← Back to blog
9 September 2026

Data Retention Explained: How Long We Keep Your Information & Why

When you book a luxury villa stay, share travel preferences, or request concierge support, you expect excellent service without losing control of your personal information. Data retention explained means understanding a simple but important question: how long is your information kept, and why? At The Source, personal information is retained only for as long as necessary to fulfill the purposes for which it was collected or to comply with applicable legal, accounting, or regulatory requirements.

That approach matters because privacy is not just about what information is collected. It is also about what happens after it is collected, who can access it, how it is protected, and when it is no longer needed. In this guide, you will learn how data retention works, why certain information may need to be kept for a period of time, and how this fits into a broader commitment to responsible guest service.

What Data Retention Means

Data retention refers to the length of time an organisation keeps personal information before it is deleted or otherwise no longer retained for active use. In practice, retention is tied to purpose.

At The Source, personal information is collected only as needed to:

Information that may be collected includes:

The key principle is straightforward: information should not be kept indefinitely without a valid reason. Retention should reflect real operational needs and legal responsibilities.

Why We Keep Personal Information for a Period of Time

There is a practical reason personal information cannot always be deleted immediately after it is received. In hospitality and travel-related services, guest information often supports several stages of the experience, from booking to stay coordination to follow-up administration.

At The Source, personal information is used solely to:

This means retention is connected to service delivery. If you request concierge arrangements, provide guest details, or complete a reservation, that information may need to remain available long enough for those services to be properly delivered and documented.

Retention may also be necessary for legal, accounting, or regulatory reasons. In many service businesses, records must be maintained for a period of time to satisfy compliance obligations, support financial recordkeeping, or respond to lawful requirements.

The Retention Standard at The Source

The clearest answer to the question of timing is this:

Personal information is retained only for as long as necessary to fulfill the purposes for which it was collected or to comply with applicable legal, accounting, or regulatory requirements.

That standard is intentionally purpose-based rather than open-ended. It reflects a privacy-conscious approach in which retention is linked to a legitimate need.

What “as long as necessary” means in practice

Although retention periods can vary depending on the type of information and the reason it was collected, the principle remains the same. Information may be kept while it is needed to:

  1. Complete and manage a reservation
  2. Coordinate concierge or guest-related services
  3. Maintain required business records
  4. Meet legal or regulatory obligations

Once those purposes no longer apply, the rationale for retaining that information is reduced or removed.

What Information May Be Retained

Not all personal information serves the same purpose, even within one guest journey. Different categories of information may be relevant for different operational reasons.

Reservation and contact information

Basic booking information, such as your name and contact details, may be needed to:

Concierge and guest preference information

Travel preferences, guest details, and other information you choose to share may be used to:

Payment information

Payment information is especially sensitive, which is why it is processed through secure, industry-standard payment providers. Financial records may also need to be retained where required for lawful accounting or regulatory purposes.

Who Can Access Retained Information

Retention is only one part of responsible privacy management. Access control matters just as much.

At The Source:

This matters because retained information should not simply sit in a system without safeguards. Limiting access helps reduce unnecessary exposure and supports a more secure handling process.

How Retained Information Is Protected

A thoughtful retention policy works best when paired with sound security practices. Keeping information only as long as necessary is important, but protecting it during that period is equally essential.

The Source takes reasonable administrative, technical, and physical safeguards to protect personal information from:

These protections support privacy throughout the information lifecycle, from initial collection through permitted use and retention.

Why Data Retention Matters to Guests

For guests, the idea of data retention can feel abstract until it is tied to real concerns. Most people want to know three things:

  1. Why was my information collected?
  2. Who is using it?
  3. How long will it remain on file?

A clear retention approach helps answer all three.

It supports trust

When a hospitality company explains that it collects only necessary information and retains it only as long as needed, that signals a more disciplined and respectful approach to privacy.

It reduces unnecessary exposure

The less information that is kept without purpose, the lower the risk of needless handling or access over time. Purpose-based retention is a practical part of responsible data management.

It aligns service with privacy

High-touch hospitality often requires detailed coordination. Guests may share preferences, payment details, and travel information to make their stay seamless. Responsible retention helps ensure that service remains personal without becoming excessive.

Quick Answers: Data Retention Explained

How long do we keep your information?

Only for as long as necessary to fulfill the purposes for which it was collected or to comply with applicable legal, accounting, or regulatory requirements.

Why do we keep it at all?

To:

Do we sell or rent your personal information?

No. Personal information is not sold or rented to third parties.

Who might information be shared with?

Only with:

How is payment information handled?

Payment information is processed through secure, industry-standard payment providers.

Practical Takeaways for Guests

If you want to make informed decisions about your personal information, these are useful points to keep in mind.

1. Share information that supports your stay

Details such as guest preferences and travel information can help create a smoother experience when they are relevant to your reservation or concierge requests.

2. Understand the purpose behind the request

When information is requested during the booking process, it is tied to specific service, operational, or legal needs.

3. Ask questions if you want more clarity

If you have questions about the Privacy Policy or want to request access to, correction of, or deletion of your personal information, you can contact The Source directly.

If you are planning a stay, it is also helpful to explore related topics such as FAQS, Contact, Book Now, or the villa collection to better understand the booking and guest experience.

Data Retention and Luxury Hospitality

In luxury villa travel, personal service often depends on thoughtful coordination behind the scenes. Reservations, concierge planning, and guest communications all rely on information being handled accurately and responsibly.

That is why data retention should never be treated as a background technical issue. It is part of the overall guest experience. A careful retention approach supports both operational excellence and privacy protection.

The Source reflects this balance by collecting only the information necessary for reservations, concierge services, communication, and guest experience enhancement, while limiting sharing, restricting access, and retaining information only as long as needed for the relevant purpose or compliance requirement.

Conclusion

Data retention explained comes down to a clear principle: personal information should be kept with purpose, protected while it is needed, and not retained longer than necessary. At The Source, that means collecting only necessary information, using it solely for defined guest-service and legal purposes, protecting it with reasonable safeguards, and retaining it only for as long as those purposes require.

Privacy and hospitality should work together. Responsible data handling helps create the confidence that great guest experiences depend on.

If you would like to learn more, have questions about the Privacy Policy, or want to request access to, correction of, or deletion of your personal information, please contact The Source directly.