Privacy
What we know about you
Last updated September 22, 2026
Miles & Lux is Daniel and Jackie. We publish a travel journal and we work as travel advisors, booking hotels through our host agency. This page covers both: what we collect when you read the journal, and what we collect when you ask us to plan something.
The short version: reading this site collects nothing unless you agree to advertising cookies. Asking us to plan a trip collects what we need to plan it. We never see your card.
Reading the site
The journal, the globe and the destination pages set no cookies and run no analytics. We do not know who you are, and our pages are served as cached files, so most of the time your visit does not reach a server of ours at all.
Our host, Netlify, processes the request itself — your IP address, the page asked for, your browser's user agent — as an ordinary part of delivering a website and for security. We do not build profiles from it.
Advertising cookies
If you agree, we run advertising pixels from Meta (Facebook and Instagram) and Google Ads. They let us show our hotel write-ups to people who have already read some, and tell us whether that worked. They are not necessary for the site to function.
Nothing loads until you say yes. If you decline, or have not answered, the scripts are not on the page — not loaded-but-disabled. If your browser sends a Global Privacy Control signal we treat that as a no and do not ask. What those platforms receive is the fact that a browser visited a page, and whether an inquiry was submitted. We do not send them your name, your email or a hashed version of either.
You can change your mind at any time, and it is the same one click either way:
You have not answered yet.Asking us to plan a trip
The form on our booking page collects your name and email, and whatever else you choose to fill in: where you are thinking of going, your dates, how many of you there are, a budget, and anything you tell us about the trip. Once you are a client we also keep a phone number, your nationality — hotels and suppliers price by it, so a quote is wrong without it — your preferred currency, and notes on what you like.
We deliberately do not collect passport numbers, and we do not ask for a date of birth unless a specific supplier requires one for a specific booking.
We never handle your card. On the bookings we place, you settle with the hotel directly. No card number, expiry or security code is ever typed into this site, stored in our database, or written to our logs, and there is no code here that could accept one.
Why we are allowed to hold it
- To do what you asked. Planning and placing a booking is the performance of the arrangement between us.
- Because you agreed. Advertising cookies, and nothing else, rest on your consent — which you can withdraw above.
- Because we have to. Booking and commission records are kept for tax and accounting.
- Because it is reasonable. Keeping the site up, secure and free of form spam.
Who else sees it
Only those who need to, and only for their part:
- Fora, our host agency, receives what a reservation requires: guest names, dates, the property, and contact details. They are the agency of record for bookings we place.
- The hotel receives your name, your dates and anything you have asked us to pass on. We only write to an address a hotel or our host has actually given us — never one we guessed.
- Supabase hosts our database, in the United States (us-east-1).
- Netlify hosts and serves the site, in the United States (us-east-2).
- Resend sends our email.
- Meta and Google, for advertising, and only with your consent.
We do not sell your personal information, and we do not share it for anyone else's advertising. We will disclose it if the law actually requires us to.
Where it goes
Our infrastructure is in the United States. If you are writing to us from the UK or the EEA, your information is transferred there, under the standard contractual clauses in our agreements with those providers. If that is not something you want, tell us and we will work with you by email instead.
How long we keep it
- An inquiry that never becomes a trip: two years, then deleted, in case you come back.
- Client records and booking history: seven years, for tax and accounting.
- Email we have sent you: kept with the trip it belongs to.
- Our activity log, which records what was done to a booking and when: kept for the life of the record. It is append-only, so a correction is a new entry rather than an edit.
- Your cookie answer: in your own browser, until you clear it.
What you can ask for
Whoever and wherever you are, write to trips@milesandlux.com and we will: tell you what we hold, send you a copy, correct it, delete it, or stop using it. We do not charge for this and we do not make it a process. We will come back to you within 30 days.
If you are in the UK or EEA, those are your rights under the GDPR — access, rectification, erasure, restriction, portability, objection, and withdrawing consent — and you may also complain to your data protection authority. If you are in California, you have the rights to know, delete, correct, and opt out of sale or sharing under the CCPA as amended by the CPRA; we honour Global Privacy Control as that opt-out, and we will not treat you differently for exercising any of it.
Children
This is not a site for children and we do not knowingly collect anything from anyone under 16. Where a booking involves a child, we hold only what the hotel needs — usually a first name and an age.
Changes
If we change what we collect or who processes it, we will change this page and move the date at the top. If the change is significant and you are a client, we will email you.
Reaching us
trips@milesandlux.com. We are the two people who read it.
This is written to be accurate and readable, and it is not legal advice. It has not been reviewed by a lawyer.