Sunkiss Caribbean Bookings LLC

Privacy Policy

Protecting your personal data — with clarity and care

Effective: 1 April 2025
Last Updated: April 2026
Operations: Barbados, West Indies

Barbados Data Protection Act 2019 EU GDPR UK GDPR ePrivacy Directive

This Privacy Policy explains how Sunkiss Caribbean Bookings LLC ("we", "us", "our") collects, uses, and protects your personal information when you visit our website (www.sunkisscaribbean.com), make a booking, or stay at one of our luxury properties in Barbados. Please read it carefully. By using our website or services, you acknowledge the practices described in this Policy.

01 Who We Are

Sunkiss Caribbean Bookings LLC is a US-registered limited liability company that operates a portfolio of luxury short-term vacation rental properties in Barbados, West Indies. We curate and manage premium villas for discerning travellers seeking exceptional Caribbean experiences.

Although Sunkiss Caribbean Bookings LLC is incorporated in the United States, all rental properties are currently located in Barbados. Accordingly, the Barbados Data Protection Act 2019 applies to the processing of personal data connected with those properties and their guests, in addition to other applicable laws set out in this Policy.

For the purposes of applicable data protection law, Sunkiss Caribbean Bookings LLC is the data controller responsible for your personal information.

REGISTERED DETAILS

Company: Sunkiss Caribbean Bookings LLC

Registered Address: 1309 Coffeen Avenue STE 1200, Sheridan, Wyoming 82801

Email: james@sunkisscaribbean.com

Website: www.sunkisscaribbean.com

02 Information We Collect

We collect personal information in several ways — directly from you, automatically through our website, and from third parties such as booking platforms. Categories of information we may collect include:

A. INFORMATION YOU PROVIDE DIRECTLY

  • Identity & Contact: Full name, email address, phone number, postal/billing address, and nationality.
  • Booking Details: Travel dates, number of guests, special requests, and dietary or accessibility requirements.
  • Identity Verification: Passport or government-issued ID details, as required under Barbados immigration and tourism regulations.
  • Payment Information: Credit/debit card details and billing address — processed securely by Stripe, Inc. through our US Stripe account. We do not store full card numbers on our own servers; all payment data is handled directly by Stripe's PCI-DSS certified infrastructure.
  • Communications: Messages, enquiries, and correspondence sent via email, contact forms, or telephone.
  • Marketing Preferences: Your opt-in choices for newsletters, promotions, and seasonal updates.

B. INFORMATION COLLECTED AUTOMATICALLY

  • Device & Technical Data: IP address, browser type and version, operating system, and device identifiers.
  • Usage Data: Pages visited, time spent on site, links clicked, referring URLs, and search terms used.
  • Location Data: Approximate geographic location derived from your IP address.
  • Cookie & Tracking Data: Data collected via Google Analytics, Google Tag Manager, Meta Pixel, and similar technologies (see Section 7).

C. INFORMATION FROM THIRD PARTIES

  • Booking Platforms: Airbnb, Vrbo, or Booking.com may share booking and profile data to facilitate your reservation.
  • Property Management Software: We use Guesty as our PMS, which processes booking data under a Data Processing Agreement.
  • Payment Processor (Stripe): Transaction confirmations, payment status, and fraud-screening results received from Stripe, Inc.
  • Travel Agents & Concierge Services: Agents acting on your behalf may provide your details to facilitate a reservation.

03 How We Use Your Information

We use the personal information we collect for the following purposes:

  • Reservation Management: Processing and confirming bookings, sending pre-arrival information, coordinating check-in and check-out, and managing your stay via Guesty.
  • Payment Processing: Charging rental fees and security deposits, and processing refunds via Stripe, Inc. Stripe processes all payment transactions through our US Stripe account on our behalf.
  • Regulatory Compliance: Meeting Barbados Tourism Product Authority (BTPA) and Barbados Immigration Department requirements, including mandatory guest registration.
  • Customer Service: Responding to enquiries, resolving issues, and providing concierge assistance before, during, and after your stay.
  • Safety & Security: Verifying guest identity, preventing fraud, and protecting our properties and staff.
  • Marketing & Communications: Sending newsletters, exclusive offers, and updates — only where you have given consent, or where we have a legitimate interest in keeping past guests informed. You may unsubscribe at any time.
  • Website Analytics & Improvement: Using Google Analytics and Google Tag Manager to analyse traffic patterns and improve the functionality, content, and user experience of our website.
  • Targeted Advertising: Using Meta Pixel to deliver relevant advertisements and measure the effectiveness of our marketing campaigns on Meta platforms (Facebook/Instagram), subject to your cookie consent.
  • Legal Obligations: Complying with applicable laws, court orders, and regulatory requirements in Barbados and internationally.
  • Reviews & Feedback: Inviting you to share your experience to help us maintain our luxury hospitality standards.

We will never sell, rent, or trade your personal information to third parties for their own marketing purposes.

04 Legal Bases for Processing

Where the GDPR or UK GDPR applies (for example, if you are an EU or UK resident), we rely on the following legal bases for processing your personal data:

  • Performance of a Contract: Processing necessary to fulfil your booking and deliver our rental services.
  • Legal Obligation: Processing required to comply with Barbados law, US law, and applicable international regulations.
  • Legitimate Interests: Fraud prevention, website analytics via Google Analytics/Tag Manager, and direct marketing to past guests — where our interests are not overridden by your rights.
  • Consent: Where you have explicitly agreed to receive marketing communications or to the use of non-essential cookies (including Meta Pixel and Google Analytics).
  • Vital Interests: In exceptional circumstances where processing is necessary to protect the safety of a guest or third party.

BARBADOS LAW

Under the Barbados Data Protection Act 2019, we are guided by the principles of lawful, fair, and transparent processing, purpose limitation, data minimisation, accuracy, storage limitation, and confidentiality. This Act applies in full to all data processing connected with our Barbados properties and their guests, independently of where the company is incorporated.

UNITED STATES LAW

Sunkiss Caribbean Bookings LLC is incorporated in the United States. The United States does not currently have a comprehensive federal privacy law governing commercial data of this nature. To the extent that US state privacy laws apply to our guests — including, where applicable, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) — we are committed to honouring the rights those laws afford. The Barbados Data Protection Act 2019 applies independently and in full, as all rental properties and associated guest data processing activities are conducted in Barbados.

05 Sharing Your Information

We may share your personal data with the following categories of recipients, strictly on a need-to-know basis and subject to appropriate confidentiality obligations:

  • Property Management (Guesty): Our PMS provider, Guesty Inc., processes booking and guest data on our behalf under a formal Data Processing Agreement and appropriate international transfer safeguards.
  • Booking Platform Partners: Airbnb, Vrbo, and Booking.com — limited data may be shared back with these platforms in connection with your booking, in accordance with their respective privacy policies.
  • Property & Housekeeping Teams: Our property management and housekeeping staff, to prepare your accommodation and ensure a seamless arrival.
  • Payment Processor (Stripe): Stripe, Inc. processes all payment card transactions on our behalf through our US-based Stripe account. Stripe acts as a data processor under its standard Data Processing Agreement and operates under PCI-DSS Level 1 certification. Payment card data flows directly to Stripe's US infrastructure; we never receive or store full card details. Stripe's privacy policy is available at stripe.com/privacy.
  • Analytics & Advertising Providers: Google (Analytics, Tag Manager) and Meta Platforms (Meta Pixel) — subject to your cookie consent. Google and Meta act as independent data controllers for data they collect via their tools.
  • Regulatory Authorities: Barbados Immigration Department, the Barbados Tourism Product Authority (BTPA), tax authorities, and law enforcement agencies, where legally required.
  • Professional Advisors: Legal counsel, accountants, and insurers, where necessary for legitimate business purposes.
  • Emergency Services: In the event of a medical or safety emergency during a guest's stay.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction, subject to equivalent protections.

06 International Data Transfers

Sunkiss Caribbean Bookings LLC is incorporated in the United States, and your personal data may be transferred to, stored in, or processed in countries outside your home jurisdiction — including the United States (our registered entity, Stripe, Guesty, Google, and Meta), Barbados, the United Kingdom, and the European Economic Area.

In particular, all payment card transactions are processed by Stripe, Inc. through our US-based Stripe account, meaning payment data is transmitted to and stored within the United States. Stripe maintains PCI-DSS Level 1 certification and implements Standard Contractual Clauses (SCCs) for transfers of personal data from the EEA and UK to the United States.

Where we transfer personal data to countries not deemed to provide an adequate level of protection, we implement appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the relevant supervisory authority, or rely on applicable derogations such as where the transfer is necessary to perform a contract with you.

Because all rental properties are located in Barbados, the Barbados Data Protection Act 2019 applies to data processing connected with those properties. All such processing is conducted in compliance with that Act and is subject to oversight by the Data Protection Commissioner of Barbados.

07 Cookies & Tracking Technologies

Our website (www.sunkisscaribbean.com) uses cookies and similar tracking technologies to enhance your browsing experience, analyse site traffic, and support our marketing activities. A cookie is a small text file placed on your device when you visit our site.

Category Purpose Consent Required
Strictly Necessary Enable core site functions — booking forms, session management, security. Cannot be disabled. No — essential
Performance / Analytics Google Analytics & Google Tag Manager — understand how visitors use our site (data anonymised where possible). Yes — opt-in via cookie banner
Functional Remember your preferences such as currency and saved searches. Yes — opt-in via cookie banner
Marketing / Targeting Meta Pixel — deliver relevant ads, retargeting, and measure campaign effectiveness. Yes — opt-in via cookie banner

Opting out of performance or marketing cookies does not affect your ability to make or manage a booking with us.

08 Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, and reporting requirements. Our general retention periods are:

  • Booking & Guest Records: Retained for 7 years following your stay, in compliance with Barbados tax and regulatory requirements.
  • Identity / Passport Data: Retained for a minimum of 1 year post-stay as required by Barbados tourism and immigration regulations; longer where specifically required by law.
  • Payment Records (Stripe): Stripe retains transaction records in accordance with its own data retention policy and applicable financial regulations. We retain Stripe-generated transaction references and confirmation records for 7 years for tax and accounting compliance.
  • Guesty Platform Data: Governed by Guesty's data retention policy under our Data Processing Agreement; we will request deletion upon termination of our agreement.
  • Marketing Data (Email / CRM): Retained until you withdraw consent or request deletion, subject to a maximum review period of 3 years from your last interaction.
  • Google Analytics Data: Typically retained for 26 months (standard GA4 setting); we configure data anonymisation where feasible.
  • Meta Pixel Data: Governed by Meta's data retention policies; we configure event data deletion windows in line with Meta's Business Tools Terms.
  • Website Enquiries & Correspondence: Retained for 2 years from the date of last contact.

Upon expiry of the relevant retention period, data is securely deleted or anonymised in accordance with our internal data disposal procedures.

09 Your Rights

Depending on your country of residence, you may have the following rights in relation to your personal data. We honour these rights for all guests, regardless of jurisdiction, to the fullest extent practicable.

Right Description
Right of Access Request a copy of all personal data we hold about you.
Right to Rectification Have inaccurate or incomplete data corrected without delay.
Right to Erasure Request deletion of your data where there is no overriding reason to retain it.
Right to Portability Receive your data in a structured, machine-readable format.
Right to Restriction Ask us to pause processing in certain circumstances.
Right to Object Object to processing based on legitimate interests, including direct marketing.
Withdraw Consent Withdraw consent for marketing or non-essential cookies at any time.
Right to Complain Lodge a complaint with the Barbados Data Protection Commissioner or your local authority.

To exercise any of these rights, please contact our Privacy Officer at james@sunkisscaribbean.com . We will respond within 30 days. We may need to verify your identity before acting on your request. There is no fee for exercising your rights, unless a request is manifestly unfounded or excessive.

EU and UK residents may also contact their local supervisory authority — including the relevant EU Data Protection Authority or the UK Information Commissioner's Office (ICO) — if they believe their rights have been infringed.

ADDITIONAL RIGHTS FOR CALIFORNIA RESIDENTS (CCPA / CPRA)

If you are a resident of California, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), may afford you additional rights in relation to your personal information.

  • Right to Know: Request disclosure of categories and specific pieces of personal information collected, sources, purposes, and third parties.
  • Right to Delete: Request deletion of personal information, subject to legal exceptions.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt Out of Sale or Sharing: We do not sell your personal information. Where applicable (e.g. Meta Pixel), you may withdraw consent via Cookie Preference Centre.
  • Right to Limit Use of Sensitive Personal Information: We limit use of sensitive data (such as passport details) to what is necessary for services and legal compliance.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights.

To submit a CCPA request, please contact james@sunkisscaribbean.com with the subject line "California Privacy Request". We will respond within 45 days as required by law. Identity verification may be required.

10 Children's Privacy

Our website and services are not directed at children under the age of 18. We do not knowingly collect personal data directly from minors. Where a booking includes minor guests, personal data collected relates to the responsible adult who made the reservation.

If you believe we have inadvertently collected personal data from a child under 18, please contact us immediately and we will take prompt steps to delete that information.

11 Security of Your Information

We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, destruction, or disclosure. These measures include:

  • Encryption: SSL/TLS encryption for all data transmitted via our website.
  • Access Controls: Role-based access restrictions ensuring data is accessible only to authorised personnel.
  • Payment Security (Stripe): All payment card transactions are processed exclusively by Stripe, Inc., a PCI-DSS Level 1 certified provider. Card details flow directly to Stripe's secure US infrastructure and are never transmitted to or stored on our own servers.
  • Vendor Assessments: Third-party providers including Stripe, Guesty, Google, and Meta are contractually required to maintain equivalent security standards and are bound by their respective Data Processing Agreements.
  • Staff Awareness: Regular data protection guidance for all team members who handle personal data.

While we take every reasonable precaution, no method of transmission over the internet is 100% secure. In the unlikely event of a data breach posing a risk to your rights and freedoms, we will notify you and the relevant regulatory authority as required by law.

12 Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will update the 'Last Updated' date at the top of this page and, where appropriate, notify you by email or via a notice on our website (www.sunkisscaribbean.com).

We encourage you to review this Policy periodically. Your continued use of our website or services following any changes constitutes your acknowledgement of the updated Policy.

13 Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or the way we handle your personal data, please contact our Privacy Officer:

Company Sunkiss Caribbean Bookings LLC
Address [Registered Office Address To Be Confirmed — USA]
Email james@sunkisscaribbean.com
Website www.sunkisscaribbean.com
Role Privacy Officer / Data Controller

For complaints, you may also contact the Barbados Data Protection Commissioner at the Office of the Data Protection Commissioner, Barbados.

© 2026 Sunkiss Caribbean Bookings LLC