Legal documents

Privacy and Data Protection Policy

Universe Travel & Business, the owner and operator of the GlobTravLink platform (the "Company"), ensures the strict protection of User personal data on the Platform in compliance with United States federal standards, Florida state laws, and international consumer privacy regulations.

1. CATEGORIES OF COLLECTED DATA


1.1. For account authentication, processing booking transactions, and commercial tracking, the Platform requests and processes the following information:

  • Full name, date of birth, gender, email address, and contact telephone number;
  • Full passport details, citizenship status, and visa summaries (collected strictly for securing international cruises, airline flights, and cross-border tours);
  • Copies of driver's licenses (when Clients book car rentals, commercial vehicle rentals, or watercraft charters);
  • Payment information (processed via encrypted payment gateways compliant with PCI-DSS standards; the Platform never retains CVV codes or full credit card numbers on its physical servers);
  • Agent commercial metrics (referral network hierarchy, commission accrual histories, retail sales volumes).

2. CHILDREN'S PRIVACY (COPPA COMPLIANCE)


2.1. Minor Data Collection: The Platform is not intended for independent use by individuals under 18 years of age. In compliance with the Children's Online Privacy Protection Act (COPPA), the Company collects personal data of children under 13 (names, dates of birth, passport details) strictly from their legal parents or guardians, and solely for the purpose of issuing tickets and booking travel services with third-party Suppliers. Children's data is never used for marketing, profiling, or sold to advertising networks.

3. PURPOSES AND THIRD-PARTY DATA TRANSFER REGULATIONS


3.1. User data is utilized exclusively for account verification, completing the booking process, distributing Agent compensation, and rendering technical user support.

3.2. Transfer to Suppliers: The User expressly agrees that the Company is authorized to transfer their personal data (including passport details, visa parameters, and driver's licenses) to third-party Suppliers (cruise lines, hotels, rental firms, tour operators, customs, and port authorities) strictly to the extent required to successfully issue tickets and deliver the paid travel service.

3.3. Prohibition on Data Selling: The Company covenants never, under any circumstances, to sell, rent, or trade User personal data to third-party marketing agencies, data brokers, or advertising networks for external commercial use.

4. SECURITY AND CONSUMER RIGHTS


4.1. The Platform deploys contemporary SSL/TLS data encryption protocols and administrative safeguards to prevent data breaches and unauthorized access.

4.2. Users maintain the right at any time to request an extraction report of their stored personal information or demand its total erasure (pursuant to CCPA protocols for US residents), except for data that the Company is statutorily mandated to preserve under Florida law for financial, tax, and corporate audit records.

4.3. International Data Transfer and GDPR Compliance: As the Platform provides international travel services, User data may be processed and stored on servers located in the United States. Users originating from the European Economic Area (EEA) and the UK expressly consent to the cross-border transfer of their data by registering on the Platform. Under the General Data Protection Regulation (GDPR), EEA Users retain the right to data portability, restriction of processing, and the right to lodge a complaint with their local supervisory authority.