What personal data does DRC Tourism collect about me?
Only what we need to answer you and deliver a booking: your name, email, phone, country, the trip details you submit, and — if you pay a deposit — a booking reference plus a masked payment token from our processor. Basic technical data (browser, language, session) is collected automatically to keep the site working.
Do you sell my data or share it with advertisers?
No. DRC Tourism does not sell, rent or trade personal data. We do not run behavioural advertising, third-party ad networks or profiling. The only external parties who see your data are the specific verified operator fulfilling your trip, our payment processors (Stripe, PayPal) and our email infrastructure (Resend) — and only for the parts they need.
How long do you keep my data?
Booking records are retained for 7 years to satisfy tax and legal obligations. Marketing consent (newsletter) is retained until you unsubscribe. Contact-form messages are kept for 24 months then deleted. You can request earlier deletion at any time.
Can I get a copy of my data or ask you to delete it?
Yes. Under GDPR and equivalent laws, you can request access, correction, deletion, portability or restriction of your data. Email privacy@drctourism.com — we respond within 30 days. Deletion requests that would break an active booking are honoured after the trip completes.
Where is my data stored?
On EU-hosted infrastructure (Lovable Cloud / Supabase, hosted in the European Union), with encryption at rest and in transit. Payment data is held by our PCI-DSS-compliant processors on their own infrastructure — we never store card numbers ourselves.
Do you use tracking cookies or analytics?
We use only essential cookies (session, language preference) and a privacy-first analytics setup that does not track individuals across sites. There is no Facebook Pixel, no ad-network tag and no cross-site profiling on drctourism.com.
How is my data protected?
256-bit SSL for every request, encryption at rest for the database, role-based access with Row Level Security so operators only see their own bookings, least-privilege access for staff, and audit logging on sensitive tables. Payment credentials never touch our servers.
Who do I contact about privacy?
Email privacy@drctourism.com. For urgent security concerns (e.g. suspected account compromise) also copy security@drctourism.com. You can raise a complaint with your national data protection authority if you are not satisfied with our response.