GDPR Privacy Policy – Startour
At Startour, we are committed to protecting your personal data and respecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
Data Controller
Startour acts as the data controller for the personal data collected through our website and booking systems.
Personal Data We Collect
We collect and process only the personal data necessary to provide our services, including:
Types of Personal Data
- Full name
- Email address
- Phone number
- Travel and booking details
Payment Information
Payment information (processed by secure third-party payment providers)
We do not store full payment card details on our servers.
Legal Basis
We process personal data based on one or more of the following legal grounds:
Legal Grounds
- Performance of a contract (to process bookings and deliver travel services)
- Legal obligations (accounting, tax, or regulatory requirements)
- Legitimate interests (customer support, fraud prevention, service improvement)
- Consent, where required (marketing communications)
How We Use Your Data
Your personal data is used strictly for:
Purposes of Processing
- Processing and confirming bookings
- Communicating essential travel information
- Providing customer support
- Meeting legal and regulatory requirements
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable laws and regulations.
Your Rights Under GDPR
Under GDPR, you have the right to:
Data Subject Rights
Requests can be made by contacting our customer support team.
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
Security Measures
- SSL/TLS encryption
- Restricted internal access controls
- Secure data storage systems
This policy may be updated periodically to reflect changes in legal requirements or operational practices. The latest version will always be available on our website.
GDPR Compliance Statement
We process personal data in accordance with the EU GDPR.
Payments are encrypted and handled by PCI-compliant providers.
We never store your card details.
