Privacy Policy
Last updated: August 2026
1. Introduction
ReadyTrip ("we", "our", or "us") provides a global marketplace for discovering and booking travel activities, tours, tickets and experiences at ReadyTrip.com (the "Platform"). This Privacy Policy explains what personal data we collect, how and why we store and use it, who we share it with, and your rights. The data controller for the processing described here is Travel Pass Inc, 8 The Green, Dover, DE 19901, USA ("ReadyTrip"). We aim to comply with applicable data-protection laws worldwide, including the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA), to the extent they apply to you.
2. Information we collect
Information you provide
- Account data: name, email address, password, and (for social login) the basic profile your provider shares.
- Booking data: the Products you book, contact details (name, email, phone), booking references and vouchers.
- Traveller details: some experiences require per-traveller information the supplier asks for (for example names, nationality, date of birth or passport/ID number for attraction entry, and dietary preferences for meal-inclusive experiences). You provide these at checkout for each traveller on the booking, including any child travellers you book for.
- Payment data: processed by our payment providers; we receive confirmation and limited details (such as card type and last digits) but do not store complete card numbers.
- Content & communications: reviews, ratings, photos, contact-form messages, newsletter sign-ups and support correspondence.
- eSIM plan data: when you buy a travel eSIM we record the plan you bought and the eSIM identifiers issued to you (such as the ICCID and your QR/activation code) so we can deliver them and support you. We do not collect your device's IMEI or EID, and we do not see the content of your internet traffic — your data session is carried by the mobile network operator at your destination, which handles it under its own terms and local telecoms law.
Information collected automatically
- Usage data: pages viewed, searches, items viewed/saved, referring URLs and interactions.
- Device & connection data: IP address, browser, operating system, device type and approximate location (including country, e.g. from network signals) to set your currency/language.
- Cookies & similar technologies: see our Cookie Policy. Some data is stored in your browser (for example recent searches).
3. How we use your information
- To operate the Platform and process, confirm and fulfil your bookings;
- To take payment, prevent fraud, and provide customer support;
- To personalise content, currency and language, and remember your preferences;
- To send transactional messages and, with your consent where required, marketing and newsletters;
- To measure and improve our services through analytics;
- To advertise our services and measure ad performance, including retargeting (see section 5);
- To comply with legal obligations and enforce our terms.
4. Legal bases (GDPR/UK GDPR)
- Performance of a contract: to create your account and process bookings;
- Consent: for marketing emails and non-essential (analytics/advertising) cookies;
- Legitimate interests: to secure, analyse and improve the Platform and to market our services proportionately;
- Legal obligation: for tax, accounting and compliance.
5. Analytics & advertising
We use analytics and advertising technologies to understand how the Platform is used and to promote our services. These include Google Analytics 4 and the Meta (Facebook) Pixel, which set cookies/identifiers and may share event data (such as page views, searches and purchases) with those providers acting as independent controllers or our processors. In our mobile app, we use Google Analytics for Firebase for the same purpose. We and these partners may use this data for measurement and for advertising and retargeting — showing you ReadyTrip ads on other sites and platforms based on your activity. None of these technologies load until you accept them in the cookie banner shown on your first visit (or the analytics setting in the app); choosing "Essential only" keeps the Platform fully functional without them, and you can withdraw your choice at any time as described in section 11 and in our Cookie Policy.
6. How we share your information
We do not sell your personal data for money. We share it only as needed:
- Operators & suppliers: the third parties who fulfil your booking receive the details necessary to deliver the experience — including our ticketing supplier GlobalTix (Singapore) for many attractions, and the local operator running your activity. Where a supplier requires traveller details (section 2), those details are passed to that supplier;
- Service providers (processors): hosting and infrastructure (Cloudflare — including database, storage, image and edge services), payment processing (Stripe; and PayU for payments in Indian Rupees — PayU may additionally collect details it needs directly from you on its own checkout page under its own privacy policy), email delivery (Resend), search infrastructure (Typesense — no customer data is indexed), and customer-support tools;
- Analytics & advertising partners: Google (Analytics on the website, Firebase Analytics in the app) and Meta, as described in section 5 — only after you consent;
- Legal & safety: where required by law, to respond to lawful requests, or to protect the rights, property or safety of ReadyTrip, our users or the public;
- Business transfers: in connection with a merger, acquisition or sale of assets, subject to this policy.
eSIM plans
Our eSIM supplier, eSIM Access (a Redtea Mobile service), provisions the plans we sell. When you buy one we send it only a booking reference and the plan code — no name, email, phone number or payment details — and it returns the eSIM identifiers and activation code we pass on to you. Once you install and use the eSIM, the mobile network operators carrying your data at your destination process connection and traffic data as independent controllers under their own terms and the telecoms law of that country, which we do not control.
Transport links to 12Go
Bus, train, ferry, transfer and flight tickets are booked on a different website, operated by 12Go Asia Pte. Ltd. (Singapore, UEN 201228224R) — including readytrip.12go.asia and 12Go's own domains. When you follow a transport link you leave ReadyTrip. From that point:
- Any details you enter — passenger names, contact details, travel documents and payment details — are collected by 12Go as an independent data controller under 12Go's own privacy policy, not this one. We do not receive them, and we cannot access, correct or delete them. Exercise your data rights for a transport booking with 12Go directly.
- Our links carry a partner tracking code so 12Go can attribute a booking to us and pay our commission. 12Go may store that code, and identifiers such as your IP address and device, in its own cookies on its own domain under its policies. We may in turn receive aggregate reporting from 12Go — bookings, routes and commission — which does not identify you to us.
- If you have accepted analytics or advertising cookies on ReadyTrip (section 5), we may also record that you clicked a transport link, as an event on our own site, to measure which pages perform. If you chose "Essential only", we do not.
Note: sharing data with advertising partners through cookies/pixels may be considered a "sale" or "sharing" of personal information under some US state laws. You can opt out (see section 11).
7. Where we store and process data (international transfers)
ReadyTrip is a global service. Your data — including account, booking and content data — is stored and processed on cloud infrastructure (Cloudflare's global network, headquartered in the United States) and by the providers in section 6. In particular, data may be transferred to the United States (Cloudflare, Stripe, Resend, Google, Meta), Singapore (GlobalTix, for bookings it fulfils; and 12Go, for transport bookings you make on its own site) and India (PayU, for INR payments). Buying an eSIM does not transfer personal data to our eSIM supplier, because none is sent to it (section 6); using the eSIM means the mobile network operator in your destination country processes your connection data there under local law. Where we transfer personal data from the EU/UK to countries without an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses. You can request a copy of the safeguards applicable to your data by emailing [email protected].
8. Data retention
We keep personal data only as long as necessary for the purposes above or as required by law:
- Account data: kept while your account is active; deleted/anonymised when you delete your account (section 9);
- Booking & payment records: booking totals, references, status and payment/refund records are kept for 7 years after the transaction as tax and accounting law requires; when you delete your account or request erasure, the personal details on them (name, email, phone, traveller answers, marketing attribution) are removed while the financial figures are retained against an anonymous record;
- Credit & referral ledger: kept for 7 years after the last entry (accounting and anti-double-spend), against an anonymous record; any unused credit is forfeited when you delete your account (you are asked to confirm this);
- Support conversations: redacted on erasure; retained for up to 24 months after closure only where a dispute or security rule applies;
- Fraud and abuse signals: kept for up to 24 months after the last event (legitimate interest in preventing repeat abuse);
- Operational logs (email delivery, audit and activity logs): retained for 12 months, then archived for up to a further 12 months in pseudonymised form (email addresses replaced by a keyed hash, free text removed) before permanent deletion;
- Marketing opt-out: when you unsubscribe or your account is erased we keep a keyed hash of your email address (not the address itself) so we can honour your choice if the address ever re-enters our systems;
- Privacy request records: a pseudonymous record of each access/erasure request (dates, type, outcome — no personal details once complete) is kept for 36 months to show it was handled;
- Sessions & sign-in codes: revoked immediately on sign-out or account deletion and deleted automatically on expiry;
- Backups: our infrastructure provider keeps point-in-time backups for up to 30 days; erased data may persist there, inaccessibly, until they expire, and is erased again if a backup is ever restored;
- Analytics data: retained per the provider's settings, in aggregated or pseudonymised form.
9. Your rights
Depending on where you live, you may have the right to:
- Access the data we hold about you;
- Correct inaccurate data;
- Delete your data;
- Restrict or object to certain processing;
- Port your data to another service;
- Withdraw consent at any time;
- Opt out of marketing, and of the "sale"/"sharing" of personal information and targeted advertising.
You can download a copy of your data and delete your account yourself at any time from your account settings (Privacy & data) — see Data Deletion for the step-by-step — and correct your name and phone number there too. Both actions ask you to confirm with a code we email you, so a stolen session alone cannot export or erase your data. When you delete your account, every session is signed out immediately, your sign-in is removed and personal details are deleted or anonymised as described in section 8; you receive a request reference for any follow-up with our providers. For anything else — or if you don't have an account — email [email protected]: we verify that you control the email address on the booking or account, and respond within one month (extendable by up to two further months for complex requests, in which case we tell you within the first month). You also have the right to lodge a complaint with your local data-protection authority.
10. Security
We use appropriate technical and organisational measures — including encryption in transit, access controls and reputable infrastructure providers — to protect your data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
11. Managing cookies, marketing & ads
- Manage cookies via your browser and our cookie controls — see the Cookie Policy;
- Unsubscribe from marketing emails using the link at the bottom of any marketing message, or your email app's one-click unsubscribe — this stops offers, reminders and review requests, and never affects booking, ticket, refund or security emails;
- Control ad personalisation at Google Ads Settings and Meta Ad Preferences, and via industry opt-outs (e.g. youradchoices.com / youronlinechoices.eu).
12. Children's privacy
ReadyTrip accounts and bookings are for adults: you must be 18 or older to create an account or make a booking. Children cannot use the Platform themselves. When you book family experiences, you — as the adult booker — may provide traveller details for child travellers where a supplier requires them (for example a child's name or date of birth for an age-based ticket). We process those details only to fulfil that booking, on the basis of our contract with you, and you confirm you hold parental responsibility (or the parent's permission) for any child you book for. Child traveller details are removed along with the rest of your data when you delete your account or request erasure. If you believe a child has used the Platform directly, contact us and we will delete their data.
13. Changes to this policy
We may update this policy from time to time. Material changes will be posted here with a revised "Last updated" date.
14. Contact us
- Controller: Travel Pass Inc, 8 The Green, Dover, DE 19901, USA
- Email: [email protected]
- Page: Contact

