booking originates on Airbnb, Booking.com, Vrbo/Expedia, or similar, that platform provides your booking and contact details to us under its own privacy policy. We do not supply your personal data to these platforms; the only content that travels back is the messages we send you in the platform’s own message thread.
- Professional advisers and authorities: accountants, lawyers, insurers, and public authorities where the law requires (for example, tourist-tax filings).
We never sell personal data, and we never share, rent, or otherwise provide personal data (including mobile phone numbers and SMS consent data) to third parties or affiliates for marketing or promotional purposes. Each provider processes data under contractual safeguards and only for the purposes described here.
International transfers
We operate from the United States, and our providers process data in the United States, the European Economic Area, and other countries. Where data protected by the GDPR or the French Data Protection Act is transferred internationally, we rely on appropriate safeguards such as adequacy decisions, the EU–US Data Privacy Framework where the recipient is certified, and standard contractual clauses.
How long we keep data
We keep personal data only as long as needed for the purposes above: booking, financial, and tax records for the retention periods required by applicable tax and accounting law (typically up to 10 years); identity-verification outcomes and fraud-prevention signals for shorter periods proportionate to their purpose; and marketing preferences until you withdraw consent. When data is no longer needed, it is deleted or anonymized.
Your rights
Subject to the conditions and exceptions of applicable law, you have the right to access the personal data we hold about you, to have it rectified or erased, to restrict or object to certain processing (including direct marketing, which we honor without exception), to withdraw consent at any time, and to data portability. You also have the right not to be subject to a decision based solely on automated processing with legal or similarly significant effects, our fraud screening always involves human review before a booking is finally refused on risk grounds.
To exercise any of these rights, write to hello@omnivillas.com. We answer within the timelines the law sets. Note that some data cannot be erased while legal retention obligations apply (for example, tax records).
If you believe we have not handled your data properly, you can complain to a supervisory authority (in France and French Polynesia, the CNIL (cnil.fr)) or to the authority of your place of residence.
Children
Our services are directed at adults. Booking accounts and check-in are for adults (18+); information about minors in a travel party (such as guest counts and ages for capacity and safety) is provided by the responsible adult and used only for the stay.
Security
We protect personal data with encryption in transit, access controls, audit logging, and the isolation of sensitive data with our specialized providers (for example, card data never touches our servers). No system is perfectly secure; if a breach affects your rights, we will notify you and the competent authority as the law requires.
Changes to this policy
We may update this policy as our services or the law evolve. The current version is always at this address, with its effective date above. For material changes, we will inform you through the sites or by email where appropriate.
Contact
OmniVillas LLC: 548 Market St, San Francisco, CA 94104, United States, hello@omnivillas.com.
This policy is drafted in English; courtesy translations are provided. The English version is the reference version.