Legal
Privacy Policy
Last updated 2026. Applies to velvetmoments.com and all enquiry and payment flows on it.
1. Who we are
Velvet Moments is a private marine celebration atelier. For the purposes of the EU General Data Protection Regulation we act as data controller for enquiry and client data submitted through this website. Written data requests are answered within thirty days.
2. What we collect
Only what a brief requires: your name, email address, optional telephone number, and the four planner answers (destination, event vision, budget tier and guest band), together with any free-text notes you choose to add. We do not run advertising trackers or sell data to third parties.
3. Payment data
Card payments are processed exclusively by Stripe Payments Europe. Card numbers, security codes and bank details never reach our servers and are never stored by us. We retain only the Stripe session reference, the amount in EUR, the package purchased and the billing email, for accounting and refund purposes.
4. Local storage on your device
Your planner answers and language preference are saved in your own browser's local storage so your blueprint survives a page refresh. You can clear them at any time through your browser settings; doing so removes them permanently.
5. Third parties
Verified Luxury Booking Desks connect to independent operating houses and marketplaces. When you follow a desk you leave this site and their own privacy terms apply. We may receive an anonymised confirmation that a booking occurred; we never receive your card details from them.
6. Retention and destruction
Enquiry data is held for twenty-four months, transaction records for the period required by tax law, and event working files are destroyed within thirty days of the programme concluding. No guest name, vessel registration or venue address is retained after that point.
7. Your rights
You may request access, correction, export or erasure of your data, and may withdraw consent at any time. Requests made by a principal's representative are honoured on written authority. Erasure is executed in full unless a legal retention duty applies.
8. Security
Data is transmitted over TLS, stored on access-controlled infrastructure, and visible only to the director assigned to your programme. Breaches affecting personal data are notified to affected clients and the competent authority within seventy-two hours.
9. Contact
Privacy requests: privacy@velvetmoments.com. Please do not include guest names, vessel names or venue addresses in correspondence.