Legal
Privacy policy
What we collect, why we need it, who we pass it to and how long we keep it. Booking a flight requires unusually sensitive data — passport details in particular — so this policy is specific about that rather than generic.
Last updated 19 August 2026
This is illustrative copy written to show the shape and specificity a real policy needs — particularly around travel documents and the ticketing partner. It has not been reviewed by a lawyer and must not be published as-is.
What we collect
Contact details: name, email address, phone number, country of residence and preferred language. We need these to administer the booking and to reach you about it.
Passenger details: full name, date of birth and gender for every traveller. Airlines require these to issue a ticket.
Travel document details for international itineraries: passport or national ID number, expiry date and issuing country. Airlines are legally required to transmit these to destination border authorities before departure, and cannot issue a ticket without them.
Booking and payment records: itineraries, fares paid, payment method type and the last four digits of a card. We do not receive or store full card numbers, expiry dates or security codes — those are captured directly by our payment gateway in fields hosted on their systems.
Marketing preferences: whether you opted in to fare alerts, and when. Consent is recorded with a timestamp so we can show why we contacted you.
Why we are allowed to hold it
Contract: most of the above is necessary to perform the booking you asked us to make. Without it there is no ticket.
Legal obligation: travel document details are processed because carriers and destination states require them. Financial records are retained because tax and anti-money-laundering rules require it.
Consent: marketing email is sent only where you opted in, and you can withdraw that at any time from your account or from any email we send.
Legitimate interests: fraud prevention, and defending or bringing legal claims.
Who we share it with
The operating airline, and the global distribution system through which the booking is made. This is unavoidable — the airline cannot carry a passenger it has no record of.
Our payment gateway, which processes the payment. They receive the card data directly from you rather than through us.
Border and immigration authorities in your destination and any transit country, where the law of that country requires advance passenger information.
We do not sell personal data, and we do not share it with advertisers.
International transfers
Air travel is inherently cross-border. Booking data will be transferred outside Nigeria — to airlines, distribution systems and destination authorities in other countries, whose data protection laws may differ from Nigeria’s. Where we choose a processor, we require contractual protection for the data. Where a state requires the data by law, we have no discretion.
How long we keep it
Booking and financial records: seven years from the date of travel, to meet tax and audit obligations.
Travel document numbers: retained only while needed to complete and support the booking, then deleted. We do not keep passport numbers indefinitely to make future bookings faster unless you have saved a passenger profile and asked us to.
Marketing contact details: until you unsubscribe, plus a short record of the withdrawal so we do not contact you again in error.
Your rights
Under the Nigeria Data Protection Act you can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it where we are not required to keep it, object to processing based on legitimate interests, and withdraw marketing consent.
Saved passenger profiles and marketing preferences can be changed directly from your account. For anything else, write to us and we will respond within one month.
If you are not satisfied with how we have handled a request you can complain to the Nigeria Data Protection Commission.
Security
Data is transmitted over TLS and access to booking records is restricted by role — customer-facing staff see what they need to serve you, and the fulfilment desk sees the additional fields it needs to issue tickets. Payment card data is out of scope of our systems by design, which is the single most effective control available to us.
Contacting us
Data protection enquiries: privacy@gotours.example. Postal address: Ikoyi, Lagos, Nigeria.
Questions about any of this? Talk to us.