PRIVACY POLICY

Last Updated: 02 June 2026

1. Who We Are

This Privacy Policy explains how Last Minute Deals collects, uses, stores, shares, and protects personal data when you visit lastminute-deals.shop, contact us, create a booking request, purchase a product, subscribe to communications, or otherwise use our services.

Data Controller: Raphael Follana, trading as Last Minute Deals
Business Address: 20 Rue des Repas, 60270 Gouvieux, France
Email: info@lastminute-deals.shop
Phone: +33 6 31 71 37 46

For privacy-related questions or requests, please contact us at:

info@lastminute-deals.shop

This Privacy Policy applies to customers, website visitors, prospects, passengers, buyers, recipients of marketing communications, and any other person whose personal data is processed through our website or services.

2. Legal Framework

We process personal data in accordance with applicable data-protection laws, including:

  • the General Data Protection Regulation (EU) 2016/679;
  • the French Data Protection Act, where applicable;
  • applicable ePrivacy and cookie rules;
  • applicable French and European consumer, e-commerce, travel, accounting, and tax obligations.

3. Personal Data We Collect

We only collect personal data that is necessary, relevant, and proportionate for the purposes described in this Privacy Policy.

3.1 Identity Data

We may collect:

  • full name;
  • title;
  • date of birth, where required for travel, passenger identification, age verification, or legal purposes;
  • nationality, where required for travel-related services;
  • passport or identity-document details, only where strictly necessary for a travel booking, supplier requirement, border-control requirement, insurance requirement, or legal obligation.

We do not ask customers to send passport or identity-document copies unless this is strictly necessary for the relevant service or legally required.

3.2 Contact Data

We may collect:

  • email address;
  • phone number;
  • billing address;
  • delivery address;
  • country of residence;
  • communication history.

3.3 Booking, Order, and Transaction Data

We may collect:

  • booking requests;
  • travel dates;
  • destination and itinerary information;
  • passenger details;
  • product orders;
  • digital-product purchases;
  • payment status;
  • invoice details;
  • refund requests;
  • cancellation requests;
  • customer-support history;
  • supplier confirmations;
  • complaints and dispute records.

3.4 Payment and Financial Data

Payments may be processed by third-party payment providers such as Stripe, PayPal, card processors, banks, or other secure payment providers.

We do not intentionally store full payment-card numbers, card-security codes, or full payment credentials on our own systems.

We may process:

  • payment status;
  • transaction reference;
  • billing details;
  • invoice details;
  • refund details;
  • fraud-prevention signals;
  • payment-provider confirmation data.

3.5 Technical Data

When you visit the website, we may collect technical information such as:

  • IP address;
  • browser type and version;
  • device type;
  • operating system;
  • language settings;
  • approximate location derived from IP address;
  • referral source;
  • session data;
  • security logs;
  • cookie identifiers;
  • consent preferences.

3.6 Usage Data

We may collect information about how users interact with the website, including:

  • pages viewed;
  • buttons clicked;
  • products or offers viewed;
  • search activity;
  • booking-flow behaviour;
  • checkout behaviour;
  • time spent on pages;
  • error messages;
  • abandoned cart or abandoned booking data;
  • user preferences.

3.7 Marketing and Communication Data

We may collect:

  • newsletter subscription status;
  • marketing consent;
  • communication preferences;
  • opt-in and opt-out records;
  • email engagement data;
  • advertising interaction data, where permitted;
  • campaign source data.

3.8 Special Category Data

For travel-related services, accessibility support, insurance-related requests, or customer assistance, we may process limited special category data only where necessary and legally permitted.

This may include:

  • dietary requirements that reveal health or religious information;
  • mobility, disability, or accessibility needs;
  • medical assistance requirements;
  • health-related travel information where required by the relevant provider, airline, hotel, insurer, authority, or emergency situation.

We only process this type of data where one of the following applies:

  • the customer has given explicit consent;
  • processing is necessary to provide requested travel assistance;
  • processing is necessary to protect vital interests;
  • processing is required by law;
  • processing is necessary for legal claims.

4. How We Collect Personal Data

We may collect personal data directly from you when you:

  • visit the website;
  • fill out a contact form;
  • submit a booking request;
  • purchase a product or service;
  • subscribe to a newsletter;
  • contact customer support;
  • communicate with us by email, phone, WhatsApp, social media, or other channels;
  • respond to marketing or advertising campaigns;
  • use payment, checkout, or booking tools;
  • provide documents or information needed for a transaction.

We may also receive personal data from:

  • travel suppliers;
  • hotels;
  • airlines;
  • transport providers;
  • payment processors;
  • fraud-prevention providers;
  • analytics providers;
  • advertising platforms;
  • delivery providers;
  • customer-support tools;
  • business partners;
  • public authorities, where legally required.

5. How We Use Personal Data and Legal Bases

We process personal data only where we have a valid legal basis.

PurposeLegal BasisData Used
Responding to enquiriesPre-contractual steps, legitimate interestsIdentity, contact, communication data
Processing bookings or ordersContractual necessityIdentity, contact, booking, order, transaction data
Confirming reservations or purchasesContractual necessityIdentity, contact, booking, order data
Processing payments and refundsContractual necessity, legal obligation, legitimate interestsPayment, billing, transaction data
Delivering products or digital contentContractual necessityIdentity, contact, order data
Providing customer supportContractual necessity, legitimate interestsIdentity, contact, booking, order, support data
Managing complaints and disputesLegal obligation, legitimate interests, legal claimsIdentity, contact, transaction, communication data
Preventing fraud and misuseLegitimate interests, legal obligationTechnical, payment, transaction, security data
Website security and maintenanceLegitimate interests, legal obligationTechnical, usage, security-log data
Website analyticsConsent where required, legitimate interests where permittedTechnical, usage, cookie data
Marketing emails and promotionsConsent, or other permitted legal basis where applicableContact, marketing, usage data
Personalised advertising and trackingConsent where requiredCookie, technical, usage, marketing data
Accounting, tax, and legal recordsLegal obligationBilling, transaction, invoice, contract data
Travel supplier coordinationContractual necessity, legal obligationIdentity, contact, travel, passenger data
Accessibility or health-related travel supportExplicit consent, vital interests, contractual necessity, legal claims where applicableLimited special category data

6. Travel-Related Data Processing

For travel-related offers, we may need to share limited personal data with suppliers and service providers involved in the requested booking.

This may include:

  • airlines;
  • hotels;
  • accommodation providers;
  • transport providers;
  • tour providers;
  • insurance providers;
  • booking platforms;
  • local travel partners;
  • border-control or immigration authorities, where required;
  • emergency assistance providers, where necessary.

We only share the data reasonably necessary for the relevant booking, reservation, travel support, legal requirement, or customer request.

Customers are responsible for ensuring that passenger details, passport information, travel dates, visa information, and contact details are accurate.

7. Product and Digital-Service Data Processing

Where we sell physical products, digital products, or online services, we may process personal data to:

  • process orders;
  • confirm purchases;
  • deliver products;
  • provide digital access;
  • manage refunds;
  • manage warranties or legal guarantees;
  • provide support;
  • comply with accounting and tax obligations.

8. Marketing Communications

We may send marketing communications only where legally permitted.

For email marketing, we generally rely on opt-in consent unless another lawful basis is clearly permitted by applicable law.

You may unsubscribe from marketing communications at any time by using the unsubscribe link in the email or by contacting:

info@lastminute-deals.shop

Withdrawing marketing consent does not affect the lawfulness of processing carried out before withdrawal.

We do not sell personal data to third-party marketers.

9. Cookies and Tracking Technologies

We use cookies and similar technologies for:

  • website functionality;
  • security;
  • session management;
  • shopping cart or booking-flow functionality;
  • remembering cookie preferences;
  • analytics;
  • performance measurement;
  • advertising;
  • retargeting;
  • personalisation.

Essential cookies may be used without prior consent where they are strictly necessary for the website to function.

Non-essential cookies, including analytics, advertising, retargeting, and marketing cookies, are used only where legally permitted and, where required, only after consent.

Users can accept, refuse, or manage non-essential cookies through the cookie banner or cookie settings available on the website.

Users can withdraw cookie consent at any time.

10. Third-Party Tools and Service Providers

We may use carefully selected third-party service providers to operate the website and provide our services.

These may include:

  • website hosting providers;
  • payment processors;
  • email providers;
  • analytics providers;
  • advertising platforms;
  • booking tools;
  • customer-support tools;
  • fraud-prevention tools;
  • accounting providers;
  • legal or professional advisers;
  • couriers and delivery providers;
  • IT maintenance providers.

Our website is hosted by Hostinger.

Where service providers process personal data on our behalf, we require appropriate contractual, technical, and organisational safeguards.

11. Data Sharing

We may share personal data with:

11.1 Essential Service Providers

This includes providers necessary for hosting, payment processing, booking management, order fulfilment, analytics, IT security, customer support, accounting, and communications.

11.2 Travel and Commercial Suppliers

Where required for a booking, product order, reservation, or service request, we may share relevant personal data with third-party suppliers.

11.3 Payment Providers

Payment providers process payment information securely. We do not intentionally store full payment-card details on our own systems.

11.4 Public Authorities and Legal Recipients

We may disclose personal data where required or permitted by law, including to:

  • courts;
  • law enforcement authorities;
  • tax and accounting authorities;
  • consumer-protection authorities;
  • data-protection authorities;
  • border-control, immigration, or travel-security authorities;
  • professional advisers;
  • insurers;
  • dispute-resolution bodies.

11.5 Business Transfers

If the business, website, domain, assets, or services are sold, transferred, merged, reorganised, or assigned, personal data may be transferred as part of that transaction, subject to applicable law.

12. International Data Transfers

Because travel, hosting, payment, analytics, advertising, and supplier services may involve providers in different countries, personal data may be transferred outside France, the European Union, or the European Economic Area.

Where personal data is transferred outside the EEA, we use appropriate safeguards where required, such as:

  • adequacy decisions;
  • Standard Contractual Clauses;
  • data-processing agreements;
  • supplier security commitments;
  • transfer-risk assessments where required;
  • other lawful transfer mechanisms.

Travel-related data may need to be sent to hotels, airlines, transport providers, tour providers, local suppliers, or public authorities located in the destination country. Such transfers may be necessary to perform the requested booking or travel service.

13. Data Retention

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy.

Retention periods depend on:

  • the type of data;
  • the purpose of processing;
  • legal obligations;
  • accounting and tax obligations;
  • contractual requirements;
  • warranty or consumer-rights periods;
  • dispute or limitation periods;
  • fraud-prevention needs;
  • security needs;
  • whether consent has been withdrawn.

Typical retention principles include:

Data TypeRetention Principle
Enquiry dataKept for the time needed to respond and follow up, then deleted or archived unless a legal reason requires longer retention
Booking and order dataKept for the duration of the customer relationship and then for the period required by legal, accounting, tax, contractual, or dispute-resolution obligations
Accounting, invoice, and transaction recordsKept for the period required by applicable French accounting and tax rules
Payment dataFull card data is handled by payment providers; payment confirmations and transaction records are kept as required for accounting, tax, refund, fraud-prevention, and dispute purposes
Travel passenger dataKept only as long as necessary for the booking, travel service, legal obligations, supplier requirements, customer support, and potential disputes
Passport or identity-document dataKept only where strictly necessary and deleted or anonymised when no longer required
Marketing dataKept until consent is withdrawn, the user unsubscribes, or the data is no longer needed
Cookie consent recordsKept as necessary to demonstrate and manage consent choices
Security logsKept for a limited period necessary for security, fraud prevention, and legal protection
Complaint and dispute recordsKept for the period necessary to handle the complaint and protect legal rights

We may anonymise data for analytics, reporting, security, or business-improvement purposes. Anonymised data is no longer personal data where individuals can no longer be identified.

14. Your Rights

Subject to applicable law and legal limitations, you may have the following rights:

  • right of access;
  • right to rectification;
  • right to erasure;
  • right to restriction of processing;
  • right to data portability;
  • right to object to processing;
  • right to withdraw consent at any time where processing is based on consent;
  • right not to be subject to unlawful automated decision-making;
  • right to lodge a complaint with a data-protection authority.

To exercise your rights, contact:

info@lastminute-deals.shop

Please clearly describe your request. We may need to verify your identity before processing the request. We will not ask for excessive identity documents. Please do not send passport copies, identity-card copies, or sensitive documents unless specifically requested and necessary.

We aim to respond to valid privacy requests within one month, unless the request is complex or multiple requests are submitted, in which case the legal response period may be extended where permitted by law.

15. Withdrawal of Consent

Where processing is based on consent, you may withdraw consent at any time.

This includes consent for:

  • marketing emails;
  • non-essential cookies;
  • advertising tracking;
  • special category data, where consent is the legal basis;
  • optional customer preferences.

Withdrawal of consent does not affect processing carried out before consent was withdrawn.

16. Objection to Direct Marketing

You may object to direct marketing at any time.

To opt out, use the unsubscribe link in the relevant email or contact:

info@lastminute-deals.shop

After opting out, we may keep limited suppression-list data to ensure that we do not contact you again for direct marketing.

17. Automated Decision-Making

We do not use personal data for decisions based solely on automated processing that produce legal or similarly significant effects on customers.

Fraud-prevention, payment-security, advertising, analytics, or booking-risk tools may involve automated signals, but important decisions may be reviewed where legally required.

18. Security Measures

We use appropriate technical and organisational measures to protect personal data, including where appropriate:

  • HTTPS/TLS encryption;
  • secure hosting;
  • access controls;
  • password protection;
  • limited internal access;
  • payment processing through secure payment providers;
  • fraud-prevention controls;
  • backup procedures;
  • system monitoring;
  • malware and abuse prevention;
  • supplier security checks;
  • confidentiality obligations.

No website, payment system, email system, or internet transmission is completely secure. Users should also take reasonable precautions, including using secure devices, strong passwords, and avoiding the transmission of sensitive documents unless necessary.

19. Data Breaches

If a personal-data breach occurs, we will assess the risk and take appropriate action in accordance with applicable law.

Where legally required, we will notify the relevant supervisory authority and affected individuals.

20. Children’s Data

Our website and services are not intended for unsupervised use by children.

Where travel bookings, family orders, or passenger arrangements involve minors, personal data relating to children may be provided by a parent, guardian, or authorised adult.

We only process children’s data where necessary for the relevant booking, order, legal obligation, travel arrangement, customer support, or safety requirement.

21. Links to Third-Party Websites

The website may contain links to third-party websites, booking engines, suppliers, payment providers, travel providers, hotels, airlines, marketplaces, or partner platforms.

We are not responsible for the privacy practices, security, content, or data handling of third-party websites.

Users should read the privacy policies of any third-party website before submitting personal data.

22. Complaints

If you have concerns about how we process personal data, please contact us first:

info@lastminute-deals.shop

Last Minute Deals
Raphael Follana
20 Rue des Repas
60270 Gouvieux
France

If you are not satisfied with our response, you may lodge a complaint with the competent data-protection authority.

For France, the competent authority is the CNIL — Commission Nationale de l’Informatique et des Libertés.

23. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect legal, technical, commercial, or operational changes.

The updated version will be posted on the website with a revised “Last Updated” date.

Where legally required, we will provide additional notice or request renewed consent.

24. Contact

For privacy questions, data requests, complaints, or withdrawal of consent, contact:

Last Minute Deals
Raphael Follana
20 Rue des Repas
60270 Gouvieux
France

Email: info@lastminute-deals.shop
Phone: +33 6 31 71 37 46

Scroll to Top