Exposha Data Policy

Your travel preferences tell a story. We treat that data with the same care we bring to designing your escape.

This Data Policy explains how Exposha handles, stores, and protects the information you share when exploring our website, planning a personalized escape, taking our travel mood quiz, or communicating with our team.

Exposha Ltd is a travel design platform registered in the United Kingdom. We curate multiday escapes, publish destination guides, and connect travelers with vetted local hosts, properties, and experience providers across destinations including Nepal, Vietnam, Indonesia, Italy, Sri Lanka, Thailand, India, and the United Kingdom.

We do not sell your personal data to advertisers or data brokers. We collect only what we need to design thoughtful escapes, keep our platform secure, and communicate with you about journeys you have asked us to help plan.

This policy works alongside our Privacy Policy, which provides the full legal detail on your rights under GDPR and other applicable laws. Read both documents together for a complete picture of how your information is handled.

By using exposha.com or any Exposha service, you acknowledge the practices described here.

Last updated: July 2026

Related: Terms of Service, Privacy Policy

01

What Data We Handle

We process data across clear categories. Each exists because it helps us design better escapes, introduce you to the right partners, or keep our platform running securely.

Identity and contact data

Includes: Full name, email address, phone number, nationality, and billing address where relevant.

  • Collected when you submit an enquiry, request a personalized escape, create an account, subscribe to our newsletter, or contact us through the website.
  • Used to respond to you, send itinerary proposals, and — with your consent — introduce you to travel partners when your escape is ready to proceed.

Travel planning and preference data

Includes: Travel party type, number of travelers and ages, preferred dates, selected destinations and experiences, trip duration, travel pace, accommodation style, budget and currency, special occasions, dietary requirements, accessibility needs, and free-text notes about how you like to travel.

  • Collected through our personalized escape planner, product enquiry forms, and direct conversations with our team.
  • This is the heart of what we do — it allows us to move beyond generic packages and compose escapes tailored to how you actually travel.

Quiz and browsing data

Includes: Answers to our travel mood quiz, saved escapes, pages viewed, search queries, and destinations or experiences you explore on the site.

  • Helps us understand what resonates with you and suggest relevant inspirations — always in service of better travel design, not unrelated advertising.

Account and communication data

Includes: Login credentials, account preferences, message history with our team, enquiry records, and itinerary revision history.

  • Enables secure access to your account, continuity across planning conversations, and a record of what was agreed as your escape takes shape.

Technical and device data

Includes: IP address, device type, browser, operating system, session cookies, referring URLs, and analytics about navigation patterns.

  • Keeps the site secure, fixes bugs — especially on mobile — and helps us understand which destinations and experiences travelers explore most.

Payment references

Includes: Transaction references, billing history, and the last four digits of a payment card where Exposha processes a payment.

  • Exposha is primarily a travel design platform. Most bookings and payments are completed directly with our partners. Where we process a payment, card numbers are encrypted and we never store your full card number.

02

How Your Data Flows Through Exposha

Understanding when and why your data moves through our platform can help you make informed choices. Here is a typical journey from first visit to partner introduction:

Step 1 — Exploring
When you browse destinations, experiences, or travel guides, we may collect anonymous or pseudonymous technical data and cookie identifiers. No personal details are required at this stage.
Step 2 — Sharing preferences
When you submit a personalized escape request or enquiry, we collect the contact and travel details you provide. This data is stored securely and accessed only by authorized members of our planning team.
Step 3 — Designing your escape
Our team uses your preferences internally to compose itinerary proposals. Your data is not shared externally during this phase unless you explicitly ask us to contact a specific partner on your behalf.
Step 4 — Partner introduction
When you approve an itinerary and consent to partner sharing, we transfer relevant details — name, contact information, travel dates, party composition, and any dietary or accessibility requirements — to the vetted partners involved in your escape.
Step 5 — After your trip
We may retain your planning history and correspondence for up to five years to assist with rebooking or follow-up questions. You can request deletion at any time, subject to legal retention requirements.

03

Why We Process Your Data

Every piece of data we hold serves a defined purpose. We do not process your information for unrelated commercial purposes without telling you first.

We do not use automated decision-making or profiling that produces legal or similarly significant effects without human review. Our team reads what you share and designs your escape personally.

Designing personalized escapes
Your preferences — from travel pace to accommodation style — allow our team to compose itineraries that reflect how you travel, not a one-size-fits-all template.
Connecting you with the right partners
When you are ready to proceed, we use your details to introduce you to hosts, guides, and properties suited to your party size, budget, destination, and interests.
Communicating with you
We use your email and phone number to confirm receipt of requests, send proposals, answer questions, and — where you have opted in — share travel inspiration and newsletters.
Improving our platform
Aggregated and anonymized data helps us understand which destinations resonate, identify technical issues in our planning forms, and refine the tools we offer travelers.
Protecting travelers and partners
We process technical and identity data to detect fraud, prevent platform abuse, and maintain the integrity of our partner network.
Legal and regulatory compliance
Certain records — particularly financial and travel documentation — must be retained for tax, accounting, or immigration purposes under applicable law.

04

What We Never Do With Your Data

Trust is central to how Exposha works. The following practices are explicitly excluded from our operations:

We never sell your data
Your travel preferences, contact details, and planning history are not sold, rented, or traded to third parties for their own marketing or commercial purposes.
We never share without purpose
Partner sharing occurs only when you have approved an itinerary and consented where required. We do not pass your details to partners you have not agreed to work with.
We never collect more than we need
Form fields exist because they help us design your escape. We do not ask for information unrelated to travel planning or platform operation.
We never retain data indefinitely
Data is deleted or anonymized when it is no longer needed for the purposes described in this policy and our Privacy Policy.

05

How We Store and Protect Data

We apply industry-standard technical and organizational safeguards throughout the data lifecycle — from the moment you submit a form to long after your escape ends.

Encryption
Data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256 encryption on our systems. Payment data is handled exclusively through PCI-DSS compliant gateways.
Access controls
Personal data is accessible only to authorized Exposha team members on a need-to-know basis. Travel designers access planning preferences; finance staff access payment references; technical staff access anonymized analytics.
Infrastructure security
Our platform is hosted on secure cloud infrastructure with regular security monitoring, patch management, and vulnerability assessments.
Partner contractual standards
Travel partners who receive your data are bound by confidentiality agreements and data handling requirements. They may use shared information only to deliver the services you have agreed to.
Retention and deletion
Active customer records are retained for up to five years after your last enquiry. Inactive accounts are removed after three years of inactivity. When data is deleted, we use secure deletion methods that prevent recovery.
Breach response
In the event of a data breach posing high risk to your rights, we notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay.

06

When Data Is Shared

Sharing is limited, purposeful, and always subject to appropriate safeguards. These are the only circumstances in which your data leaves Exposha:

You can withdraw consent for future partner sharing at any time by contacting us. Withdrawal may limit our ability to complete arrangements for an escape already in progress.

Vetted travel partners
Hotels, wellness retreats, safari lodges, guides, and experience hosts involved in your approved itinerary. We share only what they need — typically your name, contact details, travel dates, party size, and any dietary, accessibility, or special requirements you have disclosed.
Platform service providers
Trusted vendors who help us operate exposha.com — including email delivery, cloud hosting, customer messaging, analytics, and payment processing. These providers act as data processors under strict contractual terms.
Legal and regulatory authorities
When required by law, court order, or valid regulatory request — for example, customs documentation, immigration compliance, or tax audits related to international travel.
International transfers
Because Exposha works with partners across Asia, Europe, and beyond, your data may be processed outside the UK or EEA. We rely on GDPR-approved safeguards including Standard Contractual Clauses to ensure equivalent protection.

07

Your Choices and Controls

You remain in control of your data throughout your relationship with Exposha. Here is what you can do at any time:

To make any request, email privacy@exposha.com with the subject line "Data Request". Include your name, the email address associated with your account or enquiry, and a clear description of what you need. We acknowledge requests promptly and respond within 30 days.

For full details on your legal rights under GDPR, UK data protection law, and other applicable regulations, please see our Privacy Policy.

Access your data
Request a copy of the personal data we hold about you — including escape preferences, enquiry history, and correspondence — in a readable format such as CSV or PDF.
Correct inaccuracies
Ask us to update incorrect or outdated details. A misspelled name on an itinerary or an old email address can be corrected promptly upon request.
Delete your data
Request erasure of your personal data, subject to legal retention requirements for tax records, completed bookings, or immigration documentation.
Restrict or object to processing
Ask us to pause certain uses of your data or object to processing based on legitimate interests, including direct marketing.
Manage marketing communications
Unsubscribe from newsletters using the link in any marketing email, or contact us directly. Opting out of marketing does not affect communications about an active escape you are planning.
Manage cookies
Adjust cookie preferences through your browser settings or our cookie banner. Essential cookies required for login and form functionality cannot be disabled without affecting site operation.
Withdraw consent
Revoke consent for health-related data processing, partner introductions, or marketing at any time. Withdrawal does not affect processing that lawfully occurred before you withdrew.

08

Analytics, Cookies, and Tracking

We use cookies and similar technologies to keep Exposha working smoothly and to understand how travelers explore our destinations, experiences, and planning tools.

You can change cookie preferences at any time through your browser settings or our cookie banner. Disabling analytics cookies does not affect your ability to browse escapes or submit a planning request.

Essential cookies
Required for login, session management, saving progress in the personalized escape planner, and maintaining security. These cannot be disabled without breaking core site functionality.
Analytics cookies
Help us measure page performance, understand navigation patterns, and identify where travelers leave the planning form — enabled only after you opt in via our cookie banner. We use tools such as Google Analytics with IP anonymization where supported.
Marketing and social cookies
Social media pixels and campaign measurement tools — such as those used on Instagram or Facebook — activated only with your explicit consent.
Preference cookies
Remember choices you make — such as theme settings or cookie preferences — to provide a consistent experience on return visits.

10

Changes to This Policy

We may update this Data Policy as our platform evolves — for example, when we introduce new planning tools, expand to new destinations, or change how we work with partners.

Minor clarifications will be posted on this page with a revised date. Material changes that affect how we handle your data will be communicated by email where we hold your contact details, giving you reasonable notice before changes take effect.

Contact

Contact Us

Questions about how Exposha handles your data, or a request to access, correct, delete, or restrict your information? We are here to help.

Email: privacy@exposha.com

General enquiries: info@exposha.com

Phone: +7448046106

Whitton Avenue West, Greenford

London, UB6 0DY · United Kingdom