Marg
✦ Legal

Privacy Policy

Effective date: 1 August 2026 · Type of site: e-commerce (digital services)

On this page

1. Who we are 2. GDPR 3. Consent 4. Legal basis for processing 5. Personal data we collect 6. How we use personal data 7. Who we share personal data with 8. How long we store personal data 9. How we protect your personal data 10. Your rights as a user 11. Children 12. How to access, modify, or delete your data 13. How to opt out 14. International data transfers 15. Modifications 16. Complaints 17. Contact information

1. Who we are

https://margtravel.co.uk (the "Site") is owned and operated by Marg. Marg is the data controller and can be contacted at:

Email: bookmargtravel@yahoo.com

This policy tells you what personal data we collect, how we use it, who has access to it, and what rights you have. It applies in addition to our Terms & Conditions.

2. GDPR

For users in the European Union, we adhere to Regulation (EU) 2016/679 (the "GDPR"). For users in the United Kingdom, we adhere to the GDPR as enshrined in the Data Protection Act 2018.

We have not appointed a Data Protection Officer, as we do not fall within the categories of controllers and processors required to appoint one under Article 37 of the GDPR. Any questions about your data should be sent to the contact details above.

5. Personal data we collect

We only collect data that helps us achieve the purposes set out in this policy. We will not collect any additional data beyond what's listed below without notifying you first.

Data collected when you use the Site

This data is collected directly from you, when you fill out the trip intake form or make a purchase.

6. How we use personal data

Data collected on our Site is only used for the purposes specified in this Privacy Policy. We will not use your data beyond what we disclose here.

The data we collect may be used for the following purposes:

7. Who we share personal data with

Within Marg

We may disclose user data to anyone within our organisation who reasonably needs access to it to achieve the purposes set out in this policy. As Marg is currently run directly by its owner, this means access is limited to that individual — we do not have external staff or contractors with data access.

Service providers

Third partyWhat they receiveWhy
NetlifyTrip intake form submissionsHosting and form processing
StripePayment and billing detailsPayment processing

Other disclosures

We will not sell or share your data with other third parties, except in the following cases:

  1. If the law requires it;
  2. If it is required for any legal proceeding;
  3. To prove or protect our legal rights; and
  4. To buyers or potential buyers of this company, in the event that we seek to sell the company.

If you follow hyperlinks from our Site to another site — for example, a restaurant or hotel booking link in your itinerary — please note that we are not responsible for and have no control over their privacy policies and practices.

8. How long we store personal data

User data will be stored for 24 months after your last interaction with us. You will be notified if your data is kept for longer than this period.

Transaction records (the fact a payment was made, the amount, and the date — not card details, which we never hold) are kept for 6 years, in line with UK HMRC recordkeeping requirements.

9. How we protect your personal data

While we take all reasonable precautions to ensure that user data is secure, there always remains a risk of harm. The internet as a whole can be insecure at times, and we are unable to guarantee the security of user data beyond what is reasonably practical.

10. Your rights as a user

Under the GDPR, you have the following rights:

  1. Right to be informed;
  2. Right of access;
  3. Right to rectification;
  4. Right to erasure;
  5. Right to restrict processing;
  6. Right to data portability; and
  7. Right to object.

11. Children

We do not knowingly collect or use personal data from children under 16 years of age. If we learn that we have collected personal data from a child under 16, that data will be deleted as soon as possible. If a child under 16 has provided us with personal data, their parent or guardian may contact us at the details in Section 17 to have it removed.

12. How to access, modify, delete, or challenge the data collected

If you would like to know whether we have collected your personal data, how we have used it, whether we have disclosed it and to whom, if you would like your data deleted or modified in any way, or if you would like to exercise any of your other rights under the GDPR, please contact us at the details in Section 17.

13. How to opt out of data collection, use, or disclosure

In addition to the methods described in Section 12, we provide the following specific opt-out method for the data specified below:

What you can opt out of: the optional data categories — dietary/allergy information and cultural or culinary background. These are the only fields on the trip intake form that aren't required to deliver the service; everything else (name, email, trip dates, destinations) is necessary to fulfil your order.

How to opt out:

14. International data transfers

Our service providers (Netlify and Stripe) may process data outside the UK, including in the United States. Where this happens, they do so under approved safeguards such as Standard Contractual Clauses or equivalent frameworks recognised under UK GDPR.

15. Modifications

This Privacy Policy may be amended from time to time to maintain compliance with the law and to reflect any changes to our data collection process. When we amend this policy, we will update the effective date at the top of this page. We recommend reviewing this policy periodically; where necessary, we may also notify users by email of significant changes.

16. Complaints

If you have any complaints about how we process your personal data, please contact us through the details in Section 17 so that we can, where possible, resolve the issue directly.

If you feel we have not addressed your concern satisfactorily, you also have the right to lodge a complaint directly with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO), the UK's independent supervisory authority for data protection.

Information Commissioner's Office

Website: ico.org.uk

Telephone: 0303 123 1113

17. Contact information

If you have any questions, concerns, or complaints, you can contact us at:

Email: bookmargtravel@yahoo.com

Back to Marg