Privacy Policy
Introduction
PURE ONE Travel ("we", "our", "us") is the controller of personal data collected through pureonetravel.com (the "Website"). This Privacy Policy explains what personal data we collect, why, and your rights under the UK GDPR, the Data Protection Act 2018, and the EU GDPR.
1. Who we are
PURE ONE Travel is part of the PURE ONE Group Ltd, a UK-registered travel company and Protected Trust Services member (No. 5588). If you have questions about this policy or wish to exercise your rights, contact:
- Email: customer.relations@pureonetravel.com
2. Personal data we collect
a. Information you give us
- Contact details — name, email address, phone number, postal address.
- Booking and enquiry details — destinations, dates, party composition, dietary or accessibility needs, and other information you share when contacting us or completing a form.
- Payment information — processed by our payment providers; we do not store full card details on our servers.
- Correspondence — records of your communications with us.
b. Information we collect automatically
- Technical data — IP address, browser type, device, operating system, referrer, and pages viewed.
- Analytics data — collected only if you consent to analytics cookies (see our Cookie Policy).
c. Information from third parties
- Booking partners (for example, WeTravel), hosted-journey creators, and social platforms may share information you have chosen to submit through them.
3. Legal bases for processing
Under UK GDPR / EU GDPR, we rely on one or more of the following legal bases:
| Purpose | Legal basis | | --- | --- | | Responding to enquiries and providing quotes | Contract / legitimate interests | | Managing and delivering bookings | Contract | | Sending our newsletter | Consent (you can withdraw at any time) | | Setting analytics cookies | Consent | | Fulfilling legal, tax, and regulatory obligations | Legal obligation | | Protecting the Website against fraud and abuse | Legitimate interests |
4. How we use your data
We use personal data to:
- Respond to enquiries and prepare tailor-made itineraries.
- Administer and fulfil your booking, including passing necessary details to travel suppliers.
- Send you our newsletter (only if you subscribed).
- Improve the Website and our services.
- Meet our legal and regulatory obligations, including those linked to travel trust protection.
We do not sell your personal data.
5. Who we share data with
We share personal data only where necessary, with:
- Travel suppliers and partners — airlines, hotels, transfer providers, hosted-journey creators — to deliver your booking.
- Payment providers — to process payments securely.
- Trust protection scheme — Protected Trust Services (Member 5588) as required by UK travel regulation.
- Service providers — email, analytics (Google Analytics — only with your consent), form processors (e.g. FormSubmit, Brevo), hosting, and IT support, acting as our processors under written agreements.
- Authorities — where required by law.
6. International transfers
Some providers process data outside the UK/EEA (for example, Google Analytics in the US). Where this happens, we rely on UK/EU adequacy decisions or Standard Contractual Clauses (SCCs) with additional safeguards where required.
7. How long we keep data
- Enquiry data: up to 24 months from last contact, then deleted or anonymised.
- Booking data: for the duration of the booking and for up to 7 years after, to meet legal and accounting obligations.
- Newsletter data: until you unsubscribe.
- Website analytics: up to 14 months (GA4 default).
8. Your rights
Under UK GDPR / EU GDPR you have the right to:
- Access your personal data.
- Rectify inaccurate data.
- Erase data ("right to be forgotten"), subject to legal retention obligations.
- Restrict or object to processing.
- Data portability — receive your data in a portable format.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with a supervisory authority. In the UK this is the Information Commissioner's Office (ICO). In the EU, you may contact your local data protection authority.
To exercise any of these rights, email customer.relations@pureonetravel.com. We will respond within one month.
9. Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you.
10. Security
We use industry-standard technical and organisational measures — including HTTPS/TLS, access controls, and vetted processors — to protect personal data. No online service is completely secure; if you believe your data may have been compromised, contact us immediately.
11. Children
The Website and our services are intended for adults. We do not knowingly collect personal data from children under 16.
12. Changes to this policy
We may update this policy from time to time. The "last updated" date below shows when it was last revised. Material changes will be highlighted on the Website.
_Last updated: 23 July 2026._