Privacy Policy

Last Updated: September 30, 2026

1. Introduction

Justkeeps Travel, LLC ("Justkeeps Travel," "we," "us," "our") respects your privacy. This Privacy Policy explains what personal information we collect, how we use and share it, and the rights you have over it.

This Policy applies to our website and any related pages or booking portals we operate (the "Site"), to our booking and travel planning services, and to our communications with you by email, phone, and messaging platforms.

Because we arrange international travel, this Policy is written to address the requirements of United States privacy laws, the EU and UK General Data Protection Regulation ("GDPR"), and other applicable privacy laws.

Our commitment to discretion

We understand that many of our clients value privacy as much as the travel itself. We treat your itineraries, destinations, travel dates, travel companions, and personal information as confidential, and we disclose them only as necessary to arrange and service your travel or where required by law.

We will never sell or rent your client information, travel history, or itinerary details to advertisers, data brokers, or marketing companies. Where you travel, when, and with whom is not information we monetize.

Please read this Policy together with our Terms of Service.

2. Who We Are

Data Controller:

  • Justkeeps Travel, LLC (a Florida limited liability company)
  • Telephone: +1 561-300-3540
  • Email: Hello@justkeepstravel.com

For privacy questions or to exercise your rights, contact us at Hello@justkeepstravel.com.

3. Information We Collect

3.1 Information You Provide Directly

Identity and contact information

Full legal name as shown on travel documents, preferred name, date of birth, gender, postal address, email address, and telephone number.

Travel documentation

Passport number, passport issuing country, passport issue and expiry dates, visa details, nationality, citizenship, redress or Known Traveler numbers, and TSA PreCheck or Global Entry information.

How we protect these documents: Travel documents are stored securely, access is limited to the personnel and service providers who need them to arrange your travel, and passport details are shared only with the Suppliers and authorities that require them for your specific booking. We redact or delete them once they are no longer needed to service your travel, unless the law requires us to keep them.

Booking and preference information

Destinations, travel dates, party composition, seat and room preferences, loyalty program numbers, and past booking history.

Payment information

Billing name and address, and the last four digits and expiry of payment cards. If you choose to keep a card on file through your client portal, we also store the full card number, the expiry date, your billing address and photos of the front and back of the card. Card numbers and card photos are encrypted before they are stored, only our advisors can open them, and every time they do it is recorded. We never ask you to type your card's security code, but the photo of the back of your card will show it, and that photo is encrypted in the same way. We charge a card on file only for trip costs you have approved, and we share card details only with the Supplier or payment processor needed to pay for your booking. You can remove a card from your portal at any time, or ask us to remove it.

Sensitive personal information

Where you provide it so we can arrange your travel appropriately, we may collect dietary requirements, allergies, accessibility and mobility needs, medical conditions relevant to travel, and vaccination status. Under GDPR this is "special category" data and we process it only with your explicit consent or where otherwise permitted by law. You are never required to provide it, but withholding it may limit our ability to arrange suitable travel.

Information about others

When you book on behalf of companions, family members, or guests, you provide their information to us. You confirm that you are authorized to do so and that you have made them aware of this Policy.

Communications

The content of emails, WhatsApp and SMS messages, call notes, forms, and any reviews or testimonials you submit.

3.2 Information Collected Automatically

When you visit the Site, essential technical data may be processed to provide security, prevent abuse, process forms, and support core functions. With your permission, our analytics and marketing providers may also collect IP address, browser and device information, referring URL, pages viewed, time spent, interaction data, and general location inferred from IP address through the technologies described in Section 8.

3.3 Information From Third Parties

We may receive information from travel Suppliers (airlines, hotels, villa managers, tour operators, cruise lines), host agencies or consortia we work with, payment processors, and publicly available sources or social media platforms where you interact with us.

4. How We Use Your Information

We collect only what we need to plan, book, and look after your travel. Specifically, we use personal information to:

  • Prepare quotes, proposals, and itineraries
  • Book, confirm, modify, and service travel arrangements with Suppliers
  • Process payments, issue invoices, and manage credits and refunds
  • Communicate with you about your bookings, including confirmations, changes, and travel alerts
  • Provide customer support before, during, and after travel
  • Comply with legal, regulatory, and tax obligations
  • Detect, prevent, and investigate fraud, chargebacks, and misuse
  • Establish, exercise, or defend legal claims
  • Maintain business records
  • Improve the Site and our services
  • Send marketing communications where you have consented or where otherwise permitted, subject to your right to opt out at any time

We do not use your personal information to train artificial intelligence or machine learning models, and we do not permit our service providers to do so.

Automated decision-making. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.

We do not sell your personal information. See Section 10.

5. Legal Bases for Processing (GDPR)

Where GDPR applies, we rely on the following legal bases:

Purpose

Arranging and servicing your travel

Payment processing and invoicing

Tax, accounting, and regulatory compliance

Fraud prevention, security, and defending claims

Service improvement and analytics

Marketing communications

Dietary, medical, and accessibility information

Legal Basis

Performance of a contract with you

Performance of a contract; legal obligation

Legal obligation

Legitimate interests

Consent where required by applicable law; optional analytics remain disabled until permission is given through the Site's privacy controls.

Consent, or legitimate interests where permitted

Explicit consent (Article 9)

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may object to such processing; see Section 11.

6. How We Share Your Information

We share personal information only as described below. We do not sell it.

Travel Suppliers. Airlines, hotels, villa owners and managers, cruise lines, tour operators, transfer companies, activity providers, and event vendors receive the information necessary to fulfill your booking. This necessarily includes names, dates of birth, passport details where required, and any accessibility or dietary needs you have asked us to convey. Suppliers act as independent controllers of that information and handle it under their own privacy policies.

Service providers. Booking and CRM platforms, email and messaging providers, payment processors, accounting and bookkeeping providers, IT and hosting providers, and marketing platforms. These parties act as processors on our instructions and are contractually restricted from using your information for their own purposes.

Host agencies, consortia, and independent agents. Where a booking is placed through a host agency or consortium, or serviced by one of our independent travel advisors, they receive the information necessary to place and service the booking.

Insurers. Where you elect to purchase travel insurance through a referral, the insurer receives the information necessary to quote and issue the policy.

Professional advisors. Attorneys, accountants, and auditors, subject to confidentiality obligations.

Legal and regulatory disclosure. Government authorities, courts, law enforcement, border and immigration authorities, and regulators, where required by law, subpoena, or legal process, or to establish or defend legal claims. Certain destinations legally require advance passenger information to be transmitted before travel.

Business transfers. In connection with a merger, acquisition, financing, or sale of all or part of our business, subject to this Policy continuing to apply.

Payment disputes. In a chargeback or payment dispute, we may submit booking confirmations, itineraries, and your electronic communications to the payment processor, card network, or issuing bank as evidence of authorization and delivery.

7. International Data Transfers

Travel is inherently international. To arrange your travel, we transfer personal information to Suppliers and service providers located outside your country of residence, including outside the European Economic Area and the United Kingdom. These countries may not offer the same level of data protection as your home jurisdiction.

Where we transfer personal information from the EEA or UK, we rely on appropriate safeguards, including:

  • Standard Contractual Clauses approved by the European Commission, and the UK International Data Transfer Addendum where applicable;
  • Adequacy decisions, where the destination country has been recognized as providing adequate protection; or
  • Article 49 derogations, including transfers necessary for the performance of a contract with you or for the conclusion of a contract in your interest, which commonly applies when booking travel with a Supplier in a third country.

You may request further information about the safeguards applied by contacting us at Hello@justkeepstravel.com.

8. Cookies and Tracking Technologies

The Site uses essential browser storage and similar technology to provide security, prevent spam, process forms, remember privacy choices, and support core site functions. Optional Analytics and Marketing technologies remain disabled unless you grant the relevant permission through the Site's privacy controls.

Strictly necessary cookies enable core functionality such as security, form submission, and session management. These cannot be disabled.

Analytics cookies include Google Analytics 4, Google Tag Manager, and Microsoft Clarity. Google Analytics and Tag Manager help us understand visits, traffic sources, and site use. Standard Google Analytics first-party cookies, including _ga and _ga_<container-id>, may have a default expiration of up to two years, subject to browser limits and our configuration. Microsoft Clarity helps us understand aggregate interaction patterns and usability. Clarity playback data is generally retained for 30 days, while certain labeled, favorited, sampled, or aggregated data may be retained longer under Microsoft's published retention schedule. These services load only after you allow Analytics.

Advertising and social media cookies include the LinkedIn Insight Tag, which measures campaign performance and may support audience reporting or retargeting. LinkedIn states that direct identifiers are removed within seven days and remaining pseudonymized data is deleted within 180 days. The Insight Tag loads only after you allow Marketing.

Our current optional providers are Google Analytics 4 and Microsoft Clarity under Analytics, and the LinkedIn Insight Tag under Marketing. Each provider processes information under its own privacy and cookie notices.

The Site provides Accept All, Reject Non-Essential, Manage Preferences, and persistent Privacy Choices controls. Essential technology remains active for security, spam protection, form delivery, and saved privacy choices. You may change or withdraw optional permissions at any time through Privacy Choices; when permission is withdrawn, the page reloads so optional vendors do not load on the new page view. You can also restrict or delete cookies through your browser settings. Blocking optional technologies does not prevent you from browsing the Site or submitting a form.

The Site does not currently implement a separate application-level response to Global Privacy Control (GPC) or browser Do Not Track signals. Browser settings, privacy extensions, and provider controls may still block or limit relevant requests. You may also contact us to exercise any privacy right available under applicable law.

9. Data Retention

We keep personal information only as long as necessary for the purposes described in this Policy:

  • Booking and travel records: for the duration of the client relationship and for such further period as is necessary for our accounting and tax obligations and to resolve any question that may arise about a booking
  • Passport and visa details: deleted or redacted once no longer needed to service the booking, unless retention is required by law
  • Payment records: for the period required by applicable tax and financial recordkeeping obligations. A card on file and its photos are kept until you remove them, you ask us to delete them, or your client account is closed
  • Marketing contact details: until you unsubscribe or request deletion
  • Records relevant to a dispute or legal claim: until the matter is fully resolved and any limitation period has expired

Retention periods vary by record type and by the legal obligations that apply to it. When information is no longer needed for the purpose it was collected for, and no legal obligation requires us to keep it, we securely delete or anonymize it.

10. Sale and Sharing of Personal Information

We do not sell your personal information. The LinkedIn Insight Tag may process website interaction data for campaign measurement, audience reporting, or retargeting, which some United States state privacy laws may define as sharing for cross-context behavioral advertising. We have not sold personal information in the preceding twelve (12) months. We use the LinkedIn Insight Tag as described in Section 8 and respond to applicable privacy requests submitted through the contact method in Section 17.

We do not knowingly sell or share the personal information of anyone under 16.

To be explicit about what this means for travel: we do not sell, rent, trade, or otherwise make available our client lists, your travel history, your destinations, or your itinerary information to advertisers, marketing companies, data brokers, or any other third party for their own commercial purposes. The Suppliers and service providers described in Section 6 receive only what is necessary to fulfill your booking.

11. Your Privacy Rights

11.1 Rights Under GDPR (EEA and UK Residents)

You have the right to:

  • Access the personal information we hold about you
  • Rectify inaccurate or incomplete information
  • Erase your information ("right to be forgotten"), subject to our legal retention obligations
  • Restrict processing in certain circumstances
  • Data portability: Receive your information in a structured, commonly used, machine-readable format.
  • Object to processing based on legitimate interests, and to direct marketing at any time
  • Withdraw consent where processing is based on consent, without affecting the lawfulness of prior processing
  • Lodge a complaint with your local data protection supervisory authority, as EU and UK law provides

11.2 Rights Under California Law (CCPA/CPRA)

California residents have the right to:

  • Know what personal information we collect, use, disclose, and the categories of sources and recipients
  • Access a copy of the specific pieces of personal information we hold
  • Delete personal information, subject to legal exceptions
  • Correct inaccurate personal information
  • Opt out of sale or sharing (we do not sell; LinkedIn-related processing is described in Sections 8 and 10)
  • Limit the use of sensitive personal information
  • Non-discrimination: We will not deny service, charge different prices, or provide a lesser quality of service because you exercised a privacy right.

11.3 California "Shine the Light"

California residents may request information about personal information we disclosed to third parties for their direct marketing purposes in the preceding calendar year. We do not disclose personal information for third-party direct marketing purposes.

11.4 Rights Under Other U.S. State Laws

Residents of other states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and Florida, have comparable rights of access, correction, deletion, portability, and opt-out. We honor these rights on the same basis described above.

11.5 How to Exercise Your Rights

Email Hello@justkeepstravel.com with the subject line "Privacy Request." Tell us what right you wish to exercise and provide enough information for us to locate your records.

We will verify your identity before acting on a request, typically by confirming details already in our records. We do not require you to create an account.

We respond within thirty (30) days for GDPR requests and forty-five (45) days for U.S. state law requests, and may extend where permitted by law with notice to you.

An authorized agent may submit a request on your behalf with written authorization, and we may ask you to confirm the agent's authority directly.

12. Marketing Communications

Where you have opted in, or where otherwise permitted by law, we may send travel offers, destination content, and newsletters.

You can unsubscribe at any time using the link in any marketing email, or by emailing us. Opting out of marketing does not stop transactional messages about your bookings, confirmations, itinerary changes, payment reminders, and travel alerts, which are necessary to service your travel.

Where we contact you by SMS or WhatsApp for marketing, we do so only with your consent, and you may opt out by replying STOP or by contacting us.

13. Data Security

Protecting your information is something we take seriously, and we back that up with real controls: encrypted transmission of data, access limited to the people who genuinely need it, secure storage of travel documents, and written security obligations on every service provider who handles your information on our behalf.

That said, no system is completely secure and we cannot promise absolute security. Please don't send passport numbers or payment card details by ordinary email or text message. Use your client portal instead, or ask us and we will provide another secure way to send them.

If a breach occurs that is likely to result in a risk to your rights, we will notify you and the relevant authorities as required by applicable law.

14. Children's Privacy

Our services are directed to adults. We do not knowingly collect personal information directly from children under 13 (or under 16 in the EEA and UK) without parental consent.

We do collect information about minors when a parent or guardian books family travel and provides it. That information is used only to arrange the travel and is treated with the same protections described in this Policy.

If you believe a child has provided us information directly without parental consent, contact us at Hello@justkeepstravel.com and we will delete it.

15. Third-Party Websites and Suppliers

The Site may contain links to Supplier websites, booking engines, insurance providers, and social media platforms. We are not responsible for their content or privacy practices. Once your information is transferred to a Supplier, that Supplier's privacy policy governs its handling. We encourage you to read the privacy policies of any Supplier you book with.

16. Changes to This Policy

We may update this Policy from time to time. The Last Updated date at the top reflects the most recent revision. Where changes are material, we will provide prominent notice on the Site and, where required, obtain your consent. Continued use of the Site or our services after changes take effect constitutes acceptance of the revised Policy.

17. Contact Us

Questions, requests, or complaints about this Policy or our handling of your personal information:

Justkeeps Travel, LLC

Telephone: +1 561-300-3540

Email: Hello@justkeepstravel.com

A postal address for correspondence will be provided on written request to the email address above.

We aim to resolve any concern directly and encourage you to contact us first. EU and UK law also provides a right to lodge a complaint with your local data protection supervisory authority.