How Sathya Travels Lanka collects, uses, shares and protects information when you visit our website, request a quotation or book a Sri Lanka travel service.
We collect only information reasonably needed to answer enquiries, plan and deliver bookings, communicate during travel, meet legal duties and improve our services. This policy explains those practices and the choices available to you.
Sathya Travels Lanka provides and arranges Sri Lanka tours, tour packages, tour planning, airport transfers, islandwide cab services and tour-guide services.
For the personal information covered by this policy, the controller is the service provider identified as Sathya Travels Lanka in your quotation or booking confirmation. Privacy questions and requests may be sent to info@sathyatravelslanka.com.
This policy applies when you:
Independent hotels, airlines, attractions, payment providers, social networks and other suppliers have their own privacy notices for processing they control.
Name, country, email address, telephone number, messaging contact and, where genuinely required, passport or identification details.
Travel dates, passenger numbers and ages, itinerary preferences, accommodation, flight number, arrival time, pickup and drop-off points, luggage, vehicle requirements and booking history.
Amount, currency, payment status, invoice details and transaction reference. Card or bank credentials are normally handled by the bank or payment provider rather than stored by us.
Enquiries, emails, messages, quotation details, feedback, complaints, requests and notes reasonably needed to deliver the service.
Depending on the website tools enabled, this may include IP address, browser and device type, approximate location, referring page, pages visited, cookie identifiers and server-security logs.
We may receive information:
If you provide another person’s information, you confirm that you are authorised to do so and that they have been informed about this policy.
We may use personal information to:
Depending on the circumstances and applicable law, we process information where it is necessary:
Where processing depends on consent, you may withdraw that consent for future processing. Withdrawal does not make earlier lawful processing invalid.
We ask you not to send medical, health, disability, dietary, identification or other sensitive information unless it is genuinely needed for safe travel, accessibility, a supplier requirement or a legal obligation.
Where this information is necessary, we will limit collection and access, use it for the specific purpose explained, and rely on an appropriate legal condition. It may be shared with a driver, guide, hotel, activity provider, emergency service or other person only where reasonably necessary.
We do not sell personal information. We may disclose only the information reasonably needed to:
Service providers acting for us should use information only for the agreed service and protect it appropriately.
Some customers, suppliers and technology services may be located outside Sri Lanka. Email, website hosting, cloud tools, analytics, social media and messaging services such as WhatsApp may process information in other countries.
Where a cross-border transfer is regulated, we will take reasonable steps required by applicable law, which may include using an approved transfer mechanism, contractual safeguards, consent where appropriate, or another lawful basis. External platforms remain responsible for their own independent processing under their privacy notices.
Cookies are small files placed on a device. The website may use:
You can control or delete cookies through browser settings. Blocking essential cookies may prevent parts of the website from working. Where applicable law requires a choice before non-essential cookies are stored, the website should provide that choice through its cookie-consent settings.
Payments may be completed through a bank, transfer service, card provider or another payment processor. That provider processes financial credentials under its own terms and privacy notice. We generally receive confirmation details such as the payer name, amount, date, currency, reference and payment status.
Do not send complete payment-card numbers, security codes, online-banking passwords or one-time passwords through ordinary email, website forms or WhatsApp.
We may send service messages necessary for an enquiry or booking. Promotional messages are different. We will use an appropriate lawful basis and provide a reasonable method to opt out of direct marketing. You may ask us to stop future marketing at any time.
We will not use an identifiable customer photograph, private message or testimonial in advertising merely because that person booked with us. Where permission is required, we will request it separately and explain the intended use. A person may withdraw consent for future use where applicable, although removal from already-printed materials or third-party reposts may not always be possible.
We retain information only for as long as reasonably necessary for the purpose for which it was collected and for applicable legal, accounting, tax, regulatory, safety, insurance and dispute-resolution requirements.
Retention depends on the record. Unsuccessful enquiries may be removed sooner than confirmed booking and payment records. Some information may be retained longer where a complaint, chargeback, legal claim, investigation or legal preservation duty exists. When information is no longer needed, we will take reasonable steps to delete, anonymise or securely dispose of it.
We use reasonable technical and organisational measures appropriate to the nature of the information and the service. These may include access controls, strong account security, software updates, limited staff or supplier access, backups and secure disposal practices.
No internet transmission or storage system is completely secure. If a security incident affects personal information, we will investigate and take steps required by applicable law, which may include notification to affected people or the relevant authority.
Subject to the conditions, limitations and procedures in applicable law, you may have the right to:
Send a request to info@sathyatravelslanka.com. Describe the request and the information or booking concerned. We may ask for proportionate information to verify identity and protect other people’s privacy. We will respond within the period required by applicable law.
If you remain dissatisfied, information about the Data Protection Authority of Sri Lanka is available at www.dpa.gov.lk.
Bookings must be made by an adult. We may need limited information about children travelling in a group, such as name, age, passport information where required, child-seat needs or relevant accessibility information. The adult responsible for the booking must have authority to provide that information.
We do not knowingly use children’s information for interest-based advertising or publish an identifiable child’s image for promotion without the permission required by law.
The website may link to or embed maps, videos, review platforms, social networks, payment services, messaging tools and supplier websites. When you interact with an external service, that provider may collect information under its own privacy policy and cookie practices.
We are not responsible for an independent provider’s privacy practices. Review the provider’s notice before submitting sensitive information or creating an account.
We may update this policy when our services, website tools, suppliers or legal requirements change. The current version will be published on this page with its effective date. If a change materially affects how existing information is used, we will provide additional notice where required.
For a privacy question, request or complaint, contact:
For urgent matters during an active trip, use the operational or emergency contact supplied in the booking confirmation.
Contact us to ask how your booking information is used, request a correction or exercise an available privacy right.