Privacy & data
How we handle your information.
Planning travel means holding some genuinely sensitive things — passport pages, dates of birth, sometimes medical or dietary details. Here is exactly what we do with them.
What we collect
Whatever you tell us in an enquiry, questionnaire, or message: your name, contact details, travel preferences, budget, and any circumstances you'd like us to plan around. Once you engage us, the documents needed to make bookings — typically a passport photo page, and for pet travel, veterinary records.
How documents are protected
We never ask for documents by email. Instead we send you a private, expiring link to an encrypted upload page. Files are encrypted with AES-256 before they are written to disk, and the encryption key is held separately from the storage. Stored filenames are random, so nothing about a file is identifiable without the key.
Access is limited to the two of us, and every view or download is recorded in an internal audit log.
How long we keep things
- Identity documents are deleted once your travel is complete.
- Survey responses and correspondence are kept while you're a client, and for two years afterwards so we can plan your next trip well.
- You can ask us to delete anything, at any time, and we'll do it and confirm.
What we never do
- We don't sell or rent your information to anyone.
- We don't add you to a marketing list without you asking.
- We don't take card details ourselves — payments go through a processor, and the numbers never touch our systems.
- We don't use advertising or tracking cookies. The only cookie this site sets keeps your form session secure while you fill it in.
Who else sees your information
Only the suppliers required to make your bookings — the airline, the hotel, a guide, or a government authority in the case of pet documentation. We share the minimum each one needs, and we'll tell you when something unusual is required.
Asking us about your data
Write to us via the contact page and ask for a copy of what we hold, a correction, or a deletion. We'll respond within thirty days, and usually much sooner.
This page describes our actual practice. It isn't a substitute for a lawyer-reviewed privacy policy — if you're operating in a jurisdiction with specific requirements (GDPR, CCPA), have counsel review this before launch.