Privacy Policy
1. Introduction
This Privacy Policy explains how Etraveli Group AB ("Etraveli", "we", "us", "our") processes and protects any personal data we collect from you, namely as per below and your rights in relation to your personal data:
- former, present and prospective partners such as investors, shareholders, contractors, service providers, consultants, advisors, as well as your proxy holders, representatives and employees, in the context of a business relationship (“Business Partner”), as well as from media contacts (such as journalists and press representatives), and your rights in relation to your personal data.
- media contacts (such as journalists and press representatives)
- end customers, when placing an order with one of our client online merchants (“Merchants”) that sell goods or services online and we provide those Merchants services that help detect and prevent fraudulent online transactions (“Fraud Prevention Services”).
Please read the following carefully to become familiar with practices and routines – and contact us if you have any questions.
Etraveli Group AB, reg. no. 556584-4684 is the “data controller” of your personal data and is therefore responsible for the lawfulness of what we do with your personal data.
This Privacy Policy does not apply to information that we collect from you when you are using our services or accessing our online travel agency brand websites as a consumer, or as a job applicant in connection with a recruitment process (information can be found through the specific Recruitment Privacy Policy), except for Fraud Prevention Services when offered through our Merchants (as explained above).
In relation to the Fraud Prevention Services, kindly note that we do not conduct or fulfill consumer transactions, and, except as otherwise disclosed, we do not collect or receive personal data directly from you, as a consumer. We provide to Merchants our Fraud Prevention Services that are integrated on their (ecommerce) websites, platforms and mobile apps, as applicable, for consumers to place orders accordingly. Thus, we receive from the Merchants and further process transaction data that you, as consumers have provided to them when purchasing goods or services.
Please note that this Policy does not cover the practices or policies of Merchants, or any other party that may have access to your personal data. Consumers should review the privacy policies of the business entities with which they directly share their data to learn about such entities’ privacy practices. While this policy sets forth our general privacy and security practices, our detailed obligations and commitments to our Merchants are set forth in the contractual arrangements (service agreements) with them. In the event of a conflict between this Policy and a merchant contract, the service agreement we have with the Merchant prevails.
2. The personal data we collect
The specific type of data collected will depend on the communication and interaction, business relationship between you and Etraveli, your scope of work, or the service to be provided, including but not limited to:
- Contact information: such as, first and last name, personal and business address, personal and business telephone number, email address, job title, company name and industrial sector;
- Financial information: such as, bank account information, information regarding creditworthiness, invoices and tax ID number;
- Any other information collected, used or disclosed in connection with the past, existing, or potential relationship between us and the Business Partner; and
- Information collected automatically using cookies and other tracking technologies, such as browser information (details of the web pages you have visited on our website, and the content that you access). More information can be found through the Cookie Policy.
- Other identifying information such as images only in case of attendance to an event (conferences, seminars, webinars etc) organized by us or our business partners, if applicable.
If you have provided personal data of any third party individual to us, you confirm that (i) such third party individual is notified of the information in this Privacy Policy, including how we may process their personal data; (ii) you have obtained any required consent from such third party individual or other legal basis is relied on; and (iii) you have the permission to provide such personal data which allows us to lawfully process such personal data in accordance with this Privacy Policy.
We may lawfully obtain personal data about you from other sources, such as our business partners, our service providers and other independent third-party sources. We treat such personal data in accordance with this Privacy Policy.
In relation to the Fraud Prevention Services, the specific types of data processed will depend on the service agreement with the Merchants that might include but are not limited to:
- Transaction data: When you place an order with the Merchant, various data regarding your transaction that may relate to the purchase and sale of goods or services, chargeback requests, payment requests or other events such as your:
- name, email, telephone number, the items you purchased, price paid, shipping information;
- payment information and payment and billing method; In principle, we do not store full payment card details in line with applicable security regulations.
- Device data such as the Internet Protocol (“IP”) address.
Etraveli only accepts data elements from Merchants if the data is rationally related to the performance of the applicable service that a Merchant purchases from us in accordance with the respective service agreement. In addition, kindly note that if you contact us for questions or complaints, we will collect the information related to your inquiry such as name, email address, postal address, telephone number or other contact information.
3. What we do with your personal data
To be allowed to handle your personal data, the applicable data protection legislation obligates us to have a so-called “legal basis” for each of our purposes to process your personal data. For this reason, we have drafted the below table to show our legal basis for each of our purposes.
| What we do (our purposes with handling your personal data) | Our Legal basis |
| Consider the possibility of engaging in a business/contractual relationship with you (e.g. when concluding NDAs, pre-contractual agreements, the evaluation of project partnerships), as well as answering your questions and fulfilling your information requests. | Processing is necessary in order to take steps prior to entering into a contract with you and for our legitimate interest in communicating with you. |
| Establish and manage the business/contractual relationship with you, including (i) the invitation to join initiatives and/or events organized, promoted or sponsored by us, (ii) the invitation to attend surveys on your degree of satisfaction in your relationship with us, after a certain degree of business interactions with us. | Processing is necessary for the performance of a contract to which you are a party and for our legitimate interest in fulfilling purposes including communicating and improving the relationship with you and/or your employer (if you are a representative, employee, collaborator and/or contact person of the company having the agreement with us). |
| Comply with applicable government regulations and other legal requirements, obligations and/or orders. | Processing is necessary to comply with legal obligations (e.g., for accounting and tax purposes) legal proceedings, or government authorities' orders, as well as to cooperate with courts and law enforcement bodies when required. |
| Protect our assets and employees/contractors and comply with anti-money laundering and/or bribery and corruption laws and other regulatory requirements, we carry out screening (pre-contract and on a periodic basis post-contract) on owners, shareholders and directors of our Business Partners. This screening process is performed against publicly available or government issued sanctions lists and media sources, but does not involve profiling or automated decision making in relation to the counter-parties or potential counter-parties. | Processing is necessary to comply with legal obligations. |
| Contact you in response to Press Contact Page forms, in order to conduct activities in the area of public relations and associated external communications, through communication with journalists and press representatives concerning our activities or other relevant events. | Processing is based on your consent as acquired by submitting the form available through the Press Contact Page. |
| Contact you via email to provide you with marketing or promotional materials in relation to our services and solutions that may be of interest to you. |
Processing is based on your consent as lawfully acquired to use your data for marketing purposes. You may withdraw your consent at any time by contacting us as described in the section “How to Contact Us”. |
| Organize and manage events (conferences, seminars, webinars etc). We may process your personal data for processing your registration, confirming your attendance and sending registration confirmation to you. | Processing is based on your voluntary participation in the event and thus, for the performance of a contract to which you are a party. Further the processing is based on our legitimate interest in fulfilling purposes related to organizing and managing the event. |
| Send you via email information on future events similar to the ones you have registered, that might be of interest to you. |
Processing is based on your consent that may be collected through the event registration. You may withdraw your consent at any time by contacting us as described in the section “How to Contact Us”. |
In relation to the Fraud Prevention Services, we have drafted the below table regarding our legal basis for each of our purposes.
|
To render Fraud Prevention Services, we use the personal data as received, to analyze whether the transaction is fraudulent or not. Based on the fraud analysis we suggest to the Merchant to approve, further check or reject a transaction without involvement and/or decision from the Merchant. The Merchant however, determines at its own discretion, whether to accept the payment or decline it. For fraud analysis purposes, we may analyse aggregated data about your activity across the e-commerce websites, platforms and mobile apps, as applicable, operated by our Merchants to detect and prevent fraudulent behaviour in transactions. The personal data might be also used to address other transaction data management challenges or manage chargebacks in accordance with the services agreement with the Merchant. |
Your data is processed in accordance with the service agreement we have in place with the Merchant and in line with the business purposes, our and the Merchant’s legitimate interests to (i) identify and manage activities that could be fraudulent or harmful (ii) prevent fraud to the extent possible, and (iii) secure services and transactions. |
| Comply with applicable government regulations and other legal requirements, obligations and/or orders. |
Processing might be necessary to comply with legal obligations (e.g., for accounting and tax purposes) legal proceedings, or government authorities’ orders, as well as to cooperate with courts and law enforcement bodies when required. |
| To contact you in response to inquiries or complaints. | Processing is based on your consent as acquired by contacting us. |
4. How long do we retain your personal data?
Your personal data will be retained by us for the intended purposes in accordance with applicable data protection legislation and company policies. Upon your request and once your personal data is no longer required to be retained for a longer duration (by applicable laws and regulations), it will be promptly deleted or anonymized in accordance with Etraveli’s policies.
In relation to the Fraud Prevention Services, please note that the period for which personal data is retained might be determined by the service agreement between us and each Merchant and may vary based on the type of the service.
5. Sharing your personal data
We will only share your personal data where necessary for the purposes listed in this Privacy Policy, with the following potential recipients:
- Other companies within the Etraveli Group;
- Governmental authorities, law enforcement agencies, courts, regulators, to comply with legal obligations;
- Our trusted third party service providers and/or our subcontractors who help us maintain our website and/or provide other services to us (e.g. IT infrastructure providers, software solutions, finance, administrative, and legal services, logistic providers, events organizers, suppliers that carry out organizational, administrative, and/or technical activities in the context of the business/contractual relationship); as well as in order for us to be able to provide the Fraud Prevention Services.
- In relation to the Fraud Prevention Services, with the Merchants: we may share limited personal data for review or audit purposes;
- To protect against potential fraud, we may verify with service providers the information collected from the website;
- Potential partners involved in business transactions, in the event we intend to sell or transfer ownership or control of any or all of our business, operations or services to a third party, as part of any corporate reorganization process including, but not limited to, mergers, acquisitions, and sales of all or substantially all of our assets;
- To strategic partners, agents, or other unaffiliated parties, but only with your additional express consent.
When any of the above service providers act as data processors, they handle your personal data with sufficient security measures and only in accordance with instructions provided by us and applicable data protection legislation.
We inform you that some of the service providers to which we may disclose your personal data might be established outside Europe (EU), European Economic Area (EEA), UK, and Switzerland. When we transfer your personal data to such other jurisdictions, we take steps and measures to ensure that your personal data is securely transferred and that the receiving parties have in place suitable data protection standards or other derogations as allowed by applicable data protection legislation. These measures may include data processing and/or transfer agreements, implementing standard contractual clauses.
6. Third party providers and social media
Please note that our website may contain links to other websites and serve content from third party providers. This Privacy Policy only applies to our website and our services. When you follow links to other websites, or use third party services and products, you should read their privacy policies.
In addition, if you choose to contact us via social media, this Privacy Policy does not apply to any personal data submitted by you as part of such contact – in such case, we recommend that you read the privacy policy of such social media provider. In case of interacting with us through social media on an Etraveli administered social media page such as LinkedIn, kindly note that your personal data (such as your name, your profile picture, and the fact that you are interested in Etraveli) will be visible to all visitors of your personal profile depending on your privacy settings on the relevant social media platform, and will also be visible to us. Etraveli does not track your activity across the different social media sites that you use.
7. Your Rights
Certain jurisdictions (such as in the EU, Switzerland, UK, California, Colorado, Connecticut, Utah, Virginia, and other U.S. states), extend enhanced privacy rights to residents of or persons located in the jurisdiction. Exercise of these rights may be subject to receipt by us of a verifiable request from you as well as to limitations under applicable law. Your rights, depending on the jurisdiction and our reason for processing your information, may include some or all of the following:
- Right to access – You are entitled to access your personal data that we handle. You are also entitled to receive certain information about what we do with your personal data.
- Right to rectification – You are entitled to correct inaccurate personal data concerning you and to have incomplete personal data completed.
- Right to erasure – You are entitled to have your personal data erased. This is known as the “right to be forgotten.”
- Right to restriction of processing – You are entitled to restrict how we use your personal data.
- Right to data portability – You are entitled to receive your personal data (or have your personal data directly transmitted to another data controller) in a structured, commonly used and machine-readable format from us.
- Right to object – You are entitled to object to certain types of handling of personal data that we carry out. This applies to all our activities that are based on our “legitimate interest”.
- Right to withdraw consent - For the purposes you have consented to the processing of your personal data, you have the right to withdraw your consent at any time.
- Right to lodge a complaint with the applicable data protection supervisory authority, in the country in which you live, although we would encourage you to first contact us directly to resolve any concerns.
If you are a resident of a state with active privacy laws (including California, Colorado, Connecticut, Oregon, and Texas), you may designate an authorized agent to submit requests to know, delete, or correct your information on your behalf.
- Opt-Out Requests: For residents of all applicable states (including Virginia and Utah), we will honor requests from authorized agents specifically to opt-out of the "sale" or "sharing" of personal data and targeted advertising.
- Verification: To protect your privacy, we require the authorized agent to provide written permission from you. Unless the agent holds a valid Power of Attorney pursuant to your state’s law (e.g., California Probate Code sections 4000 to 4465), we may still require you to verify your identity directly with us before we fulfill the request.
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights. We will not deny you services, charge different prices, or provide a lower quality of service if you choose to exercise any of the rights described in this Policy.
- Sale and Sharing of Data: We do not "sell" your personal information for money. However, we may share identifiers and internet activity with third-party advertising partners for targeted advertising purposes. Remember that you can block non-strictly necessary Cookies (including ads and analytics cookies), as described in our Cookies Policy. You may opt-out of this sharing at any time by enabling a recognized Global Privacy Control (GPC) signal in your browser. Our site is configured to automatically honor GPC signals.
If you wish to contact us to exercise any of your rights, please complete this Data Subject Request Form. If you encounter any difficulty with the webform or for any question you may have, you can always email us at privacy@etraveligroup.com or as specified in the “How to contact us” section below.
8. Data security
In order to keep your personal data secure, we have implemented a number of technical and organizational security measures and we maintain a high level of security in all systems to safeguard the personal data in our possession against loss, theft and unauthorized use, disclosure, or modification.
In addition, we store the personal data in our servers in Europe and have adopted policies to ensure that our employees (who are subject to confidentiality obligations) do not use personal data when it is not necessary. Such policies also set out our standards for when we contract suppliers or introduce new IT systems within our operations.
Etraveli has taken reasonable steps to ensure that appropriate technical and organizational security measures are also implemented by data processors acting for and on its behalf, to ensure the security of the processing of your personal data overall.
9. How to contact us
If you have any questions regarding the handling of your personal data or our use of cookies, or if you encounter any difficulty with the webform in relation to your privacy rights, please send an email to: privacy@etraveligroup.com or use the following details:
Etraveli Group AB
Attn: Privacy Manager
P.O Box 1340
751 43 Uppsala
Sweden
10. Changes to the Privacy Policy
We reserve the right to change this Privacy Policy from time to time in our sole discretion. When we do, we will also revise the "Last Updated" date at the bottom of this Privacy Policy. Please check back frequently to see any updates or changes to our Privacy Policy.
Last updated: April 2026