Privacy Policy

SimpelTravels Ltd.

A BVI Business Company

Last Updated: [Date]

1. Introduction

SimpelTravels Ltd. (“SimpelTravels”, “we”, “us”, or “our”), a BVI Business Company incorporated under the laws of the British Virgin Islands with its registered office at [Registered Address, BVI] (Company Number: [To be inserted]), recognises the importance of privacy and is committed to protecting your personal data.

This Privacy Policy describes how we collect, use, disclose, store, and protect information that we obtain about visitors to and users of our website at simpeltravels.com (the “Website”), our mobile application (the “Mobile App”), and the services available through our platform (collectively, the “Services”).

By accessing or using the Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with this Privacy Policy, you must not access or use the Services.

This Privacy Policy should be read in conjunction with our Terms and Conditions and our Cookie Policy, which are incorporated by reference.

Data Controller

SimpelTravels Ltd. is the Data Controller for personal data collected through our Services. For privacy-related inquiries, please contact us at privacy@simpeltravels.com.

Legal Basis for Processing (EU/UK Users)

If you are located in the European Economic Area (EEA) or the United Kingdom (UK), we process your personal data on the following legal bases:

  • Contract: Processing necessary for the performance of a contract with you (e.g., processing Bookings, delivering Services);
  • Consent: Where you have given your consent (e.g., marketing communications);
  • Legitimate Interest: Processing necessary for our legitimate interests, provided these do not override your fundamental rights (e.g., fraud prevention, platform security, analytics); and
  • Legal Obligation: Processing necessary to comply with legal or regulatory obligations (e.g., AML/CTF requirements, tax obligations).

2. Information We Collect

We collect personal information directly from you, from third parties, and automatically through your use of our Services. We may combine information automatically collected with other information we have collected about you. “Personal information” means any information that can be used to directly or indirectly identify you.

2.1 Information You Provide

  • Contact information: name, address, email address, telephone number, and other contact details;
  • Identity information: passport number, passport expiration date, date of birth, nationality, and government-issued identification details;
  • Billing and payment information: credit or debit card details, billing address, and payment preferences (note: cryptocurrency payment details are primarily processed by our third-party Payment Processors);
  • Booking information: details of Travel Products and Services you have enquired about or purchased, including traveller names, travel dates, destinations, and special requirements;
  • Account information: login credentials, profile preferences, and communication preferences;
  • Cryptocurrency wallet addresses: where you choose to provide these in connection with transactions or refunds;
  • Loyalty programme details: frequent flyer numbers and membership information;
  • Health information: only where voluntarily disclosed by you in connection with special travel requirements;
  • Customer service information: feedback, survey responses, and correspondence with our support team; and
  • Any additional information you provide through your use of our Services.

2.2 Information from Third Parties

We may receive personal information about you from:

  • Service Providers: airlines, hotels, activity operators, and car rental providers, for the performance and verification of your Bookings;
  • Payment Processors: our third-party cryptocurrency and fiat payment processors, who may provide us with transaction confirmation details, KYC verification status, and payment method information;
  • Analytics and advertising partners: information about your interactions with our ads and Services;
  • Social media platforms: where you choose to log in or interact with our Services through social media; and
  • Publicly available sources: including public blockchain data associated with cryptocurrency transactions.

2.3 Information Collected Automatically

When you access our Services, we automatically collect:

  • Device information: device ID, device type, operating system, browser type, screen resolution, and system configurations;
  • Usage information: pages visited, features used, time spent on pages, search queries, click data, and navigation patterns;
  • Network information: IP address, approximate geographic location, internet service provider, and connection type;
  • Referral information: the website that led you to our Services and the website you visit after leaving; and
  • Cookie and tracking data: as described in our Cookie Policy.

2.4 Blockchain Data

We may collect data from activity that is publicly visible on blockchains. This may include blockchain addresses and information regarding cryptocurrency transactions, which may then be associated with other data you have provided to us. You acknowledge that blockchain data is inherently public and immutable, and we have no ability to modify or delete data recorded on a blockchain.

3. How We Use Your Information

We use your information for the following purposes:

3.1 Providing Our Services

  • Processing and managing your Bookings for accommodation, flights, activities, car rentals, and travel packages;
  • Facilitating payments through our Payment Processors;
  • Delivering Booking Confirmations and travel-related communications;
  • Managing your account and responding to your enquiries;
  • Processing refunds, cancellations, and changes to Bookings; and
  • Administering our loyalty programme, referral programme, and SimpelTravels Token ecosystem.

3.2 Compliance and Security

  • Complying with anti-money laundering (AML) and counter-terrorist financing (CTF) requirements;
  • Conducting identity verification and fraud prevention;
  • Complying with applicable legal and regulatory obligations, including BVI law, GDPR, and sanctions screening;
  • Monitoring transactions for suspicious activity; and
  • Cooperating with law enforcement and regulatory authorities where required.

3.3 Marketing

Where you have given your consent, we may provide you with news, special offers, promotions, and information about products and services we think may interest you. You may withdraw your consent to marketing communications at any time (see Section 10 below).

3.4 Analytics and Improvement

  • Analysing how users access and use our Services to improve our platform;
  • Conducting research and developing new features;
  • Measuring the effectiveness of our marketing and advertising; and
  • Creating aggregated, anonymised, or de-identified data for analytical purposes.

3.5 Protecting Rights and Interests

To protect our rights, privacy, safety, and property, and that of our users and the public, and to enforce our Terms and Conditions.

4. How We Disclose Your Information

We may disclose your information to the following categories of recipients:

4.1 Service Providers

We share your information with airlines, hotels, activity providers, car rental operators, and other Service Providers as necessary to fulfil your Bookings.

4.2 Payment Processors

We share transaction-related information with our third-party Payment Processors to facilitate cryptocurrency and fiat payments, conversions, and refunds. Your interactions with Payment Processors are also governed by their respective terms of service and privacy policies.

4.3 Our Group of Companies and Employees

We may disclose your information to our employees, subsidiaries, and affiliated companies to perform duties necessary to provide you with our Services.

4.4 Technology and Infrastructure Partners

We share information with our hosting providers (including Render, with servers in Frankfurt, Germany and London, United Kingdom), analytics providers, and other technology partners who assist in operating our platform.

4.5 Legal and Regulatory Disclosures

We may disclose your information where we believe it is necessary to:

  • Comply with applicable laws, regulations, legal processes, or governmental requests;
  • Enforce our Terms and Conditions;
  • Investigate or prevent fraud, security issues, or other potentially illegal activities;
  • Protect the rights, property, or safety of SimpelTravels, our users, or the public; and
  • Respond to law enforcement requests and comply with court orders.

4.6 Business Transfers

We may disclose your information in connection with a merger, acquisition, sale of assets, bankruptcy proceeding, or similar business transfer.

4.7 No Sale of Personal Data

SimpelTravels does not sell your personal information to third parties.

5. International Data Transfers

As a BVI-incorporated company with servers in the European Union (Frankfurt, Germany) and the United Kingdom (London), your personal data may be transferred to, and processed in, countries outside your country of residence, including countries that may not provide the same level of data protection as your home country.

Where we transfer personal data outside the EEA or UK, we ensure appropriate safeguards are in place, including:

  • Transfers to countries recognised by the European Commission or UK authorities as providing an adequate level of protection;
  • Standard contractual clauses approved by the European Commission or UK authorities;
  • Other appropriate cross-border transfer mechanisms as required by applicable law.

All third-party service providers who process personal data on our behalf are required to implement appropriate technical and organisational measures to protect your data, pursuant to a data processing agreement.

6. Data Retention

We retain your personal information for the duration that your account is active or as needed to provide you with our Services, and for the requisite period thereafter in accordance with applicable law. Specific retention periods include:

  • Booking and transaction records: retained for a minimum of seven (7) years from the date of the transaction, or such longer period as required by applicable AML/CTF laws or tax regulations;
  • Account information: retained for the duration of your account and for a period of five (5) years following account deactivation or closure;
  • KYC and compliance records: retained in accordance with the requirements of our Payment Processors and applicable law;
  • Marketing preferences: retained until you withdraw your consent;
  • Technical and analytics data: retained for up to twenty-four (24) months from the date of collection.

Once the applicable retention period has expired, we will securely delete or anonymise your personal information. Where anonymisation is used, the resulting data will no longer be considered personal information.

7. Data Security

We implement a range of physical, administrative, and technical measures to protect your personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. Our security measures include, but are not limited to:

  • Secure Sockets Layer (SSL) / Transport Layer Security (TLS) encryption for data in transit;
  • Encryption of sensitive data at rest;
  • Pseudonymisation and tokenisation of personal data where appropriate;
  • Internal data access restrictions on a need-to-know basis;
  • Regular security assessments and penetration testing;
  • Multi-factor authentication for administrative access; and
  • Strict physical access controls to buildings and infrastructure.

Despite our efforts, no method of electronic transmission or storage is 100% secure. If you have an account, you are responsible for maintaining the confidentiality of your login credentials.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority without undue delay, and where feasible, within seventy-two (72) hours of becoming aware of the breach, in accordance with Article 33 of the GDPR (where applicable);
  • Where the breach is likely to result in a high risk to your rights and freedoms, notify you without undue delay, providing a clear description of the nature of the breach, the likely consequences, and the measures taken or proposed to be taken to address the breach and mitigate its effects, in accordance with Article 34 of the GDPR (where applicable);
  • Maintain an internal register of all data breaches, including the facts relating to the breach, its effects, and the remedial actions taken; and
  • Cooperate with any supervisory authority investigation and provide any information requested in connection with the breach.

Where we engage third-party service providers who process personal data on our behalf, we require them to notify us immediately upon becoming aware of any personal data breach affecting your information, so that we may fulfil our own notification obligations.

8. Cookies and Tracking Technologies

We and our service providers use cookies and other tracking mechanisms to track your use of our Services. Please refer to our separate Cookie Policy for detailed information about the types of cookies we use, their purposes, and how you can manage your cookie preferences.

In summary, we use cookies and similar technologies for:

  • Essential functionality: keeping you signed in, remembering your preferences;
  • Analytics: understanding how you navigate and interact with our Services;
  • Performance: monitoring and improving the operation of our platform; and
  • Advertising: serving you relevant advertisements (with your consent where required).

9. Third-Party Services

9.1 Third-Party Analytics

We use service providers, such as Google Analytics, to evaluate the use of our Services. These providers may use cookies and other tracking technologies. To opt out of Google Analytics, visit tools.google.com/dlpage/gaoptout.

9.2 Third-Party Payment Processors

To use our Services, you may opt to use payment options that utilise third-party Payment Processors, which may facilitate transactions involving Digital Assets or Cryptocurrencies and/or fiat currencies. SimpelTravels does not hold, store, or have custody of any user funds, Digital Assets, Cryptocurrencies, or fiat currency at any time. All payments are processed exclusively by independent third-party Payment Processors, which bear primary KYC, AML, and CTF responsibility for payment transactions. Your interactions with any third-party Payment Processor are governed by their applicable terms of service and privacy policy. Any personal data collected by Payment Processors for KYC purposes is processed under their own data controller obligations and privacy policies.

9.3 Interest-Based Advertising

We may use third-party advertising networks to serve advertisements on our Services and on third-party websites. You may opt out of interest-based advertising by visiting the relevant opt-out pages provided by the Digital Advertising Alliance, the Network Advertising Initiative, or equivalent bodies in your jurisdiction.

9.4 Social Plugins

Our Services may use social plugins provided by third parties (e.g., Google login, Apple login). If you interact with these plugins, information may be shared with the relevant third party.

10. Your Rights

Depending on your jurisdiction, you may have the following rights in relation to your personal data:

RightDescription
AccessRequest a copy of the personal data we hold about you.
RectificationRequest correction of any inaccurate or incomplete personal data.
ErasureRequest deletion of your personal data when it is no longer necessary for the purposes for which it was collected, subject to legal retention requirements.
RestrictionRequest that we restrict the processing of your personal data, under certain conditions.
PortabilityRequest transfer of your personal data to another organisation or directly to you, where technically feasible.
ObjectionObject to our processing of your personal data, under certain conditions.
Withdraw ConsentWhere processing is based on consent, withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing before its withdrawal.
No Automated Decision-MakingNot be subject to decisions based solely on automated processing, including profiling, that produce legal effects concerning you.

To exercise any of these rights, please contact us at privacy@simpeltravels.com. We will respond within one (1) month of receiving your request. In complex cases, we may extend this period by an additional two (2) months, with prior notice to you.

Blockchain Data Limitation

Please be aware that we cannot edit or delete any personal information that is stored on a blockchain, as we do not have custody or control over any blockchains. Information stored on the blockchain may include transaction data associated with your wallet address.

11. Marketing Communications

We will only send you marketing communications where you have given your consent. You may opt out of marketing communications at any time by:

  • Clicking the “Unsubscribe” link in any marketing email;
  • Adjusting your communication preferences in your account settings; or
  • Contacting us at privacy@simpeltravels.com.

Please note that even if you opt out of marketing communications, you will continue to receive transactional and service-related communications (such as Booking Confirmations and account notifications).

12. Children's Privacy

Our Services are not directed to children under the age of thirteen (13), and we do not knowingly collect personal information from children under 13 without parental consent. If we discover that we have collected the personal information of a child under 13 without appropriate consent, we will promptly delete such information. We encourage children of all ages to obtain their parent's or guardian's permission before sharing personal information online.

13. User-Generated Content

Our Services may allow users to post or share content, including reviews, photos, and other materials provided by our content partners. If you post information in a publicly accessible portion of our Services, it may be viewed by other users. Please exercise caution when disclosing personal information in public areas.

14. External Links

Our Services may contain links to third-party websites. We are not responsible for the information handling practices or content of these external websites. We encourage you to read the privacy policies of third-party websites before using them.

15. Do Not Track Signals

Some browsers transmit “Do Not Track” (DNT) signals. Our Services do not currently respond to DNT signals. However, you can manage your tracking preferences through your browser settings and our Cookie Policy.

16. Additional Disclosures for Specific Jurisdictions

16.1 European Economic Area and United Kingdom

If you are located in the EEA or UK, you have additional rights under the General Data Protection Regulation (GDPR) and UK GDPR, as described in Section 10. You also have the right to lodge a complaint with your local Data Protection Authority. If you are in the EU, you can find your Data Protection Authority at edpb.europa.eu. If you are in the UK, you can contact the Information Commissioner's Office at ico.org.uk.

16.2 BVI Residents

As a BVI-incorporated company, we comply with the data protection requirements applicable under BVI law, including the Data Protection Act, 2021 (as amended). BVI residents may exercise their rights under applicable local law by contacting us at privacy@simpeltravels.com.

16.3 Other Jurisdictions

If you are located in a jurisdiction with specific data protection laws (such as Brazil's LGPD, Australia's Privacy Act, or other applicable legislation), you may have additional rights. Please contact us for further information about your specific rights.

17. Contact Us

If you have any questions or concerns about this Privacy Policy, your personal data, or wish to exercise any of your rights, please contact us at:

SimpelTravels Ltd.

Data Protection Contact

Email: privacy@simpeltravels.com

Website: simpeltravels.com

[Registered Address, British Virgin Islands]

We will do our best to resolve your concern as quickly as possible. You also have the right to lodge a complaint with your local data protection authority.

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Updated versions will be posted on our Website and Mobile App. Where changes are material, we will notify registered users by email or through our Services. Your continued use of the Services after any changes constitutes acceptance of the updated Privacy Policy.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.