Skip to main content
HomePrivacy Policy

PrivacyPolicy.

Last Updated: May 2026
Version 2.0

Your privacy is fundamental to the trust you place in us. This policy details exactly how Sri Lankan TripTip handles your personal information — transparently, responsibly, and with the care your data deserves.

01

Introduction

Sri Lankan TripTip ("we," "our," or "us") is committed to protecting your privacy and safeguarding your personal information. This Privacy Policy explains how we collect, use, disclose, and protect data when you access our website, engage with our services, or book a journey through us.

By using our platform or services, you acknowledge you have read and understood this policy. If you do not agree, please refrain from using our services.

We operate under the laws of Sri Lanka, including the Personal Data Protection Act (PDPA), and align with international best practices including the GDPR where applicable to our European guests.

02

Information We Collect

We collect information in the following categories to deliver a seamless, personalised travel experience:

Identity & Contact DataFull name, nationality, passport or national ID number, date of birth, email address, telephone number, and postal address — required for booking and travel documentation.
Booking & Itinerary DataTour preferences, travel dates, accommodation choices, dietary requirements, accessibility needs, and any special requests you submit.
Payment & Financial DataBilling address and transaction records. Card details are processed exclusively by PCI-DSS-compliant third-party payment processors and are never stored on our servers.
Communication DataRecords of correspondence via email, WhatsApp, web contact forms, or phone, including enquiries, feedback, and complaints.
Technical & Usage DataIP address, browser type, operating system, referring URLs, pages visited, time spent on site, and device identifiers — collected automatically via cookies and analytics.
Preferences & Marketing DataYour communication preferences, newsletter subscription status, and any survey responses you voluntarily provide.
03

How We Use Your Information

We process your data only for lawful, specified purposes. Our primary uses include:

  • Processing and managing tour bookings, taxi transfers, and custom travel itineraries
  • Confirming reservations, issuing vouchers, and providing pre-travel documentation
  • Processing payments and issuing invoices and receipts
  • Communicating itinerary updates, travel advisories, and operational notifications
  • Personalising your experience and recommending destinations aligned with your preferences
  • Sending promotional newsletters and special offers — only with your explicit consent
  • Conducting satisfaction surveys and gathering feedback to improve our services
  • Complying with Sri Lankan immigration, tourism, and tax regulations
  • Detecting, investigating, and preventing fraudulent or unlawful activity
  • Improving our website through aggregated, anonymised analytics
04

Information Sharing & Disclosure

We do not sell, rent, or trade your personal information. We share data only under strictly defined circumstances:

Travel & Hospitality Partners

Hotels, transport operators, guides, and activity providers who are part of your booked itinerary — limited to information operationally necessary for your trip.

Payment Processors

Authorised third-party payment gateways operating under PCI-DSS standards. We never have access to your full card numbers.

Technology Service Providers

Cloud hosting, email delivery, CRM, and analytics platforms bound by data processing agreements and prohibited from using your data for their own purposes.

Legal & Regulatory Authorities

Government bodies, immigration authorities, or law enforcement when required by law, court order, or to protect the safety of our guests and staff.

Business Transfers

In the unlikely event of a merger, acquisition, or asset sale, your data may transfer to the successor entity, subject to equivalent privacy protections.

05

Cookies & Tracking Technologies

Our website uses cookies and similar technologies to enhance functionality, analyse traffic, and improve user experience. We use the following categories:

TypePurposeRequired
EssentialSession management, security, booking flow integrityYes
FunctionalLanguage preferences, saved itinerary drafts, chat sessionsNo
AnalyticsAggregated site usage via Google Analytics (anonymised)No
MarketingRetargeting pixels for promotional campaigns (opt-in only)No

You may manage cookie preferences through your browser settings. Disabling non-essential cookies will not affect your ability to make bookings but may limit personalised features.

06

International Data Transfers

Sri Lankan TripTip is headquartered in Matara, Sri Lanka. If you are accessing our services from outside Sri Lanka — including the European Economic Area, United Kingdom, or Australia — your data may be transferred to and processed in Sri Lanka.

We apply appropriate safeguards for international transfers, including standard contractual clauses and data processing agreements with all third-party processors. Where required by the GDPR, we rely on adequacy decisions or other approved transfer mechanisms.

By engaging with our services, you acknowledge and consent to such transfers, which are necessary to fulfil your booking and deliver the services you have requested.

07

Data Retention

We retain your personal data for only as long as necessary to fulfil the purposes for which it was collected, or as required by law:

Booking & transactional records7 years (Sri Lankan tax and accounting obligations)
Customer communication records3 years after last interaction
Marketing & consent recordsUntil withdrawal of consent + 1 year
Website analytics data26 months (industry standard)
Enquiries without bookings12 months

Upon expiry, data is securely deleted or anonymised in accordance with our internal data destruction policy.

08

Your Privacy Rights

Subject to applicable law, you hold the following rights regarding your personal data. We will respond to all verifiable requests within 30 days:

Right of Access

Request a copy of the personal data we hold about you.

Right to Rectification

Correct inaccurate or incomplete information.

Right to Erasure

Request deletion of your data where no legal obligation requires retention.

Right to Restriction

Request that we limit processing of your data in certain circumstances.

Right to Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing for direct marketing or legitimate interests.

Withdraw Consent

Withdraw consent for marketing at any time without affecting prior lawful processing.

Right to Complain

Lodge a complaint with your national data protection authority.

To exercise any of these rights, contact us at info@srilankantriptip.com.

09

Data Security

We implement industry-standard technical and organisational measures to protect your personal data against unauthorised access, accidental loss, alteration, or disclosure:

  • TLS 1.3 encryption for all data in transit between your browser and our servers
  • AES-256 encryption for sensitive data stored at rest
  • Regular penetration testing and vulnerability assessments by independent auditors
  • Strict role-based access controls — staff access only the data necessary for their function
  • Multi-factor authentication required for all internal system access
  • Automated monitoring and alerting for suspicious activity
  • Formal incident response plan with guest notification within 72 hours of confirmed breach

While we apply robust safeguards, no system is entirely immune from risk. We encourage you to use strong, unique passwords and to contact us immediately if you suspect any unauthorised access to your account.

10

Third-Party Services & Links

Our website may contain links to third-party websites including hotel partners, activity providers, and review platforms such as TripAdvisor. This Privacy Policy does not apply to those external sites.

We are not responsible for the privacy practices of third-party services. We encourage you to review their privacy policies before sharing any personal information. Our partnerships with these services are purely to enhance your travel experience.

We integrate with the following third-party services that may independently collect data: Google Analytics (website analytics), Google Maps (location and directions), Supabase (secure data storage), and Resend (transactional email delivery). Each operates under their own privacy framework.

11

Children's Privacy

Our services are designed for adults and are not directed at children under the age of 16. We do not knowingly collect personal data from minors without verifiable parental or guardian consent.

When a booking includes children as travellers, we collect their travel documentation details (name, date of birth, passport number) solely for the purpose of fulfilling the tour and complying with Sri Lankan entry requirements. This data is treated with the same — or greater — level of protection as adult data.

If you believe we have inadvertently collected data from a child without proper consent, please contact us immediately and we will delete the information promptly.

12

Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or business operations. The "Last Updated" date at the top of this page will always reflect the most recent revision.

For material changes that significantly affect how we use your data, we will notify you by email (if we hold your email address) or by placing a prominent notice on our website at least 30 days prior to the changes taking effect.

Your continued use of our services after the effective date of any changes constitutes your acceptance of the revised policy.

13

Contact & Data Controller

Sri Lankan TripTip acts as the Data Controller for all personal information collected through our platform. For privacy-related enquiries, data subject requests, or to raise a concern:

Address

Madiha, Matara Sri Lanka 81000

We aim to respond to all privacy requests within 5 business days and resolve them within 30 days. For unresolved concerns, you retain the right to escalate to your national data protection authority.

Our Commitment

Privacy is not a legal checkbox for us — it is an extension of the respect we show every guest. We will never exploit your data for profit. Your trust is the foundation of every journey we craft.