Tripmeant

Privacy & Data Protection

Your trust matters to us. Learn how Tripmeant collects, uses, and protects your information to ensure a safe and secure travel experience

Privacy & Data Protection

Effective date: 01 July 2026 - Last updated: 01 July 2026

Tripmeant ("we," "us," "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website tripmeant.com, communicate with us, or use our travel planning, booking, and related services ("Services"). This Policy meets the transparency and accountability requirements of the EU General Data Protection Regulation (GDPR), the UK GDPR & Data Protection Act 2018, and major US state privacy laws including the California Consumer Privacy Act (as amended by the CPRA), Virginia CDPA, Colorado CPA, Connecticut CTDPA, and Utah UCPA. Where local law provides stronger protections, we will extend those protections to all individuals whose data we process. Please read this Policy carefully. By using our Services or providing your data, you acknowledge that you have read and understood its terms. Capitalised terms not defined here have the meanings given in our Terms & Conditions.

1. Who We Are & Contact Details

Data Controller: Tripmeant Wyoming, United States Email: discover@tripmeant.com

2. What Personal Data We Collect

We collect only the data necessary to design and deliver your travel experience, to comply with legal obligations, and to pursue our legitimate business interests. The categories we process include:

2.1 Information You Provide Directly

Identity & Contact Data: Full name, email address, phone number (including WhatsApp), country of residence, postal address (where needed for documentation).

Travel Preference Data: Destinations of interest, travel dates, number of travellers, pace and budget preferences, special interests, dietary requirements, and accessibility needs.

Traveller Data: Full names, dates of birth, nationalities, and passport details (number, issuing country, expiry date, photograph) for each traveller, collected only when necessary for bookings or visa facilitation.

Health & Medical Data: Any information you voluntarily disclose to us for Medical & Wellness packages, including medical history, existing conditions, and procedure preferences. This is treated as "special category data" under GDPR and is processed only with your explicit consent.

Payment Data: We do not store full credit/debit card numbers. Payments are processed by Stripe; we receive a transaction ID and the last four digits of your card number.

Communications: The content of emails, WhatsApp messages, call notes, and any documents you attach.

2.2 Information Collected Automatically When you visit our website, we may automatically collect:

Technical Data: Internet Protocol (IP) address, browser type and version, operating system, device type, time zone setting.

Usage Data: Pages visited, time spent on pages, referring website addresses, page interaction events.

Our site does not use third-party advertising cookies, retargeting pixels, or analytics trackers that profile you. We use only essential, session-based cookies necessary for the website to function. See Section 10 (Cookies).

2.3 Information from Third Parties We may receive information about you from:

Travel companions who include you in a booking.

Our payment processor (Stripe) - transaction confirmations.

Visa authorities or embassies - status updates (only when you use our visa facilitation service).

Third-party insurers - policy confirmation details.

3. How We Use Your Data & Our Legal Bases

We will only process your personal data when we have a lawful basis. For EU and UK residents, we rely on the following legal bases under the GDPR (and UK GDPR). For US residents, we process on the basis of contract, legitimate interest, or consent as required by applicable state laws.

Responding to your enquiries and preparing a tailored travel quote: We process your Identity, Contact, and Travel Preference data. This is necessary for the performance of a contract or to take pre-contractual steps at your request.

Designing and confirming your booking (including communicating with you about the itinerary): We process your Identity, Contact, Traveller Data, and Travel Preferences. This is necessary for the performance of our contract with you.

Making and managing payments, and issuing invoices: We process your Identity, Contact, and Payment Data. This is necessary for the performance of the contract and to comply with our legal accounting obligations.

Booking flights, hotels, clinics, guides, and other suppliers: We process all relevant data (Identity, Contact, Traveller Data, Travel Preferences, and, for medical packages, Health & Medical Data with your explicit consent). This is necessary for the performance of the contract.

Supporting visa applications and sharing data with immigration authorities: We process your Passport and Identity Data. This is necessary for the performance of the contract and to comply with legal obligations.

Sharing medical information with your chosen medical provider: We process your Health & Medical Data. We do this only with your explicit consent.

Providing emergency assistance while you travel: We process your Identity, Contact, and Traveller Data. This is based on your vital interests and our legitimate interest in ensuring traveller safety.

Sending marketing newsletters and special offers (only if you opt in): We process your Identity and Contact data. This is based solely on your consent.

Fraud prevention, risk management, and platform security: We process Technical, Usage, and Payment Data. This is based on our legitimate interests in protecting our business and complying with legal obligations.

Maintaining accounting records and complying with tax obligations: We process Identity, Contact, and Payment Data. This is necessary to comply with legal obligations.

Defending legal claims and enforcing our Terms: We process all relevant data. This is based on our legitimate interests in protecting our legal rights.

Where we rely on legitimate interests, we have balanced our interests against your rights and freedoms and concluded that the processing is necessary and does not override your interests. You may object at any time (see Section 8).

Marketing: We will send you promotional content only if you have explicitly opted in. You may unsubscribe at any time via the link in any marketing email or by contacting us. Even if you opt out, we may still send you service-related, non-promotional messages (e.g., booking confirmations, balance reminders, safety updates).

4. Special Category Data & Explicit Consent

Health and medical information you share in connection with Medical & Wellness packages is classified as "special category data" and receives heightened protection. We will:

Process such data only after we have obtained your explicit consent for the specific purpose of matching you with a medical provider and facilitating your booking.

Store it only in encrypted environments with access restricted to designated, trained personnel.

Never use it for marketing or any incompatible purpose.

Delete it within 6 months of completion of your treatment journey, unless you request earlier deletion or ask us to retain it for a follow-up booking.

You may withdraw your consent at any time by contacting discover@tripmeant.com. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal, but it may mean we can no longer provide the medical-related elements of your booking.

5. Who We Share Your Data With

We do not sell, rent, or trade your personal data with any third party for their own marketing purposes. We share data only as necessary to deliver our Services, comply with the law, or protect our rights. The categories of recipients are as follows:

Travel Suppliers (airlines, hotels, ground operators, guides, clinics, hospitals): We share your full name, contact details, passport data (where required), dietary/accessibility needs, and medical data (only for clinics and only with your explicit consent). These Suppliers act as independent controllers or processors, depending on the service.

Payment Processors (Stripe Inc. and its affiliates): We share payment instrument data, name, email, and transaction amount solely to process your payments and manage chargebacks. Stripe's own privacy policy governs their handling of your data.

Government Authorities (visa offices, immigration, customs, police): We share passport data, travel itineraries, and identity verification information where legally required or necessary to facilitate your travel.

Professional Advisers (lawyers, accountants, auditors): We share data as necessary for legal compliance, tax, and audit purposes, under strict confidentiality obligations.

IT & Cloud Service Providers (hosting, email, customer support platforms): We share technical data and communications as needed to operate our website and business systems. They process data only on our documented instructions.

Insurance Partners: When you request an insurance quotation, we share identity, contact, and travel details with insurers at your direction.

Law Enforcement & Regulatory Bodies: We disclose data when under a binding legal obligation, or when necessary to protect our legal rights.

All service providers are bound by written contracts that require them to process data only on our documented instructions and to implement appropriate security measures.

6. International Transfers

Tripmeant is based in the United States, and your data will be transferred to and processed on servers in the US. Additionally, your data may be transferred to Suppliers in your destination countries, which may be outside the European Economic Area (EEA), the UK, or your country of residence.

Where we transfer personal data from the EEA, UK, or Switzerland to countries that have not been deemed to provide an "adequate" level of protection, we put in place appropriate safeguards, including:

Standard Contractual Clauses (SCCs) - the European Commission's approved model contracts, plus the UK International Data Transfer Addendum where applicable.

Supplementary measures - technical and organisational measures (e.g., end-to-end encryption) where necessary to ensure an equivalent level of protection.

For transfers to Suppliers that are independent controllers (such as a hotel or clinic), we rely on your explicit consent or the necessity for the performance of your contract with that Supplier.

You can request a copy of the relevant safeguards by contacting discover@tripmeant.com.

7. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes we collected it for, including satisfying legal, accounting, or reporting obligations.

Enquiry data (no booking): Retained for 12 months from your last contact with us, then securely deleted.

Booking records (including traveller details, itineraries, and correspondence): Retained for 7 years after the end of your travel, to comply with accounting and tax obligations and for legal claims limitation periods.

Medical & health data: Retained for 6 months after completion of your treatment journey, unless you ask us to delete it earlier or to retain it for a follow-up booking.

Payment transaction data: Retained by Stripe according to their own retention schedule; we keep invoices and receipts for 7 years.

Marketing contact details: Retained until you unsubscribe, or until we note you have not engaged with our emails for 24 consecutive months, whichever is sooner.

Website technical logs: Retained for 90 days.

After the applicable retention period, your data will be securely deleted or anonymised.

8. Your Rights & How to Exercise Them

Depending on your jurisdiction, you have a number of rights regarding your personal data. We will not discriminate against you for exercising any of your rights.

Under the GDPR / UK GDPR (EU and UK residents)

Access - obtain a copy of your data.

Rectification - correct inaccurate or incomplete data.

Erasure - request deletion where there is no overriding legal ground.

Restriction - limit processing in certain circumstances.

Portability - receive your data in a structured, machine-readable format.

Objection - object to processing based on legitimate interests (including profiling, although we do not profile).

Withdraw Consent - where processing is based on consent.

Under US State Privacy Laws (California, Virginia, Colorado, Connecticut, Utah)

Right to Know / Access - request disclosure of the categories and specific pieces of personal data we collect, use, and disclose.

Right to Delete - request deletion of your personal data (subject to exceptions).

Right to Correct - correct inaccurate data.

Right to Opt-Out of Sale/Sharing - we do not sell your personal data or share it for cross-context behavioural advertising. We honour opt-out preference signals (e.g., Global Privacy Control) where required by law.

Right to Non-Discrimination - we will not treat you differently for exercising your privacy rights.

Authorised Agent - you may designate an authorised agent to make requests on your behalf.

How to Submit a Request

Email discover@tripmeant.com with "Privacy Request" in the subject line. We may need to verify your identity before processing your request (typically by matching your email with our records, and, for sensitive requests, requesting additional proof of identity). We will respond within:

30 days (GDPR / UK GDPR), extendable by 60 days for complex requests;

45 days (US state laws), with a possible 45-day extension upon notice.

We will provide the first copy of your data free of charge; for excessive or unfounded requests we may charge a reasonable fee.

Right to Complain

You have the right to lodge a complaint with a supervisory authority:

EU: Your local Data Protection Authority (list: edpb.europa.eu)

UK: Information Commissioner's Office (ico.org.uk)

USA (California): California Privacy Protection Agency (cppa.ca.gov)

USA (other states): Your state Attorney General's office

9. Data Security

We implement and maintain industry-standard technical and organisational measures to protect your personal data against accidental loss, alteration, disclosure, or access. These measures include:

Encryption: All data in transit is encrypted using TLS 1.2+. Sensitive documents (e.g., passport copies, medical forms) are encrypted at rest using AES-256.

Access Controls: Data access is restricted to employees and contractors on a strict need-to-know basis, enforced through multi-factor authentication and role-based permissions.

Payment Security: Full card details are never handled or stored by our systems. All payment processing is handled by Stripe, a PCI-DSS Level 1 Service Provider.

Vendor Assessment: We review the security practices of our IT and cloud service providers annually.

Breach Notification: We maintain a data breach response plan. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (where legally required) and inform you without undue delay.

No method of electronic storage is 100% secure; we cannot guarantee absolute security, but we strive to keep pace with evolving threats.

10. Cookies & Similar Technologies

Essential Cookies: Our website uses only strictly necessary session cookies to ensure basic functionality (e.g., maintaining your session state). These are set automatically and are not used for tracking or advertising. They expire when you close your browser.

Non-Essential Cookies & Analytics: Currently, we do not deploy any third-party analytics scripts (e.g., Google Analytics), advertising pixels, or social media plugins. If we introduce such technologies in the future, we will update this Policy and seek your consent via a cookie banner before they are placed on your device. You will be able to manage your preferences at any time.

Do Not Track & Global Privacy Control: Our website respects the Global Privacy Control (GPC) signal where required by applicable US state privacy law. Because we do not sell personal data, the signal's effect is to reaffirm our existing no-sale practice.

11. Children's Data

Our Services are intended for adults. We do not knowingly collect personal data directly from children under the age of 16. When a booking includes minors, their information is provided by and is the responsibility of the parent or legal guardian making the booking. The parent or guardian consents to our processing of the child's data as part of that booking.

If we learn we have inadvertently collected a child's data without such consent, we will delete it promptly. If you believe a child has submitted data to us, contact us immediately.

12. Automated Decision-Making & Profiling

We do not use automated individual decision-making (including profiling) that produces legal effects concerning you or similarly significantly affects you. The design of custom itineraries is carried out by human travel designers.

13. Changes to This Privacy Policy

We keep this Policy under regular review and may update it to reflect changes in law, technology, or our operations. The current version is always available on this page with the "Effective date" displayed at the top.

Where changes are material, we will notify active customers by email at least 15 days before the change takes effect. For non-material updates, we will update the date at the top. Your continued use of our Services after the effective date constitutes acceptance of the revised Policy where permitted by law.

14. How to Contact Us

For all privacy-related matters, including exercising your rights:

Tripmeant - Privacy Office Wyoming, United States Email: discover@tripmeant.com Phone: +971 55 305 5367