PRIVACY POLICY
Every Avenue Travel LLC is registered with the State of Florida as a Seller of Travel. Registration No. ST45213.
1. Introduction
Every Avenue Travel LLC, referred to in this Privacy Policy as “Every Avenue Travel,” the “Company,” “we,” “us,” or “our,” respects the privacy of our Travelers, Participants, parents, guardians, children, website visitors, subscribers, and other persons who interact with us.
This Privacy Policy explains how we collect, use, disclose, store, transfer, retain, and protect personal information when you:
- Visit or interact with our website;
- Read or comment on Company content;
- Join a mailing list or waitlist;
- Request information or a quote;
- Submit a booking;
- Approve an itinerary;
- Pay an invoice;
- Communicate with us by email, telephone, text message, social media, or messaging platform;
- Participate in a Trip;
- Provide information for another Traveler;
- Provide information about a Minor;
- Submit insurance, medical, allergy, accessibility, or emergency information;
- Participate in surveys, promotions, contests, or reviews;
- Join a Company-managed group communication channel; or
- Otherwise use a service that links to this Privacy Policy.
“Trip” includes any tour, retreat, cruise, port excursion, worldschooling experience, family travel program, individual itinerary, group itinerary, guided activity, adventure activity, cultural program, accommodation, transportation service, or other travel-related service arranged, coordinated, operated, hosted, or sold by the Company.
2. Scope of This Policy
This Policy applies to personal information collected by the Company through:
- EveryAvenueTravel.com and Company-operated webpages;
- Company booking and registration forms;
- Quotes, invoices, and payment requests;
- Company email and customer-support communications;
- Company-managed social-media pages;
- Company-managed newsletters;
- Company-managed Trip groups and communication channels;
- In-person interactions during Trips;
- Incident, safety, and emergency records;
- Company surveys, reviews, promotions, and testimonials; and
- Third-party platforms when the Company receives or controls the information collected through the platform.
This Policy applies to both online and offline information.
3. Third-Party Services
Some services are provided through independent third parties, including:
- Booking platforms;
- Payment processors;
- Hotels and accommodations;
- Cruise lines;
- Ground transportation providers;
- Local and inter-island flight providers;
- Guides and destination-management companies;
- Activity and excursion operators;
- Insurance companies;
- Email and communication platforms;
- Analytics and advertising providers;
- Social-media services; and
- Cloud storage and business-software providers.
A third party may process information:
- On our behalf as a service provider or processor;
- Jointly with us for a particular service; or
- For its own independent purposes as a separate business or data controller.
When a third party determines its own purposes and means of processing, its privacy policy also applies. This Policy does not control an independent third party’s practices.
Links to third-party websites, affiliate offers, social-media pages, booking services, or Supplier pages do not mean that the Company controls those services.
4. Acknowledgment and Consent
No separate signature is required solely to acknowledge this Privacy Policy.
By providing personal information, submitting a booking, paying an invoice, or using a Company service after receiving or being given access to this Policy, you acknowledge that you have been informed of the practices described here.
Acknowledgment of the Privacy Policy is not the same as consent to every possible use of personal information.
Where consent is required by applicable law, the Company will seek consent through an appropriate method, which may include:
- A booking or payment action clearly associated with the stated purpose;
- A checkbox;
- A parent or guardian authorization;
- A cookie-preference tool;
- An email confirmation;
- A form submission;
- A media-consent selection; or
- Another recorded affirmative action.
You may withdraw consent for future processing where applicable, although withdrawal does not affect processing already lawfully completed and may prevent the Company from providing a requested service.
5. Booking for Other People
A person who provides information about another person represents that the person:
- Has authority to provide the information;
- Has informed the other person of this Privacy Policy;
- Has obtained any consent required to provide the information;
- Will not provide information beyond what is reasonably necessary; and
- Will promptly inform us if the information is inaccurate or authority is withdrawn.
A Booking Client may provide basic booking information for accompanying adults. However, the Company may contact each adult directly to obtain additional information, provide legal documents, confirm preferences, or establish that adult’s individual acceptance of booking agreements.
A parent or legally authorized guardian may provide information about a Minor as described in Section 18.
6. Personal Information We May Collect
The information we collect depends on how you interact with us and the requirements of the applicable Trip.
6.1 Identity and contact information
We may collect:
- Full legal name;
- Preferred name;
- Mailing address;
- Residential address;
- Email address;
- Telephone number;
- Date of birth;
- Age;
- Gender or title where required by a Supplier;
- Nationality;
- Citizenship;
- Preferred language;
- Social-media username;
- Account username; and
- Signature or electronic acceptance records where applicable.
6.2 Booking and travel information
We may collect:
- Trip name and dates;
- Destination;
- Itinerary;
- Accommodation and rooming preferences;
- Family and travel-party composition;
- Transportation details;
- Arrival and departure information;
- Cruise information;
- Activity selections;
- Meal selections;
- Dietary preferences;
- Special requests;
- Loyalty or membership information;
- Supplier reservation numbers;
- Booking status;
- Cancellations, transfers, credits, and refund information;
- Trip attendance and participation information; and
- Information concerning missed services, late arrival, or early departure.
The Company generally does not book airfare to or from a Trip. However, we may collect flight-arrival and departure information for scheduling transfers or coordinating the itinerary.
Where a Trip expressly includes a local, charter, scenic, domestic, or inter-island flight, we may collect information required by the aviation Supplier.
6.3 Passport, visa, and government-document information
Where reasonably necessary for a Trip or Supplier, we may collect:
- Passport number;
- Passport issue and expiration dates;
- Passport issuing country;
- Passport image or copy;
- Visa or travel-authorization information;
- National identification information;
- Driver’s-license information;
- Birth certificate or proof of relationship;
- Parental travel-consent documentation;
- Custody or guardianship documentation;
- Vaccination or entry documentation; and
- Other information required by immigration, customs, transportation, accommodation, cruise, or activity providers.
We will not request these documents for every Trip. We collect them only when reasonably necessary.
6.4 Payment and transaction information
We may collect:
- Billing name and address;
- Amounts paid;
- Payment dates;
- Currency;
- Deposit and installment status;
- Invoice number;
- Refund or credit information;
- Payment method type;
- Transaction identifier;
- Limited payment-card information supplied by a processor, such as the card brand and last four digits;
- Bank-transfer information where applicable;
- Chargeback or payment-dispute information; and
- Records showing who paid for a booking.
Third-party payment processors generally collect and process full card information directly.
Unless the Company provides a specifically approved secure method, do not send us:
- A full payment-card number;
- Card security code;
- Online-banking password;
- Payment-account password; or
- Other sensitive financial authentication information
through ordinary email, text message, social media, or a group chat.
6.5 Health, medical, dietary, and accessibility information
To assess requests, communicate with Suppliers, and support safe participation, we may collect:
- Allergies;
- Dietary restrictions;
- Food sensitivities;
- Physical or mental health conditions relevant to participation;
- Mobility limitations;
- Accessibility needs;
- Pregnancy information;
- Medication requirements;
- Emergency medication information;
- Recent surgery or injury;
- Sensory, cognitive, developmental, or behavioral needs;
- Swimming ability;
- Activity restrictions;
- Medical-clearance information;
- Physician or medical-provider contact information where appropriate;
- Communicable-illness information;
- Medical incidents occurring during a Trip; and
- Information reasonably necessary for emergency response.
Please provide only information reasonably relevant to the Trip.
Every Avenue Travel is a travel company, not ordinarily a health-care provider, health plan, or health-care clearinghouse. Information provided to a travel company may not be protected by HIPAA in the same way as information held by a HIPAA-covered provider, although we protect it under this Policy and other applicable laws. HIPAA applies to covered entities and business associates meeting the applicable legal definitions.
6.6 Insurance information
Because travel insurance is required under the applicable Participant Agreements, we may collect:
- Name of insurer;
- Policy number;
- Coverage dates;
- Name of insured person;
- Certificate or declaration page;
- Emergency-assistance telephone number;
- Medical-benefit information;
- Evacuation-benefit information;
- Information showing whether relevant adventure activities are covered;
- Insurance-claim correspondence voluntarily provided to us; and
- Proof that required coverage was obtained.
We do not need your full insurance file unless it is reasonably necessary for a claim, emergency, or legal matter.
You may redact:
- Premium amounts;
- Full payment-card details;
- Unrelated insured persons; and
- Information not reasonably needed to verify coverage.
6.7 Emergency-contact information
We may collect:
- Emergency contact’s name;
- Relationship to the Traveler;
- Telephone number;
- Email address;
- Address;
- Preferred language; and
- Other information reasonably needed to reach the person.
The person providing emergency-contact information represents that the contact may reasonably be identified and contacted for the stated purpose.
6.8 Information about Minors and families
We may collect:
- Minor’s name;
- Date of birth;
- Age;
- Parent or guardian identity;
- Parent or guardian contact information;
- Parent-child relationship;
- Trip and activity participation;
- Health, allergy, dietary, developmental, behavioral, or accessibility information;
- Insurance information;
- Emergency-contact information;
- Passport and travel-document information;
- Custody, consent, or guardianship information;
- Activity eligibility information;
- Incident information; and
- Parent or guardian acceptance records.
Information about a known child may be considered sensitive personal information under applicable law.
6.9 Communications and customer-service records
We may collect and retain:
- Emails;
- Text messages;
- Telephone notes;
- Contact-form submissions;
- Chat messages;
- Social-media messages;
- Booking-platform messages;
- Complaints;
- Refund requests;
- Questions;
- Requests for accommodation;
- Survey responses;
- Reviews;
- Testimonials;
- Incident communications; and
- Records of notices and agreements provided to you.
Telephone or video calls will not be recorded without notice where notice or consent is required.
6.10 Website, device, and usage information
When you use our website, we or our service providers may automatically collect:
- Internet Protocol address;
- Browser type;
- Device type;
- Operating system;
- Device identifiers;
- Approximate location derived from an IP address;
- Referring website;
- Pages viewed;
- Links clicked;
- Time and date of access;
- Time spent on a page;
- Search terms;
- Form interaction;
- Newsletter interaction;
- Advertising interaction;
- Cookie identifiers;
- Session information;
- Error and diagnostic logs; and
- General website usage patterns.
6.11 Cookies and similar technologies
We may use:
- Cookies;
- Pixels;
- web beacons;
- tags;
- local storage;
- embedded scripts;
- software development kits;
- analytics identifiers; and
- similar technologies.
These are described further in Section 14.
6.12 Social-media information
When you interact with us through social media, we may receive:
- Public profile information;
- Username;
- Name;
- Comments;
- Messages;
- Reactions;
- Posts;
- Photographs;
- Videos;
- Contest or promotion entries; and
- Information made available by the social-media platform according to your settings.
The social-media platform’s privacy policy also applies.
6.13 Photographs, video, and audio
During Trips, we may collect:
- Photographs;
- Video recordings;
- Audio recordings;
- Image metadata;
- Date, time, and general location of an image;
- Adult media-consent or opt-out information; and
- Separate parent or guardian media consent concerning a Minor.
The Company will use an identifiable Minor as a featured promotional subject only pursuant to the separate consent process described in the Terms and Conditions and applicable media authorization.
We do not intentionally use photographs or video to create facial-recognition templates or other biometric identifiers.
6.14 Incident, conduct, and safety information
We may collect:
- Accident and injury reports;
- Witness information;
- Photographs of an incident;
- Medical-response information;
- Property-damage information;
- Conduct complaints;
- Safety-rule violations;
- Removal or denied-participation records;
- Communications with Suppliers or authorities;
- Insurance documentation; and
- Information concerning legal claims.
6.15 Marketing and preference information
We may collect:
- Newsletter subscription status;
- Trip and destination interests;
- Preferred travel type;
- Family composition;
- Marketing-consent status;
- Email engagement;
- Event or waitlist interest;
- Promotion history;
- Advertising interaction; and
- Unsubscribe or opt-out records.
6.16 Public content
If our website allows comments, reviews, profiles, discussion boards, or public submissions, information you post may become publicly visible.
Do not publicly post:
- Passport information;
- Payment information;
- Medical information;
- A child’s precise location;
- Confidential family information; or
- Information about another person without authority.
We may moderate, remove, or restrict public content in accordance with our website terms and legitimate safety or business needs.
7. Sensitive Personal Information
Depending on the Trip and applicable law, sensitive personal information may include:
- Passport and government identification information;
- Account-login credentials;
- Financial information;
- Precise geolocation;
- Health information;
- Disability or accessibility information;
- Racial or ethnic information;
- Religious information revealed by dietary or scheduling requests;
- Citizenship or immigration information;
- Information about a known child;
- Sexual-orientation information voluntarily disclosed in connection with rooming or safety requests;
- Biometric identifiers used for unique identification; and
- Contents of private communications not directed to us.
We use sensitive personal information only where reasonably necessary to:
- Provide requested travel services;
- Meet Supplier requirements;
- Assess and arrange accommodations;
- Protect health and safety;
- Respond to an emergency;
- Verify identity or authority;
- Prevent fraud or security incidents;
- Comply with law;
- Establish, exercise, or defend legal claims; or
- Fulfill another purpose expressly disclosed to you.
We do not use health, passport, insurance, or known-child information for targeted advertising.
We do not use sensitive information to infer characteristics about a person for unrelated marketing purposes.
8. Sources of Personal Information
We may obtain information from:
- You;
- A Booking Client;
- A parent or guardian;
- An adult travel companion;
- An emergency contact;
- A family member;
- A Supplier;
- A booking platform;
- A payment processor;
- A travel-insurance provider or assistance service;
- A medical or emergency provider where authorized or legally permitted;
- A social-media platform;
- Website analytics and advertising providers;
- Publicly available sources;
- Government authorities;
- Professional advisers;
- Other Participants involved in an incident or complaint; and
- A person acting with your authorization.
If information is provided by another person, we may contact you to verify, supplement, or correct it.
9. How We Use Personal Information
We may use personal information for the following purposes.
9.1 Providing travel and booking services
We may use information to:
- Respond to inquiries;
- Prepare quotes;
- Design itineraries;
- Process bookings;
- Confirm availability;
- Arrange accommodations;
- Coordinate transportation;
- Reserve activities;
- Arrange local or inter-island flights included in a Trip;
- Arrange cruise or port services;
- Coordinate rooming;
- Communicate dietary or accessibility requests;
- Administer deposits, installments, credits, transfers, and refunds;
- Provide Trip documents;
- Communicate schedules and changes;
- Manage attendance; and
- Provide customer service.
9.2 Working with Suppliers
We may use and disclose information to:
- Confirm reservations;
- Meet Supplier identification requirements;
- Coordinate rooms and transportation;
- Verify age or activity eligibility;
- Communicate health, allergy, dietary, or accessibility needs;
- Arrange special assistance;
- Issue tickets or admission documents;
- Meet cruise, vessel, accommodation, or transportation requirements;
- Process Supplier changes or refunds; and
- Address complaints or incidents.
9.3 Health, safety, and emergencies
We may use information to:
- Assess whether a disclosed need can reasonably be accommodated;
- Communicate an allergy or mobility request;
- Verify required insurance;
- Contact an emergency contact;
- Arrange emergency services;
- Assist with medical care or evacuation;
- Share relevant information with medical personnel;
- Investigate an accident;
- Protect a Minor;
- Respond to a missing-person concern;
- Protect other Participants; and
- Comply with health or safety rules.
9.4 Payments and financial administration
We may use information to:
- Generate invoices;
- Process payments;
- Record deposits and installments;
- Issue refunds or credits;
- Reconcile Supplier payments;
- Respond to chargebacks;
- Detect fraud;
- Maintain tax and accounting records; and
- Collect properly due amounts.
9.5 Legal documents and acceptance records
We may use information to:
- Provide Terms and Conditions;
- Provide cancellation terms;
- Document electronic acceptance;
- Record the version accepted;
- Document parent or guardian authority;
- Administer adult and Minor waivers;
- Maintain emergency authorization records;
- Confirm insurance compliance; and
- Establish, exercise, or defend legal rights.
9.6 Website operation and improvement
We may use information to:
- Operate the website;
- Maintain user accounts where available;
- Remember preferences;
- Diagnose technical problems;
- Improve navigation;
- Measure site performance;
- Understand use of content;
- Prevent abuse;
- Maintain security; and
- Develop new services.
9.7 Communications
We may use information to send:
- Booking confirmations;
- Payment reminders;
- Itinerary updates;
- Schedule changes;
- Safety notices;
- Supplier communications;
- Emergency communications;
- Customer-service messages;
- Requested information;
- Newsletters;
- Trip announcements;
- Surveys; and
- Marketing messages where permitted.
You cannot opt out of communications reasonably necessary to administer an active booking, safety matter, payment obligation, or legal notice.
9.8 Marketing and advertising
Subject to applicable choices and consent requirements, we may use information to:
- Send newsletters;
- Announce Trips;
- Recommend relevant content;
- Measure campaign effectiveness;
- Display advertising;
- Build audiences for advertising platforms;
- Limit repetitive advertising;
- Understand general audience interests; and
- Administer promotions.
We do not use known-child information, health information, passport data, insurance information, or emergency information for targeted advertising.
9.9 Security, fraud prevention, and legal compliance
We may use information to:
- Authenticate a booking;
- Detect suspicious payments;
- Prevent fraud;
- Investigate unauthorized access;
- Protect accounts and systems;
- Enforce our agreements;
- Respond to subpoenas or lawful requests;
- Comply with tax, accounting, insurance, regulatory, and legal obligations;
- Protect the Company, Participants, Suppliers, and the public; and
- Establish, exercise, or defend claims.
9.10 Deidentified and aggregated information
We may create aggregated or deidentified information that does not reasonably identify an individual.
We may use such information for:
- Business analysis;
- Service improvement;
- Reporting;
- Marketing analysis;
- Supplier evaluation;
- Safety planning; and
- Other lawful purposes.
We will not attempt to reidentify deidentified information except as permitted to test whether deidentification is effective or as otherwise allowed by law.
10. Legal Bases for Processing
Where a jurisdiction requires a stated legal basis, we may process personal information based on:
10.1 Performance of a contract
Processing may be necessary to:
- Prepare or administer a booking;
- Provide a Trip;
- Process payment;
- Communicate with Suppliers;
- Fulfill requests;
- Administer cancellation and refund terms; and
- Perform our contractual obligations.
10.2 Consent
We may rely on consent for:
- Optional marketing;
- Nonessential cookies;
- Featured media use;
- Certain sensitive-data processing;
- Certain Minor-related processing;
- Optional disclosure to third parties; and
- Other purposes requiring consent.
10.3 Legitimate interests
Where permitted, we may process information for legitimate interests such as:
- Operating and improving our business;
- Preventing fraud;
- Maintaining security;
- Providing customer support;
- Managing Supplier relationships;
- Documenting agreements;
- Protecting legal rights;
- Promoting relevant services; and
- Ensuring Trip safety.
We will consider the effect on the individual’s rights when relying on legitimate interests.
10.4 Legal obligations
We may process information to comply with:
- Tax and accounting requirements;
- Court orders;
- Government requests;
- Travel and immigration requirements;
- Consumer-protection obligations;
- Safety requirements;
- Insurance obligations;
- Data-protection obligations; and
- Other applicable laws.
10.5 Vital interests and emergencies
We may process information when reasonably necessary to protect:
- A Traveler’s life or health;
- A Minor;
- Another Participant;
- A Supplier representative; or
- Another person in an emergency.
10.6 Legal claims
We may process information where reasonably necessary to establish, exercise, investigate, or defend a legal or insurance claim.
11. How We Disclose Personal Information
We may disclose information to the following categories of recipients.
11.1 Travel Suppliers
We may disclose necessary information to:
- Hotels;
- Resorts;
- Retreat venues;
- Cruise lines;
- Transportation providers;
- Local flight operators;
- Destination-management companies;
- Guides;
- Activity providers;
- Excursion operators;
- Restaurants;
- Equipment providers;
- Ticketing services;
- Park or permit authorities; and
- Other travel Suppliers.
We disclose only information reasonably relevant to the service, although Suppliers may independently request additional information.
11.2 Booking, payment, and business-service providers
We may disclose information to providers that assist with:
- Booking;
- Payment processing;
- Invoicing;
- Accounting;
- Customer relationship management;
- Email delivery;
- Form collection;
- Cloud storage;
- Website hosting;
- Website security;
- Document management;
- Electronic records;
- Customer support;
- Survey administration; and
- Business operations.
11.3 Analytics and advertising providers
Subject to applicable choices, we may allow analytics or advertising providers to receive:
- Cookie identifiers;
- IP address;
- Device information;
- Approximate location;
- Website activity;
- Advertising interaction; and
- Hashed or otherwise transformed contact information used for audience matching.
See Sections 13 and 14.
11.4 Insurance, medical, and emergency recipients
Where reasonably necessary, we may disclose information to:
- Insurers;
- Travel-assistance services;
- Medical providers;
- Ambulance services;
- Search-and-rescue providers;
- Emergency personnel;
- Hospitals;
- Consular officials;
- Government authorities;
- Emergency contacts; and
- Family members.
11.5 Other Participants
For group Trips, we may disclose limited information reasonably necessary for group operations, such as:
- First name;
- Family or travel-party name;
- Rooming assignment;
- General schedule;
- Activity group;
- Meeting location; and
- Limited contact information where the Traveler agrees or the disclosure is operationally necessary.
We will not ordinarily disclose another Traveler’s:
- Passport information;
- Payment information;
- Detailed medical information;
- Insurance documents;
- Private communications; or
- Custody information
to other Participants.
11.6 Group messaging platforms
We may invite Travelers to a Trip-specific group on a service such as a group messaging or social platform.
Joining a group may make your:
- Name;
- Telephone number;
- Username;
- Profile image;
- Status;
- Messages; and
- Other profile information
visible to group members according to the platform’s settings.
Where reasonably practicable, joining a nonessential group will be optional.
The platform’s own privacy policy applies.
11.7 Professional advisers
We may disclose information to:
- Attorneys;
- Accountants;
- Auditors;
- Insurance brokers;
- Insurers;
- Claims administrators;
- Security consultants;
- Technology consultants; and
- Other professional advisers
where reasonably necessary.
11.8 Legal and protective disclosures
We may disclose information when we reasonably believe disclosure is necessary to:
- Comply with law;
- Respond to a lawful subpoena, court order, or government request;
- Report suspected abuse or danger;
- Protect a Minor;
- Prevent or investigate fraud;
- Address a security incident;
- Enforce agreements;
- Protect legal rights;
- Protect health and safety; or
- Respond to an emergency.
11.9 Business transactions
Information may be disclosed or transferred in connection with:
- A merger;
- Acquisition;
- Reorganization;
- Financing;
- Sale of assets;
- Business transition;
- Bankruptcy;
- Receivership; or
- Due diligence concerning a potential transaction.
A recipient will be required to handle the information in accordance with applicable law and the commitments applicable to the information.
11.10 With direction or consent
We may disclose information where you direct us to do so or provide legally sufficient consent.
12. We Do Not Sell Personal Information for Money
We do not sell lists of Traveler passport, medical, insurance, emergency, or Minor information for monetary payment.
We do not sell known-child information for monetary consideration.
We do not sell health or passport information for advertising.
However, certain privacy laws define “sale,” “sharing,” or “targeted advertising” broadly. Allowing an advertising or analytics provider to collect cookie identifiers, device information, or website activity may be considered a sale or sharing even when no money is exchanged.
Where applicable, you may opt out through:
- The Your Privacy Choices link;
- The Do Not Sell or Share My Personal Information link;
- The cookie-preference tool;
- A legally recognized browser opt-out preference signal; or
- A request to booking@everyavenuetravel.com.
The Company should not state that it does not “share” information for advertising if advertising cookies, audience-matching tools, or cross-site behavioral advertising are active.
13. Targeted Advertising and Privacy Choices
Depending on our website configuration, advertising providers may use information about activity over time and across websites or services to select or measure advertising.
Where required by law, we will provide a method to opt out of:
- Sale of personal information;
- Sharing for cross-context behavioral advertising;
- Targeted advertising;
- Certain profiling;
- Nonessential advertising cookies; and
- Certain uses of sensitive information.
We do not knowingly use personal information from a Minor for targeted advertising.
We will process legally recognized opt-out preference signals, such as a qualifying browser-based signal, where required by applicable law.
A privacy choice may be specific to:
- The browser;
- Device;
- Website;
- Account; or
- Email address
used to submit the choice.
You may need to repeat the choice when using another browser or device or after clearing cookies.
14. Cookies and Similar Technologies
14.1 Strictly necessary technologies
These may be used to:
- Operate the website;
- Maintain security;
- Process forms;
- Remember privacy choices;
- Maintain a shopping or booking session;
- Prevent fraud; and
- Enable essential functions.
These technologies generally cannot be disabled through our preference tool because the website may not function properly without them.
14.2 Functional technologies
These may be used to:
- Remember preferences;
- Support embedded content;
- Enable chat or customer-support features;
- Remember language or location choices; and
- Improve convenience.
14.3 Analytics technologies
These may be used to:
- Count visits;
- Understand page usage;
- Identify errors;
- Measure content performance;
- Understand general audience activity; and
- Improve the website.
14.4 Advertising technologies
These may be used to:
- Display advertising;
- Measure advertising;
- Limit repetition;
- Create or match advertising audiences;
- Understand engagement; and
- Deliver interest-based advertising.
14.5 Social-media technologies
Social-media buttons, videos, feeds, or embedded content may allow the applicable platform to receive information about your visit.
14.6 Managing cookies
You may manage nonessential technologies through:
- Our cookie-preference tool;
- Browser settings;
- Device settings;
- Advertising-industry opt-out tools;
- The provider’s own settings; and
- Legally recognized opt-out signals.
Blocking cookies may affect website functions.
14.7 Do Not Track
Some browsers transmit a “Do Not Track” signal for which no single universally applied response standard exists.
We respond to opt-out preference signals where applicable law requires us to do so, but may not respond to other Do Not Track signals.
15. Payment Security
Where a third-party processor handles payment-card data, its privacy and security terms govern its processing.
The Company generally receives transaction information rather than a complete payment-card number.
You should not send full payment-card information through ordinary email, text, social media, or group chat.
If the Company becomes aware that full card information was sent through an insecure channel, we may:
- Delete or redact it;
- Ask you to submit payment through an approved processor;
- Restrict access;
- Document the incident; and
- Take other reasonable protective measures.
16. International Travel and Cross-Border Transfers
Travel services necessarily involve international information transfers.
We are based in the United States. Personal information may be processed or stored in:
- The United States;
- The destination country;
- A transit country;
- A Supplier’s home country;
- A cloud-service location; or
- Another country in which a service provider operates.
For example, a hotel in another country may need a Traveler’s name, passport information, rooming information, dietary request, or arrival details.
Privacy laws and government-access rules in another country may differ from those in your home jurisdiction.
Where applicable law requires a transfer safeguard, we may use:
- A legally recognized adequacy decision;
- Contractual safeguards;
- Standard contractual clauses;
- A service-provider agreement;
- Consent where legally valid;
- A transfer necessary to perform a travel contract;
- A transfer necessary to protect vital interests; or
- Another lawful transfer method.
International travel may require occasional transfers that are necessary to perform a contract in the Traveler’s interest, such as providing identification to an overseas accommodation or activity provider.
17. Data Security
We use reasonable administrative, technical, and physical measures designed to protect personal information against unauthorized:
- Access;
- Use;
- Disclosure;
- Alteration;
- Loss;
- Destruction; and
- Acquisition.
Depending on the nature of the information and system, safeguards may include:
- Access controls;
- Password protections;
- Multi-factor authentication;
- Encryption or secure transmission;
- Limited staff access;
- Confidentiality obligations;
- Secure payment processors;
- Vendor review;
- Backup and recovery procedures;
- System updates;
- Malware protection;
- Incident-response procedures;
- Secure disposal; and
- Staff training.
No transmission or storage method is completely secure.
Ordinary email and messaging services may not be appropriate for highly sensitive information. When available, use the secure form, portal, or upload method provided by the Company.
Florida law requires covered commercial entities to take reasonable measures to protect and securely dispose of covered personal information and imposes notification requirements following qualifying security breaches.
18. Children’s Privacy
18.1 Services are intended for adults
Bookings must be initiated and managed by an adult.
Our website, booking forms, payment services, and Trip-registration process are intended for:
- Adults;
- Parents;
- Natural guardians;
- Legal guardians; and
- Other legally authorized adults.
A child should not independently:
- Create a booking;
- Pay an invoice;
- Submit a passport;
- Submit medical information;
- Submit insurance information;
- Join a mailing list;
- Create a public account;
- Enter a promotion; or
- Contact us with personal information
without the involvement of a parent or guardian.
18.2 Parent-provided information
A parent or guardian may provide a child’s information where reasonably necessary to:
- Arrange travel;
- Verify age;
- Arrange accommodations;
- Determine activity eligibility;
- Address dietary or accessibility needs;
- Respond to health and safety concerns;
- Obtain insurance proof;
- Prepare emergency records;
- Meet Supplier requirements; and
- Comply with legal obligations.
18.3 Children under thirteen
We do not intend to collect personal information online directly from a child under thirteen without appropriate parental involvement.
If we operate an online feature directed to children under thirteen or knowingly collect personal information online directly from a child under thirteen, we will obtain verifiable parental consent where COPPA requires it.
We will also provide applicable parental rights to:
- Review the information;
- Request deletion;
- Refuse further collection;
- Revoke consent; and
- Limit disclosure where required.
A general statement that a parent booked a Trip should not be treated as a substitute for a legally required COPPA consent method when information is being collected directly from the child.
18.4 Teenagers
Where applicable law provides enhanced protection for individuals between thirteen and seventeen, we will seek the authorization or consent required for the particular processing.
18.5 No targeted advertising using known-child information
We do not knowingly use or disclose personal information from a known child for targeted advertising.
18.6 Parent or guardian requests
A parent or legally authorized guardian may request access to, correction of, or deletion of a Minor’s personal information by following Section 22.
We may require proof of:
- The requesting adult’s identity;
- Relationship to the child;
- Parental responsibility;
- Guardianship; or
- Other legal authority.
18.7 Information submitted without authority
If you believe a child submitted information without appropriate parental permission, contact us at booking@everyavenuetravel.com with the subject line Child Privacy Request.
We will investigate and take appropriate action.
19. Data Retention
We retain personal information only for as long as reasonably necessary for the stated purpose, including to:
- Complete the Trip;
- Maintain required business records;
- Document contractual acceptance;
- Administer refunds or credits;
- Meet tax and accounting obligations;
- Address health or safety matters;
- Respond to insurance claims;
- Resolve disputes;
- Enforce agreements;
- Comply with Supplier or legal requirements;
- Protect Minors; and
- Establish, exercise, or defend legal claims.
The following is our intended retention framework. Actual retention may be longer or shorter when reasonably required by law, litigation hold, insurance, Supplier requirements, security, or an active dispute.
19.1 Inquiries and unconfirmed quotes
Generally retained for up to twenty-four months after the last substantive communication, unless the person requests earlier deletion or the record is needed for another lawful purpose.
19.2 Booking, payment, contract, and accounting records
Generally retained for at least seven years after the Trip is completed, canceled, or otherwise closed, or for the applicable tax, accounting, contractual, or claims period.
19.3 Acceptance and waiver records
Records showing delivery and acceptance of Terms, cancellation terms, adult agreements, Minor agreements, insurance obligations, and related versions may be retained for the period reasonably necessary to document the agreement and address potential claims.
Records involving a Minor may be retained longer where appropriate because legal claims involving Minors may be subject to different limitation periods.
19.4 Passport and travel-document copies
Where the Company holds a copy, our target is to delete or securely dispose of it within ninety days after the Trip ends, unless:
- A Supplier or legal requirement requires longer retention;
- An incident or claim occurred;
- The Traveler asks us to retain it for a future booking;
- The document is part of a required transaction record; or
- Another legitimate legal or security reason applies.
Supplier systems may have separate retention periods.
19.5 Health, allergy, accessibility, emergency, and insurance information
Generally retained until the Trip is completed and for a limited post-Trip period reasonably necessary to:
- Address follow-up questions;
- Document accommodations;
- Respond to an incident;
- Support an insurance claim;
- Meet legal requirements; or
- Defend a claim.
If no incident occurred, our target is to delete or minimize detailed health and insurance records within twelve months after the Trip, unless continued retention is authorized or reasonably necessary.
19.6 Incident and claim records
Retained for the duration of the incident, insurance, dispute, or legal matter and for the applicable period afterward.
19.7 Website and security logs
Generally retained for up to twenty-four months, although security, fraud, backup, and diagnostic records may be retained longer where reasonably necessary.
19.8 Marketing records
Retained while the person remains subscribed or while we have another lawful basis for marketing.
We may retain a minimal suppression record after unsubscribe so that we do not send further marketing to that address.
19.9 Cookie information
Retained according to the duration stated in the applicable cookie tool or provider settings.
19.10 Media
Photographs and videos may be retained while reasonably useful for the authorized purpose.
A consent withdrawal generally applies prospectively and may not require removal from:
- Materials already printed;
- Completed publications;
- Archived records;
- Materials already distributed;
- Legal records; or
- Third-party reposts outside our reasonable control.
19.11 Privacy-request records
Generally retained for at least twenty-four months or another period required by applicable law to document the request and response.
19.12 Backups
Information deleted from active systems may remain temporarily in backups until the backup is overwritten or securely retired.
We will not restore deleted information from backup for ordinary business use unless reasonably necessary for security, disaster recovery, or legal compliance.
20. Marketing Communications
You may unsubscribe from marketing email by:
- Using the unsubscribe link;
- Updating available preferences; or
- Emailing booking@everyavenuetravel.com.
Marketing opt-out does not stop transactional or relationship messages concerning:
- An active booking;
- Payment;
- Itinerary;
- Safety;
- Insurance;
- A refund or credit;
- A complaint;
- A legal notice; or
- Another requested service.
Commercial email recipients must be given an appropriate method to stop future marketing messages, and opt-out requests must be honored as required by law.
Where we offer marketing text messages, we will provide applicable consent and opt-out instructions.
Consent to receive marketing text messages is not a condition of purchasing a Trip unless applicable law permits and the arrangement is expressly disclosed.
21. Automated Decision-Making
Unless separately disclosed, we do not make decisions producing legal or similarly significant effects about Travelers solely through automated processing without meaningful human involvement.
We may use automated tools for limited purposes such as:
- Fraud detection;
- Spam filtering;
- Website personalization;
- Analytics;
- Email delivery;
- Payment-risk screening;
- Sorting inquiries; and
- Identifying incomplete booking information.
A Supplier or payment processor may independently use automated fraud, identity, eligibility, or security systems under its own policy.
22. Your Privacy Rights
Depending on where you live and which law applies, you may have the right to:
- Confirm whether we process your personal information;
- Access personal information;
- Correct inaccurate information;
- Request deletion;
- Obtain a portable copy;
- Restrict certain processing;
- Object to certain processing;
- Withdraw consent;
- Opt out of sale;
- Opt out of sharing for targeted or cross-context behavioral advertising;
- Opt out of certain profiling;
- Limit certain uses of sensitive personal information;
- Appeal a denied request;
- Obtain information about categories of recipients;
- Lodge a complaint with a regulator; and
- Exercise rights without unlawful discrimination.
These rights are subject to applicable exceptions.
For example, we may need to retain information to:
- Complete a booking;
- Provide requested services;
- Comply with law;
- Maintain tax or accounting records;
- Protect security;
- Prevent fraud;
- Document a waiver or agreement;
- Protect a Minor;
- Exercise free-expression rights;
- Resolve a dispute;
- Establish or defend a claim; or
- Maintain a marketing suppression list.
The Florida Digital Bill of Rights, where applicable, identifies rights including access, correction, deletion, portability, and opt-outs for sale, targeted advertising, certain profiling, and certain sensitive-data processing.
23. How to Submit a Privacy Request
Submit a request by emailing:
booking@everyavenuetravel.com
Subject line: Privacy Request
Include:
- Full name;
- Email address associated with the booking or website interaction;
- Booking or invoice number, if applicable;
- The right you wish to exercise;
- State or country of residence;
- Whether the request concerns a Minor; and
- Enough information to identify the relevant records.
Do not send:
- A complete passport copy;
- Full payment-card information;
- An account password; or
- Unnecessary medical information
in the initial request.
24. Verification of Requests
We may take reasonable steps to verify:
- Identity;
- Email control;
- Booking relationship;
- Authority to act for another person;
- Authority to act for a Minor; and
- Authenticity of the request.
Verification information will be used only for verification, security, recordkeeping, and legal compliance.
We may deny or limit a request when:
- Identity cannot be verified;
- Authority cannot be established;
- The request is fraudulent;
- An exception applies;
- Compliance would adversely affect another person’s rights;
- The request seeks information we do not control;
- Information must be retained by law; or
- The request is manifestly unfounded or excessive under applicable law.
We will explain a denial where required.
25. Authorized Agents
Where applicable law permits, an authorized agent may submit a request.
We may require:
- Written authorization;
- Verification of the individual’s identity;
- Verification of the agent’s identity;
- Proof of legal authority; or
- Direct confirmation from the individual.
A parent or guardian acting for a Minor may be required to provide proof of relationship or authority.
26. Response and Appeals
We will respond within the period required by applicable law.
Where permitted, we may extend the response period because of request complexity or volume and will provide notice of the extension.
If applicable law gives you a right to appeal a denied privacy request, submit the appeal to:
booking@everyavenuetravel.com
Subject line: Privacy Request Appeal
Explain why you believe the decision should be reconsidered.
27. No Unlawful Discrimination
We will not unlawfully discriminate against a person for exercising an applicable privacy right.
Exercising a privacy right may affect our ability to provide a service where the requested service reasonably requires the information.
For example, we may be unable to:
- Reserve an accommodation without a name;
- Arrange a restricted activity without age information;
- Provide an allergy accommodation without relevant allergy information;
- Arrange international travel without required identification;
- Confirm insurance compliance without insurance information; or
- Maintain a booking after deletion of essential booking records.
28. California and Other U.S. State Privacy Notice
This Section applies to the extent a state privacy law applies to the Company and the relevant individual.
The current California framework requires covered businesses to provide information at or before collection regarding categories, purposes, whether information is sold or shared, and retention periods, and to maintain a comprehensive privacy policy.
28.1 Categories collected during the preceding twelve months
Depending on your interaction with us, we may have collected:
Identifiers
Examples include name, email, telephone number, address, IP address, online identifier, passport number, and other government identification.
Customer-record information
Examples include contact information, booking information, payment information, travel documents, insurance information, and service records.
Protected classification information
Examples may include age, nationality, citizenship, disability, medical condition, family status, or other information voluntarily provided or required for the Trip.
Commercial information
Examples include Trip purchases, booking history, deposits, invoices, payments, cancellations, refunds, credits, interests, and service preferences.
Internet or electronic activity
Examples include browsing activity, pages visited, ad interaction, referral information, cookies, and device data.
Geolocation information
Examples include approximate location based on IP address and location voluntarily shared for transportation, Trip coordination, or an emergency.
Audio, visual, and sensory information
Examples include photographs, videos, customer-service communications, and recordings made with notice.
Professional or educational information
Examples may include work or school scheduling information voluntarily provided in connection with a booking and worldschooling interests.
Inferences
Examples may include likely Trip interests or content preferences inferred from website or booking interactions.
Sensitive personal information
Examples include passport information, financial-account information, account credentials, health information, citizenship information, precise location where voluntarily provided, and information concerning known children.
28.2 Categories of sources
We may collect these categories from:
- Consumers;
- Parents and guardians;
- Booking Clients;
- Travel companions;
- Suppliers;
- Payment and booking platforms;
- Website technologies;
- Social-media platforms;
- Insurers;
- Emergency providers;
- Public sources; and
- Authorized representatives.
28.3 Business and commercial purposes
Purposes include:
- Providing travel services;
- Processing payments;
- Fulfilling bookings;
- Communicating with Suppliers;
- Health and safety;
- Insurance verification;
- Emergency response;
- Customer support;
- Marketing;
- Analytics;
- Advertising;
- Fraud prevention;
- Security;
- Legal compliance;
- Recordkeeping; and
- Defending claims.
28.4 Categories disclosed for business purposes
We may disclose relevant categories to:
- Travel Suppliers;
- Payment processors;
- Booking platforms;
- Website and cloud providers;
- Email and communication providers;
- Analytics providers;
- Professional advisers;
- Insurers;
- Emergency providers;
- Government authorities; and
- Business transaction recipients.
28.5 Categories sold or shared
We do not sell personal information for monetary payment.
Depending on website configuration, we may share the following categories with analytics or advertising partners in a manner that may qualify as “sharing” or “sale” under a broadly defined state law:
- Identifiers such as cookie or device identifiers;
- Internet or electronic activity;
- Approximate geolocation; and
- Inferences concerning content or travel interests.
We do not knowingly sell or share for targeted advertising:
- Passport information;
- Detailed financial information;
- Health information;
- Insurance information;
- Emergency information; or
- Known-child information.
28.6 Sensitive personal information
We use sensitive personal information primarily to provide requested travel services, process payments, protect safety, verify identity, meet Supplier requirements, and comply with law.
We do not use sensitive personal information to infer unrelated characteristics for advertising.
28.7 Retention
The retention periods and criteria are described in Section 19.
28.8 State privacy requests
Where the applicable state law provides the right, a resident may request:
- Access;
- Correction;
- Deletion;
- Portability;
- Opt-out of sale;
- Opt-out of targeted advertising or sharing;
- Limitation of certain sensitive-data uses;
- Information concerning disclosure; and
- Appeal of a denied request.
Submit requests as described in Section 23.
29. European Economic Area, United Kingdom, and Switzerland
This Section applies only where the GDPR, UK GDPR, Swiss data-protection law, or comparable law applies to the processing.
Individuals in the European Economic Area may have rights including information, access, correction, deletion, restriction, portability, objection, and protections concerning automated decision-making.
29.1 Controller
For processing covered by this Policy, the controller is:
Every Avenue Travel LLC
booking@everyavenuetravel.com
29.2 Legal bases
Our legal bases are described in Section 10.
For health or other special-category information, the additional basis may include:
- Explicit consent;
- Vital interests;
- Establishment, exercise, or defense of legal claims;
- Substantial public interest where applicable; or
- Another basis permitted by law.
29.3 International transfers
Information may be transferred to the United States and to Trip destinations.
Where required, we will use an applicable safeguard or lawful transfer basis, which may include contractual safeguards, adequacy, consent, vital interests, or a transfer necessary to perform a travel contract in the individual’s interest.
29.4 Rights
Subject to applicable conditions, an individual may request:
- Access;
- Rectification;
- Erasure;
- Restriction;
- Portability;
- Objection;
- Withdrawal of consent; and
- Review of a significant solely automated decision.
29.5 Marketing objection
An individual may object at any time to processing for direct marketing.
29.6 Complaint
An individual may lodge a complaint with the data-protection authority in the individual’s country or region.
We encourage contacting us first so that we may attempt to address the concern.
29.7 Representative
If applicable law requires the Company to appoint an EEA, UK, or Swiss representative, the representative’s contact information will be added to this Policy.
30. External Links, Embedded Content, and Affiliate Offers
Our website may contain:
- External links;
- Affiliate links;
- Embedded videos;
- Social-media feeds;
- Advertising;
- Sponsored content;
- Travel deals;
- Hotel or activity links;
- Credit-card or insurance information; and
- Links to Supplier booking pages.
The third party may collect information when you:
- Click a link;
- View embedded content;
- Make a purchase;
- Create an account;
- Submit a form; or
- Interact with an advertisement.
We do not control the third party’s privacy practices.
An affiliate relationship or commission arrangement should be disclosed separately where required.
31. Testimonials, Reviews, and Public Submissions
When you voluntarily submit a review, testimonial, photograph, article, comment, or public statement, we may use it according to:
- The context in which it was submitted;
- The permission provided;
- The applicable media terms; and
- Applicable law.
We will not represent a private complaint or support email as a public endorsement without permission.
A public review posted to a third-party platform is governed by that platform’s terms.
32. Changes to This Policy
We may update this Policy to reflect:
- Changes in our services;
- New Suppliers or technology;
- New legal requirements;
- Changes in cookie or advertising practices;
- Security improvements; or
- Changes in business operations.
The revised Policy will state a new “Last Updated” date.
A revised Policy applies prospectively from its effective date.
Where required, we will provide additional notice or seek consent before using previously collected information for a materially different purpose.
We should retain archived copies of prior Privacy Policy versions associated with historical bookings.
33. Contact Us
For privacy questions, complaints, or requests, contact:
Every Avenue Travel LLC
Email: booking@everyavenuetravel.com
Subject: Privacy Request
For a child-related request, use the subject:
Child Privacy Request
For an appeal, use the subject:
Privacy Request Appeal
Please do not email full payment-card numbers, account passwords, or unnecessary passport or medical documents.
Every Avenue Travel LLC is registered with the State of Florida as a Seller of Travel. Registration No. ST45213.
Company: Every Avenue Travel LLC
Privacy Requests: booking@everyavenuetravel.com
Effective Date: 5/22/24