Privacy Policy
Last updated 24 August 2026
Wingback Travel International collects only what we need to plan and run your trip well, we keep it only as long as we have to, and we never sell it to anyone. This policy explains exactly what we hold, why we hold it, who else sees it, and what you can ask us to do about it.
1. Who is responsible for your data
The data controller is:
Wingback Travel International, a société par actions simplifiée unipersonnelle (SASU) with share capital of €70,000
Registered office: 445 Route des Milles, 13090 Aix-en-Provence, France
SIREN 994 968 386, registered with the Registre du Commerce et des Sociétés of Aix-en-Provence
Registered with Atout France as a travel operator under number IM013260008
Legal representative: Laura Leeker, President
For anything relating to your personal data, please write to privacy@wingbacktravel.com, or to the registered office above marked for the attention of Laura Leeker.
We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of the GDPR. Laura Leeker is the person accountable for these matters.
2. What information we collect
We only ever collect information that has a clear purpose in arranging your trip or in running our business properly.
Identity and contact details — full name, date of birth, postal address, email address, telephone number(s). You give us these on the booking form or by email.
Booking and travel details — the tour booked, travel dates, room and bed preferences, the name of the person you are sharing with, your final itinerary, and any special requests. These come from you and from our suppliers.
Payment information — amounts, dates, payment method, invoices and receipts, bank transfer references. These come from you, your bank, and our payment provider.
Health, dietary and accessibility information — allergies, medications, dietary requirements, reduced mobility, and any medical condition you tell us may affect your participation. You give us these on the booking form or by email. See section 4.
Identity documents — passport details, and where a hotel or supplier requires it, a copy of the passport photo page. You give us these. See section 5.
Emergency contact — name, relationship to you, and telephone number of the person we should call in an emergency. You give us these.
Correspondence — emails, text messages, and notes of telephone calls between you and us about your trip.
Marketing data — the details you give us when you ask about a tour or join our mailing list, and whether you have opened or clicked our emails. These come from you and our email provider.
Website data — IP address, browser and device type, pages viewed, and the cookie choices you make. These come from your browser, subject to your consent. See section 9.
Where a field on our booking form is required, we say so. If you choose not to give us required information, we may not be able to confirm your booking.
3. Why we use your information, and on what legal basis
Under the GDPR we must have a lawful basis for everything we do with your data. Here is ours, purpose by purpose.
Answering your inquiry — sending you a proposal, an itinerary and the pre-contractual information form required by article R.211-4 of France's Tourism Code, so you can decide whether to book. Legal basis: steps taken at your request before entering a contract (Art. 6(1)(b) GDPR), and our legal obligation (Art. 6(1)(c)).
Confirming and administering your booking — taking payment, booking hotels, guides, drivers and restaurants, and sending you pre-departure information, in order to perform our contract with you. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Adapting the trip to your dietary, medical or accessibility needs — so you can travel safely and comfortably. Legal basis: your explicit consent (Art. 9(2)(a) GDPR). See section 4.
Contacting your emergency contact — if something happens to you during the trip, to protect your vital interests or those of another traveler. Legal basis: vital interests (Art. 6(1)(d) and Art. 9(2)(c) GDPR).
Keeping our accounts — issuing invoices and meeting our obligations to Atout France, APST and the tax authorities, because the law requires it. Legal basis: legal obligation (Art. 6(1)(c) GDPR).
Handling complaints — and establishing, exercising or defending legal claims, to resolve problems fairly and protect our position. Legal basis: our legitimate interests (Art. 6(1)(f) GDPR).
Sending our newsletter and news of future tours — to stay in touch with people who want to hear from us. Legal basis: your consent (Art. 6(1)(a) GDPR), or our legitimate interest in writing to past travelers about similar tours (Art. 6(1)(f)).
Measuring how our website is used and how our advertising performs — to improve the site and spend our marketing budget sensibly. Legal basis: your consent (Art. 6(1)(a) GDPR and art. 82 of the French Data Protection Act).
Keeping our systems secure and preventing fraud — to protect you and us. Legal basis: our legitimate interests (Art. 6(1)(f) GDPR).
4. Health, dietary and accessibility information
Information about your health — allergies, medications, a medical condition, reduced mobility — is treated as a special category of data under Article 9 of the GDPR and is given extra protection.
We ask for it for one reason only: our tours involve walking, stairs, uneven ground and historic hotels, and we cannot look after you properly if we do not know what you need. We use it to brief restaurants about allergies, to choose accessible routes and rooms, and to know what to tell a doctor in an emergency.
We rely on your explicit consent, which you give by completing the relevant section of the booking form. You can withdraw that consent at any time by writing to privacy@wingbacktravel.com. If you do so before the trip, please understand that we may no longer be able to make the arrangements you need, and in some cases may not be able to confirm your participation.
We pass on to a hotel, restaurant, guide or driver only the specific detail they need to act on — for example, that a traveler must avoid shellfish — and never your full medical picture.
We delete health, dietary and accessibility information within 12 months of the end of your tour, unless a complaint or claim is open, in which case we keep it until the matter is closed.
5. Passport and identity documents
Hotels in France, Italy, Spain and most other destinations are legally required to record the identity of every guest, and some suppliers require passport details in advance. We therefore ask for your full name as it appears on your passport and, where a supplier requires it, your passport number, expiry date, or a copy of the photo page.
We collect no more than the supplier actually requires, we transmit it by the most secure means available to us, and we delete it — including any copy — within one year of the end of your tour. We do not keep passport copies on file between trips.
6. Who we share your information with
We share your information only where it is necessary, and only to the extent necessary. We never sell it, rent it, or trade it, and we do not share it for anyone else's marketing.
Travel suppliers: the hotels, guides, drivers, restaurants, museums, private estates and local ground handlers included in your itinerary. Each acts as an independent controller of the data it receives and is bound by its own local law.
Our payment provider, Stripe Payments Europe Limited (Ireland), which processes card payments. We never see or store your full card number — it goes directly to Stripe.
Our bank, for bank transfers.
Our website and email providers: Squarespace Ireland Limited (website, contact forms and mailing list) and Google Ireland Limited (email, calendar and document storage through Google Workspace).
Our email marketing provider, Squarespace, which sends our newsletter and records opens and clicks.
Our insurer and financial guarantor: Hiscox Assurances (professional liability, policy HSXIN320084058A) and the Association Professionnelle de Solidarité du Tourisme (APST), 87–89 rue La Boétie, 75008 Paris, which guarantees the funds you pay us.
Our professional advisers: our chartered accountant, and where needed our lawyers, all bound by professional secrecy.
Public authorities: Atout France, the French tax authorities, and any court or authority entitled to require the information.
A mediator: if you refer a dispute to the Médiateur du Tourisme et du Voyage, we will provide the file relating to your complaint.
7. Transfers outside the European Union
Your data is stored within the European Union or the European Economic Area wherever we can arrange it. Two situations take it further afield.
The first is your trip itself. If your itinerary includes a country outside the EEA, we necessarily send the hotels and suppliers there whatever they need to receive you. This transfer is necessary for the performance of our contract with you and is permitted by Article 49(1)(b) of the GDPR.
The second is our own suppliers. Some of them, including Google and Squarespace, are part of groups with operations in the United States. Where data reaches the United States, we rely on the European Commission's adequacy decision of 10 July 2023 for organizations certified under the EU–US Data Privacy Framework, and, where a supplier is not certified, on the Standard Contractual Clauses adopted by the European Commission on 4 June 2021, together with any additional safeguards the circumstances call for.
You may ask us for a copy of the safeguards that apply to a particular transfer by writing to privacy@wingbacktravel.com.
8. How long we keep your information
Inquiries that do not lead to a booking — three years from your last contact with us.
Booking file and correspondence — for the duration of your trip and five years afterwards, being the limitation period under article L.110-4 of the French Commercial Code.
Invoices and accounting records — ten years from the end of the financial year, as required by article L.123-22 of the French Commercial Code.
Health, dietary and accessibility information — one year after the end of your tour.
Passport details and copies — one year after the end of your tour.
Emergency contact details — one year after the end of your tour.
Mailing list — until you unsubscribe. We then keep a minimal record of your unsubscribe so that we do not write to you again.
Proof of your consent to cookies — six months, in line with CNIL guidance. Cookies themselves last no more than thirteen months, and the data they generate no more than twenty-five months.
Website and security logs — twelve months.
Where a complaint, claim or investigation is open, we keep the file until it is finally resolved and any appeal period has expired.
9. Cookies and our website
Our website, www.wingbacktravel.com, is hosted by Squarespace. Some cookies are strictly necessary to make the site work — they keep your session going and remember your cookie choices — and these are placed without consent, as French law permits.
10. Marketing emails
We write occasionally about tours we are planning and places we have found. You will only receive these if you have asked to hear from us, or if you have traveled with us before and we are writing about something similar. Every email carries an unsubscribe link, and you can also simply reply and ask us to stop. We act on the request immediately.
11. How we keep your information safe
Access to traveler files is limited to our employees and officers. Our accounts are protected by strong, unique passwords and two-factor authentication. Data is encrypted in transit and at rest. Card details never reach us; they go straight to our payment provider, which is certified to the PCI-DSS standard. Documents containing passport or health information are deleted on the schedule set out in section 8 rather than being kept indefinitely.
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the CNIL within 72 hours as Article 33 of the GDPR requires, and we will tell you directly where the risk is high.
12. Your rights
Under the GDPR and the French Data Protection Act of 6 January 1978, you have the following rights over your data:
Access — to be told whether we hold data about you and to receive a copy of it.
Rectification — to have inaccurate data corrected and incomplete data completed.
Erasure — to have your data deleted, where one of the grounds in Article 17 applies. Note that we cannot delete data we are legally required to keep, such as invoices.
Restriction — to have us pause our use of your data while a dispute about it is resolved.
Portability — to receive the data you gave us in a structured, machine-readable format, and to have it sent to another provider.
Objection — to object to processing based on our legitimate interests, and at any time and without reason to processing for direct marketing.
Withdrawal of consent — to withdraw consent at any time, without affecting anything we did lawfully beforehand.
Post-mortem directives — to give instructions about what should happen to your data after your death, in accordance with article 85 of the French Data Protection Act.
To exercise any of these, write to privacy@wingbacktravel.com. We reply within one month, which we may extend by two further months if the request is complex — we will tell you if that happens. We may ask for proof of identity if we have genuine doubt about who is writing to us, but not otherwise.
13. Automated decisions
We do not make any decision about you by automated means alone, and we do not profile you. Every decision about a booking is made by a person.
14. Children
Our tours are open only to travelers aged 18 and over, and our website is not directed at children. We do not knowingly collect data about anyone under 18. Where a parent or guardian provides emergency contact details relating to a minor, we hold them only for the purpose described in section 2.
15. Changes to this policy
We will update this policy when what we do with data changes. The date at the top always shows the current version. If a change materially affects you, we will tell you by email rather than leaving you to find it.
16. Complaints
If you are unhappy with how we have handled your data, please tell us first — we would much rather put it right ourselves. You also have the right to complain at any time to the French supervisory authority:
Commission Nationale de l'Informatique et des Libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr