1. Scope & who this applies to
• Visitors browsing our site and Customers purchasing our Services (B2C or B2B corporate/agency buyers).
• This policy applies globally, with Regional Notices that supplement or override sections as required by Japan, Taiwan, Hong Kong, Singapore, Thailand, Malaysia, Philippines, Indonesia, and certain Middle East jurisdictions (e.g., UAE, Saudi Arabia).
2. Personal data we collect
We collect only what we need to provide and improve our Services.
A. Account & identity data
Name (as in passport), preferred name, date of birth, nationality, gender (where required), contact details (email, phone), postal address, account credentials.
B. Travel & document data
Passport details (number, expiry, issuing country), visa info (if you provide it), frequent flyer/tier ID, travel companions, itinerary preferences, special assistance or dietary notes (health-related information - processed only where necessary and permitted by law).
C. Transaction & payment data
Order history, invoices/receipts, payment method tokens/last 4 digits and expiry (we use PCI-compliant processors; we do not store full card numbers), refunds, chargebacks, anti-fraud checks.
D. Communications & support
Enquiries, chat/email/phone logs, survey responses, reviews, marketing preferences.
E. Technical & usage data
IP address, device/browser type, language, time zone, cookies or similar IDs, pages viewed, clicks, referral URLs, session duration, error and performance logs.
F. B2B data (if you book for a company)
Company name, business registration number, tax ID (where applicable), billing contact details, traveller lists tied to your corporate booking.
Sensitive data (special categories). We only process sensitive data (e.g., health/medical notes for assistance, religion for meal type if you tell us, passport details) when necessary to deliver your booking, meet legal obligations, protect vital interests, or with your consent where required. You may choose not to provide optional sensitive data, but some Services may be unavailable.
Children. Our Services are not directed to children under 18. If you book on behalf of a minor, you confirm you are their parent/guardian or have lawful authority.
3. How we use personal data (and legal bases)
Purpose |
Examples |
Legal basis (illustrative across our markets) |
|---|
Provide & manage bookings |
Create account, verify identity, issue confirmations/e-tickets/vouchers, handle changes/cancellations |
Contract (perform our agreement) |
Customer care |
Respond to enquiries, live support, complaints handling |
Contract; Legitimate interests (service quality) |
Payments & fraud prevention |
Process payments, refunds, chargeback handling, risk checks |
Contract; Legitimate interests (fraud/security); Legal obligation (accounting/tax) |
Personalisation & service improvement |
Remember preferences, improve UX, analytics, A/B testing |
Legitimate interests (improve Services); Consent where required for cookies/ads |
Marketing (optional) |
Newsletters, offers, remarketing |
Consent where required; otherwise legitimate interests with easy opt-out |
Legal & compliance |
Tax/audit, record-keeping, responding to lawful requests, sanctions checks |
Legal obligation; Public interest; Legitimate interests |
Safety & security |
Detect abuse, protect accounts, maintain logs, incident response |
Legitimate interests; in emergencies vital interests |
We do not make decisions solely by automated means that produce legal or similarly significant effects about you.
4. Cookies, analytics & ads
We use cookies and similar tech to: keep you signed in, remember preferences, measure site performance, and (if you consent) deliver analytics and marketing/retargeting. You can manage preferences any time via our Cookie Settings link in the footer or your browser settings. Some features may not work without strictly necessary cookies.
5. Who we share data with (no data sales)
We do not sell your personal data. We share only as needed to operate the Services:
• Payment processors & fraud prevention (secure card processing, risk checks).
• Operational vendors (hosting/CDN, email/SMS, customer support, analytics).
• Travel fulfilment partners (e.g., airlines, hotels, ground operators engaged by us to deliver your booking). We remain the merchant and controller for our direct products.
• Professional advisors & auditors (legal, accounting).
• Authorities & regulators where lawfully required.
• Corporate transactions (merger, acquisition); your data remains protected and you'll be notified where required.
All vendors are bound by contracts with confidentiality and security obligations appropriate to their role.
6. International transfers
We operate globally. Your data may be processed in Korea and other countries where our teams or service providers are located. When transferring data across borders, we implement appropriate safeguards required by local law. See Regional Notices for country-specific transfer rules.
7. Data retention
We keep data only as long as needed for the purposes above, typically:
• Bookings, invoices, and support records: 5-7 years (depending on local accounting/limitation laws).
• Account data: while your account is active; if you close it, we minimize/archive where legally required, then delete.
• Cookie/analytics identifiers: per cookie category duration or until you withdraw consent.
If a legal claim or investigation is ongoing, we retain relevant data until it is resolved.
8. Security
We use administrative, technical, and physical safeguards: access controls, encryption in transit and at rest (including for passport numbers and other identifiers), network security, vulnerability management, multi-factor authentication for privileged access, staff training, vendor due diligence, and incident response procedures. No method is 100% secure; we'll notify you and regulators of significant breaches as required by law.
9. Your privacy choices & rights (global baseline)
Depending on your location's laws, you may have the right to:
• Access your data and receive a copy
• Correct inaccurate or incomplete data
• Delete/erase data (subject to legal retention)
• Object to or restrict certain processing
• Withdraw consent (where processing is based on consent)
• Data portability (receive data in a portable format)
• Lodge a complaint with your local regulator
How to exercise rights
Email goalmastertrip@goalmastertrip.com with your request (what you want to do and which data). We'll verify identity (to protect you) and respond within the timeframe required by your local law. If we lawfully must keep some data (e.g., tax records), we'll explain.
10. Direct marketing
We'll send marketing only with your consent where required (e.g., some markets require opt-in) and always with a clear unsubscribe. Even if you unsubscribe, we may still send essential service messages (e.g., booking updates).
11. Changes to this Policy
If we make material changes, we'll give reasonable notice. The "Effective date" tells you when this version began.
12. Contact us
Questions or requests: goalmastertrip@goalmastertrip.com