Privacy Policy
Last updated: June 17, 2026
At travel care (a brand of Travel Care IO, S.L.) we process your personal data with respect, transparency and only when there is a legitimate reason to do so. This Privacy Policy explains what data we collect, what we use it for, who we share it with, how long we keep it and how you can exercise your rights.
This processing is governed by Regulation (EU) 2016/679 (the GDPR), Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD) and, as regards electronic services, Law 34/2002 (LSSI). As a travel agency that acts as an intermediary and also organises package travel, some of the data we process is essential to manage your booking in accordance with Directive (EU) 2015/2302 and Royal Legislative Decree 1/2007 (TRLGDCU).
We also recommend that you read our Cookie Policy and our Legal Notice, where you will find the full identifying details of our entity.
Data controller
The controller of your data is Travel Care IO, S.L., a Spanish company operating under the brand travel care. You can find our full identifying details (company name, tax identification number, registered office, registration details, our travel agency registration number and the insolvency guarantee we hold) in the Legal Notice.
For any matter relating to the protection of your data, you can write to us at travel@travelcare.io. We are not required to appoint a Data Protection Officer (DPO) and have not formally designated one, but this email address is our dedicated channel for privacy matters and is handled by the person responsible for them.
Data we process
We only process the data needed to provide you with the service. Depending on your relationship with us, this may include:
- Identity and contact data: first name, surname, sex, email address, telephone number, language and country. Remember that at travel care your email address is your identity: accounts work without a password, using a magic link or a one-time code sent to your email, with an optional second factor (TOTP). We do not store passwords.
- Travellers' data: the details of the people travelling (the lead passenger and any companions), such as name, date of birth, identity document or passport and, where the service requires it, nationality or the country that issued the document. If you provide third-party data, you must have their consent to do so.
- Booking data: the services booked (accommodation, flights, activities, theme-park packages, tours, events), dates, destinations, preferences, special requests and your booking history.
- Payment data: the amount and the method you choose. Card details are processed through PCI-DSS-certified payment gateways (Redsys, Revolut) and are not stored on our systems. For cryptocurrency payments, your wallet address and the transactions are recorded publicly and immutably on the relevant blockchain (see below).
- Usage and device data: IP address, session identifiers, browser type and technical browsing data, collected for security reasons and for the proper functioning of the site.
- Communications: the content of the messages we exchange with you by email, telephone or WhatsApp in order to assist you.
Purposes and legal bases
We process your data for the following purposes, each supported by a legal basis under Article 6 of the GDPR:
- To manage your booking and provide the service (creating your account, contracting with suppliers, handling payments, issuing confirmations and dealing with cancellations). Basis: performance of the contract to which you are a party. For package travel, this processing is also necessary to comply with the organiser's obligations under Directive (EU) 2015/2302 and RDL 1/2007.
- To comply with our legal obligations, in particular accounting, tax, anti-fraud and anti-money-laundering obligations. Basis: compliance with a legal obligation.
- To send you commercial communications about offers and news, manage non-essential cookies and provide you with WhatsApp support. Basis: your consent, which you can withdraw at any time without affecting the lawfulness of processing carried out beforehand.
- To ensure the security of the platform, prevent fraud and improve our services. Basis: legitimate interest, balanced so as not to override your rights and freedoms.
Where the basis is consent or the contract, providing certain data may be mandatory in order to manage the booking; we will tell you in each case and, if you do not provide it, we will not be able to provide the service.
Data retention
We keep your data for as long as our relationship lasts (while you maintain an active account or have current bookings) and, once it ends, for the periods required by law and those needed to address any potential liabilities.
In particular, data linked to accounting and tax obligations is kept for the periods laid down in commercial and tax legislation, and the rest for the limitation periods of any claims that may arise from the contract. Once those periods have elapsed, your data is erased or irreversibly anonymised.
Please note that cryptocurrency payment transactions are recorded permanently on public blockchains, beyond our control (see the section on international transfers).
Recipients of the data
In order to provide the service, we share strictly necessary data with:
- Travel suppliers involved in your booking (hotels and hotel chains, airlines, activity organisers, tour operators and the aggregators that give us access to their inventory), to whom we pass on the data essential to confirm and provide each service.
- Processors that provide us with services under contract and on our instructions: payment gateways (Redsys, Revolut), Microsoft for transactional email, Meta/WhatsApp for the support channel, and hosting and cloud-service providers.
- Public blockchain networks, when you choose to pay with cryptocurrency: the transaction is broadcast and recorded on a public, decentralised network.
- Public authorities and government bodies (judicial, tax or law-enforcement) where there is a legal obligation to provide the information.
We do not sell your data, nor do we share it with third parties for those third parties' own commercial purposes.
International transfers
As a general rule, your data is processed within the European Economic Area (EEA). Where a supplier or processor processes data outside the EEA, it will only do so if there is an adequacy decision by the European Commission or if the appropriate safeguards provided for in the GDPR have been put in place, principally the European Union's Standard Contractual Clauses, together with any additional measures that may be required.
By their very nature, blockchain networks are global and decentralised: when you pay with cryptocurrency, the transaction may be replicated and validated by nodes located anywhere in the world. This dissemination is inherent to the technology and we cannot limit it geographically.
Your rights
You can exercise the following rights over your data at any time:
- Access to the data we process about you.
- Rectification of inaccurate or incomplete data.
- Erasure (the "right to be forgotten") when the data is no longer necessary.
- Restriction of processing in the cases provided for by law.
- Portability of the data you have provided to us, in a structured, commonly used format.
- Objection to processing based on our legitimate interest.
- Withdrawal of consent at any time, with no retroactive effect.
To exercise them, write to us at travel@travelcare.io. We may ask you to prove your identity in order to protect your information. We will respond within a maximum of one month, which may be extended where the request is particularly complex.
If you believe we have not handled your rights properly, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es) or with the supervisory authority in your place of residence.
Automated decisions
To protect the platform and prevent fraud, we may apply automated risk controls to bookings and payments (for example, anti-fraud and security checks).
We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you without human intervention: when one of these controls flags an issue, a person will review the case before any decision is taken.
Minors
Our services are aimed exclusively at people over the age of 18. We do not knowingly create accounts for minors, nor do we intentionally collect their data for the purpose of registering as users.
Minors may appear as travellers on a booking, in which case their data is provided by the responsible adult making the booking, who warrants that they are entitled to do so. If we detect that an account has been created in a minor's name, we will delete it.
Data security
We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss or alteration. These include:
- Encryption of communications in transit.
- Passwordless access (magic link or one-time code) with an optional second factor, meaning we do not store passwords.
- The principle of least privilege for internal access to information, restricted to those who need it for their work.
- The use of PCI-DSS-certified payment gateways, which prevent card details from reaching our systems.
No security measure is infallible, but we work continuously to maintain a level of protection appropriate to the risk.
Changes to this policy
We may update this Privacy Policy to reflect legal, technical or service-related changes. When we do, we will revise the "last updated" date shown at the start of this document; the date shown above corresponds to the latest revision.
If the changes are significant, we will notify you by appropriate means. We recommend that you check this page periodically.
Contact
For any query relating to the protection of your personal data or the exercise of your rights, you can write to us at travel@travelcare.io.
You will find the full identifying details of our entity in the Legal Notice.
Questions about this document?
Our customer care team is here to help.