Privacy policy
Last updated
Your privacy is fundamental to how we build Villantra. This policy explains what data we collect, why we collect it and how we protect it.
1. Information we collect
We collect information you provide directly, including name, email address, phone number, business details and payment information when you register for or use our services.
We automatically collect certain technical information including IP addresses, browser type, device identifiers and usage data when you interact with our platform.
For providers, we collect business information including service menus, pricing, staff details, booking records and financial data necessary to operate the platform.
2. How we use your information
We use your information to provide, maintain and improve our platform; process transactions and send related information; send administrative messages, updates and security alerts; respond to comments and questions; and comply with legal obligations.
We analyse usage patterns to improve the platform, develop new features and keep it secure. We do not sell your personal data to third parties.
3. Multi-tenant data isolation
Villantra is a multi-tenant platform. All data is logically isolated at the database level by provider identifier. No provider can access, view or affect another provider's data. Our architecture enforces this isolation at the application, service and database layers.
Staff members within a provider can only access data within their assigned scope as determined by their role (Owner, Manager or Staff).
4. Payment data
Payment card data is handled exclusively by our payment processor (Tap Payments). Villantra does not store, process or transmit cardholder data. All financial transactions are tokenised and PCI-DSS compliant.
We store transaction records including amounts, timestamps and commission calculations for accounting and audit purposes.
5. Data retention
We retain your data for as long as your account is active or as needed to provide services. If you close your account, we retain certain data for legal compliance, dispute resolution and fraud prevention for up to 7 years.
Booking records and financial data are retained as required by applicable tax and commercial law in Qatar and Algeria.
6. Your rights
You have the right to access, correct or delete your personal data. You may request a copy of your data or its deletion by contacting us at privacy@villantra.com.
To delete your account and the data linked to it, follow the steps on our account deletion page at https://villantra.com/delete-account.
For providers in Algeria, additional rights apply under Algerian data protection law. For providers in Qatar, rights are governed by Qatar's data protection framework.
7. Security
We implement industry-standard security measures including TLS 1.3 encryption in transit, AES-256 encryption at rest, regular security audits and access controls. All data is backed up daily with point-in-time recovery.
No system is perfectly secure. Please use strong passwords and notify us immediately of any suspected unauthorised access.
8. Contact
For privacy-related questions or to exercise your rights, contact our Data Protection Officer at privacy@villantra.com or in writing at our registered office in Doha, Qatar.
Questions about this document? Contact our team or email legal@villantra.com.