1. Overview
We are committed to complying with the General Data Protection Regulation (GDPR) (EU 2016/679) and all applicable data protection laws.
2. Data We Collect
- Contact Information: Name, email address, phone number, country of residence — collected when you submit a travel inquiry or contact us.
- Travel Preferences: Desired destinations, travel dates, group size, budget range, dietary requirements, and any preferences you share with us.
- Booking Information: Passport details (for visa support and bookings), hotel preferences, emergency contact information — collected only after you confirm a booking.
- Usage Data: Pages visited, time on site, referring URL, browser type, IP address — collected automatically through cookies and analytics.
3. How We Use Your Data
- To respond to your travel inquiries and provide personalized itinerary suggestions
- To process bookings, arrange tours, and coordinate with local service providers (hotels, guides, transport)
- To provide pre-trip information, visa support, and travel documentation
- To communicate with you during your trip (24/7 support)
- To improve our website, services, and tour offerings
- To send travel-related communications (only with your explicit consent)
- To comply with legal and regulatory obligations
4. Legal Basis for Processing
- Consent (Art. 6(1)(a)): When you submit an inquiry form, you consent to us processing the provided data to respond to your inquiry.
- Contract (Art. 6(1)(b)): When you book a tour, we process your data to fulfill the travel service contract.
- Legal obligation (Art. 6(1)(c)): We retain certain records to comply with Chinese tourism regulations and tax laws.
- Legitimate interest (Art. 6(1)(f)): We use anonymized usage data to improve our website and services.
5. Data Sharing
- Service providers: Hotels, transport companies, local guides, and venues — only the data necessary to deliver your booked services.
- Payment processors: When payment is collected, your payment data is processed by our payment provider (e.g., Stripe) under their own GDPR-compliant terms. We do not store full card numbers.
- Legal authorities: If required by law, court order, or government regulation.
6. Data Retention
- Inquiry data (no booking): Deleted or anonymized after 12 months of no activity.
- Booking data: Retained for 7 years to comply with tax and legal obligations, then deleted.
- Usage data: Anonymized after 26 months.
- Marketing data: Deleted immediately upon your unsubscribe request.
7. Your Rights (GDPR)
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): Request deletion of your personal data, subject to legal retention obligations.
- Right to restrict processing: Request that we limit how we use your data.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interest.
- Right to withdraw consent: Withdraw consent at any time without affecting prior processing.
To exercise any of these rights, please contact us at privacy@bailutrip.com. We will respond within 30 days as required by GDPR.
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority or the supervisory authority in the EU member state where you reside.
8. Cookies
- Essential cookies: Required for the website to function (e.g., language preference).
- Analytics cookies: Help us understand how visitors use the website (e.g., Google Analytics, anonymized).
- No advertising cookies: We do not use third-party advertising or tracking cookies.
You can manage cookie preferences through your browser settings. Essential cookies cannot be disabled as they are required for core website functionality.
9. Data Security
- SSL/TLS encryption for all data transmission
- Secure server infrastructure with access controls
- Regular security reviews and updates
- Staff training on data protection and privacy
- Limited access — only authorized staff can access personal data
In the event of a data breach, we will notify affected users and the relevant supervisory authority within 72 hours, as required by GDPR Article 33.