Privacy Policy

Effective version: 2026-06-16

This Privacy Policy explains how the SunTravel platform ("SunTravel", "we") processes personal data in connection with its business-to-business reservation gateway. SunTravel is a B2B service used solely by tour operators ("Operators"); we do not market to or contract with travel agencies or end consumers directly.

1. Who We Are

The controller for Operator account data is [Legal entity name, registered address, contact]. For data-protection questions, contact [privacy/DPO contact].

2. Controller and Processor Roles

We act as controller for personal data relating to Operator accounts and our own operation of the Platform (e.g. account contacts, authentication, billing and usage logs). For personal data of Guests that an Operator submits to make a Booking, the Operator is the controller and SunTravel acts as a processor on the Operator's behalf, processing such data only to provide the Service and as described here.

3. Data We Process

Operator account data: company name, address, contact name, email, phone, login credentials (stored hashed), API tokens, and commercial settings. Transactional data: searches, Bookings, wallet movements, invoices and related records. Guest data (on the Operator's behalf): guest name, email, phone, nationality and booking details required by the Supplier to fulfil the reservation. Technical data: IP address, device/browser data, request logs and audit records used for security, fraud prevention and diagnostics.

4. Purposes & Legal Bases

We process data to: create and administer accounts; authenticate users; execute searches and Bookings with Suppliers; operate the Wallet and billing; provide support; ensure security, prevent fraud and abuse; comply with legal obligations; and improve the Service. Legal bases include performance of a contract, our legitimate interests (security, service operation and improvement), and compliance with legal obligations. For Guest data, the Operator is responsible for establishing a valid legal basis.

5. Sharing & Recipients

We share data only as needed to provide the Service: with Suppliers and the underlying providers to fulfil Bookings; with infrastructure and service sub-processors (cloud hosting and database, transactional email delivery, payment/virtual-card processing); and with authorities or advisers where required by law or to protect our rights. We do not sell personal data. Sub-processors are bound by appropriate confidentiality and data-protection obligations.

6. International Transfers

Because Suppliers and providers operate globally, fulfilling a Booking may involve transferring the necessary Guest data to recipients in other countries. Where required, such transfers rely on appropriate safeguards (e.g. standard contractual clauses or an adequacy decision).

7. Retention

We retain account and transactional data for as long as the account is active and thereafter as required to meet legal, accounting, tax and dispute-resolution obligations. Technical/audit logs are retained for a limited period for security and diagnostics. Guest data is retained only as needed to provide and evidence the Booking, then deleted or anonymised in line with our retention schedule and the Operator's instructions.

8. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit, hashed credentials, access controls, network protection and audit logging. No system is perfectly secure; we cannot guarantee absolute security but work to protect data and to notify of incidents as required by law.

9. Your Rights

Subject to applicable law, individuals may request access to, correction, deletion or restriction of their personal data, object to certain processing, or request portability. Operators may exercise rights for their own account data via the operator panel or by contacting us. Requests concerning Guest data should be directed to the relevant Operator (the controller); we will assist Operators in responding.

10. Cookies

The Platform uses only strictly necessary cookies (for authentication and session security). We do not use advertising or third-party tracking cookies in the operator panel.

11. Children

The Platform is a business service and is not directed to children. Guest data is provided by Operators in the context of a travel booking and is processed only for that purpose.

12. Changes

We may update this Policy; material changes increment the effective version shown above. Continued use of the Platform after the effective date constitutes acknowledgement of the updated Policy.

13. Contact

For privacy questions or to exercise rights, contact your account manager or [privacy/DPO contact].

← Go back