Privacy
Effective date: 1 October 2026
Travel 360 Pte. Ltd. (“Travel360”) follows Singapore’s Personal Data Protection Act 2012 (PDPA). This policy explains how we collect, use, disclose and protect your personal data.
All privacy questions, access or correction requests, consent withdrawals and complaints go to our Data Protection Officer: roy@travel360.sg, or by post to 171 Tras Street, #05-173 Union Building, Singapore 079025.
We share personal data only as needed to deliver your trip: airlines, hotels, cruise lines, ground operators, guides, insurers, visa offices and government authorities, and our IT and payment service providers. We do not sell personal data.
Travel involves overseas suppliers, so your data will be sent outside Singapore to fulfil your booking. By booking with us you consent to these transfers. We take reasonable steps to ensure recipients protect your data to a standard comparable to the PDPA.
We send promotions by email, SMS or WhatsApp only with your consent. You can opt out at any time by replying STOP or emailing roy@travel360.sg. Opting out does not affect messages about your bookings.
We may photograph group activities for our marketing. Tell us in writing if you do not want images of you used.
If you give us personal data of other travellers, such as family or group members, you confirm that you have their consent to do so and have told them about this policy.
You may withdraw consent by writing to our Data Protection Officer. We will act within 10 business days and explain the consequences. If we cannot use the data needed for your booking, we may be unable to continue it, and the Terms and Conditions cancellation charges will apply.
Write to our Data Protection Officer. We aim to respond within 30 days. A reasonable fee may apply to access requests, and we will tell you the fee first.
Booking and payment records are kept for at least 5 years to meet accounting and tax obligations. Passport copies and documents for a specific trip are deleted within 90 days after the trip ends, unless needed for an ongoing claim or legal requirement.
We use reasonable administrative, physical and technical measures to protect personal data. No transmission over the internet or messaging apps is fully secure. Please do not send passport or card images through channels other than those we ask you to use. If a data breach occurs, we will assess and notify the PDPC and affected individuals as the PDPA requires.
Our website may use cookies and analytics to understand how visitors use it. You can disable cookies in your browser settings.
We may update this policy and will post the latest version here with its effective date.
Effective date: 1 October 2026