Privacy Policy

Holiday Market Tourism LLC ("Holiday Market", "we", "us" or "our") respects your privacy. This Privacy Policy explains what personal data we collect through holidaymarket.ae (the "Website") and our booking, sales and customer service channels, why we collect it, how we use and protect it, and the choices and rights you have. It applies together with our Terms and Conditions.

This Policy is designed to meet the requirements of UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "UAE PDPL") and its executive regulations, as applicable to a Dubai-based travel and tourism business.

1. Who We Are

Holiday Market Tourism LLC is the data controller responsible for your personal data in connection with the Website and our Services. Our registered office is 18th Floor, Control Tower, Motor City, Dubai, United Arab Emirates. You can contact us about privacy matters at info@holidaymarket.ae.

2. Personal Data We Collect

Data you give us directly — identity and contact details (full name as per passport, date of birth, nationality, gender, email address, phone number, and, for group or corporate bookings, company name); travel document details (passport number, issue/expiry dates, and passport copies where you choose to upload them to speed up visa or booking processing); booking and preference information (destinations, travel dates, party composition, holiday style or mood preferences, and any special requirements you choose to disclose); payment information (billing name and address, and payment confirmation details — card numbers and CVV are entered directly into our payment gateway, PayMob, and are not stored on our servers, see Section 6); communications (messages sent via enquiry forms, the concierge/custom-package request tool, email, phone or WhatsApp, including recordings or transcripts made for quality and training purposes where you are notified); and marketing preferences (your choices about receiving offers and newsletters).

Certain information provided for travel purposes, including health information, disability or accessibility requirements, biometric information contained in travel documents, and information revealing religious beliefs through dietary or pilgrimage-travel requests, may constitute sensitive personal data. We process such information only where necessary to provide the requested Services, where you have provided valid consent, or where another lawful basis is available under applicable law.

Data we collect automatically — device and usage data (IP address, browser type, device identifiers, pages viewed, search filters used, referring website, and approximate location derived from your IP address), and cookies and similar technologies, as described in Section 8.

Data from third parties — airlines, hotels, DMCs, visa processing centres and other Suppliers, where they confirm or update your booking or travel document status; PayMob and our banking partners, who confirm payment status and provide fraud-prevention signals; and publicly available sources, where relevant to verifying identity for visa applications.

If you provide personal data relating to another traveller, you confirm that you are authorised to provide that information and to receive booking-related communications on that traveller's behalf. You must provide the traveller with access to this Privacy Policy and, where required, obtain their consent before providing sensitive personal data or travel documents to us.

3. How We Use Your Data

To respond to enquiries and provide quotations for packages, staycations, visas, custom itineraries and group bookings.

To create and manage bookings, process payments and refunds, and communicate confirmations, e-tickets, vouchers and itinerary changes.

To submit visa applications and supporting documents to embassies, consulates or visa processing centres on your behalf, where you have purchased a visa service.

To liaise with Suppliers (airlines, hotels, transport and activity providers) so that your travel arrangements can be delivered.

To provide customer support, handle complaints, and meet our obligations under the Visa Rejection Shield or other add-ons you purchase.

To detect and prevent fraud, abuse of the Website, and to protect the security of our systems.

To send you marketing communications about offers, destinations and promotions, where you have opted in or as otherwise permitted by law; you can opt out at any time (see Section 9).

To comply with legal, tax, immigration, anti-money-laundering and regulatory obligations, and to respond to lawful requests from authorities.

To improve the Website, understand booking trends, and personalise the destinations and packages shown to you.

4. Legal Basis for Processing

We process your personal data on one or more of the following bases: performance of a contract with you (e.g. to process your booking); your consent (e.g. for marketing communications or uploading a passport copy); our legitimate interests (e.g. fraud prevention, Website security, service improvement), balanced against your rights; and compliance with a legal obligation (e.g. record-keeping for tax or immigration purposes). Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

We may use automated tools to identify suspected fraudulent transactions, personalise Website content or analyse customer preferences. We do not make decisions based solely on automated processing that produce significant legal or similarly material effects on you unless permitted by applicable law and appropriate safeguards are implemented. Where applicable, you may request information about such processing and seek human review of a decision.

5. Sharing Your Data

We share personal data only as necessary to deliver the Services, and require recipients to protect it appropriately.

Suppliers — airlines, hotels, resorts, ground handlers, transfer and activity providers, and visa processing centres, to the extent needed to book and deliver your travel arrangements or process your visa application.

Payment processing — PayMob, a PCI-DSS-compliant payment gateway, processes your card payment on our behalf; we receive confirmation of payment but not your full card number.

Service providers — IT hosting, customer support, marketing and analytics providers who process data on our instructions and under confidentiality obligations.

Government and regulatory authorities — embassies, consulates, immigration and tourism authorities, and UAE regulators, where required for visa processing, legal compliance, or upon lawful request.

Professional advisers and insurers, including our travel insurance partner, where you are covered under a complimentary or purchased insurance policy.

Business transfers — if HolidayMarket.ae is involved in a merger, acquisition or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate safeguards.

We do not sell your personal data to third parties.

Where a service provider processes personal data solely on our behalf, we require it by contract to process the data only for authorised purposes, maintain appropriate confidentiality and security measures, assist us with data-subject requests and data breaches, and delete or return the data when its services end, subject to lawful retention requirements.

Airlines, hotels, embassies, immigration authorities and certain other travel Suppliers may process personal data as independent controllers under their own privacy policies. Their processing may therefore be governed by their own legal obligations and privacy terms.

Where Holiday Market discloses personal data to an independent Supplier, airline, hotel, payment provider, visa processing centre, embassy, consulate or immigration authority so that the requested travel or related service can be provided, that recipient may process the personal data as an independent data controller under its own privacy notice and applicable law. Holiday Market does not control, and to the fullest extent permitted by applicable law is not responsible for, that recipient's independent processing after lawful disclosure.

Holiday Market remains responsible for the lawfulness and security of its own collection, use and disclosure of personal data and for any obligations that applicable data-protection law places on Holiday Market in relation to the recipient or transfer.

6. Payment Data and PCI Compliance

Card payments on the Website are processed by PayMob, an independent, PCI-DSS-compliant payment service provider. Your full card details are transmitted directly to PayMob's secure environment and are not stored on Holiday Market's own servers. We retain only limited payment metadata (such as the last four digits of your card, transaction reference, amount and status) needed for booking records, reconciliation and dispute handling.

7. International Data Transfers

Because travel arrangements are, by nature, international, your data (such as passport details for a visa application, or booking details for an overseas hotel) may be transferred to and processed in countries outside the UAE, including your destination country, which may not have data protection laws equivalent to the UAE PDPL. Where we make such transfers, we take reasonable steps to ensure the recipient is bound by appropriate confidentiality and security obligations, consistent with UAE PDPL requirements for cross-border transfers.

Where personal data is transferred outside the UAE, we shall apply a transfer mechanism permitted under the UAE PDPL, which may include transfer to a jurisdiction recognised as providing an adequate level of protection, contractual safeguards, explicit consent where legally permitted, or another statutory exception. We shall also limit the data transferred to what is reasonably necessary for the booking, visa application or other requested Service.

8. Cookies and Similar Technologies

The Website uses cookies and similar technologies to: keep the Website functioning correctly (essential cookies); remember your search filters and preferences; understand how visitors use the Website (analytics cookies); and, where you consent, show you relevant offers on our Website and elsewhere (marketing/advertising cookies). You can manage or withdraw consent for non-essential cookies through your browser settings or any cookie-preference tool on the Website; disabling essential cookies may affect the Website's functionality.

Non-essential analytics, personalisation and advertising cookies will not be activated until the user has made the required consent selection. Users may accept, reject or manage cookie categories through the Website's cookie-preference tool. Withdrawing consent shall be as easy as providing it. Further information, including cookie providers, purposes and expiry periods, shall be provided in a separate Cookie Notice.

9. Marketing Communications

Where you have opted in, we may send you emails, SMS or WhatsApp messages about offers, new destinations, flash sales and travel tips. Every marketing email includes an unsubscribe link, and you may also opt out at any time by emailing info@holidaymarket.ae or contacting us at 800 ALFRED. Opting out of marketing does not affect transactional communications about a booking you have made.

10. Data Retention

We retain personal data for as long as reasonably necessary to fulfil the purposes described in this Policy, including for the duration of any booking, applicable voucher validity period, and any additional period required to comply with legal, tax, accounting, regulatory, dispute-resolution or record-keeping obligations. Financial and booking records may therefore be retained for several years, as required under applicable UAE laws.

Where a customer creates or is provided with an online account or login ID, relevant personal data, booking history, transaction details, vouchers and account preferences may be retained for as long as the account remains active and thereafter for any period required for the purposes stated above. Access to the account will be protected through appropriate authentication measures, such as a password, one-time password (OTP), multi-factor authentication or other security controls. Customers are responsible for maintaining the confidentiality of their login credentials and promptly notifying us of any suspected unauthorised access.

Passport copies, visa application documents and other identification records will be retained only for as long as necessary to process the relevant application and address any related dispute, complaint, regulatory requirement or claim under the Visa Rejection Shield. Once the applicable retention period expires, such documents will be securely deleted or anonymised, unless continued retention is required by applicable law.

Closing or deactivating an account will not necessarily result in the immediate deletion of all personal data where retention is required by law or is reasonably necessary to establish, exercise or defend legal claims, prevent fraud, resolve disputes or enforce our terms.

11. Data Security

We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or alteration, including restricted access to booking systems, secure transmission (HTTPS/TLS), and reliance on a PCI-DSS-compliant payment gateway for card data. No system is completely secure, and we cannot guarantee absolute security of information transmitted over the internet.

We maintain procedures to identify, investigate, contain and remediate suspected personal-data breaches. Where required by applicable law, we will notify the UAE Data Office or other competent authority and affected individuals within the legally prescribed manner and timeframe. Our notification will describe the nature and likely consequences of the breach and the measures taken or proposed to address it, to the extent required by law.

While Holiday Market implements reasonable and appropriate technical and organisational measures designed to protect personal data, no electronic transmission, network, platform or storage system can be guaranteed to be completely secure.

To the fullest extent permitted by applicable law, Holiday Market shall not be liable for unauthorised access, loss, misuse or disclosure resulting from circumstances beyond its reasonable control, provided that Holiday Market has complied with its applicable legal obligations. Nothing in this paragraph limits Holiday Market's obligations to investigate, mitigate or notify a personal-data breach where required by applicable law.

Customers are responsible for maintaining the confidentiality of their login credentials, verification codes and devices used to access Holiday Market's Services; using strong and unique passwords; restricting access to their accounts and devices; and notifying Holiday Market promptly of any suspected unauthorised access.

To the fullest extent permitted by applicable law, Holiday Market shall not be liable for unauthorised access or loss resulting from a Customer's failure to take reasonable steps to protect those credentials or devices, except to the extent caused or contributed to by Holiday Market's breach of applicable law, fraud, wilful misconduct or proven negligence.

12. Your Rights

Subject to the conditions and exceptions set out in the UAE PDPL and other laws, you may have the right to: request access to the personal data we hold about you; request correction of inaccurate or incomplete data; request erasure of your data in certain circumstances; object to or request restriction of certain processing (including marketing); request a copy of your data in a portable format; and withdraw consent where processing is based on consent. To exercise any of these rights, contact us at info@holidaymarket.ae. We may need to verify your identity and may not be able to action a request where we have an overriding legal or contractual reason to retain the data (for example, an open booking or a legal record-keeping obligation).

If you are not satisfied with our response, you may have the right to lodge a complaint with the UAE Data Office or the relevant competent authority.

We will acknowledge a verified privacy request and respond within the period prescribed under applicable law. Where a request is complex or repetitive, or where an exception applies, we will inform you of any lawful extension, refusal or limitation and the relevant reason.

13. Children's Privacy

The Website is intended for use by adults arranging travel, including on behalf of children travelling with them. We do not knowingly collect personal data directly from children; where a child's details (e.g. name, date of birth, passport number) are provided as part of a family booking, this is provided and controlled by the adult making the booking, who is responsible for ensuring they are authorised to share that information with us.

14. Third-Party Links

The Website may link to third-party websites, including Suppliers, payment providers, or airline/hotel websites. This Policy does not cover, and we are not responsible for, the privacy practices of those third-party sites; we encourage you to review their own privacy policies.

15. Changes to This Policy

We will review the policy at a frequency not less than annually or immediately in case of major changes in our processes, services and applicable data protection laws and regulations. The updated version will be posted on the Website with a revised effective date; where changes are material, we will take reasonable steps to notify you, for example by email or a Website notice.

16. Contact Us

Holiday Market Tourism LLC

18th Floor, Control Tower, Motor City, Dubai, United Arab Emirates

Trade license number 1448683

Customer support: askalfred@holidaymarket.ae

General enquiries and privacy requests: info@holidaymarket.ae

Sales: sales.uae@holidaymarket.ae

Phone: 800 ALFRED