Privacy Policy

Last updated 26 August 2026

Wingback Travel International collects only what we need to plan and run your trip well, we keep it only as long as we have to, and we never sell it to anyone. This policy explains exactly what we hold, why we hold it, who else sees it, and what you can ask us to do about it.

1. Who is responsible for your data

The data controller is:

  • Wingback Travel International, a société par actions simplifiée unipersonnelle (SASU) with share capital of €70,000

  • Registered office: 445 Route des Milles, 13090 Aix-en-Provence, France

  • SIREN 994 968 386, registered with the Registre du Commerce et des Sociétés of Aix-en-Provence

  • Registered with Atout France as a travel operator under number IM013260008

  • Legal representative: Laura Leeker, President

For anything relating to your personal data, please write to privacy@wingbacktravel.com, or to the registered office above marked for the attention of Laura Leeker.

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of the GDPR. Laura Leeker is the person accountable for these matters.

2. What information we collect

We only ever collect information that has a clear purpose in arranging your trip or in running our business properly.

  • Identity and contact details — full name, date of birth, postal address, email address, telephone number(s). You give us these on the booking form or by email.

  • Booking and travel details — the tour booked, travel dates, room and bed preferences, the name of the person you are sharing with, your final itinerary, and any special requests. These come from you and from our suppliers.

  • Payment information — amounts, dates, payment method, invoices and receipts, bank transfer references. These come from you, your bank, and our payment provider.

  • Health, dietary and accessibility information — allergies, medications, dietary requirements, reduced mobility, and any medical condition you tell us may affect your participation. You give us these on the booking form or by email. See section 4.

  • Identity documents — passport details, and where a hotel or supplier requires it, a copy of the passport photo page. You give us these. See section 5.

  • Emergency contact — name, relationship to you, and telephone number of the person we should call in an emergency. You give us these.

  • Correspondence — emails, text messages, and notes of telephone calls between you and us about your trip.

  • Marketing data — the details you give us when you ask about a tour or join our mailing list; and whether you opened one of our emails or clicked a link in it, recorded by a small tracking pixel. These come from you and our email provider. See section 10.

  • Website data — IP address, browser and device type, pages viewed, where you arrived from, and the cookie choices you make. These come from your browser through the trackers listed in section 9, and only where you have agreed to them.

Where a field on our booking form is required, we say so. If you choose not to give us required information, we may not be able to confirm your booking.

One note on emergency contacts. Those details come from you, not from the person named, so that person may not know we hold them. Please tell them you have given us their name and number, and make sure they are content for you to do so. If you are that person and you would like to know what we hold or ask us to delete it, write to privacy@wingbacktravel.com — we hold nothing beyond a name, a relationship to the traveler and a telephone number, and we delete it one year after the tour ends.

3. Why we use your information, and on what legal basis

Under the GDPR we must have a lawful basis for everything we do with your data. Here is ours, purpose by purpose.

  • Answering your inquiry — sending you a proposal, an itinerary and the pre-contractual information form required by article R.211-4 of France's Tourism Code, so you can decide whether to book. Legal basis: steps taken at your request before entering a contract (Art. 6(1)(b) GDPR), and our legal obligation (Art. 6(1)(c)).

  • Confirming and administering your booking — taking payment, booking hotels, guides, drivers and restaurants, and sending you pre-departure information, in order to perform our contract with you. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

  • Adapting the trip to your dietary, medical or accessibility needs — so you can travel safely and comfortably. Legal basis: your explicit consent (Art. 9(2)(a) GDPR). See section 4.

  • Contacting your emergency contact — if something happens to you during the trip, to protect your vital interests or those of another traveler. Legal basis: vital interests (Art. 6(1)(d) and Art. 9(2)(c) GDPR).

  • Keeping our accounts — issuing invoices and meeting our obligations to Atout France, APST and the tax authorities, because the law requires it. Legal basis: legal obligation (Art. 6(1)(c) GDPR).

  • Handling complaints — and establishing, exercising or defending legal claims, to resolve problems fairly and protect our position. Legal basis: our legitimate interests (Art. 6(1)(f) GDPR).

  • Sending our newsletter and news of future tours — to stay in touch with people who want to hear from us. Legal basis: your consent (Art. 6(1)(a) GDPR), or our legitimate interest in writing to past travelers about similar tours (Art. 6(1)(f)).

  • Collecting your passport details and passing them to a hotel or supplier that requires them — so the supplier can register you as a guest and we can deliver the trip you booked. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). The legal duty to register guests is the supplier's, not ours — our own basis is our contract with you. See section 5.

  • Measuring how our website is used — to see which tours people look at and make the site better. Legal basis: your consent (Art. 6(1)(a) GDPR and art. 82 of the French Data Protection Act). See section 9.

  • Measuring how our advertising performs — to know whether an advertisement led to an inquiry, and spend our marketing budget sensibly. Legal basis: your consent (Art. 6(1)(a) GDPR and art. 82 of the French Data Protection Act). See section 9.

  • Recording whether you open our emails and whether you click a link in them — to understand which of our travel letters people find worth reading. Legal basis: your consent (Art. 6(1)(a) GDPR and art. 82 of the French Data Protection Act). See section 10.

  • Keeping our systems secure and preventing fraud — to protect you and us. Legal basis: our legitimate interests (Art. 6(1)(f) GDPR).

4. Health, dietary and accessibility information

Information about your health — allergies, medications, a medical condition, reduced mobility — is treated as a special category of data under Article 9 of the GDPR and is given extra protection.

We ask for it for one reason only: our tours involve walking, stairs, uneven ground and historic hotels, and we cannot look after you properly if we do not know what you need. We use it to brief restaurants about allergies, to choose accessible routes and rooms, and to know what to tell a doctor in an emergency.

We rely on your explicit consent, which you give by completing the relevant section of the booking form. You can withdraw that consent at any time by writing to privacy@wingbacktravel.com. If you do so before the trip, please understand that we may no longer be able to make the arrangements you need, and in some cases may not be able to confirm your participation.

We pass on to a hotel, restaurant, guide or driver only the specific detail they need to act on — for example, that a traveler must avoid shellfish — and never your full medical picture.

We delete health, dietary and accessibility information within 12 months of the end of your tour, unless a complaint or claim is open, in which case we keep it until the matter is closed.

5. Passport and identity documents

Hotels in France, Italy, Spain and most other destinations are legally required to record the identity of every guest, and some suppliers require passport details in advance. We therefore ask for your full name as it appears on your passport and, where a supplier requires it, your passport number, expiry date, or a copy of the photo page.

We collect no more than the supplier actually requires, we transmit it by the most secure means available to us, and we delete it — including any copy — within one year of the end of your tour. We do not keep passport copies on file between trips.

6. Who we share your information with

We share your information only where it is necessary, and only to the extent necessary. We never sell it, rent it, or trade it, and we do not share it for anyone else's marketing.

  • Travel suppliers: the hotels, guides, drivers, restaurants, museums, private estates and local ground handlers included in your itinerary. Where a supplier decides for itself why and how it uses what we send — a hotel registering you as a guest under its own local law, for example — it acts as an independent controller. Where a supplier only acts on our instructions, it acts as our processor. Which of the two applies depends on the actual relationship, not on what a contract happens to call it.

  • Our payment provider, Stripe Payments Europe Limited (Ireland), which processes card payments. We never see or store your full card number — it goes directly to Stripe.

  • Our bank, for bank transfers.

  • Our analytics and advertising provider, but only where you have agreed to the trackers described in section 9: Google Ireland Limited, for Google Analytics and Google Ads.

  • Our website and email providers: Squarespace Ireland Limited (website, contact forms and mailing list) and Google Ireland Limited (email, calendar and document storage through Google Workspace).

  • Our email marketing provider, Squarespace, which sends our newsletter and records opens and clicks.

  • Our electronic signature provider, SignWell (Docsketch, LLC, Portland, Oregon, United States), through which we send you the booking form and the tour contract to complete and sign. Everything you enter on that form passes through and is stored on their systems, including the health, dietary and access information, your emergency contact details, and your name and date of birth as they appear on your passport.

  • Our insurer and financial guarantor: Hiscox Assurances (professional liability, policy HSXIN320084058A) and the Association Professionnelle de Solidarité du Tourisme (APST), 87–89 rue La Boétie, 75008 Paris, which guarantees the funds you pay us.

  • Our professional advisers: our chartered accountant, and where needed our lawyers, all bound by professional secrecy.

  • Public authorities: Atout France, the French tax authorities, and any court or authority entitled to require the information.

  • A mediator: if you refer a dispute to the Médiateur du Tourisme et du Voyage, we will provide the file relating to your complaint.

7. Transfers outside the European Union

Your data is stored within the European Union or the European Economic Area wherever we can arrange it. Three situations take it further afield.

The first is your trip itself. If your itinerary includes a country outside the EEA, we necessarily send the hotels and suppliers there whatever they need to receive you. This transfer is necessary for the performance of our contract with you and is permitted by Article 49(1)(b) of the GDPR.

The second is our own suppliers. Some of them, including Google and Squarespace, are part of groups with operations in the United States. Where data reaches the United States, we rely on the European Commission's adequacy decision of 10 July 2023 for organizations certified under the EU–US Data Privacy Framework, and, where a supplier is not certified, on the Standard Contractual Clauses adopted by the European Commission on 4 June 2021, together with any additional safeguards the circumstances call for.

The third is our electronic signature provider. SignWell is a United States company and stores completed documents on Amazon Web Services infrastructure in the United States. That means your booking form, including the health information and emergency contact details it carries, is held there rather than in Europe.

That transfer is covered by a data processing agreement we signed with SignWell on 26 August 2026, which incorporates in full the Standard Contractual Clauses adopted by the European Commission on 4 June 2021, on the controller-to-processor module. Under that agreement the CNIL is the competent supervisory authority, SignWell must tell us before it adds any new sub-processor, and it must delete or return the documents when we ask. Documents are encrypted in transit and at rest.

You may ask us for a copy of the safeguards that apply to a particular transfer by writing to privacy@wingbacktravel.com.

8. How long we keep your information

  • Inquiries that do not lead to a booking — three years from your last contact with us.

  • Booking file and correspondence — for the duration of your trip and five years afterwards, being the limitation period under article L.110-4 of the French Commercial Code.

  • Invoices and accounting records — ten years from the end of the financial year, as required by article L.123-22 of the French Commercial Code.

  • Health, dietary and accessibility information — one year after the end of your tour.

  • Passport details and copies — one year after the end of your tour.

  • Emergency contact details — one year after the end of your tour.

  • Mailing list — until you unsubscribe. We then keep a minimal record of your unsubscribe so that we do not write to you again.

  • Proof of your consent to cookies — six months, in line with CNIL guidance. Cookies themselves last no more than thirteen months, and the data they generate no more than twenty-five months.

  • Website and security logs — twelve months.

Where a complaint, claim or investigation is open, we keep the file until it is finally resolved and any appeal period has expired.

9. Cookies and the trackers on our website

Our website, www.wingbacktravel.com, is hosted by Squarespace. Like most websites it uses cookies and similar technologies. A few of them are strictly necessary to make the site work and to protect our forms, and those are placed without asking, as article 82 of the French Data Protection Act permits. Everything else — measuring how the site is used, and measuring how our advertising performs — is placed only if you have agreed to it.

Here is everything currently in use.

  • Squarespace Ireland Limited — session and security cookies. They keep the site working while you move around it, protect our forms from abuse, and remember the cookie choices you make. Category: strictly necessary. Consent: not required. Duration: from the end of your visit, up to six months for the record of your choices. Outside the EU: Squarespace has operations in the United States — see section 7.

  • Google Ireland Limited — Google Analytics 4 (measurement ID G-LRVCVCVSQP). Counts visits, pages viewed and where visitors arrived from, so we can see which tours people are looking at. Category: audience measurement. Consent: required. Duration: up to 13 months, and up to 25 months for data derived from them. Outside the EU: yes — see section 7.

  • Google Ireland Limited — Google Ads conversion measurement. Tells us whether someone who clicked one of our advertisements went on to inquire about a tour. Category: advertising. Consent: required. Duration: up to 13 months. Outside the EU: yes — see section 7.

  • Google Ireland Limited — reCAPTCHA Enterprise. Tells a real visitor from an automated program when a form is submitted, so our contact form is not abused. Category: strictly necessary to protect our forms. Consent: not required. Duration: about six months. Outside the EU: yes — see section 7.

How to accept, refuse, or change your mind. When you first visit, a banner asks whether you accept the trackers that need consent. You can accept them all, refuse them all, or choose category by category, and refusing takes no more effort than accepting. Nothing in the audience measurement or advertising entries above is placed before you have agreed to it.

You can change or withdraw your choice at any time through the cookie settings link at the foot of every page, and withdrawing is as easy as agreeing was. You can also block or delete cookies through your browser's own settings. Refusing has no effect on your ability to use the site or to book with us. If you refuse, we keep a record of that refusal for six months so that we do not put the question to you again on every visit.

This policy tells you what the trackers are. It is not itself how we obtain your consent — that is what the banner is for.

10. Marketing emails, and what we can see about them

We write occasionally about tours we are planning and places we have found. You will only receive these if you have asked to hear from us, or if you have traveled with us before and we are writing about something similar. Every email carries an unsubscribe link, and you can also simply reply and ask us to stop. We act on the request immediately.

Our emails contain a small invisible image, usually called a tracking pixel, which records whether you opened the message and whether you clicked a link in it. We use that to understand which of our travel letters are worth writing. This is a separate question from whether you want the emails at all, and we treat it separately: we ask for your agreement to it when you join our mailing list, and you can say yes to the letters and no to the tracking.

You can withdraw that agreement at any time by writing to privacy@wingbacktravel.com, and unsubscribing stops it as well. Withdrawing is as easy as giving it, and takes effect for every email we send you afterwards. We follow the French data protection authority's recommendation of 12 March 2026 on tracking pixels in email.

11. How we keep your information safe

Access to traveler files is limited to our employees and officers. Our accounts are protected by strong, unique passwords and two-factor authentication. Data is encrypted in transit and at rest. The booking form and the tour contract are completed through SignWell, which encrypts documents in transit and at rest and holds a SOC 2 Type II report. Card details never reach us; they go straight to our payment provider, which is certified to the PCI-DSS standard. Documents containing passport or health information are deleted on the schedule set out in section 8 rather than being kept indefinitely.

If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the CNIL within 72 hours as Article 33 of the GDPR requires, and we will tell you directly where the risk is high.

12. Your rights

Under the GDPR and the French Data Protection Act of 6 January 1978, you have the following rights over your data:

  • Access — to be told whether we hold data about you and to receive a copy of it.

  • Rectification — to have inaccurate data corrected and incomplete data completed.

  • Erasure — to have your data deleted, where one of the grounds in Article 17 applies. Note that we cannot delete data we are legally required to keep, such as invoices.

  • Restriction — to have us pause our use of your data while a dispute about it is resolved.

  • Portability — to receive the data you gave us in a structured, machine-readable format, and to have it sent to another provider.

  • Objection — to object to processing based on our legitimate interests, and at any time and without reason to processing for direct marketing.

  • Withdrawal of consent — to withdraw consent at any time, without affecting anything we did lawfully beforehand.

  • Post-mortem directives — to give instructions about what should happen to your data after your death, in accordance with article 85 of the French Data Protection Act.

To exercise any of these, write to privacy@wingbacktravel.com. We reply within one month, which we may extend by two further months if the request is complex — we will tell you if that happens. We may ask for proof of identity if we have genuine doubt about who is writing to us, but not otherwise.

13. Automated decisions

We do not make any decision about you by automated means alone, and we do not profile you. Every decision about a booking is made by a person.

14. Children

Our tours are open only to travelers aged 18 and over, and our website is not directed at children. We do not knowingly collect data about anyone under 18. Where a parent or guardian provides emergency contact details relating to a minor, we hold them only for the purpose described in section 2.

15. Changes to this policy

We will update this policy when what we do with data changes. The date at the top always shows the current version. If a change materially affects you, we will tell you by email rather than leaving you to find it.

16. Complaints

If you are unhappy with how we have handled your data, please tell us first — we would much rather put it right ourselves.

You also have the right to complain at any time to the French supervisory authority:

Commission Nationale de l'Informatique et des Libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr