Privacy policy
Last updated: May 2026
Who we are
We're a tour booking service connecting travellers with licensed Bhutanese guides certified by the Department of Tourism. We act as the data controller for your personal information collected through this website.
Contact: [email protected]
What we collect
We collect the following personal information:
- Identity data: Full name, nationality/country
- Contact data: Email address, phone number
- Travel data: Travel dates, tour preferences, special requests
- Passport data: When required for visa/permit applications
- Technical data: IP address, browser type, device information
- Usage data: Pages visited, booking interactions
Payment data: Card payments are processed directly by Stripe. We do not store full card numbers or CVV codes.
Legal basis for processing (GDPR)
We process your personal data under the following legal bases:
- Contract performance: Processing bookings, arranging tours, coordinating with guides, sending booking confirmations
- Legal obligation: Visa/permit applications, tax records, responding to lawful requests from authorities
- Legitimate interests: Fraud prevention, improving our services, responding to inquiries, internal analytics
- Consent: Marketing communications, analytics cookies (where required). You can withdraw consent at any time.
How we use your data
- Process and manage your tour bookings
- Arrange visas, permits, and travel documentation
- Coordinate with licensed Bhutanese guides on the ground
- Send booking confirmations, updates, and travel information
- Handle change requests and customer support inquiries
- Process payments and refunds
- Comply with legal and regulatory requirements
- Improve our website and services
Third-party processors
We share your data with these trusted service providers:
| Provider | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | USA (DPF / SCCs) |
| Supabase | Database & authentication | USA/EU |
| Resend | Transactional emails | USA |
| Vercel | Website hosting | USA/Global CDN |
| Google Analytics | Website analytics | USA |
| Licensed Bhutanese guides | On-ground tour delivery | Bhutan |
We also share necessary information with Bhutan's Tourism Council and Immigration Department for visa and permit processing.
Data retention periods
We retain your personal data for the following periods:
| Data type | Retention period | Reason |
|---|---|---|
| Booking records | 7 years | Tax & legal compliance |
| Payment records | 7 years | Financial regulations |
| Visa/permit copies | 3 years after travel | Immigration compliance |
| Support correspondence | 2 years | Service improvement |
| Inquiry forms (non-booking) | 1 year | Follow-up purposes |
| Analytics data | 26 months | Website optimization |
After these periods, data is securely deleted or anonymized.
International data transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the USA and Bhutan. We ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) with service providers
- Data Processing Agreements with all processors
- Encryption in transit and at rest
Your rights (GDPR)
Under GDPR and applicable data protection laws, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Limit how we use your data
- Portability: Receive your data in a machine-readable format
- Object: Object to processing based on legitimate interests
- Withdraw consent: Where processing is based on consent
Note: Some data (e.g., completed bookings, tax records) must be retained for legal compliance and cannot be deleted upon request.
To exercise your rights, email us at [email protected]. We will respond within 30 days.
Right to lodge a complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. For EU residents, this is typically the data protection authority in your country of residence.
We encourage you to contact us first at [email protected] so we can address your concerns directly.
Cookies & analytics
We use essential cookies for website functionality and optional analytics cookies (Google Analytics) to understand how visitors use our site.
- Essential cookies: Required for site operation (no consent needed)
- Analytics cookies: Only set with your consent via our cookie banner
You can manage cookie preferences through our cookie consent banner or your browser settings.
Security measures
We protect your data with:
- HTTPS encryption for all data transmission
- Encrypted database storage
- Access controls limited to authorized personnel
- Regular security reviews and updates
- PCI-compliant payment processing via Stripe
While no system is 100% secure, we take reasonable measures to protect your data.
Changes to this policy
We may update this policy from time to time. Significant changes will be communicated via email or website notice. The "last updated" date at the top of this page indicates when this policy was last revised.
Contact
For privacy-related requests or questions:
Email: [email protected]
Response time: Within 30 days
Related policies
See also our terms & conditions and refund policy.