Privacy Policy

Last updated: August 2026

Our Promise to You

We are committed to protecting your privacy and handling your personal information with care, transparency and respect. Our promise to you is to:

  • Hold your data securely.
  • Share it only where you agree or where we must in order to deliver your travel arrangements.
  • Use it to tailor the information we provide, arrange your travel and improve our services.
  • Put you in control by allowing you to access, update, restrict, object to and delete your data.

Please read this policy carefully. If you book on behalf of others, you are responsible for ensuring that they are aware of its contents and agree to you supplying their personal data to make a booking or enquiry. This policy is published in English only to ensure consistency of interpretation.

1. Who We Are

Global Travel Moments is a trading name of @LUXURYLONDONGUY LTD, a company registered in England and Wales. We are the data controller for the personal information described in this policy, which means we decide how and why it is processed.

Legal entity: @LUXURYLONDONGUY LTD, trading as Global Travel Moments

Company number: 11333275

VAT number: 326199584

ICO registration number: ZC111050

Registered office: 162-164 High Street, Rayleigh, Essex, SS6 7BS, United Kingdom

Correspondence address: Global Travel Moments, c/o Global Travel Collection, 101 St. Martin’s Lane, London, WC2N 4AZ, United Kingdom

Data protection contact: marketing@globaltravelmoments.com

We are not required to appoint a Data Protection Officer. Responsibility for data protection sits with the Director, who can be reached using the contact details above.

2. The Information We Collect

2.1 Information you give us

This is what you provide when you enquire, book, or otherwise deal with us. It typically includes your name, postal address, email address, telephone number, date of birth, passport details, payment information, and your travel preferences and arrangements.

2.2 Special category information

In some cases we need more sensitive information — for example medical conditions, disabilities, mobility requirements, or dietary requests that may indicate religious or philosophical beliefs. We collect this only where it is necessary to arrange your travel safely and to your requirements.

Where we process special category information, we do so on the basis of your explicit consent, which we will ask for separately and clearly at the point of collection. You may withdraw that consent at any time, although this may affect our ability to arrange elements of your trip. We keep the collection of this information to a minimum and handle it with additional care.

2.3 Information we collect automatically

When you visit our website, we may collect your IP address, browser type and version, time zone, device information, the pages and products you view, search terms, and how you interact with the site. This is collected using cookies and similar technologies, which are explained in Section 8.

2.4 Information from third parties

We may receive your information from people you have authorised to share it — a travel companion, someone booking on your behalf, a corporate travel coordinator, or one of our promotional partners. We may also receive it from someone who refers you to us, in which case we ask them to confirm that you are happy to hear from us.

3. How and Why We Use Your Information

Data protection law requires us to have a valid reason — a "lawful basis" — for everything we do with your information. Set out below is what we use it for, grouped by the basis we rely on.

3.1 To perform our contract with you, or take steps before entering one

  • Responding to your enquiry and preparing a proposal or quotation.
  • Processing and administering your booking, and issuing itineraries, confirmations and invoices.
  • Sharing your details with airlines, hotels, ground operators, cruise lines and other suppliers so your arrangements can be delivered.
  • Taking payment and issuing refunds.

3.2 Because we have a legitimate interest in running our business well

  • Personalising our service based on your travel history and preferences.
  • Conducting customer satisfaction surveys and improving what we offer.
  • Marketing similar services to existing clients (you can opt out at any time).
  • Preventing fraud and verifying identity.
  • Establishing or defending legal claims and protecting our rights.
  • Business administration, systems testing, IT maintenance and staff training.
  • Where we rely on legitimate interests, we have considered whether our interests are overridden by your rights and freedoms. You can ask us for details of that assessment, and you have the right to object — see Section 9.

3.3 Because you have given us your consent

  • Arranging accessibility, medical or dietary requirements (explicit consent).
  • Sending you marketing where you are not an existing client.
  • Setting non-essential cookies on our website.
  • You can withdraw consent at any time. Doing so will not affect anything we did before you withdrew it.

3.4 Because the law requires it

  • Maintaining accounting and tax records.
  • Meeting anti-money laundering, sanctions and fraud prevention obligations.
  • Responding to lawful requests from regulators, border agencies, law enforcement and the courts.

4. Who We Share Your Information With

We do not sell your personal information. We share it only where it is necessary to deliver your travel arrangements, to run our business, or where the law requires it.

4.1 Travel suppliers and partners

Airlines, hotels, resorts, villa operators, cruise lines, rail operators, destination management companies, tour operators, transfer providers, insurers and other suppliers involved in your trip. These organisations are usually independent data controllers in their own right and will handle your information under their own privacy policies.

4.2 Host agency and consortia

We operate in association with Global Travel Collection and are a member of travel industry consortia. Your booking information may be processed by these organisations for ticketing, accreditation, supplier relationships, commission reconciliation and client benefits.

4.3 Technology providers

We use a small number of trusted providers to run our business. Other than as noted below in respect of AI tools, each is engaged under a written data processing agreement requiring them to process your information only on our instructions and to keep it secure.

4.4 Professional advisers and authorities

Our accountants, auditors, insurers, bankers and legal advisers, where necessary. We may also disclose information to regulators, law enforcement, border agencies or courts where we are legally required to do so, or where it is necessary to protect our rights or the safety of others.

4.5 Business transfers

If our business is sold, restructured or merged, your information may be transferred to the acquiring party. We will notify you if this happens, and your information will continue to be protected under terms no less favourable than this policy.

5. Our Use of Artificial Intelligence

We use AI tools — currently Anthropic’s Claude — to help us work more efficiently. We use them for three things: researching destinations, suppliers and travel options; supporting the drafting of proposals and itineraries; and helping to draft correspondence.

We believe you should know exactly how this works, including its limits:

  • We do not use AI tools to store your information. They are not a database, and we do not keep client records in them. Your booking and client records are held in our secure client management system, described in Section 4.3.
  • We minimise what we share. Where we use AI to help draft a proposal or an email, limited details such as your name, destination or itinerary may be included in order to produce that draft. We avoid this wherever the task can be done without it. We do not input passport numbers, payment card details, or special category information such as medical, dietary or accessibility data.
  • Model training is switched off. We have disabled the setting that would allow our conversations to be used to train the provider’s AI models. With this setting disabled, conversations are held by the provider for a limited period — currently 30 days — and are then deleted.
  • Work is kept separate and access-restricted. We organise work into closed, access-restricted projects rather than a single shared workspace.
  • A human always decides. We do not make decisions about you by automated means alone. AI assists our team; it does not replace their judgement. You are not subject to automated decision-making or profiling that produces legal or similarly significant effects.
  • Our contractual position, stated plainly. We currently access these tools under the provider’s standard consumer terms of service rather than an enterprise agreement. This means that, alongside the safeguards we apply ourselves, the provider handles information under its own terms and privacy policy rather than solely under our instructions. We think you should know that, and we keep the arrangement under active review as our business grows.
  • If you would prefer that we do not use AI tools in connection with your booking or enquiry, please tell us and we will accommodate that request. You can do so at any time by emailing marketing@globaltravelmoments.com.

6. Marketing

We will only send you marketing where you have opted in to receive it, or where you are an existing client and we are marketing services similar to those you have already booked. In either case you can opt out at any time.

Every marketing email includes an unsubscribe link. You can also email marketing@globaltravelmoments.com and we will remove you promptly. Opting out of marketing will not affect any communications relating to a booking you have made with us.

Where we ask for your consent to marketing, we always ask for it separately and never bundle it with anything else. Giving or withholding that consent will not affect any other service we provide to you.

6.1 Advertising and audience tools

We use advertising platforms to show our services to people who may be interested. You can control this directly:

7. How Long We Keep Your Information

We keep your information only for as long as we need it. Our standard retention periods are set out below. We may hold information for longer where the law requires it or where it is needed for an ongoing legal claim.

  • Enquiries that do not lead to a booking — 24 months from last contact.
  • Booking and itinerary records — 7 years from the end of travel.
  • Financial and payment records — 7 years from the end of the relevant financial year, as required by HMRC.
  • Passport and identity documents — deleted once travel is complete and any supplier requirement has passed.
  • Medical, dietary and accessibility information — deleted within 12 months of travel, unless you ask us to keep it for future trips.
  • Marketing contacts and preferences — until you unsubscribe. We then keep a minimal suppression record indefinitely so that we do not contact you again by mistake.
  • Website analytics data — between 30 minutes and 24 months, depending on the cookie.
  • Complaints and correspondence — 6 years from resolution.
  • When information reaches the end of its retention period, it is securely deleted or irreversibly anonymised.

8. Cookies and Similar Technologies

A cookie is a small file placed on your device when you visit our website. Cookies help the site work properly, remember your preferences, and tell us how the site is being used.

We ask for your consent before placing any cookie that is not strictly necessary. You can accept, reject or change your preferences at any time using the cookie banner or the preferences link on our website. Rejecting non-essential cookies will not prevent you from using the site.

  • Strictly necessary — enables core site functions, security and form submission. Set by Webflow. No consent required.
  • Analytics and performance — helps us understand how the site is used. Set by Google Analytics and Microsoft Clarity. Consent required.
  • Advertising and targeting — measures advertising performance and shows relevant advertising. Set by Meta, Google and Microsoft. Consent required.
  • Functional — remembers your choices and preferences. Consent required.
  • Session cookies expire when you close your browser. Persistent cookies remain until they expire or you delete them, typically between 30 minutes and 24 months. You can also block or delete cookies through your browser settings, though this may affect how the site works.

8.1 Microsoft Clarity

We use Microsoft Clarity to understand how visitors use our website. Clarity records how pages are viewed and interacted with, including mouse movement, scrolling and clicks, and combines this into aggregated heatmaps and session replays. We use this to find and fix problems with the site, not to identify you personally.

Clarity does not run until you accept analytics cookies. If you reject them, it is not loaded at all. You can read Microsoft's privacy statement at privacy.microsoft.com/privacystatement.

8.2 Global Privacy Control and Do Not Track

We recognise and honour the Global Privacy Control (GPC) signal as a valid opt-out of the sale or sharing of personal information and of targeted advertising, where applicable law requires it. Because there is still no consistent industry standard for "Do Not Track" browser signals, we do not currently respond to them separately.

9. Your Rights

9.1 If you are in the United Kingdom or the European Economic Area

You have the following rights in relation to your personal information:

  • Access — to be told what we hold about you and to receive a copy of it.
  • Rectification — to have inaccurate or incomplete information corrected.
  • Erasure — to have your information deleted where there is no continuing reason for us to hold it.
  • Restriction — to ask us to limit how we use your information while a concern is resolved.
  • Objection — to object to processing based on our legitimate interests and to object to direct marketing at any time.
  • Portability — to receive certain information in a portable format or have it sent to another provider.
  • Withdrawal of consent — where we rely on your consent, withdraw it at any time without affecting processing carried out beforehand.
  • Automated decisions — not to be subject to a decision based solely on automated processing with legal or similarly significant effects. We do not carry out such processing.
  • To exercise any of these rights, email marketing@globaltravelmoments.com. We will respond within one month. If your request is complex, we may extend this by a further two months, and we will tell you if that applies. There is no charge unless a request is manifestly unfounded or excessive. We may ask you to verify your identity before we act.

9.2 If you are in the United States

Depending on your state of residence, you may have rights to know what personal information we collect and how we use it; to access, correct or delete it; to receive it in a portable format; to opt out of targeted advertising, the sale or sharing of personal information, and certain profiling; to limit the use of sensitive personal information; and not to be discriminated against for exercising your rights.

These rights are available to residents of states with comprehensive privacy legislation in force, which currently includes California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia and Washington.

We do not sell your personal information for money, and we do not knowingly sell or share the personal information of anyone under 16. To exercise your rights, or to opt out of any sharing of personal information for cross-contextual behavioural advertising, email marketing@globaltravelmoments.com with the subject line "Privacy Request". You may use an authorised agent, provided we can verify their authority to act for you.

If we decline your request, you may appeal by replying to our response. We will tell you the outcome of any appeal and how to escalate the matter to your state Attorney General.

10. International Transfers

Travel is international by nature. To arrange your trip, we will often need to send your information to suppliers and partners outside the United Kingdom, including to countries which do not have the same standard of data protection law.

Where we transfer your information outside the UK, we rely on one of the following safeguards:

  • An adequacy decision, where the UK Government has determined that the destination country provides an adequate level of protection. This includes the European Economic Area.
  • The UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, incorporated into our contract with the recipient.
  • The UK Extension to the EU–US Data Privacy Framework, where the recipient is a certified US organisation.
  • Where none of the above is available, the transfer is necessary to perform our contract with you or to conclude or perform a contract in your interest — for example, sending your name to a hotel abroad so that your room can be reserved.
  • You may request a copy of the safeguards we have in place by contacting us.

11. How We Keep Your Information Secure

We take appropriate technical and organisational measures to protect your information against unauthorised access, loss, alteration or disclosure. These include:

  • Encryption of data in transit and at rest.
  • Multi-factor authentication on all business systems.
  • Access controls, so that team members and contractors can only reach what they need.
  • Written contracts with our processors requiring equivalent standards of security.
  • Secure deletion of information at the end of its retention period.
  • Regular review of our systems, suppliers and working practices.

No system can be guaranteed completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office within 72 hours, and where the risk is high, we will notify you directly and without undue delay.

12. Children

Our website and services are directed at adults. We do not knowingly collect personal information from children, and bookings may only be made by those aged 18 or over, as a booking creates a binding contract.

We do collect information about children where they are travelling as part of a family booking. That information is provided by the responsible adult making the booking and is used only to arrange the travel concerned.

If you are a parent or guardian and believe a child has provided us with personal information directly, please contact hello@globaltravelmoments.com and we will delete it.

13. Booking on Behalf of Others

If you make a booking or enquiry for other people, you confirm that you have their permission to share their information with us, that you have made them aware of this policy, and that where special category information such as medical or dietary requirements is involved, you have their explicit consent to provide it.

14. Changes to This Policy

We may update this policy from time to time to reflect changes in our practices, our suppliers, or the law. The date at the top of this document shows when it was last revised. Where changes are significant, we will bring them to your attention directly.

15. Contact Us and How to Complain

If you have questions about this policy, wish to exercise your rights, or would like to make a complaint about how we have handled your information, please contact us:

Data protection and privacy requests: marketing@globaltravelmoments.com

General enquiries: hello@globaltravelmoments.com

Post: Global Travel Moments, c/o Global Travel Collection, 101 St. Martin’s Lane, London, WC2N 4AZ, United Kingdom

Website: www.globaltravelmoments.com

We take complaints seriously and will always try to resolve them with you directly in the first instance.

If you are not satisfied with our response, you have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection:

  • Website — ico.org.uk/make-a-complaint
  • Helpline — 0303 123 1113
  • Post — Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

If you are based in the European Economic Area, you may also complain to your local data protection authority. If you are a US resident, you may contact your state Attorney General

Forgot password?

No worries, we'll send you reset instructions.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.