Privacy Policy
Last updated: 2026-05-31
Who we are
Resort Buggy is operated by [Legal Entity Name]. Contact: [email protected].
What data we collect
From resort/club staff (admins, drivers): name, email (admin), access codes, IP, browser info.
From guests: name/room identifier (provided by the resort), access code, pickup/dropoff selections, GPS location while the app is active, push notification token (if subscribed).
From the property organization: property details, map data, operational metrics.
How we use it
- Operating the service
- Improving the product
- Aggregate analytics (no cross-property tracking)
- Push notifications related to active orders
- Customer support
What we don't do
- Sell data to third parties
- Share data with advertisers
- Track guests across other apps or websites
- Use guest data for marketing
Your rights (GDPR / CCPA)
Access, correct, delete, export, or object to processing of your data. Email [email protected].
Data retention
Ride history: 12 months default (configurable). Access codes: until manually deleted or expired. Backups: 30 days.
Third parties we use
- Hosting: Hetzner Cloud (EU)
- Maps: Esri (satellite imagery tiles), CARTO (label tiles), OpenStreetMap Nominatim (admin address search) — full list in our DPA
- Email: Resend (transactional)
- Anti-spam: Cloudflare Turnstile
- Demo scheduling: Cal.com — loads only on the Book a Demo page and receives the name and email you submit when booking, plus the campaign (UTM) tags from the link that first brought you to the site (Cal.com's privacy policy)
Security
TLS in transit, encryption at rest, multi-tenant isolation, access controls. See our Security page.
Changes to this policy
We post changes here with an updated "last updated" date. Material changes are emailed to customers.