Legal

Privacy Policy

Last updated 24 June 2026. Working draft pending external legal review — email hello@starholidaysclub.com with corrections.

1. The short version

We collect the minimum we need to make the watchlist work: your email, your password (hashed, never stored in plaintext), the trips you ask us to watch, and the basic web traffic any site collects to keep itself up. We don’t sell your data, we don’t share it with operators, and you can delete the lot by replying to any of our emails.

2. What we collect

  • Sign-up data: the email address you give us, and a password (stored only as a one-way hash by Supabase Auth). The concierge step asks for travel preferences — who you travel with, what airports you fly from, what you like — and we store your answers against your account.
  • Watchlist: the hotels, dates, party shapes and routes you ask us to watch, plus the price snapshots we collect against them. This is the whole reason the product exists.
  • Search and click logs: when you search, view a hotel page or follow an outbound link to an operator, we record the action with a timestamp so we can improve the product.
  • Traffic basics: IP address (truncated for analytics), browser type, and the page you came from — handled by Vercel and Google Search Console at the platform level.
  • Email events: Resend reports whether our emails were delivered, opened or clicked; we use that to keep deliverability up and stop emailing addresses that bounce.

What we don’t collect: payment details (we don’t take payment), passport details, anything from your inbox, or any data from other sites about you.

3. Why we use it

Strictly to run the service you signed up for: maintain your account, run your watchlist, email you when a price moves, debug problems, and improve the product. We also use anonymised, aggregated patterns (e.g. “how many people search Tenerife in June”) for editorial decisions on the country pages.

4. Who we share it with

Three categories of processor, each chosen because we couldn’t reasonably do their job ourselves:

  • Supabase — our database and authentication. Servers in the EU.
  • Vercel — hosts the site. Servers in the EU/US depending on region.
  • Resend — sends our emails. Servers in the EU.
  • LiteAPI / Duffel — hotel and flight data. We send them the search parameters; they don’t see your account.
  • Google Search Console — provides aggregate, anonymous data about how people find us in search results. They don’t see your account either.

We never sell your data, and we never share your email or watchlist with TUI, Jet2, Thomas Cook or any other operator. If you click an operator’s outbound link, what you do on their site after that is between you and them.

5. How long we keep it

Your account and watchlist stay while you’re a member. If you delete your account, we wipe your profile, watchlist and email address within seven days, and the operational backups within 30 days. We keep anonymised aggregate analytics (page views with no user link) indefinitely.

6. Your rights

Under UK GDPR you can ask us to: (a) show you everything we hold about you, (b) correct anything wrong, (c) delete it, (d) export it to another service, (e) stop sending you the Sunday emails. Reply to any email from us, or write to hello@starholidaysclub.com; we honour requests within 30 days, usually the same day.

7. Cookies

See our cookie page — short version: a Supabase auth cookie when you’re signed in (mandatory for the product to function) and Vercel’s anonymous analytics. No advertising or third-party trackers.

8. Children

The service is for adults booking holidays. Don’t sign up if you’re under 18; we’ll delete any account where we find that’s the case.

9. Changes

We bump the “Last updated” date when this changes. Material changes get a heads-up email to members at least 14 days in advance.

10. Complaints

If you’re not satisfied with how we’ve handled your data, you can complain to the UK’s Information Commissioner’s Office (ico.org.uk). We’d rather you came to us first so we can fix it.