top of page

PRIVACY POLICY

1. Who We Are

YourUKStory (“we”, “us”, “our”) provides personalised and private tours within the United Kingdom.

For the purposes of UK data protection law, we are the Data Controller of your personal data under:

  • UK General Data Protection Regulation

  • Data Protection Act 2018

This Privacy Policy explains how we collect, use, store, and protect your personal data.

2. What Personal Data We Collect

We may collect and process the following information:

A. Identity Data

  • Full name

  • Date of birth

  • Nationality

  • Passport details (if required for bookings)

B. Contact Data

  • Email address

  • Telephone number

  • Billing address

C. Booking Information

  • Travel dates

  • Accommodation preferences

  • Special requests

  • Dietary requirements

D. Special Category Data (only where necessary)

  • Health or mobility information

  • Medical conditions relevant to your tour

We collect this only with your explicit consent.

E. Payment Information

  • Payment details (processed securely via third-party payment providers — we do not store full card details)

F. Technical Data

  • IP address

  • Browser type

  • Website usage data (via cookies and analytics tools)

3. How We Collect Your Data

We collect personal data when you:

  • Submit an enquiry form

  • Make a booking

  • Contact us by email or phone

  • Subscribe to marketing communications

  • Use our website (via cookies)

4. Legal Bases for Processing

Under UK GDPR, we rely on the following lawful bases:

Contractual Necessity

To process your booking and provide travel services.

Legitimate Interests

To operate and improve our business, respond to enquiries, and manage customer relationships.

Legal Obligation

To comply with tax, accounting, and regulatory requirements.

Consent

For:

  • Marketing communications

  • Processing special category health data

You may withdraw consent at any time.

5. How We Use Your Data

We use your personal data to:

  • Arrange and manage your personalised tour

  • Communicate with hotels, transport providers, and guides

  • Process payments

  • Provide customer support

  • Send marketing emails (if opted in)

  • Improve our website and services

6. Sharing Your Data

We may share your data with:

  • Accommodation providers

  • Transport companies

  • Tour guides

  • Attraction operators

  • Payment processors

  • Accountants or legal advisers

We only share information necessary to deliver your services.

We do not sell your personal data.

7. International Transfers

If we transfer data outside the UK (e.g., if you are based overseas or use non-UK providers), we ensure appropriate safeguards are in place, such as:

  • UK adequacy regulations

  • Standard Contractual Clauses

8. Data Retention

We retain personal data only as long as necessary:

  • Booking records: 6–7 years (for tax/legal compliance)

  • Marketing data: Until you withdraw consent

  • Enquiry data (no booking): Up to 24 months

After this period, data is securely deleted.

9. Your Rights Under UK GDPR

You have the right to:

  • Access your personal data

  • Request correction of inaccurate data

  • Request erasure (“right to be forgotten”)

  • Restrict processing

  • Object to processing

  • Data portability

  • Withdraw consent at any time

  • Lodge a complaint with the UK regulator

The UK supervisory authority is:

Information Commissioner's Office

Website: ico.org.uk

10. Data Security

We implement appropriate technical and organisational measures to protect your data, including:

  • Secure servers

  • Encrypted payment processing

  • Limited staff access

  • Password protection

  • Secure email systems

11. Cookies

Our website uses cookies to:

  • Improve user experience

  • Analyse website traffic

  • Support marketing campaigns

You may manage cookie preferences via your browser settings.

(You may wish to create a separate detailed Cookie Policy.)

12. Marketing Communications

We will only send marketing emails if:

  • You have opted in; or

  • You are an existing customer and have not opted out.

You can unsubscribe at any time by clicking the unsubscribe link or contacting us directly.

13. Children’s Data

Our services are not directed at children under 16 without parental consent. Where bookings involve minors, data is processed with parental authority.

14. Changes to This Policy

We may update this Privacy Policy periodically. The latest version will always be available on our website.

bottom of page