Skip to content

Privacy policy

1. Data controller

Agencia de Viajes Ingrid Travel 81, S.L.U. (hereinafter "Ingrid Travel"), with tax ID B56216047, registered office at Calle Alonso Zamora Vicente 9, 28702 San Sebastián de los Reyes (Madrid) and travel agency licence C.I.C.MA 4505, is the controller of the personal data you provide through this website.

You can contact us at info@ingridtravel.com for any matter related to the protection of your data.

2. Data we process

  • Contact and booking data: first name, surname, email, phone and preferred language.
  • Traveller data: full name, date of birth, nationality and document number (ID card or passport), required to issue tickets and contract travel services.
  • Payment data: card payments are processed through Stripe; Ingrid Travel does not store full card details on its servers.
  • Account data (customer area): if you register, we process your email and an encrypted password (never in plain text), your email verification status, the travellers you save (name, document, date of birth), your favourite destinations and the references of the cards you save with Stripe (payment method identifiers; never the full card number, which is stored solely by Stripe).
  • Browsing data: IP address (pseudonymised), language and flight search data, for statistical and security purposes.

3. Purposes and legal basis

Purpose Legal basis
Managing quotes, bookings and ticket issuance Performance of a contract (art. 6.1.b GDPR)
Invoicing and tax obligations Legal obligation (art. 6.1.c GDPR)
Customer service before, during and after the trip Performance of a contract and legitimate interest (art. 6.1.f GDPR)
Usage statistics and site security Legitimate interest (art. 6.1.f GDPR)
Commercial communications, where authorised Consent (art. 6.1.a GDPR)

4. Recipients

To provide the contracted services, we share the strictly necessary data with: airlines and distribution systems (GDS), hotels and tourism suppliers at the destination, the Stripe payment gateway, and public authorities where legally required. Some suppliers (for example, airlines from third countries) may be located outside the European Economic Area; in that case the transfer is necessary for the performance of the travel contract (art. 49.1.b GDPR).

5. Retention periods

Booking and invoicing data are kept for the periods required by tax and consumer regulations (generally 6 years under the Spanish Commercial Code). Browsing data are kept for a maximum of 12 months. Data for commercial communications are kept until you withdraw your consent.

6. Your rights

You may exercise at any time your rights of access, rectification, erasure, objection, restriction of processing and portability by writing to info@ingridtravel.com, attaching a copy of your identity document. You are also entitled to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).

7. Customer area, account and right to erasure

If you create an account, we manage access via email and password with prior verification of your email address. From your customer area you can view your bookings, manage your saved travellers and cards (of which we only keep Stripe references) and your favourites.

You may request the deletion of your account at any time. When you do, we will irreversibly anonymise your personal data: your profile, travellers, favourites and payment references will no longer be linked to an identifiable person. However, we will retain the minimum booking and invoice data for the periods required by tax and commercial law (generally 6 years), as there is a legal retention obligation that prevails over the right to erasure in respect of those documents (art. 17.3.b GDPR).

8. Security

We apply appropriate technical and organisational measures in accordance with the GDPR and Spanish Organic Law 3/2018 (LOPDGDD): TLS encryption on all communications, access control, IP pseudonymisation and periodic audits.