Privacy Statement and Cookie Statement
Last Updated: August 5, 2022
Travel Plums Sdn. Bhd. (“we” or “us”) values you as our customer and recognizes that privacy is important to you. This Privacy Statement explains how we collect, use, and disclose data when you use our platform and associated services, your rights in determining what we do with the information that we collect or hold about you and tells you how to contact us. Our system is owned and operated by Travel Plums Sdn. Bhd.
We believe you should be informed about what kind of personal data we collect and how we use it in our system, both through our website and/or app (the “Site“). By reading this Privacy Policy, you can always make the best decision about the personal data that you share with us. Personal data here refers to any information which is related to an identified or identifiable natural person (“Personal Data“). By clicking “agree”, you acknowledge that you have read this Privacy Policy and the TravelWalla Terms of Use (link) and understand their content and consequences, and you agree and give consent to us for the collection, use, disclosure and processing of your Personal Data in accordance with this Privacy Policy and/or the Terms of Use. Further, you acknowledge that every Personal Data that you have provided or will provide is yours to share and is true and accurate.
Our privacy practices will be continuously assessed against new technologies, business practices and our users’ needs. As we update and diversify our services, our Privacy Policy may evolve. We reserve the right to change its Privacy Policy at any time and notify you by posting an updated version of the policy on the App and Site. If you do not agree with any changes or modifications to the Privacy Policy, please do not continue using the Site. You will be deemed to have consented to any modification of the Privacy Policy when you use the Site after the effective date of the modification.
Categories of Personal Information We Collect
When you use our Site, or associated tools or services, we may collect the following kinds of personal information from you as needed:
- Name, username, email address, telephone number, and home, business, and billing addressees (including street and postal code)
- Government issued Identification required for booking or identity verification, such as passport, driver’s license, government redress numbers, and country of residence (for travel insurance purposes), and for vacation property owners, tax identification number,
- Payment information such as payment card number, expiration date, billing address, and financial account number
- Travel-related preferences and requests such as favourite destination and accommodation types, and special dietary and accessibility needs, as available
- Loyalty program and membership information
- Birth date and gender
- Geolocation
- Images (including facial photographs), videos, and other recordings
- Social media account ID and other publicly available information
- Communications with us (such as recordings of calls with customer service representatives for quality assurance and training purposes)
- Searches you conduct, transactions, and other interactions with you on our online services and Site
- Other communications that occur through the platform among partners and travelers,
and in-group chat and traveler-collaboration tools - The searches and transactions conducted through the platform
- Data you give us about other people, such as your travel companions or others for whom you are making a booking
- Information we receive about you from other subsidiaries, affiliated companies and third parties such as our business and affiliate partners and authorized service providers which may include updated contact information, demographic information, interests, and purchase history, which we may add to your account or profile and use for market research and analysis
When you install or use any of our Site, we automatically collect the following types of information from your device:
- IP address
- Device type
- Unique device identification numbers
- Internet browser-type (such as Firefox, Safari, Chrome, and Internet Explorer)
- Internet Service Provider
- Operating System
- Mobile carrier
- How your device has interacted with our online services, including the pages accessed, links clicked, trips viewed, and features used, along with associated dates and times
- Details of any referring website or exit pages, as well as general geographic location (such as at the country or city-level)
Mobile Apps
When you download and use any of our mobile apps, we collect certain technical information from your device to enable the app to work properly and as otherwise described in this Privacy Statement. That technical information includes:
- Device and telephone connectivity information such as your carrier, network type, network operator, subscriber identity module (“SIM”) operator, and SIM country
- Operating system and version
- Device model
- Performance and data usage
- Usage data, such as dates and times the app accesses our servers, the features and links clicked in the app, searches, transactions, and the data and files downloaded to the app
- Device settings selected or enabled, such as Wi-Fi, Global Positioning System (“GPS”), and Bluetooth (which may be used for location services, subject to your permission as explained below)
- Mobile device settings
- Other technical information such as app name, type, and version as needed to provide you with services
Permissions for Location-Based Services:
Depending on your device’s settings and permissions and your choice to participate in certain programs, we may collect the location of your device by using GPS signals, cell phone towers, Wi-Fi signals, Bluetooth or other technologies. We will collect this information, if you opt in through the app or other program (either during your initial login or later) to enable certain location-based services available within the app (for example, locating available lodging closest to you). To disable location capabilities of the app, you can log off or change your mobile device’s settings.
How Do we use the Personal Information we Collect
We use the information collected about you for a variety of purposes. Your personal data may be used in the following ways:
- Trip Reservations:
First and foremost, we use your personal data to complete and administer your online trip reservation – which is essential for us to provide this service for you. This includes sending you communications that relate to your trip reservation, such as confirmations, modifications and reminders. In some cases, this may also include processing your personal data to enable online check-in with the travel provider or processing personal data in relation to possible damage deposits.
- Customer service:
We provide international customer service from our local offices and we’re here to help 24 hours a day, 7 days a week. Sharing relevant details, such as reservation information or information about your user account with our customer service staff allows us to respond when you need us. This includes helping you to contact the right travel provider and responding to any questions you might have about your trip reservation (or any other queries, for that matter).
- Account facilities:
TravelWalla users can create an account on our Site. We use the information you give us to administer this account, allowing you to do a number of useful things. You can manage your trip reservations, take advantage of special offers, make future trip reservations easily and manage your personal settings any to use any other features that we may choose to introduce to you in the future.
- Online groups:
We give account holders the chance to connect and interact with each other through online groups or forums, such as travel communities.
- Marketing activities:
We use your information for marketing activities. These activities include:
- Using your contact information to send you regular news about travel-related products and services. You can unsubscribe from email marketing communications quickly, easily and at any time. All you need to do is click on the ‘Unsubscribe’ link included in each newsletter or other communication.
- Based on your information, individualised offers might be shown to you on the Site, in mobile apps or on third-party websites/apps (including social media sites) and the content of the Site displayed to you might be personalised. These could be offers that you can book directly on the Site, on co-branded sites, or other third-party offers or products we think you might find interesting.
- When you participate in other promotional activities (such as sweepstakes, referral programmes or competitions), only relevant information will be used to administer these promotions.
- Communicating with you:
There might be other times when we get in touch, including by email, by chatbot, by post, by phone or by texting you. Which method we choose depends on the contact information you’ve previously shared. We process the communications you send to us. There could be a number of reasons for this, including:
- Responding to and handling any requests you or your booked travel provider have made. We also offer customers and travel providers various ways to exchange information, requests and comments about travel providers and existing trip reservations via our Site.
- If you have started but not finished a trip reservation online, we might contact you to invite you to continue with your reservation. We believe that this additional service benefits you as it allows you to pick up the process where you left off without having to search for a travel provider or fill in your reservation details again.
- When you use our services, we might send you a questionnaire or invite you to provide a review about your experience with us or the travel provider.
- We also send you other material related to your travel reservations, such as how to contact us if you need assistance while you’re away, and information that we feel might be useful to you in planning or getting the best out of your travel. We might also send you material related to upcoming travel reservations or a summary of previous travel reservations you made through us.
- We may to send you other administrative messages, which could include security alerts.
- In case of misconduct, we may send you a notice and/or warning.
- Market research:
We sometimes invite our customers to take part in market research. Please see the information that accompanies this kind of invitation to understand what personal data will be collected and how that data is used.
- Improving our services:
We also use personal data for analytical purposes and product improvement. This is part of our commitment to making our services better and enhancing the user experience. In this case, we use data for testing and troubleshooting purposes, as well as to generate statistics about our business. The main goal here is to get insights into how our services perform, how they are used, and ultimately to optimise and customise our website and apps, making them easier and more meaningful to use. As much as possible, we strive to use anonymised and de-identified personal data for this analytical work.
- Providing the best price applicable to you, depending on where you are based:
When you search our Site, for example to find an accommodation, a rental car or a flight, we process your IP address to confirm whether you are in the European Economic Area (EEA) or in another country. We do this to offer you the best price for the region (EEA) or country (non-EEA) where you are based.
- Customer reviews and other destination-related information:
During and after your travel, we might invite you to submit a review. We can also make it possible for the people you’re travelling with or whom you’ve booked a reservation for to do this instead. This invite asks for information about the travel provider or the destination. By completing a review, you’re agreeing that it can be displayed (as described in detail in our Terms and Conditions) on, for example, the relevant travel provider information page on our websites, on our mobile apps, on our social media accounts and social media apps, or on the online platform of the relevant travel provider or business partner’s website. This is to inform other travellers about the quality of the travel service you used, the destination you have chosen or any other experiences you choose to share.
- Call monitoring:
When you make calls to our customer service team, we use an automated telephone number detection system to match your telephone number to your existing reservations. This can help save time for both you and our customer service staff. However, our customer service staff may still ask for authentication, which helps to keep your reservation details confidential. During calls with our customer service team, live listening might be carried out or calls might be recorded for quality control and training purposes. This includes the usage of the recordings for the handling of complaints, legal claims and for fraud detection. We do not record all calls. In the case that a call is recorded, each recording is kept for a limited amount of time before being automatically deleted. This is unless we have determined that it’s necessary to keep the recording for fraud investigation or legal purposes.
- Promotion of a safe and trustworthy service:
To create a trustworthy environment for you, your travel partners, our business partners and our travel providers, we continuously analyse and use certain personal data to detect and prevent fraud and other illegal or unwanted activities. Similarly, we use personal data for risk assessment and security purposes, including when you report a safety concern, or for the authentication of users and reservations. When we do this we may have to stop or put certain travel reservations on hold until we’ve finished our assessment.
- Legal purposes:
Finally, in certain cases, we may need to use your information to handle and resolve legal claims and disputes, for regulatory investigations and compliance, to enforce our online reservation service terms of use or to comply with lawful requests from law enforcement.
Lawful bases for processing:
Personal Data being provided to us is purely on a voluntary basis. However, we may only be able to provide you with certain services if we can collect some personal data. For instance, we can’t process your travel reservation if we don’t collect your name and contact details.
Rest assured, we will collect personal information from you only (i) where the personal information is necessary to perform a contract with you (e.g., manage your booking, process payments, or create an account at your request), (ii) where the processing is in our legitimate interests and not overridden by your rights (as explained below), or (iii) where we have your consent to do so (e.g., sending you marketing communications where consent is required). In some cases, we will have a legal obligation to collect personal information from you such as where it is necessary to use your transaction history to complete our financial and tax obligations under the law.
If we ask you to provide personal information to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your personal information is mandatory or not (as well as of the possible consequences if you do not provide your personal information).
Certain countries and regions allow us to process personal information on the basis of legitimate interests. If we collect and use your personal information in reliance on our legitimate interests (or the legitimate interests of any third-party), this interest will typically be to operate or improve our platform and communicate with you as necessary to provide our services to you, for security verification purposes when you contact us, to respond to your queries, undertaking marketing, or for the purposes of potentially detecting or preventing illegal activities.
We may in some cases use automated decision-making, for example, in relation to assessing fraudulent transactions or suspicious activity on our site. As part of this processing, automated decisions may be made by putting your personal information into a system and the decision is calculated using automatic processes. If you pose a fraud risk, this may affect your ability to book on our site. You may have rights in relation to automated decision making, including the ability to request a manual decision-making process instead or contest a decision based solely on automated processing.
Sharing of your Personal Data
In connection with your visit to our Site and use of our services, we may share your information as follows:
- Travel Providers – such as accommodation properties (e.g., the specific accommodation that you have requested us to reserve) and/or third party accommodation suppliers, airline, car rental, insurance, and, where available, activity providers, who fulfil your travel reservations. These suppliers may contact you as necessary to obtain additional information about you, facilitate your travel reservation including communicating with you prior to arrival about your upcoming stay, or respond to a review you may submit in accordance with their own independent privacy policies.
- Third Party Service Providers – who provide data processing services to us (for example web hosting), or who otherwise process personal information for purposes such as credit card and payment processing, business analytics, customer service, marketing, or distribution of surveys, to facilitate the delivery of online services and advertising tailored to your interests, and/or fraud prevention. Our third party service providers will only process information as needed to perform their functions. They are not permitted to share or use the information for any other purpose.
- Business Partners – with whom we may jointly offer products or services, or whose products or services may be offered on our Site. You can tell when a third-party business partner is involved in a product or service you have requested because their name will appear, either alone or with ours. If you choose to access these optional services, we will on occasion share your personal information with those partners. Examples of business partners would be (i) a third-party loyalty program that you will earn points for, through a booking, or (ii) a third-party tour or activity provider that we share information with in connection with tours/activities you book through our Site.
- Our Affiliated Group Companies – our affiliated (group) companies who have access to this information with our permission and who need to know or have access to this information in order to: perform the service requested by you (including to make, administer, and manage reservations or handle payments, “single sign-on”, and customer service); analyze how you use our independent and affiliated platforms, improve and provide new and personalized offers, products and services, and marketing; detect, prevent, and investigate fraudulent transactions and/or activities, other illegal activities, and data breaches; internal (audit/compliance) investigations; or as otherwise required or permitted by applicable law.
- Where Required or Permitted by Law – such as to protect ourselves against liability, to respond to subpoenas, judicial processes, legitimate requests, warrants or equivalent by law enforcement officials or authorities, to investigate fraud or other wrongdoing or as otherwise required or necessary in order to comply with applicable law, protect our legitimate interests or to the purchasers in connection with any sale, assignment, or other transfer of all or a part of our business or company. We may also, in compliance with applicable law, disclose your information to enforce or apply the terms and conditions applicable to our services or to protect the rights, property, or safety of us, our users, or others.
- Business Reorganization – such as part of any sale, assignment or other transfer of our business, or transition of service to another provider. We will ask for your consent if required by applicable law.
We provide appropriate protections for such sharing as required by applicable law to prohibit third parties from using your information for their own purposes, and to address the security and confidentiality of your information. Except as disclosed in this Privacy Policy or as required or permitted by applicable law, we will not disclose your information to third parties without your consent.
Your rights to your Personal Data
You have certain rights and choices with respect to your personal information, as described below:
- If you have an account with us, you may change your communication preferences by either (1) logging in and updating the information in your account or (2) contacting us here.
- You can control our use of certain cookies by following the guidance in our Cookie Statement in this Privacy Statement.
- You can access, amend, inquire about deletion, or update the accuracy of your information at any time by either logging into your account or contacting us.
- If you no longer wish to receive marketing and promotional emails, you may unsubscribe by clicking the ‘unsubscribe’ link in the email. You can also log into your account to change communication settingsor contacting us here. Please note that if you choose to unsubscribe from or opt out of marketing emails, we may still send you important transactional and account-related messages from which you will not be able to unsubscribe.
- For our mobile apps, you can view and manage notifications and preferences in the settings menus of the app and of your operating system.
- If we are processing your personal information on the basis of consent, you may withdraw that consent at any time by contacting us. Withdrawing your consent will not affect the lawfulness of any processing that occurred before you withdrew consent and it will not affect our processing of your personal information that is conducted in reliance on a legal basis other than consent
Access to or Correction of Your Personal Data
When you provide us with your Personal Data, please ensure that it is accurate and complete. If you believe that any of your information under our possession contains errors or omissions, please log into your account on the Site and correct the information. In addition, please update your Personal Data through your account in a timely manner, should there be any changes. If you wish to correct an error or omission in any Personal Data under our possession that cannot be corrected via our Site, or to access your Personal Data under our possession or control, or as provided for by applicable laws, please submit your request to our contact details listed below.
Withdrawing Consent
You may withdraw your consent to our collection, use or disclosure of your Personal Data, by giving us a reasonable notice. If you wish to withdraw your consent, please inform us at our contact details listed below. Upon your request, we will cease to collect, use or disclose your Personal Data, unless required by law or if we have legitimate business or legal purposes for retaining such data. Note that by withdrawing your consent to our collection, use or disclosure of your Personal Data, we may not be able to continue providing you with our services and you agree that we will not be liable to you for any losses or damages arising out of or in relation to such termination of services. If after withdrawing consent, you decide to again use our services, you will need to click “agree” again to confirm on your consent as stated above in this Privacy Policy.
Removal of Your Personal Data
You may have the right to ask your Personal Data collected and processed by us to be removed, by giving us a reasonable reason. If you wish to remove your data, you should inform us at our contact details listed below.
Upon your request, we will strive to remove your Personal Data in our system. We will also cease to collect, use or disclose your personal data, unless required by law or if we have legitimate business or legal purposes for retaining such data. Note that by requesting us to remove your Personal Data, we may not be able to continue providing you without services and you agree that we will not be liable to you for any losses or damages arising out of or in relation to such termination of services.
Retention of Your Personal Data
Your Personal Data will be retained for as long as your account is still in existence and as needed to provide you without services. We shall cease to retain Personal Data, or with reasonable effort to remove the means by which the Personal Data can be associated with You as an individual, as soon as, 1) the purpose for which Personal Data was collected is no longer being served by the retention of data; and 2) it is not required by the applicable laws and/ or not necessary for business purposes.
For questions about privacy, your rights and choices, and in order to make a request to amend or update your information, or to inquire about deletion, please contact us in accordance to our Contact Us statement below.
In addition to the above rights, you may have the right to complain to a data protection authority about our collection and use of your personal information. However, we encourage you to contact us first so we can do our best to resolve your concern. You may submit your request to us using the information in the Contact Us section. We respond to all requests we receive from individuals wanting to exercise their personal data protection rights in accordance with applicable data protection laws.
Minors Privacy
We do not and do not intend to, transact through the Site directly with anyone we know to be under the age of 18. If you are under the age of 18, you should use the Site only with the involvement of a parent or guardian and should not submit any Personal Data to us. By providing any Personal Data to us, you declare that you are over the age of 18.
How Do We Protect Your Personal Data
We want you to feel confident about using our Site and all associated tools and services, and as such we are committed to taking reasonable and appropriate steps to protect the information we collect. While we are unable to absolutely guarantee security, we do take reasonable steps to implement appropriate physical, technical, and organizational measures to protect the personal information that we collect and process. If there is any breach of Personal Data, we will notify you through our channels, whether directly or indirectly, to give you sufficient information regarding such breach of Personal Data. Following the notification, we will strive with our utmost best effort to recover the security of your Personal Data on our Site.
Links to External Websites
Our Site may contain links to other websites of interest. However, do take note that if you have chosen to use the links to leave our Site, we do not have any control over that other website. Please note that we are not responsible for the privacy policy or practices of such other websites and advise you to read the privacy policy of each website you visit which collects your Personal Data.
Sensitive Personal Information
‘Sensitive personal information’ is any information that, if leaked or illegally used, could easily lead to the infringement of human dignity or cause harm to an individual or their property. When using the Site or the services offered by us, the following sensitive personal information may be collected by us or a third party vendor:
- Information necessary to process your payment (such as your bank account and payment card number, provided by you or in your name),
- Information about minors, provided with the authorisation of the parent or guardian (see below for further information),
- Location information, in order to show you city guides, to recommend the accommodation and attractions closest to your current location or to give other recommendations.
In furtherance thereof, certain search parameters that you have selected may reveal information about your sexual orientation, religion and health.
We will ask for your consent before we collect sensitive personal information. However, where you voluntarily provide sensitive personal information, we will assume that you have given us consent to process that information within the context it was submitted.
International Data Transfer
The personal information we process may be transmitted or transferred to countries other than the country in which you reside. Those countries may have data protection laws that
are different from the laws of your country. The servers for our platform are located in the (insert), and our company and third-party service providers operate in many countries around the world. As such, when your personal information is collected, we may process it in any of those countries.
We have taken appropriate steps and put safeguards in place to help ensure that your personal information remains protected in accordance with this Privacy Statement.
We also require that third-party service providers to whom a data transfer is made has appropriate safeguards in place to protect your personal information, in compliance with applicable data protection law.
Cookies Statement
Our Site may use and allow third parties to place cookies (session and persistent), pixels/tags, SDKs, application program interfaces (“APIs”), and other technologies (collectively, “Cookies”) on our Site that may collect and store certain information about you. Some of these Cookies are necessary to provide, secure, and maintain the basic functions of the Site, such as to keep you logged in while your visit our Site (“Functional Cookies”), while other Cookies are used to provide you with a better user experience, such as:
- To personalize the Site by remembering information about your activities on the Site (e.g., the language you selected or your log-in details). We may also use Cookies together with other automatically collected usage information to recognize a user across different devices, sessions or browsers (including when they have not logged-in) so as to deliver tailored information;
- Perform non-essential website analytics, such as impression reporting, demographic reporting and interest reporting. This may include the recording of mouse clicks, movements, page scrolling and restricted text entered into our Site forms through selected third parties but we will take sufficient precautions to ensure that personal information will not be collected during such recordings e.g. through the adoption of irreversible masking. Website analytics is used to improve our Site and services; and
- To provide you advertising tailored to your interest (collectively, “Non-Functional Cookies”).
Types of information collected by cookies
The types of information that we collect through cookies include:
- IP address
- Device ID
- Viewed pages
- Browser type
- Browsing information
- Operating system
- Internet Service Provider
- Whether you have responded to, or interacted with, an advertisement
- Referring or referred links or URLs
- Features used and activities engaged in on our sites and in our apps
Our use of Functional Cookies and Non-Functional Cookies is subject to geographic implementation as detailed below.
EU/UK Site Visitors
For individuals that access our Site from within the European Union (“EU”) or the United Kingdom (“UK”) (“EU/UK Site Visitors”), we may use Functional Cookies on the Site.
We do not use Non-Functional Cookies on the Site that we offer within the EU or the UK.
Non-EU/UK Site Visitors
For individuals that access our Site from a jurisdiction outside of the EU and the UK (“Non-EU/UK Site Visitors”), we may use both Functional Cookies and Non-Functional Cookies on the Site. In addition, below we have provided information for Non-EU/UK Site Visitors specific to our use of Non-Functional Cookies on the Site that we offer outside of the EU and the UK.
Interest Based Advertising
We may allow certain third parties to place Non-Functional Cookies on our Site to collect information about your online activities on our Site (e.g., pages visited on the Site and searches you performed) and over time and across different websites you may visit. This information is used to provide advertising tailored to your interests from us (via email, on our Site, and on other websites) and by third parties on other websites you may visit, also known as interest based advertising, and to analyze the effectiveness of such interest based advertising. We may also share one-way hashed information with third party partners (e.g., Facebook) who may combine hashed information with other identifiers in order to serve custom TravelWalla advertisements on other websites or mobile apps based on your prior visits to the Site. TravelWalla neither supports nor endorses the goals, causes, or statements of any websites or mobile apps that display our advertisements.
Cross-Device Tracking
We may also combine information collected through Non-Functional Cookies and certain usage information from a particular browser or mobile device with another computer or device that may be linked to you (cross-device tracking) to optimize our services and provide tailored TravelWalla communications and advertisements to you.
Your Choices
Please review your Internet browser settings, typically under the sections “Help” or “Internet Options,” to exercise choices you have for certain Functional Cookies and Non-Functional Cookies. If you disable or delete certain Functional Cookies or Non-Functional Cookies in your Internet browser settings, you might not be able to access or use important functions or features of this Site, and you may be required to re-enter your log-in details.
By exercising such choices regarding interest-based advertising, you may still receive advertisements, but the network from which you opted out will no longer deliver ads tailored to your interests. You should also know that logging out of your user account does not actually mean that you opt out of personalized advertisements.
You may need to make such choices on each browser and device you may use to exercise choice regarding certain Functional Cookies and Non-Functional Cookies. Lastly, at this time the Site is not configured to honor browsers’ “Do Not Track” signals, except where required by applicable law.
Miscellaneous Provisions
Language
This Privacy Policy has originally been drawn up in the English language. Translations in other languages are available for your convenience. In case of conflict between the English language version and a translated version, the English language version shall prevail.
Terms of Use
Please review the Terms of Use for more details on using our Site. This Privacy Policy forms an integral part of our Terms of Use. Where there is any discrepancy between the terms hereof and the Terms of Use, the terms hereof shall prevail.
Transfer of Business
In the event of change of control or ownership of TravelWalla’s business or group of companies, then the Personal Data collected in the Site may be part of transfer of the assets.
Contacting Us
If you have any questions about this Privacy Policy or our privacy practices, please contact our TravelWalla Data Protection Officer by email at privacy@travelwalla.com or by sending a registered letter to the address at:
Travel Plums Sdn Bhd
(insert address)