Privacy Policy

Learn how we collect, use, and protect your personal data as a traveller using Tourbox.

1. Who we are

Tourbox Systems Limited ("Tourbox", "we", "us", "our") is a company registered in England and Wales under company number 15613075. Our registered address is 125 Freshfield Road, Brighton, England, BN2 0BR.

We are registered with the Information Commissioner's Office (ICO) under registration number ZC103797.

For any question about your data, email privacy@tourbox.com.

2. Who this policy is for

This policy is for travellers: people who have booked a trip with a tour operator that uses Tourbox, and who see their trip through a link we host or by signing in to the Tourbox traveller app.

If you are a tour operator using Tourbox to run your business, this policy does not apply to you. See the Operator Privacy Policy instead.

3. Start here: your tour operator is in charge of your data

This is the most useful thing to know, so we have put it first.

Tourbox is the software your tour operator uses to plan and run your trip. We do not sell trips, and we have no relationship with you separate from theirs. Your operator decides what information to collect about you, why, and how long to keep it. We hold it for them and act on their instructions.

In data protection terms, for almost everything about your trip your tour operator is the data controller and Tourbox is their data processor.

What that means in practice:

  • To see, correct, or delete your information, ask your tour operator first. They can act on it directly. If they ask us to help, we will.
  • If you ask us instead, we cannot change your data without their instruction, but we will not ignore you. We will point you to the right contact and let your operator know you have been in touch.
  • The exception is the small amount of data we hold in our own right, described in section 5. For that, you can come to us directly.

4. What your operator may hold about you in Tourbox

The exact list depends on your operator and your trip. Not every operator collects everything below.

4.1 Who you are, and how to reach you

Your title, first name, last name and any preferred name, your date of birth, email address, phone number and postal address.

4.2 Passport and travel document details

Where your trip needs them: your name exactly as it appears on your passport, passport number, nationality, and the issue date, expiry date and issuing country. Your operator may also hold scans or photographs of documents you send them.

4.3 Dietary, accessibility and medical needs

Anything you tell your operator about dietary requirements, accessibility needs, room preferences or other special requests.

Some of this is treated as special category data under UK data protection law, because it can reveal something about your health, or about your religious or philosophical beliefs. A nut allergy, a mobility need or a halal or kosher meal request all fall into this. It is given extra protection in law, and your operator needs a specific reason to collect it: normally your explicit consent, or protecting someone's vital interests. Only share what your operator needs to look after you properly.

4.4 Your trip

Your itinerary, travel dates, booking reference, who else is travelling with you, and the documents your operator shares with you.

4.5 Payments

A summary of what your trip costs, what has been paid, and what is still owed. We do not hold your card or bank details. If you pay online, your payment goes to your operator's own payment provider, not to us.

4.6 Emergency contacts

The name, relationship and phone number of the person you nominate. If you give us someone else's details, please make sure they are happy for you to do so.

4.7 What you confirm

When you tick something like confirming your travel insurance or accepting your operator's booking conditions, we record which box you ticked and when.

5. What we hold in our own right

This is the short list, and for it we are the controller rather than your operator's processor.

  • Your sign-in. If you sign in to the traveller app, we hold your email address and the credentials that prove it is you. Sign-in is passwordless and handled by Hanko, our authentication provider. There is no password for you to remember or for anyone to steal.
  • Basic usage statistics. We count page views on trip pages so we know the service is working. This is measured with Umami, which is cookieless and does not build a profile of you, follow you between websites, or record anything that identifies you personally.
  • Security and error logs. When something goes wrong we record what happened so we can fix it. These logs run on our own servers in the EU, and personal data is switched off in them by default.

6. Cookies

We do not use advertising or tracking cookies, and we do not use cookies to build a profile of you.

If you sign in, we set a cookie so you stay signed in. That is the only cookie the traveller app needs to work. Full details are in our Cookie Policy.

7. Why we are allowed to process your data

Under UK GDPR, both your operator and we need a lawful basis. Ours are:

Legal basisWhat we use it for
Contract (Art. 6(1)(b))Running the traveller app for you, including keeping you signed in
Legitimate interests (Art. 6(1)(f))Keeping the service secure and working, and fixing faults
Consent (Art. 6(1)(a))Anything you have specifically agreed to

For special category data such as dietary or accessibility needs (section 4.3), the additional condition is normally your explicit consent (Art. 9(2)(a)), or protecting someone's vital interests (Art. 9(2)(c)) in an emergency. Your operator is responsible for obtaining that consent.

Your operator relies on its own lawful bases for the trip data it holds. Ask them if you want to know which.

8. Who else can see your data

We use a small number of suppliers to run Tourbox. Each is contractually bound to protect your data and to use it only for the purpose we have set.

  • Authentication: Hanko (verifying it is you when you sign in), EU
  • Hosting: Northflank (our servers and databases), EU
  • File storage: OVHcloud (your documents, photos and PDFs), France
  • Encrypted backups: Scaleway (encrypted before it leaves our systems, so they cannot read it), France
  • Content delivery: Cloudflare (delivers pages and images quickly; it passes data through and caches it, it does not process it)
  • Email: Mailgun (sending you trip emails on your operator's behalf), EU
  • Maps: MapTiler (map tiles and place lookups), Switzerland

Your operator may also connect its own services, such as its accounting or payment provider. Those connections are your operator's choice and its responsibility.

A complete, current list is on our Sub-processor page.

We do not sell your personal data, and we never will.

9. Where your data is held

Your trip data is held in the EU.

A few suppliers operate globally or outside the UK and EU. Where that happens we put approved legal safeguards in place, either the UK International Data Transfer Agreement or the Standard Contractual Clauses.

Any artificial intelligence used on your operator's account runs with EU-based providers, and no provider is allowed to train its models on your data.

10. How long we keep it

Your operator decides how long to keep your trip data, and we follow their instruction. If they stop using Tourbox, we delete or return their data within 30 days.

For the data we hold in our own right: sign-in data lasts as long as your account, then goes within 30 days of closure. Error logs are kept for 90 days.

When we delete something, it goes from our live systems straight away. Copies inside encrypted backups are overwritten as those backups rotate.

11. Your rights

You have the right to ask for a copy of your data, to have it corrected, to have it deleted, to restrict or object to how it is used, to receive it in a portable format, and to withdraw consent you have given.

For your trip data, ask your tour operator. They hold it and can act on it. We will help them respond.

For the data in section 5, ask us at privacy@tourbox.com. We will reply within one month.

If you are unhappy with how your data has been handled, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. If the complaint is about your trip data, the ICO will normally expect you to raise it with your tour operator first.

12. How we keep it safe

  • Each operator's data is separated at the database level, so one operator can never see another's
  • Everything travels over an encrypted connection
  • Your documents are stored privately and reached only through links that expire
  • Sign-in is passwordless, so there is no password to be guessed or reused
  • Access to your data inside Tourbox is limited by role

No system is perfectly secure. If you find a security problem, please tell us at privacy@tourbox.com.

13. Children

Children often travel as part of a family booking, and their details are given to the operator by a parent or guardian. We do not offer accounts to under-16s, and we do not knowingly collect data directly from children. If you think a child has given us data directly, contact us and we will delete it.

14. Changes to this policy

If we change this policy in a way that matters, we will say so on this page and update the date at the top.

15. Contact us

Tourbox Systems Limited 125 Freshfield Road, Brighton, England, BN2 0BR Email: privacy@tourbox.com

Related: Cookie Policy and Terms of Use.