Sumba Luxury Tour Privacy Policy

Sumba Luxury Tour Privacy Policy

Sumba Luxury Tour collects only the personal data needed to quote, book and run a guided Sumba tour: your name, contact details, travel dates, passport details for lodge and flight bookings, and the WhatsApp or email messages you send us. We share it with partner lodges, guides and drivers only as far as a booking requires, and we never sell it.

Effective date: 15 September 2026. This Sumba Luxury Tour privacy policy covers sumbaluxurytour.com, our enquiry form, our WhatsApp line and our email inbox, in plain language on purpose.

Who is responsible for your data?

Sumba Luxury Tour is a brand operated by Indonesia Juara Trip, part of Juara Holding Group. Under Indonesia’s Personal Data Protection Law (Law No. 27 of 2022, “UU PDP”), Indonesia Juara Trip is the data controller for everything you share with us.

We arrange guided tours; we do not own NIHI Sumba, Lelewatu, Cap Karoso, Maringi Eco Resort, the aircraft or the 4x4s, which come from vetted licensed partners. Once a lodge or airline confirms your reservation, it becomes a separate controller of the data it holds, and its own privacy notice applies alongside this one.

What data do we collect, and where does it come from?

Source What we receive Why
Enquiry form Name, email, phone or WhatsApp number, travel dates, party size, preferred lodge and region, your message To prepare a quote
WhatsApp (+62 811-9941-919) or email (sales@indonesiajuara.asia) Your number or address, profile name, the conversation, any photos or documents you send To answer you and hold a booking conversation
Confirmed booking Passport name, number, nationality, date of birth and expiry; dietary needs; emergency contact; health notes you choose to share for riding, waterfall hikes or Pasola crowds Lodge check-in, domestic flight tickets, guide and driver safety briefings
Payment Bank-transfer confirmation or the reference returned by a payment processor To match money to a booking
Website visit IP address, device type, pages viewed, referring site Analytics and security

We never store full card numbers; card payments, where offered, run through a third-party processor under its own rules.

Health information is specific (sensitive) personal data under UU PDP and a special category under the EU GDPR. We record it only when you volunteer it, only for safety, and only with your explicit consent.

Why do we use your data, and on what legal basis?

UU PDP (Article 20) and, for European Economic Area and United Kingdom visitors, GDPR Article 6 require a lawful basis for each use. Ours are:

Purpose Lawful basis
Preparing and sending a quote Steps taken at your request before a contract
Confirming lodges, guides, drivers, flights and village permits Performance of the contract
Recording health notes for riding, hiking or ritual-ground visits Your explicit consent
Keeping invoices and payment records Legal obligation (Indonesian tax rules require ten years)
Passing guest identity to lodges Legal obligation of accommodation providers to register guests
Replying to WhatsApp and email messages Legitimate interest in answering people who contact us
Sending seasonal updates, such as Pasola date confirmations Your consent, withdrawable at any time

We make no automated decisions about you and do not profile you for advertising.

Who do we share your data with?

Only the parties a specific booking needs, and only the fields each one needs:

  • Partner lodges: guest names, passport details, arrival and departure dates, dietary and accessibility needs. Never your chat history.
  • Licensed guides and drivers: names, pickup points, timings, dietary needs and safety-relevant health notes. They hold your phone number only for the days you travel together.
  • Airlines and ferry operators: passenger names and passport details for ticketing.
  • Payment processors and banks: what they need to settle an invoice.
  • Technology providers hosting our website, email and booking records. WhatsApp is operated by Meta, whose own policy governs the app on your phone.
  • Juara Holding Group companies handling accounting and reservations on our behalf.

We do not sell personal data, rent lists, or pass your details to advertisers or data brokers.

Some providers sit outside Indonesia, so your data may cross borders. UU PDP Article 56 requires equivalent protection in the receiving country, a binding safeguard, or your consent. For EEA and UK visitors, transfers to Indonesia rely on their being necessary to perform your booking (GDPR Article 49(1)(b)) and on your consent where you volunteer health data.

How long do we keep it?

Record Retention (as of September 2026)
Enquiry that never becomes a booking 12 months from the last message, then deleted
WhatsApp and email booking conversations 24 months after your tour ends
Passport copies and images Deleted within 90 days after your tour ends
Health notes Deleted within 30 days after your tour ends
Invoices and payment records 10 years, as Indonesian tax law requires
Website analytics Up to 14 months, then aggregated
Marketing consent Until you withdraw it

Encrypted backups clear a deleted record within a further 30 days.

Do we use cookies and analytics?

Yes, lightly. As of September 2026 the site uses essential cookies that keep forms working and block spam; analytics that record page views, device type and browsing country with IP addresses truncated; and a tap-tracking event when you press a WhatsApp button, so we know which page prompted the conversation. That event cannot read your chat. We run no retargeting pixels or advertising cookies, and the site still works if you block cookies in your browser.

What are your rights?

UU PDP gives you the right to know who holds your data, to access and correct it, to have it deleted, to withdraw consent, to object to automated decisions, to receive a copy in a usable format, and to claim compensation for a breach that harms you. GDPR gives EEA and UK visitors the matching rights under Articles 15 to 22.

To use any of them, message us on WhatsApp or email with the subject “Privacy request”. We confirm receipt within three working days and complete the request within 30 days, or sooner where the law sets a shorter clock. We may ask you to verify your identity first. You may also complain to Indonesia’s personal-data protection authority designated under UU PDP or, for EEA and UK residents, to your local supervisory authority.

How do we protect it, and what do we not promise?

Access to booking records is limited to the reservations team. Accounts use two-factor authentication, passport images sit in encrypted folders rather than chat threads, and we delete them on the schedule above. If a breach affects your data, UU PDP Article 46 obliges us to notify you and the authority within 3 x 24 hours, and we will.

Two honest limits. We cannot control how a lodge, an airline or WhatsApp handles data once it leaves us; their policies are theirs. And this page is a privacy policy, not a booking contract: prices on this site are land-only until lodge nights are confirmed, every total is a quote until then, and booking, cancellation and liability terms live on our Terms and Conditions page.

Children’s names and passport details are held only when a parent or guardian supplies them for a family booking; we do not knowingly take enquiries from anyone under 18.

Will this policy change?

Yes. Indonesian tourism levies, drone rules and guide-licensing standards all shifted in 2025 and 2026, and data rules move too. Any change is posted here with a new effective date; one affecting a live booking is sent to you directly.

How can you reach us?

  • WhatsApp: +62 811-9941-919
  • Email: sales@indonesiajuara.asia
  • Post: registered office details available on request through either channel.

Put “Privacy request” in the first line and a person, not a bot, will reply.

WhatsApp the concierge
Scroll to Top