Privacy Policy

Last Updated: February 2025

Our Commitment to Privacy

GraandVooyager is committed to protecting your personal data and respecting your privacy. This policy explains how we collect, use, store, and protect your information when you use our luxury travel services.

We understand that booking transformative travel experiences requires trust, and we take our responsibility to safeguard your personal information seriously. This policy applies to our website, services, and all interactions with GraandVooyager.

For any privacy-related questions or concerns, please contact us at [email protected] or +65 6829 4576.

Information We Collect

Personal Information You Provide

We collect information you directly provide to us when you:

  • Contact Information: Name, email address, phone number, mailing address
  • Travel Information: Passport details, emergency contacts, travel preferences, dietary requirements
  • Payment Information: Billing address, payment method details (processed securely through third-party providers)
  • Communication Data: Messages sent through contact forms, email correspondence, phone call records

Information We Automatically Collect

When you visit our website, we automatically collect:

  • Usage Data: IP address, browser type, device information, pages visited, time spent on pages
  • Cookie Data: Preferences, session information, and analytics data (see our Cookie Policy)
  • Location Data: General geographic location based on IP address (not precise location)

How We Use Your Information

Primary Service Delivery

  • Plan and organize your luxury travel experiences
  • Communicate with you about your bookings and travel arrangements
  • Process payments and manage financial transactions
  • Provide customer support and respond to inquiries

Service Improvement & Personalization

  • Analyze website usage to improve our services and user experience
  • Personalize travel recommendations based on your preferences
  • Develop new services and travel experiences

Legal and Business Operations

  • Comply with legal requirements and regulatory obligations
  • Maintain business records and financial reporting
  • Protect against fraud, security threats, and legal claims

Data Protection & Security

Security Measures

We implement comprehensive security measures to protect your personal information:

  • Encryption: All data transmission uses SSL/TLS encryption protocols
  • Secure Storage: Data stored on secure servers with restricted access controls
  • Access Controls: Limited employee access on a need-to-know basis
  • Regular Monitoring: Continuous security monitoring and vulnerability assessments
  • Incident Response: Procedures for immediate response to any security breaches

Data Retention

We retain your personal data only as long as necessary for the purposes outlined in this policy:

  • Contact form submissions: 3 years from last interaction
  • Service records and bookings: 5 years for customer service and legal compliance
  • Financial records: 7 years as required by Singapore tax regulations
  • Marketing communications: Until consent is withdrawn
  • Website analytics: 26 months maximum

Breach Notification

In the unlikely event of a data breach that poses a risk to your privacy, we will notify relevant authorities within 72 hours and affected individuals without undue delay, as required by applicable data protection laws.

Legal Basis for Processing

We process your personal data based on the following legal grounds:

Consent

For marketing communications, cookies (except essential), and optional data processing activities

Contractual Necessity

To provide travel services, process bookings, and fulfill our service agreements

Legitimate Interest

For business operations, service improvement, fraud prevention, and customer support

Legal Obligation

For tax compliance, regulatory reporting, and legal requirements

Third-Party Services & Data Sharing

We work with trusted third-party service providers to deliver our services. We only share necessary information and require all partners to maintain strict confidentiality:

Service Partners

  • Accommodation providers and monasteries
  • Transportation and expedition operators
  • Local guides and cultural liaisons
  • Travel insurance providers

Technology Partners

  • Payment processors (Stripe, PayPal)
  • Email service providers
  • Cloud hosting and storage services
  • Analytics providers (Google Analytics)

We never sell your personal information to third parties. Data sharing is limited to what's necessary for service delivery and always governed by strict contractual agreements.

Your Privacy Rights

Under applicable data protection laws, you have several rights regarding your personal information:

Right to Access

Request access to your personal data and information about how we process it

Right to Rectification

Request correction of inaccurate or incomplete personal data

Right to Erasure

Request deletion of your personal data under certain circumstances

Right to Data Portability

Receive your personal data in a structured, machine-readable format

Right to Object

Object to processing of your personal data for marketing or legitimate interests

Right to Withdraw Consent

Withdraw consent at any time where processing is based on consent

How to Exercise Your Rights

To exercise any of these rights, please contact us using the information below. We will respond to your request within 30 days.

  • Email: [email protected]
  • Phone: +65 6829 4576
  • Address: 168 Orchard Boulevard, Singapore 248653

International Data Transfers

Some of our service providers and travel partners are located outside Singapore. When we transfer your personal data internationally, we ensure appropriate safeguards are in place:

  • Adequacy Decisions: Transfers to countries recognized by Singapore as having adequate data protection
  • Standard Contractual Clauses: Binding agreements with international partners for data protection
  • Privacy Shield & Similar Frameworks: Certified providers with recognized data protection standards

Policy Updates

We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Notify you via email at least 30 days before changes take effect
  • Post the updated policy on our website with the revision date
  • Highlight significant changes in the notification

Your continued use of our services after policy changes indicates acceptance of the updated terms.

Contact & Complaints

Data Protection Officer

For all privacy-related inquiries, data protection concerns, or to exercise your rights, please contact our Data Protection Officer:

Supervisory Authority

If you're not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with the relevant data protection authority: