This Privacy Notice explains how Concierge Comptoir, LLC handles personal information across its public website, guest experience, protected demo, and operator accounts. It does not claim GDPR certification or complete compliance.
1. Who we are
- Legal entity: Concierge Comptoir, LLC
- Legal form: Limited liability company (LLC)
- Country: United States
- Address: 650 E. Palisades Ave, Englewood Cliffs, NJ 07632, USA
- State of formation: New Jersey
- Privacy and legal contact: info@conciergecomptoir.com
- Data Protection Officer (if appointed): No DPO appointed.
Website domain: conciergecomptoir.com.
Concierge Comptoir provides cosmetic skincare recommendations using the guest’s selected skin preferences and hotel-location weather. The hotel retains its full reservation and PMS records and fulfills any products the guest selects. Legal roles between Concierge Comptoir and each hotel (controller, processor, or joint controller) depend on the hotel arrangement and who determines the purposes and essential means of each processing activity; the product workflow alone does not settle those roles.
2. Scope of this notice
This notice covers personal data processed in connection with:
- the public B2B marketing website at the site root;
-
the hotel guest questionnaire under
/b2c/app/(opaque guest links); - the protected Maison Aurelia demonstration at
/demo/; - operator accounts used in Panneau and hotel administration inside the Flutter app.
See also the GDPR & data-protection information page and Legal Notice.
3. Marketing website visitors
What we collect
The marketing pages do not use first-party analytics or advertising pixels. The hotel partnership page collects the business/property name, contact name, work email, and any optional phone, role, location, or message the visitor provides. Cloudflare Turnstile checks the submission for automated abuse; the form sends valid inquiries to Concierge Comptoir through its Supabase Edge Function and configured email provider.
- If you email info@conciergecomptoir.com, we receive your message and email address through ordinary email systems.
- Our web host (Hostinger) and network providers may process standard technical logs such as IP address, user agent, and requested URLs while serving the site. Hostinger access logs are typically retained for 14–30 days.
-
Pages load webfonts from Google Fonts
(
fonts.googleapis.com/fonts.gstatic.com). Your browser may transmit technical data (such as IP address) to Google when fetching those fonts.
Purposes
Operate and secure the public website; respond to partnership inquiries you initiate.
Concierge Comptoir does not collect guest email addresses for marketing and does not send marketing email to guests. The public site provides a partnership inquiry form; the visitor chooses whether to submit their business contact details. Where the GDPR applies, Concierge Comptoir intends to rely on Article 6(1)(b) when responding to a partnership inquiry that asks it to take steps toward a business relationship, and Article 6(1)(f) for necessary website security processing, where those bases fit the specific activity.
4. Hotel guest experience
What the hotel keeps vs what Concierge Comptoir receives
Hotels retain their complete property-management (PMS) and reservation records. Concierge Comptoir, LLC does not receive the guest’s complete hotel profile or full PMS record.
To provide the digital skin-concierge service, Concierge Comptoir does receive and process limited, stay-specific data. That information can identify or be linked to a guest; it is not anonymous, and it does reach Concierge Comptoir systems. As implemented, it includes:
- guest display name;
- hotel identity and location (hotel/organization identifiers and hotel coordinates / weather timezone used for forecasts);
- confirmation / reservation reference;
- stay start and end dates;
- optional locale;
- guest questionnaire inputs (selected skin type, optional adult age band, and related preference flags stored as versioned input snapshots—not anonymous);
- recommendation outputs and, if the guest requests products, selected product codes / quantities and related fulfillment snapshots;
-
session and security data (hashed opaque link and guest-session
tokens; short-lived HttpOnly
cc_guest_sessioncookie after link exchange).
Hotels invite a guest with an opaque link of the form
/b2c/app/#/s/{token}. Reservation details are not placed
in query parameters. The browser talks to same-origin
guest-api.php, which bridges allowlisted guest actions
to Supabase Edge Functions.
Weather forecasts for the hotel location are obtained server-side from WeatherAPI.com for recommendation runs. Provider attribution is shown where weather-derived content appears.
The questionnaire asks guests to self-select cosmetic skincare preferences and, optionally, an adult age band (for example 25–34 or “Prefer not to say”). Concierge Comptoir does not collect date of birth or exact age. Answers are used only to tailor cosmetic product recommendations. They are not used to diagnose a condition, infer medical conditions from age or skin-type choices, provide medical care, or send guest marketing email. One current option is labeled “Redness / Rosacea.” Because that wording may refer to a medical condition, Concierge Comptoir does not claim that selecting it is automatically outside GDPR Article 9 (special-category / health data) merely because the service is cosmetic. Classification depends on applicable law and context. Where a response is treated as health data, Article 6(1)(b) alone is not enough; an Article 9 condition would also be required. A guest may skip the questionnaire.
Fulfillment sharing with the hotel
Generating a recommendation does not create a hotel fulfillment request by itself. The guest must explicitly choose products for a fulfillment request to be created. If the guest declines, no hotel queue item is created. If the guest accepts and selects products, Concierge Comptoir creates a fulfillment request and sends the hotel only the selected products and the stay context needed to match the request (through the fulfillment email and hotel report). Concierge Comptoir provides recommendations; the hotel fulfills the products. That path is designed to include operational fields such as reservation reference, stay dates, and item details—not the guest’s full vanity history or weather dumps. The current application emails selected-product requests to the hotel's stored spa notification address(es) and provides an authorized hotel operator with a separate fulfillment report. It does not send hotel webhooks. No payment is taken through the questionnaire.
Purposes
- Authenticate the opaque guest link and operate the session;
- prepare a stay-oriented spa product routine;
- create a hotel fulfillment request only when the guest requests selected products;
- security, abuse prevention, and operational integrity.
Lawful bases
Where the GDPR applies and the processing is lawfully characterised as necessary for a contract (or pre-contractual steps) with the guest, Concierge Comptoir intends to rely on Article 6(1)(b) for guest-requested cosmetic recommendations and related session processing needed to deliver that service. The hotel—not Concierge Comptoir—fulfills products the guest selects. Article 6(1)(b) alone is insufficient if an answer is classified as health data under Article 9; an applicable Article 9 condition would then also be required. Whether Article 6(1)(b) fits a given booking arrangement depends on the facts and applicable law.
5. Protected demo (/demo/)
-
Demo operator accounts are invited or granted by a Site Admin.
Authentication uses Supabase Auth. New invitees set a password;
sessions persist in browser storage under
cc-demo-auth. - Demo guest sessions use a fixed fictional guest and reservation for the Maison Aurelia storyboard.
- Demo User emails and invitation/recovery messages are processed through Supabase Auth (and any configured SMTP).
- The demo page loads the Supabase JavaScript client from jsDelivr and may load Google Fonts.
6. Operator / admin accounts
Site Admins, Demo Users, and hotel staff/admins authenticate via Supabase Auth. Profile records may include email and optional name fields. Roles and grants live in the application database. Password reset and invitation emails use Auth redirect URLs configured for this domain. Flutter web persists Auth sessions in browser storage (SharedPreferences / localStorage).
7. Cookies and local storage
- Marketing site: no first-party cookies are set by the marketing scripts in this repository.
-
Guest experience: HttpOnly
cc_guest_sessioncookie (Secure in production; SameSite Lax) after successful opaque-link exchange. -
Demo: Supabase Auth persistence under
cc-demo-auth. - Flutter app: Auth/session material in browser local storage via SharedPreferences.
No analytics or advertising cookies are identified in the current marketing-site code. The guest session cookie and app authentication storage support requested service functions. Whether any additional notice or consent is required depends on the applicable law and the technologies in use. We do not use these functional storage items for advertising or cross-site tracking.
8. Service providers and recipients
Depending on the feature in use, personal data may be processed by:
- Supabase — authentication, database, and Edge Functions for the application;
-
Hostinger — website hosting for
conciergecomptoir.com, and SMTP used for operator invitation, password-reset, partnership inquiry, and fulfillment notification emails; - Cloudflare Turnstile — verifies partnership-form submissions and may process technical information needed to distinguish people from automated abuse;
- WeatherAPI.com — receives hotel coordinates and a forecast-day count from the server so Concierge Comptoir can obtain location weather. In the current implementation it does not receive the guest name, reservation reference, or skin questionnaire answers;
- Google Fonts — browser-side webfont delivery when pages load fonts from Google;
- jsDelivr — browser-side CDN delivery of the Supabase JavaScript client on demo pages;
- Hotel staff — receive the hotel name/location, reservation reference, stay dates, and selected products after the guest explicitly requests fulfillment. The request is emailed to the hotel's stored spa notification address(es) and is also available through the hotel-staff report; the system does not send hotel webhooks.
These providers receive only what is needed to operate the relevant feature. Exact hosting regions and contracting entities may vary by service and account.
9. International transfers
Concierge Comptoir, LLC is established in the United States. Vendors such as Supabase, Hostinger, WeatherAPI, Google, CDNs, and email providers may process data in countries other than the individual’s country of residence, including outside the EEA/UK where applicable.
Where Supabase’s Data Processing Addendum applies, it incorporates Standard Contractual Clauses (SCCs) under the conditions stated in that DPA. Concierge Comptoir describes those SCCs only as provided by Supabase’s DPA where applicable; it does not independently certify transfer mechanisms for every vendor. Other providers’ transfer terms depend on their service agreements and configuration. Concierge Comptoir does not claim EU–US Data Privacy Framework certification for itself or its vendors, and does not promise vendor deletion or retention schedules beyond what is described in this notice or verified in the applicable vendor terms.
10. Retention
-
Concierge sessions: retained for
six months or less from session creation. The
default purge path
(
purge_expired_concierge_session_data) uses the same clear path as a manual clear. - Manual clear: removes session credentials; scrubs guest display name and reservation reference on the session; replaces guest input snapshots with a cleared marker; scrubs weather values and recommendation output snapshots; rotates the guest public id. Minimal fulfillment operational shells may remain (for example request ids, hotel id, statuses, timestamps, stay dates on the request, item codes/quantities already sent, and delivery outbox status metadata with guest-identifying fields removed where applicable).
- Weather provider values: scrubbed in under 24 hours under the current implementation.
- Admin accounts: retained while the administrative relationship remains active and afterward only as needed for statutory, audit, and security requirements.
- Invitations: retained until accepted, expired, or revoked; the typical invitation window is 30–90 days.
- Email inquiries: no guest marketing list is maintained. Partnership correspondence is retained only as long as needed to respond and maintain business records.
- Hostinger logs: typically retained for 14–30 days.
11. Security approach
Technical measures reflected in the product include, among others:
- opaque guest tokens (hashed at rest; not placed in query strings);
- HttpOnly guest session cookies; referrer policy on guest bridges;
- role-separated access (site admin, demo user, hotel staff);
- service-role secrets confined to Edge Functions / server config;
- weather and recommendation scrubbing / session clear paths.
No security measure is absolute. Report suspected incidents to info@conciergecomptoir.com. Our response process is to contain the incident, assess risk to individuals, document the event and remediation, and make required notifications. Where the GDPR applies and notification is required, a supervisory authority will be notified without undue delay and, where feasible, within 72 hours; affected individuals will be notified without undue delay where the breach is likely to create a high risk. If acting as a processor, we will notify the relevant controller without undue delay.
12. Your rights
Depending on applicable law (including the EU GDPR where it applies), you may have rights to access, rectification, erasure, restriction, objection, portability, and withdrawal of consent where processing is consent-based. See the GDPR information page for a plain-language overview and official references.
To exercise rights, email info@conciergecomptoir.com. We may need to verify your identity and the scope of the request. We may verify a request through email correspondence. Hotel guests should contact their hotel about reservation and stay-related data.
13. How to contact us
Privacy and legal requests:
info@conciergecomptoir.com
Postal:
Concierge Comptoir, LLC, 650 E. Palisades Ave, Englewood Cliffs, NJ
07632, USA
14. Complaints
Where the GDPR applies, you may have the right to lodge a complaint with a supervisory authority, in particular in your EU/EEA Member State of residence, place of work, or place of the alleged infringement.
Concierge Comptoir, LLC is established in the United States and has not designated an EU/EEA lead supervisory authority. Where the GDPR applies, individuals may contact the competent supervisory authority in the EU/EEA country of their habitual residence, place of work, or the alleged infringement.
EU Commission overview: Data protection in the EU.
Related pages: GDPR & data protection · Legal Notice · Home