Privacy policy

Last updated 23 July 2026. This policy applies to the Sommet customer app, the Sommet Partner app and this website.

Sommet operates a members' concierge and booking service for stays at participating resorts, live now on (Anti)Paros. This policy explains what personal data we collect, why, who we share it with, how long we keep it and the rights you have. The data controller is Sommet Paros/Antiparos Single Member P.C. (Μονοπρόσωπη Ι.Κ.Ε.), a company incorporated in Greece with its registered office at Tepeleniou 23, 16673 Voula, Attica, Greece, registered in the General Commercial Registry (GEMI) under number 194942201000, tax number (AFM) 803341350, EU VAT identifier EL803341350. For any privacy request, email support@sommet.life.

Where we hold your data

We store and process your personal data in the European Union. Where a processor operates outside the EU or European Economic Area, we rely on an approved transfer mechanism, such as an adequacy decision or standard contractual clauses. Some of our providers, including Stripe, Clerk and OpenAI, are based in the United States; where they process your data we rely on standard contractual clauses or an adequacy decision such as the EU-US Data Privacy Framework.

What we collect

  • Account and identity: your name, email address and phone number, handled through our sign-in provider, Clerk. If you choose Sign in with Apple or Google, we receive the account details those services share with us.
  • Booking data: the transfers, tables, charters, experiences and other services you request, and the related dates, times, party details and locations.
  • Payment data:processed by our payment provider, Stripe. Sommet never stores your card details. Vendors are the merchant of record for what you book and are paid directly through Stripe; Sommet takes a platform fee. The Sommet Pass is the exception: we sell it to you directly and charge it to Sommet's own Stripe account, so for that purchase Sommet is the merchant of record.
  • Location: precise location. In the customer app we use location while you are using the app for transport, dispatch and resort context. In the Sommet Partner app we may use background location only while a partner is on an active job, so the guest and operations team can see fulfilment progress until the job is complete. We do not track partners while they are off shift. You can turn this off in your device settings, although some active-job features may then be unavailable.
  • Partner identity and KYB: if you use the Sommet Partner app, we collect the information needed to verify you and your business, including government ID, business-registration documents, proof of insurance, licences, verification status, review notes and related metadata. We use Didit to run identity verification and KYB checks, and Stripe Connect to support partner payouts and merchant onboarding.
  • Concierge messages: the messages you exchange with our human concierge team, and any preferences you share to help with a booking.
  • Partner referral attribution:if you choose to continue from a partner's invitation link, we keep a short-lived, random invitation token and, when you create an account, record which partner introduced your household. We use this to apply the agreed platform fee to eligible bookings and to show the partner privacy-protected aggregate performance. Opening the web link alone does not attach a referral to you.
  • Diagnostics and usage data: crash and error diagnostics through Sentry (EU region). With your separate permission, product analytics through our Zurich-hosted PostHog service help us understand visits and app-store journeys. Maps are provided by Mapbox.

Why we use it, and our legal bases

We use your data to create and run your account, to fulfil the bookings you make, to take payment through Stripe, to let the concierge team help you, to keep the service secure and reliable, and to meet our legal, accounting and tax obligations. Our legal bases are the performance of our contract with you (for your account and bookings), your consent (for optional marketing email and optional product analytics, each controlled separately and withdrawable at any time), our legitimate interest in running a safe and reliable service (for diagnostics, security and preventing abuse), and compliance with a legal obligation (for financial and tax records).

Who we share it with

We share the minimum needed to deliver a booking with the Vendor or partner fulfilling it, for example the driver of your transfer. We use trusted processors who act on our instructions under a data-processing agreement, including Clerk (sign-in), Sentry (crash diagnostics, EU region), PostHog (optional product analytics), Mapbox (maps), Didit (partner identity and KYB verification), Postmark and Resend (email) and our hosting provider. Stripe processes payments as an independent controller under its own terms, not as our processor. If you use our optional AI trip-planner, we send a limited, minimised set of stay details to OpenAI, our AI provider in the United States, to draft itinerary ideas from our own venue catalogue. That set covers your stay dates and how you are arriving, your party size including how many adults and children are travelling and the ages of any children, the name of your accommodation and its approximate location (its town, and coordinates rounded to roughly a kilometre rather than a precise address), your stated preferences and notes, the ideas already in your itinerary and the local weather. The ideas are pencilled suggestions, not bookings, and you choose whether to act on them. If you use menu import in the Sommet Partner app, we send the menu photograph you upload to the same provider so it can read the dish names and prices into a draft you then check and correct before anything is published. We do not sell your personal data, we do not use it for advertising or cross-app tracking, and we do not use it, or permit our providers to use it, to train artificial-intelligence models. Our concierge is a human team, not a bot, and the optional AI trip-planner and Partner menu import are the only features that send your data to an AI provider.

How long we keep it

We keep account and booking data for as long as your account is open. When you delete your account, we close it and delete or anonymise your personal data on our own systems immediately, except for records we must keep longer by law. At the same time we instruct our analytics provider to erase its copy, which normally completes within a few hours. We keep financial, invoicing and tax records for the Greek statutory accounting and tax period (generally at least five years). We keep partner identity and anti-money-laundering (KYB) records for five years after the business relationship ends, as anti-money-laundering law requires. We may keep the minimum needed to handle a live dispute, claim or fraud investigation until it is resolved. When a record is no longer needed for any of these purposes, we delete or anonymise it. See our account deletion page for the full deleted-versus-retained split.

Your rights

You can ask to access, correct, export or delete your personal data, and you can object to or restrict certain processing. To delete your account and data, use the in-app path or the email path on our account deletion page. You can withdraw consent to marketing at any time. If you are in the EU or the EEA you have these rights under the GDPR; if you are in Switzerland, the revised Swiss Federal Act on Data Protection gives you equivalent rights. You also have the right to complain to your local data-protection authority, which in Greece is the Hellenic Data Protection Authority.

Website analytics choice

Website analytics is off until you allow it. You can change or withdraw that choice here at any time. Form contents are never captured by this setting.

Current website analytics choice: not chosen.

Cookies and local storage

Our website uses no advertising or tracking cookies. It sets only what is strictly necessary to run the site and remember your choices, which does not require your consent. Only if you allow analytics above, our analytics provider (PostHog) stores a small identifier in your browser's local storage and a cookie so it can count a visit without profiling you; you can withdraw that at any time using the control on this page, which removes it. The Sommet apps do not use web cookies.

Children

Only adults may hold a Sommet account, and we do not knowingly collect personal data directly from anyone under 18. A member may tell us how many children are travelling in their party and their ages, so that bookings and suggestions, including those from the optional AI trip-planner, suit the party. We use that limited information only to arrange and plan the stay, and it is covered by the same retention and deletion rules as the rest of the member's account data.

Contact

Email support@sommet.life for any privacy request or question, or write to Sommet Paros/Antiparos Single Member P.C., Tepeleniou 23, 16673 Voula, Attica, Greece.