Privacy Policy
Last updated: June 2026
This Privacy Policy explains how Best Sri Lankan Tour ("we", "us", "our") collects, uses, and protects your personal information when you use our website or book a tour with us.
1. Information We Collect
We collect information you voluntarily provide:
- Contact details β name, email, phone, country, when you submit inquiries or bookings
- Travel details β passport numbers, dates of birth, dietary restrictions, medical needs (only when required for tour planning)
- Payment information β processed securely by PayPal; we never see or store full card numbers
- Communication history β emails, WhatsApp messages, and notes from our calls
We also collect technical information automatically:
- IP address, browser type, device type, pages visited (via Google Analytics)
- Cookies for site functionality and analytics
2. How We Use It
Your information is used to:
- Plan and deliver your tour (sharing necessary details with hotels, drivers, guides)
- Communicate with you about your booking
- Send you our newsletter (only if you opt in β unsubscribe anytime)
- Improve our website and services
- Comply with legal and tax obligations
3. Who We Share It With
We share the minimum necessary information with:
- Hotels & activity providers β to confirm your bookings
- Drivers & guides β your name, group size, dates only
- Payment processors (PayPal) β handle their own privacy compliance
- Email services for delivery of confirmations and newsletters
We never sell your data. We never share it for marketing purposes outside our own communications.
4. Cookies
Our site uses cookies for:
- Essential cookies β site functionality, login sessions, security
- Analytics cookies (Google Analytics) β anonymous usage statistics
- Marketing cookies (Facebook Pixel, if enabled) β measure ad performance
You can disable cookies in your browser settings, though some site features may not work properly.
5. Data Retention
We retain booking data for 7 years for tax and legal purposes. Inquiry data is retained for 3 years to maintain conversation history. Newsletter subscribers can unsubscribe instantly via the link in any newsletter email.
6. Your Rights (GDPR)
If you're an EU/EEA/UK resident, you have the right to:
- Access β request a copy of the personal data we hold about you
- Rectify β ask us to correct inaccurate data
- Erase β request deletion (subject to legal retention requirements)
- Restrict processing β limit how we use your data
- Portability β receive your data in a portable format
- Object β to marketing communications
- Withdraw consent at any time
To exercise any of these rights, email us at bestsrilankantour@gmail.com.
7. Security
We protect your data using:
- SSL/TLS encryption on all pages
- Hashed passwords (bcrypt) for any account access
- Limited access β only authorised team members handle your data
- Regular software updates and security audits
8. International Transfers
Our servers are based in Sri Lanka. Some of our service providers (PayPal, Google) may process data internationally. We ensure all third-party processors maintain appropriate data protection standards.
9. Children's Privacy
Our services are intended for adults. We don't knowingly collect data from children under 16. If you book a family tour, the parent/guardian's data is the primary record.
10. Changes to This Policy
We may update this policy. The "Last updated" date at the top reflects the most recent change. Significant changes will be communicated via email to active customers.
11. Contact
Questions or concerns? Reach our data protection contact at bestsrilankantour@gmail.com.