TripZoneFly

Privacy Policy

Last updated: April 1, 2026 · Ley N.° 29733 (Peru)

1. Data Controller

TripZoneFly, operated by Multiservicios Kada EIRL (Jr. Arica 280, Miraflores, Lima, Peru), is the data controller for personal data collected through tripzonefly.com. Contact: legal@tripzonefly.com

2. Data We Collect

From travelers:

  • Contact details when submitting an inquiry or booking: name, email, phone number.
  • Payment data processed securely by Izipay (we do not store card numbers).
  • Nationality and passport number (required for certain products, e.g. Machu Picchu entry tickets).
  • Booking history and preferences (for registered users).
  • Anonymous usage data: pages visited, search queries (no personal identification).
  • Wishlist items (stored locally in your browser — not sent to our servers).

From agencies:

  • Business name, RUC (Peruvian tax ID), registered address.
  • MINCETUR license number and expiry date.
  • Contact person name, corporate email, phone.
  • Bank account details for payout settlements.
  • Published content (packages, photos, itineraries).

3. How We Use Your Data

  • Process bookings and inquiries: connecting travelers with the relevant agency.
  • Send confirmations and vouchers: booking confirmation, voucher, updates by email and WhatsApp.
  • Payments: processing transactions and issuing receipts via Izipay.
  • Customer support: resolving disputes and complaints.
  • Platform improvements: analyzing usage patterns to improve search and recommendations.
  • Legal compliance: fulfilling obligations under Peruvian law.
  • Re-engagement (with consent): reminders about saved wishlist items or incomplete bookings.

4. Data Sharing

We share your data only in the following cases:

  • With the agency: your name, email, phone, and booking details are shared with the agency you book with, so they can provide the service.
  • With Izipay: payment data for transaction processing. Izipay's privacy policy applies to card data.
  • With Twilio/WhatsApp: your phone number for booking notifications and confirmations.
  • With Mapbox: anonymized location for map display.
  • Legal obligation: when required by law (e.g. tax authorities).

We do not sell or share your data with third parties for advertising purposes.

5. Data Retention

  • Booking data: 5 years (tax and legal compliance).
  • Inquiry data (no booking completed): 2 years from last interaction.
  • Agency accounts: for the duration of the relationship plus 2 years after closure.
  • Marketing communications: until you unsubscribe.

You may request early deletion — see Section 7 below.

6. Cookies and Local Storage

We use essential cookies for session management and your wishlist is stored locally in your browser (localStorage) — it is never sent to our servers. For full details, see our Cookie Policy.

7. Your Rights (ARCO Rights)

Under Ley N.° 29733 (Peru's Personal Data Protection Law), you have the right to:

Access

Know what personal data we hold about you.

Rectification

Correct inaccurate or incomplete data.

Erasure

Request deletion of your data when no longer necessary.

Objection

Object to processing for direct marketing.

How to exercise your rights:

Email: legal@tripzonefly.com

Response within 20 business days. Please include your name and the email used for your booking.

You may also lodge a complaint with Peru's Directorate General for Personal Data Protection (MINJUS).

8. Security and Data Breach Notification

All data transmissions are protected by TLS/HTTPS encryption. Card payments are processed by Izipay using PCI-DSS compliant infrastructure — TripZoneFly never stores card numbers. We maintain server-side security logs and restrict access to personal data to authorized personnel only.

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, TripZoneFly will:

  • Notify Peru's Directorate General for Personal Data Protection (MINJUS/INDECOPI) within 72 hours of becoming aware of the breach
  • Notify affected individuals within 5 business days, via email and/or platform notification, with details of what happened and what steps you should take
  • Publish a summary of the incident in the Security section of our platform

9. Changes to This Policy

Material changes will be communicated via email to registered users 30 days in advance. The current version is always available at this URL.