Privacy Policy
This policy explains what personal information StayPrestige collects, why we collect it, who we share it with, how long we keep it and what you can ask us to do with it. It is written to be read, not to be skimmed past. If anything here is unclear, email us and we will explain it.
Who we are
StayPrestige is a hotel booking service operated by JML Interactive, based in Melbourne, Victoria, Australia. In this policy, "we", "us" and "StayPrestige" mean JML Interactive. We are the data controller for the information described below, which means we decide why and how it is used.
You can contact us about privacy at julien@stayprestige.com, by phone on +1 (662) 499-4445, or by post at StayPrestige, Melbourne, Victoria, Australia. We have not appointed a Data Protection Officer, as we are not required to. Privacy requests go to the address above and are handled by a person, not by Julien.
What we collect
- Account details. Your email address, your password (held and hashed by Google Firebase Authentication, never visible to us), and your display name. If you sign in with Google, we receive the name, email address and profile picture on that Google account.
- An anonymous session. Every visitor is signed in automatically as an anonymous Firebase user so the site can hold your search, your basket and your conversation with Julien before you create an account. That anonymous record holds no name or email until you give us one.
- Booking details. First and last name, email address, phone number, the hotel, room and board you chose, your check-in and check-out dates, the number of adults and children, the ages of any children, whether you are travelling with a pet, special requests, your chosen language and currency, any promo or referral code, and the amount paid.
- Details of other guests. If you book for someone else, we collect that person's name, and their email address if you give it to us so we can send them the confirmation. Please only give us someone else's details if they are content for you to do so.
- Payment information. Card details are entered into a payment form provided by our supplier LiteAPI and go straight to them. They never reach our servers and we never store them. We receive only a transaction reference and the amount.
- Conversations with Julien. The text of what you type or say to our AI concierge, and what Julien says back, along with the page you were on, the language you selected, the search you were building and a random session identifier. See the two sections on Julien below.
- Phone calls. If you call us, a written transcript of the call and a partly masked version of your calling number. See "Julien on the phone" below.
- Support messages. Enquiries you send through the contact form or the support tools in My Trips, and replies you send to our booking emails, which we file against the relevant booking.
- Loyalty and vouchers. Your points balance, redemptions and issued voucher codes, which are held with our supplier LiteAPI against a guest profile linked to your email address.
- Saved preferences. Your wishlist, your saved checkout preferences, and your currency and language choices.
- Usage information. Standard web analytics collected by Google Analytics, such as pages viewed, approximate location derived from your IP address, device and browser type, and events like starting a search or completing a booking.
Why we use it, and our legal basis
Under the UK and EU GDPR we must have a lawful basis for every use of your information. Ours are:
- To take and fulfil your booking, including sending it to the hotel, taking payment, sending your confirmation, producing your travel guide, and handling changes, cancellations and refunds. Basis: performance of a contract with you.
- To run My Trips and your account, so you can see and manage what you have booked. Basis: performance of a contract with you.
- To answer your questions, whether through Julien, the contact form, email or the phone line. Basis: performance of a contract where it concerns a booking, and our legitimate interest in helping visitors who are not yet customers.
- To operate the AI concierge by voice, which requires access to your microphone. Basis: your consent, given when your browser asks and you allow it. You can refuse and type instead, and you can withdraw it at any time in your browser settings.
- To keep transcripts of conversations and calls so we can resolve disputes about what was agreed, investigate complaints and check that Julien is behaving correctly. Basis: our legitimate interest in an accurate record and in a concierge that works.
- To protect the service, including rate limiting, fraud checks and security logging. Basis: our legitimate interest in preventing abuse.
- To measure how the site is used through Google Analytics. Basis: your consent where consent is required for the cookies involved. See the note under "Cookies" below about the current position.
- To keep records of transactions for tax and accounting. Basis: compliance with a legal obligation.
We do not use your information for advertising, we do not sell it, and we do not share it with advertising networks or data brokers.
Julien, our AI concierge on this site
Julien is an artificial intelligence, not a person. Julien is powered by Google Gemini. Please read this section before starting a voice conversation.
- Voice is off until you turn it on. Nothing is captured from your microphone unless you start a voice conversation and your browser asks you for permission. If you decline, Julien still works by text.
- Your voice is streamed to Google. While a voice conversation is running, the audio from your microphone is sent live, as you speak, from your browser directly to Google's Gemini service, using a short-lived access token we issue for that session. Google processes the audio to understand you and to generate a spoken reply.
- We keep the words, not the audio. We do not record or store the sound of your voice. We store the written transcript of the conversation, which includes what you said, in our database.
- Julien can read the page you are on. To answer questions about what is in front of you, Julien reads the visible text of the page. Before that text is sent to Google, any email addresses and phone numbers in it are replaced with placeholders.
- Julien cannot touch your card. Julien can fill in guest details on the checkout form for you to check, but cannot see, enter or store card details. You always type those yourself into the payment form.
- Transcripts are linked to you where we can. If you are signed in, the conversation is linked to your account. If you are not, it is linked to a random identifier stored in your browser.
Julien on the phone
When you call our number, the call is answered by Julien. Before your call is connected, a recorded greeting tells you that you are speaking with an automated AI concierge and that the call is transcribed and stored. If you would rather not be transcribed, please hang up and email us instead.
- Twilio carries the call and passes the audio to us. We pass it straight to Google Gemini so that Julien can understand you and reply.
- We store a written transcript of both sides of the call. We do not store an audio recording.
- Before a transcript is saved, phone numbers, email addresses and card-length number sequences spoken during the call are automatically replaced with placeholders. Your calling number is stored with only the last four digits visible.
- Phone transcripts are readable only by our administrators. They are not visible to other users and not visible in your account.
- If you ask Julien to send you an SMS, your number is passed to Twilio to deliver it.
Julien does not make automated decisions that have a legal or similarly significant effect on you. Whether a room is available and whether a booking is accepted is decided by the hotel and our supplier, not by the AI.
Who we share your information with
We use the following service providers. Each of them processes personal information on our instructions, under a contract, for the purpose listed and no other.
- Google. Gemini, for the AI concierge in voice, text and phone, and for generating your travel guide. Firebase Authentication, for sign-in. Cloud Firestore, our database. Firebase App Hosting, which serves this website. Google Analytics, for usage measurement.
- LiteAPI. Our hotel supply and payment partner. Your name, email address, phone number, stay dates, room selection, guest details and any add-ons are sent to LiteAPI, which passes what the property needs to the hotel and arranges payment. Card details are collected by LiteAPI directly through their payment form.
- The hotel you book. Receives the reservation details it needs to hold your room, including guest names, dates, room and board type, and any special requests.
- Add-on suppliers. If you add an Uber voucher or an eSIM at checkout, the details needed to issue it are handled through LiteAPI and passed to the relevant supplier.
- Twilio. Carries inbound phone calls and any SMS we send you.
- Resend. Sends your booking confirmation, cancellation, amendment and travel guide emails.
- Our mail host. Some support and request confirmation emails are still sent over SMTP through the mail server that runs stayprestige.com email.
- OpenStreetMap. If our supplier does not return coordinates for a hotel, we look up the hotel name and city through the Nominatim geocoding service. No guest information is sent.
We will also disclose information if we are legally required to, for example in response to a valid order from a court or regulator, or where it is necessary to establish or defend a legal claim.
Where your information is held, and transfers abroad
Our database is hosted by Google Cloud in Melbourne, Australia. Our other providers operate internationally and most process data in the United States, including Google Gemini, Google Analytics, Twilio, Resend and LiteAPI. If you are in the European Economic Area or the United Kingdom, this means your information is transferred outside that area.
For those transfers we rely on the data protection terms in each provider's agreement with us, which use the Standard Contractual Clauses approved by the European Commission and the UK addendum to them, or the EU-US Data Privacy Framework where the provider is certified under it. You can ask us which mechanism applies to a specific provider and we will tell you.
How long we keep it
We will be straightforward with you: we do not currently run an automated deletion schedule. Booking records, account details, conversation transcripts and phone transcripts stay in our database until you ask us to delete them, or until we delete them as part of a review. We would rather tell you the real position than publish a retention table our systems do not enforce.
The intended position, which we apply when we act on a request or a review, is that booking and payment records are kept for seven years because tax and accounting law requires it, and that everything else, including conversation and phone transcripts, wishlists and preferences, is deleted once it is no longer needed. If you ask us to erase your information, we will do so and keep only what the law requires us to keep. Anonymous usage statistics held by Google Analytics are retained under Google's own settings and cannot be traced back to you by us.
Payment details
We never see, handle or store your card number, expiry date or security code. They are entered into a payment form hosted by LiteAPI and go directly to them. Julien is deliberately unable to take card details, by voice or otherwise, and will always ask you to type them yourself. If anyone claiming to be from StayPrestige asks you to read out a card number, it is not us.
Cookies and similar technologies
We use cookies and browser storage to keep you signed in, to remember your language and currency, to hold your conversation with Julien, and to measure use of the site through Google Analytics. Our Cookie Policy sets out the detail.
Analytics is off until you turn it on. When you first arrive we ask, and until you accept, the Google Analytics script is not loaded at all: no request is made to Google and no analytics cookie is written. Declining is one click, exactly like accepting, and we do not ask again. You can change your mind at any time from the Cookie Policy page. The cookies that keep you signed in and remember your language and currency are not optional, because the site cannot work without them.
Your rights
If the UK or EU GDPR applies to you, you have the following rights. We apply them to everyone who asks, wherever you live, because it is simpler and fairer than checking your address first.
- Access. Ask for a copy of the personal information we hold about you, and for an explanation of how we use it.
- Rectification. Ask us to correct anything inaccurate, or to complete anything incomplete.
- Erasure. Ask us to delete your personal information. We will do so unless we are required to keep it, for example transaction records held for tax purposes, in which case we will tell you exactly what we kept and why.
- Restriction. Ask us to stop using your information while a dispute about its accuracy or our use of it is resolved.
- Portability. Ask for the information you gave us in a structured, commonly used, machine-readable format, or ask us to send it to another provider.
- Objection. Object to any use we base on our legitimate interests, including keeping conversation transcripts. We will stop unless we can show compelling grounds that override your objection.
- Withdraw consent. Where we rely on your consent, such as microphone access, you can withdraw it at any time. That does not affect anything done before you withdrew it.
- Automated decisions. You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. As explained above, we do not make such decisions.
- Complain. You can complain to a data protection supervisory authority. See below.
How to make a request
Email julien@stayprestige.com with "Privacy request" in the subject line, and tell us what you want us to do. Please write from the email address on your account or booking, or give us a booking reference, so that we can be sure the request is yours. If we cannot match you to a record we may ask for one further piece of information, and no more than that.
There is no self-service delete button in the site today. Every request is carried out by hand by a person, across your account, your bookings, your conversation transcripts and any phone transcripts. We will acknowledge your request and complete it within 30 days. If it is genuinely complex we may extend that by up to two further months, and we will tell you why before the first month is up. Requests are free. We will only charge, or refuse, if a request is manifestly unfounded or repetitive, and we will explain our reasoning if that ever happens.
Complaining to a supervisory authority
If you think we have handled your personal information badly, please tell us first so that we can try to put it right. You do not have to, and it does not affect your right to complain to a regulator.
- Australia: the Office of the Australian Information Commissioner, at oaic.gov.au.
- United Kingdom: the Information Commissioner's Office, at ico.org.uk.
- European Economic Area: the supervisory authority in the country where you live, where you work, or where you believe the problem occurred.
Children
StayPrestige is intended for adults booking travel. We do not knowingly collect personal information directly from anyone under 16, and children cannot create an account or make a booking with us.
An adult booker can give us the number and ages of children travelling, and the name of a child staying in the room, because hotels need that to price and prepare the stay. That information is provided by the adult making the booking, is used only to complete that booking, and is passed only to our supplier and the hotel. If you believe a child has given us information directly, email us and we will delete it.
How we protect your information
All traffic to and from this site is encrypted in transit. Access to your account, bookings, wishlists and preferences is enforced at the database level, so one signed-in user cannot read another user's records. Phone transcripts are restricted to administrators. Personal details spoken during a call are masked before the transcript is written. Card details never reach our systems at all. Sensitive endpoints are rate limited, and calls from our telephony provider are signature-verified before they are accepted.
No system is perfectly secure. If a breach affects your personal information and is likely to put your rights at risk, we will tell you and the relevant regulator as the law requires.
Changes to this policy
If we change how we use your information, we will update this page and change the date below. Where a change materially affects information you have already given us, we will say so here rather than change the wording quietly.
Last updated: August 6, 2026