Last updated: 20 August 2026

Privacy Policy

Ordering a travel document means handing over real personal information: passport names, dates of birth, travel dates, sometimes employment and financial detail. This policy sets out exactly what we ask for, why each item is needed, who else ever sees it, how long we hold it and how to make us delete it.

It covers reservationpoints.com and every order placed through it, and it is written to the UK GDPR and the EU GDPR. Read it with our Terms of Service.

1

About this policy

Ordering a travel document means handing over real personal information: passport names, dates of birth, travel dates, and on a cover letter your job, your income and your reasons for coming home. This policy sets out exactly what we ask for, why each item is needed, who else ever sees it, how long we hold it and how to make us delete it.

It covers reservationpoints.com and every order placed through it, and it is written to the UK GDPR and the EU GDPR.

The short version

We collect what a document needs and nothing extra. We pass passenger names to airlines because that is the only way a booking reference can be real. We never sell your data. Passport numbers are deleted within 90 days. You can ask us to erase everything else and we will.

2

Who is responsible for your data

ReservationPoints.com is the data controller for everything described here. That means we decide what is collected and why, and we are the ones answerable for it.

Email: [email protected]

Phone: +44 77561 525115

Contact form: reservationpoints.com/contact-us

Website: https://reservationpoints.com

We are not required to appoint a Data Protection Officer and have not appointed one. Privacy questions go to the contact address above and are handled by the people who run the service.

3

What we collect, product by product

Different documents need different things. Rather than one flat list, here is what each product actually asks for.

ProductWhat we collect
Every orderYour name, your email address, and the order record itself: products, prices, timestamps, delivery status and your Order Reference.
Onward ticket, dummy ticket, flight itinerary, flight reservationPassenger full names exactly as printed in the passport, title, the route, travel dates, the number of travellers, and where the carrier requires it, date of birth and passport number.
Hotel reservationGuest names, the property, the city, and the check-in and check-out dates.
Visa cover letterEmployment and occupation details, income or funding arrangements, who is paying for the trip, the purpose of the trip, family or other ties to your home country, the destination and visa category, and the consulate the letter is addressed to.
Travel planDestinations, dates and the shape of the trip.
Visa application helpWhatever the application itself requires, which can include prior travel history and previous refusals.

Collected automatically

Your IP address, device type, browser, the pages you visit, the site that referred you, and cookie identifiers. This is standard web telemetry and it is described in sections 16 and 17.

Collected when you talk to us

The content of emails, contact form messages and support conversations, including anything you attach to them.

Payments

We never receive or store your full card number. Our payment provider handles the card and returns a token, the last four digits, the card brand, the billing country and the result. That is all we hold.

4

Where your information comes from

  • From you: everything you type into an order form, a generator or a message.
  • From your device: the technical data in section 3, gathered automatically as you browse.
  • From our payment provider: the outcome of a payment, the last four digits of the card and the billing country.
  • From a referrer or affiliate: where you arrived through a partner link, the fact of the referral.
  • From someone ordering for you: where a friend, a relative or an employer places an order on your behalf. In that case they have confirmed to us that they have your authority to give us your details.
5

Why we use it, and our lawful basis

Every use of your data has to rest on a lawful basis. Ours are set out here in full.

PurposeWhat it coversLawful basis
Delivering your orderBuilding the document, placing the booking, taking payment, order tracking and support.Performance of a contract
Fraud preventionChecking payments, spotting abuse, and defending a payment dispute.Legitimate interests
SecurityProtecting our systems, logging access and preventing misuse.Legitimate interests
Improving the serviceAggregate analytics on how the site is used and where it fails.Legitimate interests
Defending legal claimsKeeping enough record to answer a complaint or a claim.Legitimate interests
Analytics and advertising cookiesMeasurement tags and advertising pixels.Consent
Marketing emailOffers and product news, only if you asked for them.Consent
Tax and accounting recordsInvoices, payment records and statutory bookkeeping.Legal obligation
Lawful requestsResponding to a court order or a properly made request from an authority.Legal obligation

Where we rely on legitimate interests we have weighed our interest against your rights, and you can object at any time. See section 14.

6

Sensitive information, and what we avoid asking for

We do not ask for health data, religious or philosophical beliefs, political opinions, sexual orientation, trade union membership or biometric data, and you should not send them to us.

A passport number and a nationality are identity data rather than special category data under the GDPR, but they are sensitive in every ordinary sense of the word and we treat them with the same care. Section 7 sets out how.

Free text boxes

If you volunteer sensitive detail in a free-text field, for example a medical reason for travel in a cover letter, we use it only to complete the document you asked for and it is deleted with the rest of that order. Please leave out anything the document does not need.

7

Passport and identity details

Some carriers will not hold a booking without a date of birth or a passport number. Where that is the case we ask for it, and we ask for it for that reason alone.

  • We use it to create the booking and for nothing else.
  • We do not verify it against any government or immigration record, and we have no ability to do so.
  • We never sell it, rent it, or share it with anyone outside the processors named in section 8.
  • It is deleted on a shorter clock than the rest of the order: within 90 days of the order being fulfilled.
8

Who else handles your data

We use a small number of specialist providers to run the service. Each is bound by contract to process your data only on our instructions, and each sees only the part it needs.

WhoWhat they doWhat they see
StripeProcesses card payments and handles disputesThe card and billing details. Not your travel data
Airlines and their distribution systemsHold the flight bookingPassenger name, route, dates, and any identity detail the carrier requires
Accommodation providers and booking platformsHold the roomGuest name and stay dates
Our email infrastructureSends confirmations and delivers documentsYour email address and the document itself
DigitalOceanHosts the applicationData at rest and in transit through the platform
MongoDB AtlasStores the order databaseThe order record
Cloudflare R2Stores generated documentsThe document files
ValkeyCaching and short-lived session dataTransient session data
Google Analytics 4 and Google AdsMeasurement and advertisingCookie identifiers and page activity, only after consent
Meta PixelAdvertising measurementCookie identifiers and page activity, only after consent
Microsoft ClarityInteraction and session analyticsPage interaction, only after consent. Input fields are masked
Professional advisers and authoritiesLegal, accounting and statutory obligationsOnly what the obligation requires

Three things we do not do

We do not sell personal data. We do not share it with data brokers or list companies. We do not disclose it so that anyone else can market to you.

9

Sending your details to airlines and accommodation providers

This one deserves its own section, because it is the transfer people least expect and the one we cannot avoid.

A reservation document is worth something precisely because the booking is real. To make it real, the passenger name has to go into the airline’s own live system, which is what allows you or a consular officer to look the reference up afterwards. The same applies to a guest name and a property.

Airline distribution systems are global. Once a booking exists, the data may be processed in several countries under the carrier’s own privacy policy and its own retention rules, neither of which we control. We share the minimum the carrier requires and nothing more.

A limit on erasure, stated plainly

Once a name is in a carrier’s system we cannot pull it back out. We can delete our own copy, and we will, but a booking record held by an airline is theirs. Section 14 says more about this.

10

Payments and card data

Card details are entered directly into our payment provider’s hosted fields. They do not pass through our servers and they are not stored on them. PCI DSS compliance for card handling sits with the provider, which is exactly where it should sit.

What we receive back and keep is limited to:

  • A payment token that identifies the transaction.
  • The last four digits of the card.
  • The card brand.
  • The billing country.
  • Whether the payment succeeded or failed.

We keep those because we need to identify a payment, issue a refund to the original method, and defend a payment dispute. Nothing on that list can be used to make a charge.

11

Sending data outside the UK and EEA

Some of the providers in section 8 operate outside the UK and the EEA, chiefly in the United States. Where personal data goes to them, the transfer relies on one of the following:

  • UK adequacy regulations, where the destination country has been recognised as offering adequate protection.
  • The UK International Data Transfer Agreement, or the International Data Transfer Addendum to the EU Standard Contractual Clauses.
  • The EU Standard Contractual Clauses, for transfers subject to the EU GDPR.

We also carry out our own assessment of a provider before we use it. Transfers to airlines and accommodation providers are a necessary part of performing the contract you asked us to perform, which is a separate lawful route under the GDPR.

12

How long we keep things

Nothing is kept indefinitely and nothing is kept without a reason. These are the actual clocks.

WhatHow longWhy
Order records, invoices and payment records6 years from the end of the tax yearTax and accounting law
Passport numbers and dates of birthDeleted within 90 days of fulfilmentNeeded only to create the booking
Delivered documents in file storage12 monthsSo we can resend one if you lose it
Cover letter and travel plan answers12 months, then deletedTo support revisions and reissues
Support correspondence24 monthsTo handle follow-up questions and complaints
Chargeback and dispute evidence24 months from the dispute closingCard schemes allow re-presentment within that period
Marketing contactsUntil you unsubscribe, plus a suppression recordThe suppression record is how we make sure we never email you again
Analytics dataThe provider’s own retention, typically up to 14 monthsAggregate measurement
13

How your data is protected

  • Encrypted in transit: every connection to this site uses TLS.
  • Encrypted at rest: the order database and file storage are encrypted by the platform.
  • Access limited: only staff who need a record to do their job can reach it, and access is logged.
  • Multi-factor authentication: required on administrative systems.
  • No card data on our systems: the one category we most want off our infrastructure is never on it.

No honest company claims perfect security

These measures reduce risk. They do not eliminate it, and anyone who tells you their system cannot be breached is telling you something they cannot know. What we can promise is that we hold as little as the job requires, for as short a time as the law allows, and that section 20 says what happens if something goes wrong.

14

Your rights, and how to use them

Under the UK and EU GDPR you have all of the following, and exercising any of them is free.

RightWhat it lets you do
AccessGet a copy of the personal data we hold about you.
RectificationHave anything inaccurate corrected.
ErasureHave your data deleted, subject to the limits below.
RestrictionHave us pause processing while a dispute about accuracy or lawfulness is resolved.
PortabilityReceive the data you gave us in a machine-readable format, or have it sent elsewhere.
ObjectionObject to processing based on legitimate interests, including profiling.
Withdraw consentWithdraw consent to cookies or marketing at any time, without affecting what was done beforehand.
ComplainRaise the matter with a supervisory authority. See section 23.

How to make a request

Email [email protected] from the address on your order and say what you want. We respond within one month. If a request is genuinely complex we may extend that by up to two further months, and we will tell you why inside the first month. We may ask you to confirm your identity, because handing an order file to the wrong person would be the very failure this policy exists to prevent.

The limits, stated honestly

  • We cannot erase records we are legally required to keep, chiefly invoices and payment records held for tax purposes. We restrict them instead, so they are kept but not used.
  • We cannot remove a passenger name from an airline’s system once a booking has been made. That record belongs to the carrier and their own policy governs it.
  • A request that is manifestly unfounded or excessive, particularly a repetitive one, may attract a reasonable fee or be refused. We will explain the reasoning if that ever happens.
15

Marketing, and how to stop it

We email you about your order whether or not you have opted into anything, because that correspondence is the contract: a confirmation, a delivery, a question about your details. Those are service messages and they have no unsubscribe link, for the same reason a receipt does not.

Marketing email is different and goes out only with your consent. Every marketing message carries an unsubscribe link that works immediately, and you can also just reply and ask. Unsubscribing never affects an order or the support you get on it.

16

Cookies and similar technologies

A cookie is a small file a site stores on your device. We use four categories, and only two of them need your permission.

CategoryWhat it doesConsent needed
Strictly necessarySessions, the order in progress, security and fraud prevention. The site cannot work without these.No
PreferenceRemembers your language and currency choice.No
AnalyticsTells us which pages are used and where the site fails.Yes
AdvertisingMeasures advertising and supports remarketing.Yes

The cookie banner is where consent is given, and it is also where it is withdrawn: reopen it at any time and change your choices. Your browser settings can block cookies entirely, but blocking the strictly necessary ones will break checkout.

17

Analytics and advertising

These tags load only after you have given consent, and not before.

  • Google Analytics 4: aggregate measurement of traffic, pages and conversions.
  • Google Ads: measures whether an advert led to an order, and supports remarketing.
  • Meta Pixel: the same measurement for advertising on Meta platforms.
  • Microsoft Clarity: records how people interact with pages, including session replay, so we can see where a form or a page is failing. We configure it to mask input fields, so what you type is not captured.

Each of these providers processes data under its own privacy policy as well as ours. Withdrawing analytics or advertising consent in the cookie banner stops all of them.

18

Automated decision-making

Two parts of the service run automatically, and you should know about both.

The cover letter generator

It assembles text from the answers you give it. It does not judge you, score you or decide anything about you: it writes a draft, you read it, and you decide whether to use it.

Payment fraud checks

Our payment provider runs automated risk checks and may decline a payment without a human involved. Where an order is declined on that basis, a person reviews it if you ask, and you can always ask.

Neither process produces a legal effect or a similarly significant effect of the kind Article 22 of the GDPR is concerned with. If you want a human to look at anything, email us and one will.

19

Children

This service is not directed at children and only an adult may place an order. We do not knowingly collect data from anyone under 18 acting on their own behalf.

A child’s name and date of birth may appear as a named traveller on a family booking, supplied by a parent or another responsible adult. That data is handled exactly like any other traveller’s, under the same retention clocks in section 12. If you believe a child has given us data directly, tell us and we will delete it.

20

If something goes wrong

If there is a personal data breach, this is what happens and how quickly.

  1. 1We contain and investigate immediately: the first priority is stopping it, the second is establishing exactly what was affected.
  2. 2We notify the regulator within 72 hours: where the breach is likely to result in a risk to people’s rights, as the law requires.
  3. 3We tell you directly: where the risk to you is high, in plain language, saying what happened, what it means for you and what to do about it.
  4. 4We fix the cause: and record what changed, so the same failure cannot happen twice.
21

Other websites

Our pages link to airlines, consulates, visa centres and other third parties where it is useful to do so. A link is a convenience, not an endorsement. Once you follow one you are on that site’s terms and its privacy policy, and this policy stops applying. Read theirs before you give them anything.

22

Changes to this policy

We update this policy when the service or the law changes, and the current version always sits on this page with the date it took effect. Where a change materially affects how we use your data we will tell you by email or with a notice on the site rather than relying on you to notice. The version in force when you placed an order governs that order.

23

Contact us, and how to complain

Any question about this policy, or any request under section 14, goes to:

If we have not put it right

You can complain to the UK Information Commissioner’s Office at ico.org.uk, or on 0303 123 1113. If you live in the EU you may complain to the supervisory authority in your own country instead.

Come to us first if you can

You are entitled to go straight to a regulator and nothing here asks you to give that up. But we can usually fix a data problem the same week, and a regulator cannot. Tell us what is wrong and give us the chance.

By using ReservationPoints.com you acknowledge that you have read this Privacy Policy and understand how your personal data is collected, used, shared and deleted.