Privacy policy
Last updated: 5 August 2026
1. Who this policy applies to
This policy explains how Erova Trips (“Erova Trips”, “we”, “us”) handles personal information when you use this website, submit an enquiry, communicate with us or book travel services.
2. Information we collect
We may collect your name, email, phone or WhatsApp number, travel dates, destinations, traveller details, budget direction, preferences, messages, referral or campaign information, and technical data such as IP address, browser type and page visited.
3. Why we use it
- To respond to enquiries and prepare travel proposals.
- To arrange confirmed services and provide trip support.
- To prevent spam, fraud and misuse of the website.
- To understand website performance when optional analytics are enabled.
- To meet legal, accounting and dispute-resolution obligations.
4. Legal basis and consent
We process enquiry information to take steps at your request before a potential booking, to perform a confirmed contract, to meet legal obligations and, where required, on the basis of your consent.
5. Service providers
Information may be processed by hosting, email, form-security, analytics, payment, accommodation, transport, guide and destination partners where necessary. We share only what is reasonably needed for the relevant purpose.
6. WhatsApp and external platforms
When you contact us through WhatsApp or another external platform, that platform’s own privacy terms also apply. Do not send card details, passwords or sensitive identity documents through an unsecured chat unless we specifically provide a secure method.
7. Retention
Unconfirmed enquiry data is retained only as long as reasonably useful for follow-up, business records and legal needs. Confirmed booking records may be kept longer for accounting, contractual and regulatory purposes.
8. Your choices
You may ask to access, correct or delete eligible personal information, withdraw marketing consent or raise a privacy question by emailing hello@erovatech.com. Some records may need to be retained where law or legitimate business obligations require it.
9. Security
We use reasonable administrative and technical safeguards, but no internet system is completely risk-free. Production deployment should use HTTPS, protected environment variables, restricted staff access and a verified email domain.
10. Changes
We may update this policy as the website, providers or legal requirements change. The date above identifies the latest published version.