Follow us

Monday – Friday, 10:00 am – 5:00 pm (CET – Warsaw time)

GO UP

Privacy Policy

  /  Privacy Policy

Privacy Policy

Effective Date: 05.02.2025

This Privacy Policy explains how Luxury Quests, operated by Adventura Luxe Group sp. z o.o., collects, uses, and protects your personal data when you visit our website, book our services, or interact with us in any way.

1. Who we are

Company Name: Adventura Luxe Group sp. z o.o.
Registered Address: ul. Zygmunta Augusta 5/2, 31-504 Kraków, Poland
NIP: PL6701809449
KRS: 0001154048
Website: https://www.luxuryquests.com
Contact: [email protected]

2. What data we collect and why

We may collect the following categories of personal data:

a) When you visit our website

IP address

Browser and device type

Cookies (see Section 6)

Purpose: For analytics, website performance, security, and improvement of user experience.

b) When you fill out a form or contact us

Name and surname

Email address

Phone number (if provided)

Country of residence

Travel preferences

Message content

Purpose: To respond to your inquiry, provide tailored travel services, and follow up on your request.

c) When you become a client or partner

Company name (if applicable)

Billing details

Payment method (processed securely via third-party services like Stripe)

Contractual correspondence

Booking history

Purpose: To process bookings, manage the partnership or agreement, comply with legal obligations, and deliver our services.

3. Legal basis for processing

We process your data under the following legal grounds:

Your consent, when you voluntarily provide data via forms

Contractual necessity, when you book services

Legitimate interest, for communication, analytics, and fraud prevention

Legal obligation, for compliance with Polish and EU law

4. How long we retain your data

We retain personal data only as long as necessary to fulfil the purposes for which it was collected.

Contact form data: up to 12 months

Booking and invoicing data: up to 6 years (for legal and tax compliance)

Email marketing consent: until you withdraw consent

5. Sharing your data

We do not sell or rent your data. We may share it with:

Our trusted partners (e.g., hotels, guides, transportation providers) solely for booking purposes

IT and cloud service providers

Payment processors (e.g., Stripe)

Legal authorities if required by law

6. Cookies

We use cookies to enhance your experience and analyse traffic.

Necessary cookies: for security and functionality

Preference cookies: to store your preferences

Analytics cookies: to understand visitor behaviour (e.g., via Google Analytics)

You can adjust cookie preferences in our cookie banner or through your browser settings. For detailed information, see our Cookie Policy.

7. Your rights

Under the GDPR, you have the right to:

Access your data

Correct or update inaccurate data

Request deletion of your data (“right to be forgotten”)

Restrict or object to processing

Withdraw consent at any time

File a complaint with your local Data Protection Authority (in Poland: UODO)

To exercise your rights, contact: [email protected]

8. Data protection and security

We use appropriate technical and organisational measures to protect your data against loss, misuse, unauthorised access, and disclosure. These include:

SSL encryption

Secure payment gateways

Limited access based on roles

Regular updates and security reviews

9. Third-party links

Our website may include links to other websites. We are not responsible for their content or privacy practices. Please read their privacy policies separately.

10. Use of Third-Party Tools and Plugins

Our website may include links to other websites. We are not responsible for their content or privacy practices. Please read their privacy policies separately.

Solid Security

What personal data we collect and why we collect it
Cookies

A cookie named “itsec_interstitial_browser” is created to track a user’s login process to implement enhanced security features.

Security Logs

The IP address of visitors, user ID of logged in users, and username of login attempts are conditionally logged to check for malicious activity and to protect the site from specific kinds of attacks. Examples of conditions when logging occurs include login attempts, log out requests, requests for suspicious URLs, changes to site content, and password updates. This information is retained for 60 days.

Who we share your data with

A QR code image is generated for users that set up two-factor authentication for this site. This image is generated using a SolidWP-hosted API. In the process of generating this image, your username is sent to the API. This data is not logged. For privacy policy details, please see the SolidWP Privacy Policy.

This site is scanned for potential malware and vulnerabilities by the SolidWP Site Scanner. We do not send personal information to the scanner; however, the scanner could find personal information posted publicly (such as in comments) during the scan.

How long we retain your data

Security logs are retained for 60 days.

Privacy Suite for WordPress by Complianz

This website uses the Privacy Suite for WordPress by Complianz to collect and record Browser and Device-based Consent.

For this functionality, your IP address is anonymised and stored in our database. This service does not process any personally identifiable information and does not share any data with the service provider. For more information, see the Complianz Privacy Statement.

Stripe

When you pay via Stripe, you share your data with the payment provider. You may check Stripe’s Privacy Policies here.

Mailchimp for WooCommerce

When shopping, Mailchimp keeps a record of your email and the basket contents for up to 30 days on their server. This record is kept to repopulate the contents of your basket if you switch devices or need to come back another day.

Read Mailchimp’s Privacy Policy here.

KIT

When you subscribe to our newsletter or fill out a form created with ConvertKit, your personal data (such as name and email address) is securely transferred and stored by ConvertKit LLC, our external email marketing provider based in the United States.

ConvertKit acts as a data processor on our behalf. The transfer is protected by Standard Contractual Clauses (SCCs) in accordance with GDPR requirements.

For more information, please refer to ConvertKit’s Privacy Policy.

WP Forms

When you submit a form on our website, your data is processed via WPForms, a form-building tool integrated with our system.

Depending on the type of form (e.g., contact, pre-booking, feedback), we may collect your name, email address, country, preferences, and other relevant details.

The submitted data is securely stored on our WordPress server and may be used only for the purpose indicated in the form (such as contacting you, confirming a reservation, or providing service details).

WPForms itself does not access or use your data for any purpose. Data is stored under our control in accordance with GDPR compliance measures.

In specific cases, data submitted via WPForms may be securely transferred to external services such as ConvertKit (for email marketing) or Stripe (for payment processing). Each transfer is handled with appropriate security measures and legal safeguards under GDPR.

Google for WooCommerce

We use Google’s tools for Analytics hence some data is shared with Google.

Read Google’s Privacy Policy here.

WooCommerce Tax

We use WooCommerce Tax extension (by Jetpack) for calculating taxes in our shop. Read the Jetpack’s Privacy Policies here.

11. International data transfers

If your data is transferred outside the EU/EEA, we ensure an adequate level of protection via standard contractual clauses or data transfer agreements.

12. Updates to this Privacy Policy

We may update this Privacy Policy from time to time. The most recent version will always be available on our website.

Last updated: 15.07.2025

error: