Legal

Privacy Policy

Last updated: June 1, 2026 · Effective: June 15, 2026

Travelia Lda. ("Travelia," "we," "us," or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, share, and safeguard your information when you visit our website travelia.co, use our services, book a tour, contact us, or interact with us in any way.

We are registered in Portugal under company number PT123456789, with our registered office at 24 Sunset Boulevard, Lisbon 1200-001, Portugal. Travelia is the data controller for the personal data processed under this policy.

Key summary: We collect only the data we need to plan and book your trips. We never sell your personal information to third parties. You have full control over your data, and we make it easy to access, update, or delete it at any time.

1. Information We Collect

We collect information you provide directly to us, information collected automatically when you use our website, and information from third-party sources.

1.1 Information You Provide Directly

  • Identity & Contact Data: Full name, email address, phone number, postal address, date of birth, passport details (when required for bookings).
  • Booking & Travel Data: Destination preferences, travel dates, number of travelers, special requirements (dietary, medical, accessibility), hotel preferences, flight details.
  • Payment Data: Credit/debit card information, billing address, bank transfer details. Note: Full card numbers are processed by our PCI-DSS compliant payment partners (Stripe) and are never stored on our servers.
  • Communications: Messages, inquiries, feedback, reviews, and any other content you send to us via forms, email, phone, or chat.
  • Account Data: If you create an account: username, password hash, saved preferences, booking history.

1.2 Information Collected Automatically

  • Technical Data: IP address, browser type and version, operating system, device type, screen resolution, time zone setting.
  • Usage Data: Pages visited, time spent on pages, links clicked, search queries, referring URLs, exit pages, scroll depth.
  • Location Data: Approximate geographic location derived from your IP address (country and city level only).
  • Cookies & Similar Technologies: See Section 4 (Cookies & Tracking Technologies) for full details.

1.3 Information From Third Parties

  • Travel Partners: Airlines, hotels, and tour operators may share booking confirmations and updates.
  • Payment Processors: Stripe shares transaction IDs, payment status, and the last four digits of your card for verification.
  • Analytics Providers: Google Analytics provides aggregated and anonymized usage data.
  • Social Media Platforms: If you interact with us on Instagram, Facebook, or Twitter, we may see your public profile information.

2. How We Use Your Information

We use your personal data only for the purposes described below and always on a lawful basis (contractual necessity, legitimate interest, legal obligation, or your consent).

2.1 Core Service Delivery (Contractual Necessity)

  • Processing and confirming your tour bookings
  • Creating customized travel itineraries and quotes
  • Communicating with airlines, hotels, and local partners on your behalf
  • Processing payments, refunds, and cancellations
  • Providing 24/7 customer support before, during, and after your trip
  • Sending booking confirmations, e-tickets, and travel documents

2.2 Legitimate Business Interests

  • Improving our website, services, and user experience
  • Analyzing usage patterns to optimize our tour offerings
  • Personalizing content and recommendations based on your preferences
  • Sending relevant marketing communications (with opt-out available)
  • Preventing fraud, abuse, and unauthorized access
  • Training our support team to serve you better

2.3 Legal Obligations

  • Complying with tax, accounting, and regulatory requirements
  • Responding to lawful requests from government authorities
  • Maintaining records as required by Portuguese and EU law

2.4 With Your Consent

  • Sending our monthly newsletter and promotional emails (you can unsubscribe anytime)
  • Placing non-essential cookies on your device (you can manage preferences)
  • Featuring your travel photos or testimonials on our website or social media
Purpose Legal Basis Data Categories
Booking & trip management Contractual necessity Identity, contact, booking, payment
Customer support Contractual necessity Identity, contact, communications
Website improvement Legitimate interest Technical, usage
Marketing & newsletter Consent / Legitimate interest Identity, contact, preferences
Legal compliance Legal obligation Identity, payment, booking

3. Data Sharing & Disclosure

We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We share data only as necessary to deliver our services:

3.1 Service Providers & Partners

  • Payment Processors: Stripe, Inc. (PCI-DSS Level 1 certified) — processes your payments securely.
  • Cloud & Hosting: Amazon Web Services (AWS) — hosts our website and databases on EU-based servers.
  • Email & Communication: SendGrid (Twilio) — delivers our transactional and marketing emails.
  • Analytics: Google Analytics (Google LLC) — provides anonymized usage insights.
  • Travel Partners: Airlines, hotels, local tour operators, and transfer companies — only the data necessary to fulfill your booking (name, travel dates, special requirements).
  • Insurance Partners: If you purchase travel insurance through us, relevant data is shared with the insurance provider.

3.2 Legal & Regulatory Disclosures

We may disclose your information if required by law, court order, or governmental regulation, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.

3.3 Business Transfers

In the event of a merger, acquisition, or sale of all or part of our assets, your data may be transferred as part of that transaction. We will notify you via email and a prominent notice on our website before your data becomes subject to a different privacy policy.

4. Cookies & Tracking Technologies

We use cookies and similar technologies to enhance your browsing experience, analyze website traffic, and personalize content.

4.1 What Are Cookies?

Cookies are small text files stored on your device by your web browser. They help websites remember your preferences, login status, and activity over time.

4.2 Types of Cookies We Use

Cookie Type Purpose Duration Example
Essential Core website functionality, security, booking flow Session – 1 year Session ID, CSRF token
Analytics Understand how visitors use our site 1 day – 2 years Google Analytics (_ga, _gid)
Preferences Remember your choices (language, currency) 30 days – 1 year Language preference
Marketing Personalized ads & retargeting 90 days Facebook Pixel, Google Ads

4.3 Managing Your Cookie Preferences

You can manage or disable cookies at any time through your browser settings or our cookie consent banner. Please note that disabling essential cookies may affect website functionality.

  • Browser Settings: Chrome, Firefox, Safari, and Edge all allow you to block or delete cookies.
  • Our Cookie Banner: When you first visit our site, you can accept or reject non-essential cookies.
  • Opt-Out Tools: You can opt out of Google Analytics at tools.google.com/dlpage/gaoptout.

5. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:

  • Encryption: All data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256.
  • Access Controls: Strict role-based access; only authorized personnel can access personal data.
  • PCI-DSS Compliance: Payment data is handled exclusively by Stripe, a PCI-DSS Level 1 Service Provider.
  • Regular Audits: We conduct quarterly security reviews and penetration testing.
  • Two-Factor Authentication: Required for all employee accounts accessing personal data.
  • Data Minimization: We collect only the data necessary for each specific purpose.

While we strive to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We encourage you to use strong passwords and keep your login credentials confidential.

6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law:

  • Booking Data: Retained for 7 years after your last booking for tax and legal compliance.
  • Inquiry Data (no booking): Retained for 18 months after your last interaction, then anonymized.
  • Newsletter Subscription: Retained until you unsubscribe.
  • Website Analytics: Anonymized after 26 months.
  • Payment Records: Retained for 10 years per Portuguese tax law.
  • Account Data: Retained until you delete your account or after 3 years of inactivity.

When data is no longer needed, we securely delete or irreversibly anonymize it.

7. Your Rights

Under the EU General Data Protection Regulation (GDPR) and applicable data protection laws, you have the following rights:

Right to Access

Request a copy of the personal data we hold about you.

Right to Rectification

Correct any inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your data ("right to be forgotten").

Right to Restrict Processing

Limit how we use your data in certain circumstances.

Right to Data Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests or direct marketing.

To exercise any of these rights, please contact us at privacy@travelia.co. We will respond within 30 days. We may need to verify your identity before processing your request. There is no fee for exercising your rights unless your request is manifestly unfounded or excessive.

If you believe our processing of your data violates GDPR, you have the right to lodge a complaint with the Portuguese Data Protection Authority (Comissão Nacional de Proteção de Dados — CNPD) or your local supervisory authority.

8. International Data Transfers

Travelia is based in Portugal, and your data is primarily stored and processed within the European Economic Area (EEA). However, to deliver our travel services, we may need to transfer your data to:

  • Hotels, tour operators, and local partners in your destination country
  • Service providers in countries that may have different data protection laws

When we transfer data outside the EEA, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs): Approved by the European Commission
  • Adequacy Decisions: For countries recognized as providing adequate protection (e.g., UK, Switzerland, Japan)
  • Your Explicit Consent: For transfers necessary to fulfill your booking

9. Children's Privacy

Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately. We will take steps to delete such information promptly.

For family bookings, we collect children's data (name, age, passport details) only as provided by the parent or legal guardian and solely for travel booking purposes.

Our website may contain links to third-party websites, plugins, and applications (e.g., hotel websites, airline portals, social media platforms). Clicking those links may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. We encourage you to read the privacy policy of every website you visit.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. When we make material changes, we will:

  • Post a prominent notice on our website at least 14 days before the changes take effect
  • Send an email notification to users who have booked with us or subscribed to our newsletter
  • Update the "Last updated" date at the top of this page

We encourage you to review this page periodically. Continued use of our services after changes take effect constitutes acceptance of the updated policy.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our Data Protection Officer:

Data Protection Officer

Maria Silva
Travelia Lda.

Contact Details

Email: privacy@travelia.co
Phone: +351 912 345 678
Address: 24 Sunset Boulevard,
Lisbon 1200-001, Portugal

We aim to respond to all privacy-related inquiries within 48 hours and resolve any concerns within 30 days.

Your privacy is our priority.

Have questions about how we handle your data? We're here to help.