Privacy & Data Protection Policy

Welcome to WeTravels. We are committed to safeguarding your personal privacy and protecting the information you share with us. This Privacy Policy explains in detail how we collect, handle, process, store, and protect your personal information while you browse our website, inquire about fares, or book travel services with us.

Website: wetravels.co.ukUK GDPR & PECR CompliantLast Updated: August 2026
01

Key Definitions

To help you navigate this document clearly:

  • "We", "Us", "Our": Refers to WeTravels (and any of its trading divisions, affiliated subsidiaries, or brand names operating under wetravels.co.uk).
  • "You", "Your", "The User": Refers to any individual accessing our website, making inquiries, or completing travel bookings.
  • UK GDPR: The UK General Data Protection Regulation, which governs data privacy, rights, and processing obligations in the United Kingdom.
  • PECR: The Privacy and Electronic Communications Regulations, which cover electronic communications, cookies, and digital direct marketing.
  • ICO: The Information Commissioner’s Office, the UK’s independent supervisory authority for data privacy and protection.
  • Cookies: Small text data files placed on your device/computer hard drive to optimize browsing performance, retain user preferences, and support site functionality.

02

Lawful Basis & ICO Registration

Under the UK GDPR, WeTravels acts as a Data Controller and Data Processor for your electronic data.

  • We process personal data under strictly defined lawful bases: Contractual Necessity, Legal Obligation, Legitimate Interests, and Explicit Consent.
  • We are registered with the Information Commissioner’s Office (ICO) on the UK Data Protection Register.
  • Changes to Lawful Basis: If the legal grounds on which we process your data change, we will update this policy and notify you where required. Should a previously used lawful basis no longer apply, we will immediately cease that specific processing activity.

By using wetravels.co.uk, you acknowledge that your personal data is handled in strict compliance with the UK Data Protection Act 2018 and UK GDPR.


03

Personal Information That We Collect

Personal information refers to any data relating to an identifiable living person who can be identified directly or indirectly (e.g., by name, identification number, location data, or social/economic identity). It does not include completely anonymized or aggregated data.

A. Information You Provide Directly

  • Identity & Contact Details: Full name (as it appears on your passport), title, gender, date of birth, residential address, email address, and telephone/mobile numbers.
  • Travel Documentation: Passport details, nationality, emergency contact details, frequent flyer information, and special service requests.
  • Voluntary Information: Providing optional details is entirely voluntary; however, providing mandatory booking and identity details is necessary for us to issue travel tickets and confirm reservations.

B. Information from Third Parties & Verification Sources

  • Where permitted by UK law, we may supplement the information you provide with data from third-party sources (e.g., identity verification databases, fraud prevention agencies, and demographic data providers) to ensure transaction safety and regulatory compliance.

C. Social Media Interactions & Third-Party Plug-Ins

  • Social Sharing: If you interact with WeTravels via social platforms (such as Meta/Facebook, Instagram, or WhatsApp), those services may transmit limited profile information to us based on your account settings.
  • Video Content & Widgets: If you view embedded content on our site, analytics may be retained in accordance with external platform policies.

D. Providing Data on Behalf of Other Travelers

If you provide personal or travel details for another individual (e.g., family members, colleagues, or travel companions), you must ensure you have their explicit consent and authorization to share their data with WeTravels under this policy.


04

How We Use the Information We Collect

We process your personal information across a range of operational and legal purposes:

A. Core Service Delivery & Contractual Fulfillment

  • To process, confirm, issue, and service your flight bookings, hotel reservations, and travel arrangements.
  • To fulfill our binding contract with you and meet statutory aviation and travel requirements.
  • To provide real-time updates regarding flight schedule changes, cancellations, or baggage policies.
  • To contact you via telephone, email, WhatsApp, or SMS regarding your booking or customer support inquiries.
  • To manage customer care, troubleshoot account issues, resolve disputes, and collect outstanding dues.

B. Legitimate Interests of WeTravels

  • Technical Optimization: Reviewing error logs and site crashes experienced by users to resolve bugs and enhance site speed.
  • Security & Fraud Detection: Monitoring unusual traffic, investigating security breaches, and preventing financial crime or ticket fraud.
  • Personalized Experience: Customizing our site content, flight search recommendations, and interface based on user preferences.
  • Policy & Industry Updates: Reaching out regarding critical regulatory or public policy changes affecting your ability to use travel services.

C. Marketing & Promotional Communications (With Your Consent)

  • With your explicit consent, we may send you targeted travel newsletters, discounted airfares, seasonal promotions, and customer satisfaction surveys via email, SMS, or phone.
  • Right to Withdraw: You retain the right to withdraw your marketing consent at any time by clicking the "Unsubscribe" link in any promotional email or contacting our team at reservations@wetravels.co.uk.

05

How We Might Share Your Personal Information

We do not sell, rent, or trade your personal information to third parties for their independent marketing purposes. We share data only with authorized recipients under strict data processing agreements:

A. Service Providers & Fulfillment Partners

  • Airlines, Consolidators & GDS Partners: Global Distribution Systems (e.g., Amadeus, Sabre) and operating carriers to issue confirmed electronic tickets and manage itinerary changes.
  • Customer Support & IT Infrastructure: Secure cloud hosting, customer relationship management (CRM) software, and communication gateway providers.
  • Payment Processing: Handled directly through certified, PCI-DSS compliant payment gateways. We never store or hold raw credit/debit card numbers on our servers.

B. Legal, Regulatory & Security Disclosures

  • When required by applicable UK or international laws, court orders, or statutory mandates.
  • When necessary to investigate, prevent, or address suspected fraud, security breaches, or illegal transactions.
  • When required to protect the vital interests, safety, or legal rights of our customers, employees, or the public.

06

Business Transfers & Change of Ownership

In the event that WeTravels undergoes a business transition (such as a merger, acquisition, joint venture, reorganization, or asset sale):

  • Customer data may be transferred to the acquiring entity in accordance with international data protection standards.
  • The recipient entity will remain bound by the protections outlined in this Privacy Policy.
  • If your personal information is to be processed for purposes outside the scope of this policy, you will receive prior notification.

07

How Long We Retain Your Personal Information

We retain your personal data only as long as necessary to fulfill the purposes for which it was collected and to satisfy legal, tax, accounting, or reporting obligations.

  • Booking Records & Service Delivery: Retained throughout the duration of your trip and for a subsequent period to handle post-travel inquiries, refunds, or compensation claims.
  • Financial & Accounting Compliance: Kept for 6 to 7 years in compliance with UK tax law (HMRC) and corporate record-keeping requirements.
  • Dispute & Litigation Defense: Retained for the duration of statutory limitation periods under UK contract law.
  • Sensitive/Special Category Data: Retained for the absolute minimum time required to facilitate specific airport assistance or travel arrangements.

Once the retention criteria have expired, your data is securely and permanently deleted, destroyed, or irreversibly anonymized.


08

Security of Your Personal Information

We employ comprehensive technical and organizational measures to safeguard your personal information against unauthorized access, loss, misuse, or alteration:

  • SSL/TLS Encryption: All data transmitted between your browser and our servers is encrypted with modern 256-bit SSL protocols.
  • Access Control: Access to personal records is restricted strictly to authorized employees and contractors who require it for operational duties.
  • Regular Audits & Monitoring: Continuous security monitoring and server vulnerability assessments to protect against unauthorized intrusion.

09

Your Individual Rights Under UK GDPR

Under UK data privacy legislation, you have clear legal rights regarding the personal information we hold about you:

1

Right to be Informed

Transparent information on how your data is collected and processed.

2

Right of Access

Request a formal copy of all personal data held about you (SAR).

3

Right to Rectification

Have inaccurate, incomplete, or outdated details corrected without delay.

4

Right to Erasure

Request deletion of your data when no ongoing legal basis exists.

5

Right to Restrict Processing

Temporarily suspend processing of your data under specific conditions.

6

Right to Data Portability

Receive your personal data in a structured, machine-readable format.

7

Right to Object

Object at any time to processing based on legitimate interests or direct marketing.

8

Automated Decision Rights

Protection against decisions based solely on automated profiling.


10

How to Submit a Request or Contact Us

If you wish to exercise any of your statutory data rights, update your personal details, or ask any questions regarding this policy: