Legal

Privacy Policy — London to Vegas.

How London to Vegas handles your personal data. Written plainly. Compliant with the UK GDPR and the Data Protection Act 2018 for UK visitors; California CCPA rights honoured for US visitors.

Last updated: 2 July 2026

1. Who we are

London to Vegas (this website, at londontovegas.com) is operated by MyRSVP Group LLC, a Nevada limited liability company with its registered mailing address at 6020 Badura Ave, Ste 110 #10012, Las Vegas, NV 89118, United States.

For the purposes of the UK GDPR and the Data Protection Act 2018, MyRSVP Group LLC is the "controller" of the personal data described in this policy. We do not currently appoint a UK representative under Article 27; if you are a UK-based data subject you may contact us directly using the details below.

Contact us: enquiries@londontovegas.com (privacy enquiries), or write to us at the postal address above.

2. What personal data we collect

We only collect data we actually need to answer your enquiry, deliver a service, or run the site. Specifically:

  • Enquiry form data. Name, email, WhatsApp / phone number, travel dates, group size, budget band, and free-text notes that you choose to include.
  • Booking data. Where you proceed to a confirmed booking: billing address, passport name (as required by venues and airlines), dietary or accessibility requirements you volunteer, and payment authorisation records. Card numbers are processed directly by Stripe and never stored on our servers.
  • Correspondence. Emails, WhatsApp messages, and phone-note summaries exchanged between you and our team.
  • Website telemetry. IP address, browser and device type, pages viewed, referrer, and interaction events (measured only if you accept analytics cookies: see section 5).

We do not collect special-category personal data (health, religion, sexuality, etc.) as a matter of course. If you volunteer such information because it is relevant to your booking (for example, a dietary requirement tied to a medical condition), we handle it on the basis of your explicit consent (Article 9(2)(a)) and share it only with the specific supplier who needs it.

3. Why we use it (legal bases)

  • Answering your enquiry. Legal basis: Article 6(1)(b) - steps taken at your request prior to entering a contract.
  • Delivering your booking. Legal basis: Article 6(1)(b) - performance of the concierge contract, including sharing details with the specific venues, transport operators and hotels needed to fulfil it.
  • Marketing follow-up. Where you have opted in, legal basis: Article 6(1)(a) - consent. You can withdraw at any time via the unsubscribe link in every marketing email, or by emailing enquiries@londontovegas.com.
  • Site analytics and performance. Legal basis: Article 6(1)(a) - consent. Analytics are default-denied under Consent Mode v2 (see section 5) and only fire if you accept.
  • Fraud prevention, security, tax records. Legal basis: Article 6(1)(c) and 6(1)(f) - legal obligation and our legitimate interest in operating a lawful business.

4. Who we share it with

We share the minimum data required, with specific processors, for specific reasons:

  • Fulfilment partners. The specific venues, restaurants, transport operators, hotels and event organisers we book on your behalf. Only the details they need to hold your reservation.
  • Stripe, Inc. Payment processing (card, Apple Pay, Google Pay). Stripe is a PCI-DSS Level 1 provider and acts as an independent controller for anti- fraud purposes.
  • Resend, Inc. Transactional and enquiry-notification email delivery.
  • Vercel, Inc. Hosting and edge delivery of this website.
  • Google LLC (Analytics 4 and Tag Manager) and Microsoft Corporation (Clarity). Web analytics, subject to your cookie consent. Consent Mode v2 anonymises IPs and defaults all storage to denied.
  • Sister brands within the MyRSVP Group (casinohostvegas.com, golfinlv.com, myrsvp.com). If you specifically request an introduction (for example, a golf itinerary added to your Vegas trip), we share only the information required for that referral. We do not use sister-brand data for cross-marketing without your consent.

We do not sell personal data. We do not share personal data with data brokers, ad networks, or non-processor third parties for their own marketing.

5. Cookies and tracking

On first visit, our cookie banner defaults every category to denied under Google Consent Mode v2. Only strictly necessary cookies (session, CSRF, consent state) are set before you make a choice. Nothing you do on the site is measured until you accept analytics or marketing categories.

  • Strictly necessary. Session, security, and your consent choice itself (stored for 12 months in localStorage).
  • Analytics. Google Analytics 4 (page and event measurement), Microsoft Clarity (session behaviour). Fires only if you accept the analytics category.
  • Marketing. None currently active. If we add remarketing pixels in future, they will fire only if you accept the marketing category.

You can change your choice at any time via the "Cookie preferences" link in the footer. UK visitors also have the option to configure their browser to refuse cookies entirely.

6. International transfers

Because we are a Nevada-registered concierge, most personal data is processed in the United States. Where we transfer personal data of UK data subjects to the US, we rely on:

  • The UK Extension to the EU-US Data Privacy Framework, where the recipient (for example, Stripe, Vercel, Google) is a certified DPF participant; or
  • Standard Contractual Clauses issued by the UK Information Commissioner (the International Data Transfer Addendum) with supplementary technical safeguards, where DPF certification is not available.

7. How long we keep it

  • Enquiries that do not convert: 24 months from last contact, then deleted or anonymised.
  • Completed bookings: 7 years for tax and accounting purposes, then deleted.
  • Marketing consent: until you withdraw, then removed from active lists within 30 days.
  • Analytics telemetry: 14 months from collection.

8. Your rights

Under the UK GDPR you have the right to:

  • Access the personal data we hold about you (subject access request).
  • Ask us to correct inaccurate data.
  • Ask us to delete your data (subject to the retention periods above).
  • Restrict or object to our processing.
  • Data portability where processing is by consent or contract.
  • Withdraw consent at any time where processing relies on it.
  • Complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.

California residents have analogous rights under the CCPA (right to know, delete, and opt out of sale). We do not sell personal data.

To exercise any of these rights, email enquiries@londontovegas.com. We will respond within 30 days (UK) or 45 days (California).

9. Children

London to Vegas does not knowingly collect personal data from anyone under 16. Our services are marketed to adults planning travel and hospitality in Las Vegas, where the legal age for casinos, gambling and alcohol is 21. If you believe a minor has provided personal data through this site, contact us and we will delete it.

10. Security

We host on Vercel with TLS 1.3, encrypt data at rest at the database layer, and restrict staff access on a need-to-know basis. No system is perfectly secure; we commit to notify UK data subjects within 72 hours of becoming aware of a breach that is likely to result in a high risk to their rights, in line with Article 34.

11. Updates to this policy

We will update this page when our processing changes materially. The "last updated" date at the top reflects the most recent revision. Material changes are also notified by email to anyone with an active enquiry or booking.

12. Contact

MyRSVP Group LLC
6020 Badura Ave, Ste 110 #10012, Las Vegas, NV 89118, United States
Email: enquiries@londontovegas.com