How we handle your details
Privacy policy
We collect the least we can get away with, we use it to run your holiday, and we do not sell it to anybody. This page sets out the detail.
Who we are
Luxury Retreats Travel is a UK-based travel business. We are the data controller for the personal information described on this page. If you want to talk to us about anything here, contact us through the contact page and mark it for the attention of the data controller.
What we collect
When you send us an enquiry: your name, your email address, the trip you asked about, and whatever you write in the message.
When you book: the above plus your passport name and passport details where the airline or hotel requires them, your date of birth where a supplier requires it, your contact details, your rooming preference, and anything you tell us about dietary, medical, accessibility or mobility needs.
When you pay: your payment is taken by Stripe, and by Klarna where you choose Klarna. We never see or store your card number. What comes back to us is a confirmation that the payment succeeded, the amount, and the last four digits.
When you visit the site: your browser sends the usual technical information — IP address, browser type, which pages you looked at. This is ordinary web server logging.
Why we hold it, and on what basis
- To run your booking — because we need it to perform the contract between us
- To answer your enquiry — because you asked us to
- To meet our legal and accounting obligations — because the law requires it
- Health, dietary and accessibility information — only with your explicit consent, given when you tell it to us, and only so that we can pass it to the resort
We do not send marketing emails unless you have asked us to, and if we ever do you can stop them with one reply.
Who we share it with
Only the people who need it to make your trip happen: the hotels you are staying in, the transfer operators, the excursion providers, and where relevant the airline. Some of those are outside the UK — that is unavoidable when the holiday is abroad — and we share only what that supplier needs.
We also use Stripe to take payments and our website host to run this site. Both act as processors on our behalf.
We do not sell your data, and we do not pass it to anyone for their own marketing.
How long we keep it
Enquiries that never become bookings: up to 12 months, then deleted.
Bookings: seven years after the trip, because that is how long we have to keep financial records.
Health, dietary and accessibility details: deleted once the trip is over and any complaint window has passed, because we have no reason to keep them.
Your rights
Under UK data protection law you can ask us to tell you what we hold about you, to correct it if it is wrong, to delete it where we no longer need it, to restrict what we do with it, or to send it to you in a portable form. You can also withdraw consent where we relied on consent, and object to processing we based on legitimate interests.
Ask us and we will do it, free, within one month. If you are not happy with how we handle it you can complain to the Information Commissioner's Office at ico.org.uk.
Cookies
This site uses the cookies WordPress needs to work, and Stripe sets its own cookies on the checkout to detect fraud. We do not run advertising trackers or sell audience data. You can block cookies in your browser, though the checkout will not work without Stripe's.
Security
The site runs over HTTPS, payments never touch our servers, and access to booking records is limited to the people who need it. No system is perfect, but if there is ever a breach that puts you at risk we will tell you and the ICO, as the law requires.
Changes to this policy
If we change how we handle your information we will update this page. Anything material, we will tell people who have a live booking with us directly.
Want to know what we hold?
Ask, and we will tell you — and delete it if you would rather we did not have it.