How we collect, use, and protect your personal information when you use goldentourseg.com and our travel services.
Privacy Policy, Terms & Conditions, and Legal Notice for goldentourseg.com. Scroll through each section below or use the menu on desktop to jump to a document.
This Privacy Policy explains how Golden Tours (“we”, “us”, “our”) handles personal information when you use goldentourseg.com and related services. Please read it together with our Terms & Conditions.
Golden Tours (“we”, “us”, “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, store, and protect personal information when you visit goldentourseg.com, create an account, request quotes or itineraries, make bookings, join programmes such as Travelers Club, or otherwise interact with our services.
We aim to meet widely recognised data-protection expectations (including transparency and accountability principles reflected in the GDPR and similar laws). Where local law grants you stronger rights, those rights apply alongside this Policy.
This Policy should be read together with our Terms & Conditions and Cookie practices described below. If anything here conflicts with terms you accepted at checkout for a specific trip, the checkout terms prevail only for that booking.
Depending on how you use our services, we may process:
We do not knowingly collect personal information from children for marketing. Travel arrangements typically involve adults; where a minor is named only as a traveller, processing is limited to fulfilling the booking.
We process personal information for the following purposes, relying on appropriate lawful bases under GDPR-style frameworks:
Where we rely on legitimate interests, we balance our interests against your rights and expectations. You may object to certain processing as described under “Your privacy rights”.
We retain personal information only as long as needed for the purposes above, including satisfying legal, accounting, or reporting requirements. Typical criteria include the duration of your customer relationship, statutory limitation periods, and backup cycles.
We share data with vetted service providers who process it on our instructions—such as cloud hosting and authentication, payment processing, email delivery, and analytics—under contracts that require security and confidentiality.
Our infrastructure or subprocessors may be located outside your country (including the European Economic Area or United States). Where required, we implement appropriate safeguards such as standard contractual clauses approved by regulators or equivalent mechanisms.
We may disclose information if required by law or to protect rights, safety, or the integrity of our services.
We implement technical and organisational measures appropriate to the sensitivity of the data we handle, including encryption in transit (HTTPS), access controls, separation of environments, monitoring, and principle-of-least-privilege access for staff and systems.
No online service can guarantee absolute security. If we become aware of an incident that poses a risk to your rights, we will notify you and regulators where required by law.
This appendix summarises common categories we process; specific trips may require additional items you voluntarily provide.
Profiling & automated decisions: we do not use automated processing that produces legal or similarly significant effects solely without human review.
Depending on where you live, you may have rights to access, rectify, erase, restrict processing of, or port your personal data, and to object to certain processing (including direct marketing). You may also withdraw consent where processing is consent-based.
To exercise these rights, email info@goldentourseg.com or write to us using the contact details in our Legal Notice. We may need to verify your identity before responding.
If you believe we have infringed applicable privacy law, you may lodge a complaint with your local supervisory authority.
Supervisory contacts vary by country (for example, citizens in the European Economic Area may contact their national Data Protection Authority).