Visit Socotra
Privacy Policy
How Visit Socotra collects, uses, and protects your personal information.
Effective August 2026
1. Introduction
Visit Socotra respects the privacy of travellers, customers, website visitors, and people who communicate with our team.
This Privacy Policy explains how we collect, use, store, disclose, and protect personal information in connection with our website and expedition services.
2. Information We Collect
We may collect information when you:
- browse the website;
- request information;
- create a booking;
- make a payment;
- create an account;
- communicate with our team;
- upload travel documents;
- request visa assistance;
- request a flight quotation;
- join a waiting list;
- request a private expedition; or
- complete post-booking onboarding.
3. Traveller Information
Traveller information may include:
- full legal name;
- email address;
- telephone number;
- country of residence;
- nationality;
- gender where required;
- date of birth;
- passport number;
- passport expiry date;
- passport copy;
- personal photograph;
- emergency contact details;
- dietary requirements;
- accessibility requirements;
- travel preferences; and
- other information necessary to operate the expedition.
4. Passport and Identity Documents
Passport copies and identification documents may be required for:
- visa processing;
- manifests;
- permits;
- travel arrangements;
- identity verification; and
- legal or operational requirements.
These documents are considered sensitive operational information and access should be restricted to authorized personnel and providers who genuinely require them.
5. Payment Information
Payments may be processed by third-party providers such as payment gateways or PayPal.
Visit Socotra does not need to store complete card numbers where payment processing is handled directly by the payment provider.
We may retain:
- transaction reference;
- payment status;
- amount;
- currency;
- invoice information;
- payment method;
- refund information; and
- related accounting records.
6. Technical Information
When using the website, we may automatically collect technical information such as:
- IP address;
- browser;
- device type;
- operating system;
- language;
- referring page;
- pages viewed;
- session information;
- security logs; and
- approximate location derived from technical data.
7. How We Use Personal Information
We may use information to:
- process bookings;
- calculate traveller pricing;
- determine visa requirements;
- process payments;
- operate customer accounts;
- arrange visas;
- coordinate guides and logistics;
- arrange accommodation;
- prepare manifests;
- assist with flight requests;
- communicate trip information;
- provide customer support;
- send service notifications;
- prevent fraud;
- maintain security;
- comply with accounting obligations;
- comply with legal obligations; and
- improve our services.
8. Traveller Pricing and Nationality
Date of birth and nationality may be used to determine:
- applicable traveller category;
- expedition pricing;
- visa requirement;
- visa fee;
- onboarding requirements; and
- relevant travel documentation.
9. Sharing With Service Providers
We may share necessary information with third parties that assist us in delivering the expedition.
These may include:
- local tour operators;
- guides;
- transport providers;
- hotels;
- camps;
- visa and government authorities;
- airlines or flight partners;
- payment processors;
- email providers;
- cloud hosting providers;
- document-storage providers;
- security providers;
- professional advisers; and
- technical service providers.
Only information reasonably necessary for the relevant purpose should be shared.
10. Government and Visa Authorities
Passport and identity information may be provided to government agencies or authorised intermediaries where required for visas, permits, immigration, or travel administration.
Once information is legally submitted to a government authority, its processing may also be governed by that authority's rules.
11. We Do Not Sell Personal Information
Visit Socotra does not sell personal information to third parties.
12. Marketing Communications
Transactional communications necessary to operate a booking may be sent regardless of marketing preferences.
These include:
- booking confirmations;
- payment confirmations;
- document requests;
- visa updates;
- travel briefings;
- flight information;
- safety information; and
- departure reminders.
Promotional messages, where used, may provide an unsubscribe option.
13. Cookies and Similar Technologies
The website may use cookies or similar technologies for:
- session management;
- authentication;
- preferences;
- security;
- fraud prevention;
- analytics; and
- website performance.
14. Security
We use reasonable technical and organisational safeguards to protect information.
These may include:
- authentication;
- access controls;
- role-based permissions;
- encrypted data transmission;
- secure storage;
- audit logs;
- monitoring; and
- restricted administrative access.
No internet-based system can guarantee absolute security.
15. Document Access
Customer passport files and other uploaded documents should not be publicly accessible.
Access is restricted to the customer, authorised Visit Socotra staff, or authorised providers where required to deliver the service.
16. Data Retention
We retain information for as long as reasonably necessary to:
- operate the booking;
- deliver the expedition;
- provide customer support;
- meet legal requirements;
- meet accounting requirements;
- prevent fraud;
- resolve disputes; and
- maintain business records.
Different categories of information may have different retention periods.
17. Data Deletion
Where legally and operationally permitted, customers may request deletion of personal information.
Some records may need to be retained despite a deletion request, including:
- financial records;
- payment records;
- invoices;
- fraud-prevention records;
- legal records; and
- records required to resolve disputes.
18. Access and Correction
Customers may request:
- access to their personal information;
- correction of inaccurate information;
- updates to traveller details;
- export of certain information; or
- deletion where applicable.
Some booking information cannot be changed after permits, visas, payments, or third-party services have already been issued without additional review.
19. International Data Processing
Because Visit Socotra serves international travellers and coordinates services across multiple countries, personal information may be processed or transmitted outside the traveller's country of residence.
We take reasonable steps to use trusted providers and appropriate safeguards.
20. Children
Where a child or infant travels as part of a booking, their information may be provided by the parent, guardian, or responsible lead booker.
The lead booker confirms that they are authorised to provide the information necessary to arrange the child's travel.
21. Third-Party Websites and Providers
Our website or communications may link to third-party services.
Their privacy practices are governed by their own policies.
Visit Socotra is not responsible for the privacy practices of unrelated third-party websites.
22. Changes to This Privacy Policy
We may update this policy to reflect changes to:
- our services;
- technology;
- providers;
- legal requirements; or
- operating procedures.
The latest version will be published on the website.
23. Contact
Privacy requests and questions may be sent to:
hello@visit-socotra.com
