1. Introduction & Scope
SPARROW TRVL FZ-LLC (“SPARROW TRVL”, “we”, “us”, “our”) is a global travel studio and Online Travel Agency (OTA) licensed as a free-zone limited liability company in the United Arab Emirates. We are committed to protecting your personal data and handling it transparently in accordance with global privacy standards and local laws, including Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “PDPL”) of the United Arab Emirates.
We review and adapt this policy from time to time to ensure it rigorously covers the various privacy laws around the world. We define ‘personal data’ broadly as any information pertaining to you as an identifiable individual. Your name, email address, contact details, IP address, or device IDs all satisfy this definition. Because we work with global suppliers (travel sites, airlines, hotel aggregators) who receive your information to fulfill bookings, we ensure you have access to review their respective policies during the transaction process.
2. How Do We Collect Personal Data?
As users visit our sites or use our applications, a myriad of information is collected and stored regarding their experience. We operate on the principle of data minimization—collecting only what is strictly necessary. We collect information in three distinct ways:
2.1 You Give It To Us Voluntarily
Information you choose to give us includes personal data needed to book travel for yourself and others. This ranges from the dates and destinations you select, to the vital details required for making a booking with a Travel Supplier (such as legal names, passport details, and contact information). It also includes reviews, feedback, or concierge inquiries you initiate.
2.2 We Generate or Collect It Automatically
We generate or collect specific information from your computer or mobile device automatically as you use our services. This includes your IP address, device model, operating system, browser type, the website URL you visited us from, and the third-party sites you visit when you click on links to exit the SPARROW TRVL site. We also approximate your geographic location to ensure we provide the correct currency, language settings, and localized pricing.
2.3 We Receive It From Third Parties
Sometimes we receive information about you from external third parties. For example, when you log into your SPARROW TRVL account using a social network login feature, or when you use a third-party payment gateway to finalize a booking (where we receive a masked confirmation token). Additionally, if you are redirected to a Travel Supplier's platform to finalize a booking, we may securely collect status updates from them regarding your reservation.
3. Children's Privacy
Our sophisticated travel services are strictly not intended for children under 18 years of age. No one under the age of 18 should provide any personal information directly to, on, or via our services. We do not knowingly collect personal data directly from minors. If we learn we have collected personal data belonging to a child that was not provided by, or with the express consent of, the child’s parent or legal guardian (e.g., during the execution of a family booking), we will immediately delete that information from our servers.
4. Specific Types of Personal Data We Collect
Depending on how you interact with our global services, we may collect or process the following specific categories of personal data:
| Category | Examples & Details |
|---|---|
| Contact Information | Name, billing address, email address, telephone/WhatsApp number, and similar communicative details. |
| Identification Information | Details of your passport or government ID (nationality, gender, date of birth, immigration status) strictly when legally required by an airline, border control, or specific hotel supplier. |
| Payment Information | We do not collect, process, or store your full credit/debit card number or CVV code. Transactions are handled by PCI-compliant third-party payment gateways. We store only masked tokens to verify the booking status. |
| Travel & Booking Data | Your booking reference, passenger name record (“PNR”), booking history, requested routes, layovers, and full travel itinerary. |
| Demographic Information | Your age, gender, location, and preferred language. |
| Device & Location Data | Generic details from your device (IP address, make, model, OS). Specific GPS location data (only if you explicitly grant us access via device settings), and approximated location based on IP. |
| Application Usage Data | Search history, preferences, time spent on pages, A/B testing interactions, and the identity of Travel Suppliers you select. |
| User Preferences & Comms | Marketing consents, email preferences, customer service chat logs, help requests, and associated metadata (timestamps). |
| Social Media Linked Data | If you use a third-party social media platform to log in, your email address and publicly accessible profile data are securely collected to authenticate your SPARROW TRVL account. |
5. How and Why We Use Your Data
We only use information for which explicit consent has been given, or where a legitimate business or legal obligation exists. We process your data for the following situations:
5.1 Service Delivery and Bookings (Contractual Necessity)
- Tailoring our website presentation to seamlessly fit your specific device.
- Providing dynamic search results matching your requirements (origin, dates, guest counts).
- Transferring necessary data (contact information, passenger details) directly to our Travel Suppliers' systems to finalize your transaction.
- Contacting you with critical messages, booking confirmation emails, flight status alerts, and updates to our Terms of Service.
5.2 Legal Compliance and Obligations
We may retain and use your information in connection with legal claims, or for compliance, regulatory, and auditing purposes within the UAE and internationally. Furthermore, when you exercise your legal privacy rights (e.g., requesting data deletion), we may request verification documents to securely confirm your identity.
5.3 Normal Business Usage and Strategic Analytics
We use data to protect our legitimate interests and aggressively optimize the platform. Examples include:
- Security and Fraud Prevention: Utilizing IP addresses to check payment origins against booking details, and deploying tools to prevent automated software agents (bots) from scraping our systems.
- A/B Testing & Optimization: Executing A/B tests that display alternate versions of our applications to different user groups to evaluate the impact of design changes.
- Strategic Data Analytics: Performing high-level analytics based on the anonymized requests of millions of users. This helps us see global demand for routes, specific suppliers, and emerging travel trends to inform strategic business decisions.
- Customer Support: Assisting our supplier partners in understanding your user journey prior to arriving at their specific properties or flights to resolve disputes.
5.4 Consent for Data Usage (Marketing)
We will explicitly obtain your consent before sending one-way (push) communications, such as price alerts or email newsletters. You can withdraw this consent at any time via your profile settings or by clicking 'unsubscribe' in any marketing email.
6. Sharing Personal Information with Third Parties
We share information with third parties in three specific scenarios: when you ask us to, when it is a necessary part of the business flow, or when legally required.
6.1 Sharing with Processors Under Our Strict Instruction
We share information with selected third parties who provide technical infrastructure (Third-Party Processors). We legally require these processors to keep the information secure and use it solely as we instruct. They may never use it for their own purposes. Examples include:
- Payment Processors: Industry-leading gateways engaged to securely handle payments.
- Email Distributors: Tools used to manage the reliable delivery of our confirmations and newsletters.
- Fraud Prevention Services: Agencies used to identify malicious bot traffic and prevent API abuse.
- Cloud Storage: Providers of highly secure, global cloud storage and IT support services.
6.2 Sharing with Travel Suppliers (Outside Our Control)
If you purchase travel via SPARROW TRVL, the personal data you submit must be securely shared with the relevant Travel Supplier (e.g., specific hotel chains, airlines, transfer companies) to allow the booking to be executed. Once transferred, this data is subject to that Supplier’s own independent privacy policy and terms. Suppliers may also use this data for their own internal fraud-detection purposes.
6.3 Disclosing Information for Legal Reasons
We may disclose your information if it is strictly necessary to enforce our Terms of Service, prevent or prosecute illegal activities (including payment fraud), or respond to legally binding requests, court orders, or UAE regulatory bodies.
7. Advertising and Personalization
7.1 Advertisements on SPARROW TRVL
You may see advertisements when you use our platform. Sometimes these are personalized to make them highly relevant. For example, if you recently searched for a flight to the Maldives, SPARROW TRVL might serve a relevant advertisement for luxury resorts in that location. This personalization relies on search history but will never expose your name or contact details to the advertiser.
7.2 Advertisements on Non-SPARROW TRVL Platforms
You may also see advertisements for our services once you have left our website. This occurs when a non-SPARROW TRVL platform makes advertising space available, and a Third-Party Ad Solution we work with purchases that space to remarket to you based on your previous interactions with us.
8. Cookies, Web Beacons, and Tracking Technologies
We use cookies, pixels, and tracking codes to collect information in line with this policy.
8.1 What is a Cookie?
Cookies are tiny data files stored on your web browser or device. They record your preferences (such as currency and language), assist with secure logins, and help us track the success of new interface experiments.
8.2 What are Web Beacons and Tracking Codes?
Web beacons or pixels are extremely small (often 1 pixel) transparent image files inside a web page or email. We use them to understand if you have successfully completed a booking after being redirected, or to gather information on whether you’ve opened a marketing email. Tracking codes are snippets placed on our pages to measure global visits and technical interactions.
8.3 Types of Third-Party Cookies We Use
| Category | Purpose & Examples |
|---|---|
| Necessary Cookies | Required for the secure operation of the site, CDN image delivery, and tracking user cookie privacy permissions (e.g., Cloudflare, AWS Cloudfront, Cedexis). |
| Statistics Cookies | Used to identify the source of app downloads and perform business analytics (e.g., Google Analytics, AppsFlyer). |
| Marketing Cookies | Used to personalize ads on global advertising networks and track EDM marketing efforts (e.g., Google Ads, WebEngage). |
8.4 How to Opt-Out of Cookies
Current web browsers allow you to set notifications for receiving cookies or to block them entirely. Note that blocking necessary cookies may break essential booking functionalities.
- Microsoft Edge: Settings > View advanced settings > Cookies (Select blocking options).
- Firefox: Options > Privacy panel > Use custom settings for history.
- Chrome: Settings > Privacy and security > Cookies and other site data.
9. Data Security and Global Storage
Keeping your personal data secure is our absolute highest priority. While no app can guarantee complete security, we have implemented world-class organizational processes:
- Encryption: All transmission of data uses end-to-end TLS and HTTPS/SSL encryption. Data at rest is encrypted on-disc.
- Principle of Least Privilege (PoLP): We strictly limit access to your data. Only SPARROW TRVL employees who require the information to perform their specific jobs are granted access.
- Global Storage: We store the information we collect on secure servers managed by major Third-Party Cloud Platform suppliers holding audited ISO 27001, SOC 2, SOC 3, and CSA Star certifications. Data may be stored globally based on technical infrastructure routing, but always governed by high common denominators of security compliant with UAE law.
10. How Long We Store Your Data
Our policy is to store data strictly for only as long as is necessary to satisfy legal requirements or fulfill the purposes outlined in this policy (e.g., fulfilling a booking contract). Once this period is complete, we securely anonymize and aggregate the data (rendering it non-personally identifiable) or delete it entirely.
If you have a SPARROW TRVL account, we will keep your profile details active so you can log in. You can ask us to aggressively delete your personal data at any time, subject to our legal tax and auditing retention duties.
11. Your Privacy Rights and Choices
If you have a SPARROW TRVL account, you can access, edit, or delete the key personal data associated with your profile at any time. Subject to the UAE PDPL and applicable global laws, you have the right to:
- Access: Ask us for a copy of the personal data we hold about you.
- Correction: Request that we correct inaccurate or incomplete data.
- Erasure: Ask us to delete your personal data (The Right to be Forgotten), assuming we don't have a compelling legal or security interest to retain it.
- Restriction & Objection: Object to the processing of your data, particularly for direct marketing purposes or automated profiling.
- Portability: Obtain the personal data you provided to us in a structured, machine-readable format.
- Withdraw Consent: Withdraw previously given consent at any time without affecting the lawfulness of prior processing.
12. Who Are We & How to Contact Us
SPARROW TRVL is provided by SPARROW TRVL FZ-LLC, a free-zone company registered in Dubai, United Arab Emirates. We act as the primary Data Controller.
SPARROW TRVL FZ-LLC
Dubai, United Arab Emirates
Privacy & Data Protection Officer: privacy@sparrowtrvl.com
General Support: sales@sparrowtrvl.com
If you have unresolved concerns regarding how we handle your data, you have the right to lodge a formal complaint with a competent UAE data protection authority.