Privacy Policy
We maintain an unwavering dedication to protecting and preserving all personal data provided by our website visitors and service users, implementing robust and comprehensive security measures throughout our services and operations.
This policy applies where we are acting as a data controller with respect to the personal data of our website visitors and service users; in other words, where we determine the purposes and means of the processing of that personal data. In this role, we are responsible for ensuring the proper handling, processing, and protection of all personal data submitted through our website.
We may process usage data (“usage data”), which comprehensively includes browser type, operating system, page views, navigation paths, timing and duration of visits, click patterns, and interaction metrics. This information is collected through server logs, cookies, and analytics tools and may include search preferences, booking history, and travel itinerary views. The source of this data is our analytics software and server monitoring systems. We process this information for several important purposes, including improving website performance, enhancing user experience, analyzing travel trends, and optimizing our service offerings, which enables us to personalize content delivery, refine our travel recommendations, and enhance platform security. The legal basis for this processing is our legitimate interests in monitoring and improving our website and services.
We may process account data (“account data”), which comprehensively includes name, email address, telephone number, postal address, payment information, and account preferences. This information is collected through registration forms, booking processes, and account updates and may include travel preferences, loyalty program details, and communication settings. The source of this data is your direct input during account creation and subsequent interactions. We process this information for managing user accounts, processing travel bookings, facilitating communications, and maintaining service records, which enables us to provide personalized travel services, process transactions, and ensure account security. The legal basis for this processing is the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract.
We may process profile data (“profile data”), which comprehensively includes your travel preferences, past bookings, saved destinations, reviews, and ratings. This information is collected through profile customization, booking history, and interactive features and may include travel interests, destination wishlists, and feedback submissions. The source of this data is your interactions with our platform and explicit profile settings. We process this information for personalizing travel recommendations, improving service delivery, analyzing travel patterns, and enhancing user experience, which enables us to provide tailored travel suggestions, improve our services, and create more relevant content. The legal basis for this processing is our legitimate interests in providing personalized travel services and maintaining an effective user experience.
Your Rights:
Right to Access: You have the right to obtain confirmation about whether we process your personal data and request copies of this data. This includes the ability to receive information about data categories, processing purposes, and third-party disclosures. To exercise this right, you can submit a formal request through our dedicated privacy portal or contact our data protection team directly. We will respond within 30 days and may require government-issued identification, proof of address, and account verification to confirm your identity.
Right to Rectification: You have the right to have inaccurate personal data corrected and incomplete data completed. This includes the ability to update profile information, correct booking details, and modify account preferences. To exercise this right, you can either use our account settings interface or submit a formal correction request. We will process your request within 15 days and may require account verification, supporting documentation, and specific details about the information to be corrected.
Right to Erasure: You have the right to request the deletion of your personal data when it is no longer necessary for the purposes for which it was collected. This includes the ability to delete your account, remove specific data entries, and withdraw processing consent. To exercise this right, you can submit an erasure request through our privacy center or contact our support team. We will respond within 30 days and may require password confirmation, identity verification, and specific data identification.
Right to Restrict Processing: You have the right to limit how we use your personal data while we verify its accuracy or our legitimate interests. This includes the ability to pause marketing communications, limit data processing, and temporarily suspend profile visibility. To exercise this right, you can adjust your privacy settings or submit a formal restriction request. We will respond within 15 days and may require account authentication, specific processing details, and restriction period specification.
Right to Data Portability: You have the right to receive your personal data in a structured, commonly used format and transmit it to another service provider. This includes the ability to export travel history, download profile data, and transfer booking information. To exercise this right, you can use our data export tool or submit a portability request through our privacy portal. We will respond within 30 days and may require two-factor authentication, service provider details, and data format specification.Data Processing and Security
At AOSTTravel.com, we carefully handle various types of personal data to provide you with exceptional travel services while maintaining the highest standards of data protection and security.
Data Types and Processing
We process Service Data which includes travel preferences, booking details, itinerary selections, and accommodation requirements. This processing involves automated booking systems and manual review procedures, enabling us to coordinate travel arrangements and personalize your experience. For example, in the context of travel, this includes flight preferences, dietary requirements, and special assistance needs. The legal basis for this processing is contract performance and legitimate interests, specifically to fulfill your travel arrangements and enhance your user experience.
We process Technical Data which includes device information, IP addresses, browser types, and website interaction patterns. This processing involves automated logging systems and analytics tools, enabling us to optimize website performance and ensure security. For example, in the context of travel, this includes session tracking for saved itineraries and cross-device booking continuity. The legal basis for this processing is legitimate interests and consent, specifically to maintain service functionality and improve user experience.
We process Communication Data which includes email correspondence, chat logs, feedback forms, and customer service interactions. This processing involves customer relationship management systems and communication platforms, enabling us to provide support and assistance. For example, in the context of travel, this includes travel inquiry responses and booking confirmation communications. The legal basis for this processing is contract performance and legitimate interests, specifically to maintain effective communication channels with our users.
We process Transaction Data which includes payment details, booking records, purchase history, and refund information. This processing involves secure payment gateways and booking management systems, enabling us to process travel bookings and manage financial transactions. For example, in the context of travel, this includes flight purchases and accommodation payments. The legal basis for this processing is contract performance and legal obligations, specifically to complete financial transactions and maintain required records.
We process Preference Data which includes saved destinations, favorite hotels, travel preferences, and notification settings. This processing involves preference management systems and personalization tools, enabling us to customize your experience and provide relevant recommendations. For example, in the context of travel, this includes preferred airline selections and destination interests. The legal basis for this processing is consent and legitimate interests, specifically to enhance user experience and provide personalized services.
Security Measures
Our comprehensive encryption protocols ensure end-to-end protection of your data, incorporating industry-standard algorithms and regular security updates to maintain data integrity. This includes regular security assessments and penetration testing by qualified professionals.
We implement multi-layered security infrastructure, including advanced firewalls and intrusion detection systems that continuously monitor for and prevent unauthorized access attempts. This infrastructure undergoes regular updates and enhancements.
Access to personal data is strictly controlled through role-based permissions, multi-factor authentication, and detailed access logs. We maintain comprehensive audit trails of all data access and modifications.
Our continuous monitoring systems provide real-time threat detection and automated response protocols, ensuring immediate action against potential security threats.
We maintain comprehensive backup procedures with encrypted offsite storage and regular recovery testing, ensuring data availability and integrity.
All staff undergo regular security awareness training and must comply with detailed data protection protocols, including specific training for handling sensitive travel-related data.
International Transfers
We may transfer your personal data to countries outside your jurisdiction. These transfers are protected by appropriate safeguards, including Standard Contractual Clauses, Binding Corporate Rules, and certified compliance frameworks. Each international transfer is conducted under strict protocols that ensure:
– Adequate data protection standards
– Compliant processing procedures
– Enforceable data subject rights
– Effective legal remedies
International transfers are protected by EU-US Privacy Shield Framework, GDPR requirements, and ISO 27001 standards, ensuring compliance with international data protection regulations. We implement additional measures including:
– Regular compliance audits
– Data protection impact assessments
– Documented transfer mechanisms
– Continuous monitoring procedures
Regarding international transfers, you maintain specific rights including:
– Right to information about transfers
– Right to object to transfers
– Right to withdraw consent
– Right to data protection guarantees
Data Retention
We maintain specific retention periods for different data categories:
Account Information: Retained for the duration of active account plus 2 years for legal and service continuity purposes
Usage Data: Retained for 12 months to analyze usage patterns and improve services
Transaction Records: Retained for 7 years to comply with financial regulations and tax requirements
Communication History: Retained for 3 years to maintain service continuity and handle disputes
Technical Logs: Retained for 6 months for security and performance monitoring
These retention periods are determined by:
– Legal requirements
– Business purposes
– Technical necessities
– User preferences
Special circumstances affecting retention:
– Legal obligations
– Dispute resolution
– Security investigationsCookie Policy for AOSTTravel.com
Essential cookies serve fundamental functions for our travel platform’s core operations. These cookies process authentication data, session information, and security tokens to enable basic website functionality. For example, in our travel context, these cookies maintain your logged-in status while browsing different vacation packages and secure your booking sessions.
Essential cookies manage:
– User authentication for secure account access
– Security measures to protect booking information
– Basic site operations for seamless navigation
– Session management during trip planning
– Technical stability throughout the booking process
Functional cookies enhance your travel planning experience by remembering your preferences. These cookies process preference data to customize your interaction with our platform. For example, they remember your preferred currency, language choice, and favorite destinations for a more personalized booking experience.
Functional cookies enable:
– Language preferences for international travelers
– Region-specific travel content and deals
– User interface customization for easier navigation
– Feature optimization for booking tools
– Personalized settings for trip planning
Analytics cookies help us understand how travelers use our platform. They collect anonymous information about your interactions with our site to improve our services. For example, these cookies track which destinations are most popular and how users navigate through our booking process.
Analytics cookies monitor:
– Page interactions with travel content
– Navigation patterns through booking flows
– Feature usage of travel planning tools
– Session duration during trip research
– User preferences for destinations and services
Performance cookies assess and optimize your experience on AOSTTravel.com by processing technical performance data. They help us ensure fast loading times for flight searches and smooth booking processes.
Performance cookies focus on:
– Monitoring site speed during peak booking periods
– Identifying technical issues in the reservation system
– Optimizing content delivery for travel media
– Analyzing user experience during bookings
– Tracking system performance for multiple users
Cookie Management
You can control your cookie preferences through:
– Browser settings for cookie permissions
– Cookie consent tools on our platform
– Privacy preferences in your account
– Account settings for personalization
GDPR Compliance
For EU residents, we ensure:
– Explicit consent mechanisms before setting non-essential cookies
– Data minimization in travel-related data collection
– Purpose limitation for collected information
– Storage limitations on booking data
– Processing transparency for all user data
CCPA Compliance
California residents have additional rights regarding their travel data:
– Right to know about personal information collected during bookings
– Right to delete personal travel history and preferences
– Right to opt-out of data sales to travel partners
– Right to non-discrimination in service quality
– Right to access collected travel information
COPPA Compliance
Regarding users under 13:
– Age verification requirements for account creation
– Parental consent procedures for youth bookings
– Limited data collection from minor travelers
– Special protection measures for family bookings
– Parental access rights to minor’s travel data
Updates and Changes
Our privacy commitments include:
– Regular review procedures of privacy practices
– User notifications of policy updates
– Consent renewal when policies change
– Clear change documentation
– Continuous compliance monitoring
Contact Information
For privacy-related inquiries:
– Primary Contact: [email protected]
– Response Time: Within 48 hours
– Verification Required: For data-related requests
– Available Support: Privacy concerns, data requests, rights exercise
This policy was created specifically for aosttravel.com and covers all associated services within the travel industry.