DRC Tourism

    Trust & Privacy

    Privacy & Data Handling

    DRC Tourism collects only the personal data needed to answer your enquiry, deliver a booking and meet legal obligations. Data is stored encrypted on EU-hosted infrastructure, never sold or shared with advertisers, and you can access, correct or delete it at any time by emailing privacy@drctourism.com. Payment card numbers are never stored by us — they are handled by PCI-DSS-compliant processors (Stripe, PayPal).

    Six Data-Handling Principles

    Data Minimisation

    We collect only what a booking or enquiry actually needs. No hidden fields, no pre-ticked marketing opt-ins.

    Encryption Everywhere

    256-bit SSL in transit, encryption at rest on the database, PCI-DSS processors for payment credentials.

    Essential Cookies Only

    Session and language cookies. No ad-tech, no cross-site tracking, no behavioural profiling.

    Your Rights, Respected

    Access, correction, deletion, portability and objection — all honoured within 30 days, at no cost.

    EU-Hosted Infrastructure

    Data lives on EU-based cloud infrastructure with role-based access, Row Level Security and audit logging.

    Clear Marketing Consent

    Newsletter is opt-in only, single-click unsubscribe in every email, and separate from booking communications.

    What We Collect and Why

    DataWhy we need it
    Name, email, phone, countryReply to your enquiry, issue booking confirmations, contact you during the trip.
    Trip details you submit (dates, corridors, budget)Match you with the right verified operator and produce an itinerary.
    Booking reference & masked payment tokenReconcile your deposit and balance payments. Card numbers themselves stay with Stripe / PayPal.
    Newsletter opt-inOnly sent if you tick the box. Unsubscribe anywhere with one click.
    Basic technical data (browser, language, session)Keep the site functional and accessible. Not used for advertising or profiling.

    Who Sees Your Data

    Access is limited to the parties who actually need it to deliver your trip:

    • The verified operator fulfilling your specific trip — receives only what they need to run your logistics (name, contact, dates, dietary and mobility notes).
    • Payment processors — Stripe and PayPal handle card data on their own PCI-DSS infrastructure.
    • Email infrastructure — Resend delivers your booking confirmations and any newsletter you opted in to.
    • Legal authorities — only when compelled by valid legal process.

    We never sell, rent or trade your data. There is no advertising business built on top of drctourism.com.

    Your Rights (GDPR & Equivalent)

    • Access — a copy of the data we hold about you.
    • Correction — fix anything that is wrong or out of date.
    • Deletion — erase your data, unless we are legally required to retain it (e.g. tax records for 7 years).
    • Portability — receive your data in a machine-readable format.
    • Objection — object to any specific processing, including all marketing.
    • Withdraw consent — at any time, with no impact on the lawfulness of prior processing.

    Email privacy@drctourism.com. We respond within 30 days at no cost. If you are not satisfied, you can complain to your national data protection authority.

    Security Measures

    • 256-bit SSL/TLS on every request.
    • Encryption at rest on the primary database.
    • Row Level Security so operators cannot see one another's bookings and travellers cannot see other travellers' data.
    • PCI-DSS-compliant payment processors — card numbers never touch our servers.
    • Least-privilege staff access, audit logging on sensitive tables, and mandatory two-factor authentication for administrative accounts.
    • Regular dependency and security scanning.

    Privacy Questions or Requests

    Email our privacy team directly. We reply within one business day and resolve formal requests within 30 days.

    Related: Booking Protection & Refunds · Terms of Service.

    Frequently Asked Questions

    What personal data does DRC Tourism collect about me?

    Only what we need to answer you and deliver a booking: your name, email, phone, country, the trip details you submit, and — if you pay a deposit — a booking reference plus a masked payment token from our processor. Basic technical data (browser, language, session) is collected automatically to keep the site working.

    Do you sell my data or share it with advertisers?

    No. DRC Tourism does not sell, rent or trade personal data. We do not run behavioural advertising, third-party ad networks or profiling. The only external parties who see your data are the specific verified operator fulfilling your trip, our payment processors (Stripe, PayPal) and our email infrastructure (Resend) — and only for the parts they need.

    How long do you keep my data?

    Booking records are retained for 7 years to satisfy tax and legal obligations. Marketing consent (newsletter) is retained until you unsubscribe. Contact-form messages are kept for 24 months then deleted. You can request earlier deletion at any time.

    Can I get a copy of my data or ask you to delete it?

    Yes. Under GDPR and equivalent laws, you can request access, correction, deletion, portability or restriction of your data. Email privacy@drctourism.com — we respond within 30 days. Deletion requests that would break an active booking are honoured after the trip completes.

    Where is my data stored?

    On EU-hosted infrastructure (Lovable Cloud / Supabase, hosted in the European Union), with encryption at rest and in transit. Payment data is held by our PCI-DSS-compliant processors on their own infrastructure — we never store card numbers ourselves.

    Do you use tracking cookies or analytics?

    We use only essential cookies (session, language preference) and a privacy-first analytics setup that does not track individuals across sites. There is no Facebook Pixel, no ad-network tag and no cross-site profiling on drctourism.com.

    How is my data protected?

    256-bit SSL for every request, encryption at rest for the database, role-based access with Row Level Security so operators only see their own bookings, least-privilege access for staff, and audit logging on sensitive tables. Payment credentials never touch our servers.

    Who do I contact about privacy?

    Email privacy@drctourism.com. For urgent security concerns (e.g. suspected account compromise) also copy security@drctourism.com. You can raise a complaint with your national data protection authority if you are not satisfied with our response.

    Plan With Confidence