All Legal Documents
Official Compliance Notice

The Romanian language version constitutes the official and legally controlling text. Translations are provided for accessibility and consumer transparency.

Authorized Intermediary Travel AgencyVersion 1.0

Privacy Policy & GDPR

Regulations regarding the protection of personal data within DollarTrips operations, compliant with GDPR.

Last updated: 21 August 2026Status: In force
Contact Support

DollarTrips' commitment to data privacy:

We respect the privacy and security of every traveler's data. We collect only the data strictly necessary for providing travel consulting, searching for the best travel offers, and intermediating bookings. We do not sell or rent your personal data.

1. Data Controller

The controller responsible for processing personal data on the DollarTrips platform is:

  • Company: DollarTrips S.R.L.
  • VAT ID: RO49821034Nr. Reg. Com.: J40/5621/2024
  • Registered Office: București, România
  • Status: Intermediary Travel Agency (Licența nr. 3145 / 2024)
  • Data Protection Officer / GDPR Contact: gdpr@dollartrips.ro
  • Phone: +40 771 480 837

2. What is Personal Data

Under GDPR, 'personal data' means any information relating to an identified or identifiable natural person ('data subject').

3. GDPR Roles in Travel Intermediation

Within our travel agency operations, the data flow involves clear roles:

  • DollarTrips as Independent Controller: We process your data to manage travel requests, communicate with you, issue fiscal documents, and ensure platform functionality.
  • Third-Party Providers as Independent Controllers: Once you confirm a booking, passenger data is transmitted to transport and accommodation providers. They become independent data controllers subject to their own policies.

4. Categories of Data Subjects

We process data of the following categories of persons:

  • Site users and visitors
  • Offer requesters
  • Travelers / Passengers
  • Persons submitting complaints or requests

5. Data We Collect

We collect strictly necessary data based on the interaction stage:

A. Contact and Identity Data

Name, phone number, email address, departure city.

B. Travel Preferences & Budget

Chosen destination, dates, number of passengers, estimated budget, preferences.

C. Booking & Ticketing Data

ID/passport data (series, number, DOB, nationality) — only when legally required by the airline or hotel.

D. Technical and Navigation Data

IP address, security logs, aggregated traffic data.

6. Data of Other Group Travelers

If you input data of other travelers, you are obliged to ensure you have informed them about this Privacy Policy and obtained their consent.

7. Minors' Data

DollarTrips does not intentionally collect data from minors without consent from legal representatives. Minors' data is collected exclusively through the parent or legal guardian.

8. Special Categories of Data

By default, we do not process sensitive data. However, if required for specific services (e.g., airport assistance, medical meals), we process it strictly based on explicit consent.

9. Payment Data Security

DollarTrips does not retain direct bank card data. All online payments are processed via 3D-Secure through authorized payment processors.

10. Purposes and Legal Grounds

Processing PurposeLegal Ground (GDPR)
Sending personalized offers.Art. 6(1)(b) - Pre-contractual steps
Booking flights and accommodation.Art. 6(1)(b) - Contract performance
Customer support.Art. 6(1)(f) - Legitimate interest
Accounting and invoicing.Art. 6(1)(c) - Legal obligation
Direct marketing.Art. 6(1)(a) - Explicit consent
Platform cybersecurity.Art. 6(1)(f) - Legitimate interest

11. Data Recipients

To fulfill our contractual obligations, data is transmitted to:

  • Travel Providers: Airlines, hotels (only upon booking confirmation).
  • IT Providers: Hosting platforms, email processors.
  • Public Authorities: Border police, tax authorities (based on strict legal obligations).

12. International Data Transfers

If you purchase travel services outside the European Economic Area (EEA), transmitting data to providers in the destination country is strictly necessary for contract execution (Art. 49(1)(b) GDPR).

13. Data Retention Periods

  • Financial-accounting data: 10 years.
  • Travel package contracts: 3 years after trip completion.
  • Unfinalized requests: 12 months.
  • Marketing data: Until consent withdrawal.

14. Security Measures

We implement rigorous procedures: HTTPS/TLS, encrypted databases, strict access policies, and periodic security audits.

15. Your Rights

  • Right of access (Art. 15)
  • Right to rectification (Art. 16)
  • Right to erasure (Art. 17)
  • Right to restriction of processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object (Art. 21)

16. How to Exercise Your Rights

You can exercise these rights using our dedicated form or via email at gdpr@dollartrips.ro. We respond within 30 days.

17. Complaints

If you are dissatisfied with how we processed your data, you can lodge a complaint with your local Data Protection Authority.