Privacy Policy
Effective July 3, 2026. Your trust is the business. This policy explains what we collect, why, who we share it with, and the rights you have. The short version: we collect what a trip requires, we share only what a booking requires, and we never sell your personal information.
Drafted to travel industry standards. Final confirmation by licensed counsel is pending.
1. What we collect
Contact and identity details you share with us: name, email, phone, and for bookings, the details suppliers require such as date of birth, passport information, known traveler numbers, and loyalty program numbers.
Trip information: destinations, dates, traveler counts, budgets, preferences, dietary and accessibility needs you choose to share, and the dream you describe in your inquiry.
Payment information is handled by our payment processors. Card and bank details are entered on Stripe's secure pages and never touch or rest on our servers. Zelle payments happen entirely within your bank. We keep records of amounts, dates, and references, not account numbers.
Technical basics when you use the site: a session cookie if you sign in to your portal, and standard server logs. We also use your browser's session storage to save form progress so going back never loses your answers.
2. How we use it
To plan and book your travel, to send proposals, invoices, receipts, reminders, and trip documents, to provide the client portal, to respond to you, and to meet legal and accounting obligations.
With your consent, to send the weekly deals email. Every marketing email includes a one click unsubscribe that works immediately, as the CAN SPAM Act requires. Transactional messages about your active trip (receipts, reminders, documents) are not marketing and continue while your trip is active.
If you opt in to text messages, we text only about your active trips, and you can reply STOP at any time to end them.
3. Who we share it with, and who we never share it with
Travel suppliers: we share exactly what a supplier needs to fulfill the booking you asked for, a resort needs names and dates, an airline needs passport details. Suppliers use that information under their own privacy policies.
Service providers who run our operations under contract: Stripe (payments), Resend (email delivery), Vercel (website hosting), and Supabase (secure database hosting). Each receives only what its function requires.
Law and safety: we disclose information if a law, court order, or government authority validly requires it, or to protect the rights and safety of our clients and business.
We never sell your personal information, we never share it for cross context behavioral advertising, and we have not done either in the preceding twelve months. There are no third party advertising trackers on this site.
4. Your rights and choices
You can ask us at any time to access the personal information we hold about you, correct it, delete it, or receive a copy of it. Email beulahbeyondtravel@gmail.com and we will take care of it personally, verifying your identity first, and respond within 45 days.
Residents of California, Virginia, Colorado, Connecticut, and other states with consumer privacy laws have these rights by statute, including the right not to be discriminated against for exercising them. Because we do not sell or share personal information for targeted advertising, there is nothing to opt out of, but the request channel above works for every right your state provides.
Deletion has limits: we keep what tax, accounting, and legal obligations require us to keep, and records of trips already taken may be retained for those purposes even after other data is deleted.
5. Cookies and tracking
We use one essential cookie: a secure, httpOnly session cookie that keeps you signed in to your portal. It is not used for advertising and is not shared with anyone.
We honor the spirit of do not track: there is no cross site tracking here to disable.
6. How long we keep it
Inquiries that never become trips: up to 3 years, so returning dreamers do not have to start over. Client and trip records: 7 years, matching tax and accounting requirements. Email subscriptions: until you unsubscribe. Sign in sessions: 30 days. Expired sign in links: deleted automatically.
7. How we protect it
All traffic is encrypted in transit (HTTPS). The database is hosted with encryption at rest. Sign in uses one time email links, no passwords exist to steal. Payment credentials live with PCI compliant processors, not with us. Access to client records is limited to people who need it to serve you.
No system is perfect. If a breach ever affects your personal information, we will notify you and the authorities as applicable law requires, promptly and plainly.
8. Children
Our services are for adults. We do not knowingly collect personal information directly from children under 13. When a parent or guardian books family travel, they provide the traveler details for their children, and we use them only for that booking.
9. Changes and contact
If this policy changes materially, we will post the new version here with a new effective date, and for significant changes we will email active clients.
Privacy questions and requests: beulahbeyondtravel@gmail.com, or +1 (240) 906 3140. A real person reads every one.