Privacy Policy
Last updated: January 2026Welcome to Wanderlust. We respect your privacy and are committed to protecting your personal data. This privacy policy will inform you as to how we look after your personal data whenever you visit our website and use our travel planning services. It also tells you about your privacy rights and how the law protects you.
1. Data Controller
Wanderlust is the data controller responsible for your personal information. We are registered in Germany and committed to complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Information We Collect
We collect information about you when you interact with our website, contact us for a quote, or purchase our travel services. This may include:
Personal Data
- Identification Data: First name, last name, date of birth, passport details (for bookings).
- Contact Data: Email address, phone number, mailing address.
- Financial Data: Billing address, payment card details (processed securely via third-party payment processors).
- Travel Preferences: Destination interests, dietary restrictions, mobility requirements, seating preferences.
Technical Data
- Usage Data: Pages visited, time spent on the site, click paths, and browser type.
- Device Data: IP address, browser type and version, operating system, and unique device identifiers.
- Cookies: Data stored on your device via cookies and similar technologies (see our Cookie Policy for details).
3. How We Use Your Information
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- To provide and manage our services: Processing bookings, issuing tickets, arranging transport and accommodation.
- To communicate with you: Sending itinerary updates, travel alerts, and responding to your inquiries.
- For marketing purposes: Sending you newsletters or travel offers (only with your consent).
- To comply with legal obligations: Verifying identity, preventing fraud, and complying with travel regulations and border control requirements.
- To improve our services: Analyzing usage data to enhance user experience and website functionality.
4. Legal Basis for Processing
Under the GDPR, we rely on the following legal bases to process your data:
- Contract Necessity: We need your data to fulfill our contract with you, such as booking a trip.
- Legitimate Interests: We process data for our legitimate business interests, such as fraud prevention and website security, provided these do not override your rights.
- Consent: We process data based on your explicit consent for direct marketing and non-essential cookies.
- Legal Obligation: We process data to comply with tax, accounting, and other legal regulations.
5. Sharing Your Information
We may share your personal data with third parties to enable us to provide our services. These parties include:
- Service Providers: Airlines, hotels, tour operators, and transport partners essential to your travel itinerary.
- Financial Institutions: Banks and payment gateways used to process payments securely.
- Technical Service Providers: IT service providers, hosting platforms, and analytics tools (e.g., Google Analytics).
- Authorities: Government bodies, customs, and immigration authorities where required by law.
We do not sell your personal data to third parties for marketing purposes. All third-party data processors are contractually bound to protect your data and only use it for specified purposes.
6. Data Security
We have implemented appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way, altered, or disclosed. We limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
7. International Data Transfers
As we offer travel services worldwide, your information may be transferred to countries outside the European Economic Area (EEA). If this occurs, we ensure appropriate safeguards are in place to guarantee your data remains protected. These safeguards include Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring a level of data protection equivalent to that within the EEA.
8. Data Retention
We will only retain your personal data for as long as is necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements.
- Client Records: Retained for the duration of our business relationship and for 7 years thereafter for tax and legal purposes.
- Marketing Data: Retained until you withdraw your consent or request deletion.
- Website Data: Aggregated analytics data may be retained indefinitely; individual user logs are typically deleted after 2 years.
9. Your Legal Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct any inaccurate or incomplete data.
- Right to Erasure: You can ask us to delete your personal data (subject to certain legal exceptions).
- Right to Restrict Processing: You can request that we limit the way we use your data.
- Right to Data Portability: You can ask us to transfer your data to another organization.
- Right to Object: You can object to our processing of your data, particularly for direct marketing.
- Right to Withdraw Consent: You can withdraw consent at any time where we rely on consent to process your data.
To exercise these rights, please contact us using the details provided below. We will respond to your request within one month.
Contact Us
If you have any questions about this privacy policy or our handling of your personal data, please contact our Data Protection Officer at:
Wanderlust
Leopoldstraße 45
80802 München, Germany
Email: [email protected]
Phone: +49 69 990 9324
If you believe we are processing your personal data in breach of the law, you also have the right to lodge a complaint with the relevant data protection authority.