Privacy Policy
Last updated:
This policy explains what personal information The Portal Passport collects through www.theportalpassport.com, the Traveller portal and our emails, why we collect it, who we share it with, how long we keep it and what your rights are. We have tried to write it in plain language and to describe this website specifically. If anything here does not match what you see the site doing, please tell us.
1. Who we are
The Portal Passport is a trading name of SELECTRO LTD, a private company limited by shares incorporated in Mauritius on 1 August 2013 (company file number C117790, business registration number C13117790), with its registered office at C2 Bonne Terre, Vacoas, Mauritius.
Selectro Ltd is the controller of the personal information described in this policy. This means we decide why and how it is used and we are responsible for protecting it under the Mauritius Data Protection Act 2017. Selectro Ltd is registered with the Data Protection Office of Mauritius as a controller.
How to contact us about this policy:
- Use the contact form on the Contact page of www.theportalpassport.com. You do not need a booking or an account to do this.
- If you have a booking, an order or a request with us, you can also sign in to the Traveller portal with your email address and message us there.
- Or write to: Data protection, Selectro Ltd, C2 Bonne Terre, Vacoas, Mauritius.
Our emails are sent from a no-reply address, so replies to them are not read. Please use the contact form or the Traveller portal instead.
2. The short version
- We collect only what you give us and what we need to run the website, your bookings and your orders.
- We do not sell your information, and we do not use it for advertising.
- The website has no advertising or tracking cookies. We count page visits in aggregate with Vercel Web Analytics, which uses no cookies and does not identify individual visitors.
- We do not take card payments. You pay by bank transfer from your own bank. We never see your card details or your online banking login.
- We do not collect passport scans or copies of identity documents through this website.
- Some of our service providers are outside Mauritius, so your information may be stored or processed abroad. Section 8 explains where and how it is protected.
- You can ask to see, correct or delete your information at any time. Section 10 explains how.
3. What we collect and why
3.1 When you browse the website
| What | Why | Legal basis |
|---|---|---|
| Technical information your browser sends automatically, such as your IP address, browser type and the pages you request | To deliver the website securely, prevent abuse and fix problems | Our legitimate interest in running a secure website |
| A one-way coded version (a "hash") of your IP address or email address, kept for a short time window | To limit how many times one person can submit a form, request a sign-in link or ask a question, so the site cannot be flooded | Our legitimate interest in preventing abuse |
We use Vercel Web Analytics to count page visits in aggregate. It uses no cookies and does not identify individual visitors. The data is processed by Vercel (section 7).
Our hosting provider also keeps short-term server logs for security and reliability. See section 7.
3.2 When you use Ask Portal (our website assistant)
Ask Portal answers questions about our journeys. Many questions are answered from text we have written in advance and stored on our own website. If no prepared answer fits, your question and the conversation so far are sent to our artificial intelligence (AI) model provider, OpenAI, which generates a reply using only the information we have published.
| What | Why | Legal basis |
|---|---|---|
| Your question, the conversation so far and the language you are using | To answer your question | Our legitimate interest in answering enquiries, and steps you ask us to take before booking |
Please do not type personal details such as passport numbers, health information or bank details into Ask Portal. It is not a channel for bookings or payments, and its answers are general information, not a quote or a promise. If something matters to your booking, confirm it with our team.
Ask Portal does not make any decision about you. We use OpenAI's business service (its API). Under OpenAI's published terms for that service, data we send is not used to train OpenAI's models unless we choose to allow it, which we have not. OpenAI may keep it for a limited period to monitor for abuse.
3.3 When you join our mailing list or register interest in a journey
| What | Why | Legal basis |
|---|---|---|
| Your name, email address, the journey you are interested in, your language and, if you choose, a short message | To tell you about that journey when there is news, and to answer your message | Your consent for marketing emails; our legitimate interest in replying to an interest request you send |
Registering interest does not reserve a place and does not commit you to pay anything.
Marketing consent is always a separate, unticked choice. You can withdraw it at any time by using the unsubscribe link in any marketing email or by contacting us (section 1). Withdrawing it does not affect anything else you have with us.
3.4 When you ask for a custom package
| What | Why | Legal basis |
|---|---|---|
| Your name, email address, number of travellers, preferred dates and your message, plus anything you add later in the conversation | To understand your request, prepare a proposal and reply to you | Steps you ask us to take before entering into a contract; our legitimate interest in answering enquiries |
3.5 When you create a Traveller portal account and sign in
We do not use passwords. You sign in with a single-use link sent to your email address. Sign-in links expire after a short time.
| What | Why | Legal basis |
|---|---|---|
| Your email address, display name, preferred language, and records of sign-in links sent and sessions opened | To give you secure access to your bookings, orders and messages | Performance of our contract with you, or steps before a contract |
| A record of important actions on your account (an "audit log"), such as who changed a booking and when | Security, preventing fraud, and resolving disputes | Our legitimate interest in keeping accurate records; our legal obligations |
3.6 When you book a journey
The person who makes a booking (the "lead booker") may book for other people. If you book for others, please make sure they have seen this policy.
| What | Why | Legal basis |
|---|---|---|
| For each traveller: full name as it appears on the passport, email address, festival ticket reference where the journey requires one, a confirmation that the traveller is an adult, and the package and options chosen (for example flights, hotel legs, room type, room-sharing preferences and named roommates) | To make the reservation, arrange flights, rooms and activities with our suppliers, and send each traveller their own invitation to the Traveller portal | Performance of our contract with you |
| Payment records: amounts due, amounts received, dates, the bank reference you used and the name on the paying account | To match your bank transfer to your booking, confirm your payment and keep accounting records | Performance of our contract; our legal obligations (accounting and tax records) |
| Proof-of-payment files you upload (for example a screenshot or PDF of your transfer confirmation). These can show your name, bank, account number and transaction details | To help us find and check your transfer. A proof is evidence only: your payment counts as received when the money reaches our account | Performance of our contract |
| Messages between you and our team, and requests you make (for example a change request) | To answer you and manage your booking | Performance of our contract; our legitimate interest in providing a good service |
Passports. We do not collect passport scans or identity document copies through this website. If a supplier, such as an airline, later needs passport details to issue a ticket, we will tell you exactly what is needed, why, who receives it, how it will be collected securely and when it will be deleted, before we ask for it.
Health information. We do not ask for health information. If you choose to tell us about a medical, dietary or accessibility need so that we can make arrangements, we will use it only for that purpose, share it only with the supplier who needs it, and delete it after the journey.
Private messages stay private. In a group booking, each traveller's private messages with our team are visible only to that traveller and our staff, not to the rest of the group.
3.7 When you pre-order from our shop
| What | Why | Legal basis |
|---|---|---|
| Your name, email address, items, sizes and quantities ordered, your delivery choice (hand-over before a journey, island-wide delivery or collection) and, for delivery, your address in Mauritius or Rodrigues | To take, produce, deliver and support your order | Performance of our contract with you |
| Payment records and proof-of-payment files, as for journeys above | To match and confirm your payment | Performance of our contract; our legal obligations |
| Messages about your order | To answer you and handle any problem with your order | Performance of our contract |
3.8 Emails we send
We send service emails about your account, bookings, orders and payments (for example a sign-in link, a booking received notice, a payment reminder or a change to your journey). They come from a no-reply address. To reply or ask a question, message us through the Traveller portal. Service emails are necessary to provide the service and are not marketing. We only send marketing emails if you have opted in (section 3.3).
3.9 Our staff tools
Our team uses a private staff dashboard to manage journeys, bookings, payments, orders and messages. Only authorised staff can sign in to it, and important actions are recorded.
Some staff tools use our AI model provider, OpenAI, to help draft replies, summaries or checklists. When they do, the relevant information from your booking, order or messages may be sent to OpenAI for that purpose only. A member of our team reviews every draft before anything is sent to you, and no decision about you is made automatically.
3.10 Children
Our journeys are designed for adults. We do not knowingly collect information about children under 16 except from, and with the consent of, a parent or guardian, as Mauritian law requires.
4. Where we get your information
Mostly from you. We may also receive information:
- from the lead booker, when they book on your behalf or name you as a roommate;
- from our suppliers, for example a flight booking reference or a change to your hotel;
- from your bank, in the form of the transfer details that appear on our bank statement.
5. Information we do not collect
- Card numbers or online banking credentials. There is no card payment form on this website.
- Passport or identity document scans (see section 3.6).
- Advertising identifiers, or information from social media advertising tools. The website has no advertising or tracking scripts. Our only analytics is Vercel Web Analytics, which counts page visits in aggregate without cookies.
6. Cookies and similar technologies
We use only what the website needs to work:
| Name | Type | Purpose | Duration |
|---|---|---|---|
pp_session | Strictly necessary cookie | Keeps you signed in to the Traveller portal or the staff dashboard | Up to 7 days, or until you sign out |
NEXT_LOCALE | Strictly necessary cookie | Remembers whether you are reading the site in English or French | Until you close your browser |
Session storage on your own device (pp-s3-intro and pp-boom-booking-draft) | Strictly necessary or functional | Remembers that you have seen the introduction, and keeps a booking form you have not yet submitted if the page reloads | Until you close the tab. It stays on your device and is not sent to us |
Local storage on your own device (pp-s3-stamps, and the items in your shop bag) | Functional | Remembers which passport "stamps" you have collected on the site and the items in your shop bag | Until you clear your browser storage. It stays on your device and is not sent to us |
| App cache on your own device | Functional | Keeps public images, styles and an offline page so the site still opens on a weak connection. It never stores your account, bookings or messages | Until you clear your browser storage |
We do not use advertising, social media or tracking cookies. Vercel Web Analytics, which we use to count page visits in aggregate, sets no cookies and does not identify individual visitors. If this ever changes we will update this policy and ask for your consent first where the law requires it.
7. Who we share your information with
We never sell your personal information. We share it only as follows.
7.1 Service providers who process it for us. They may use it only on our instructions and must keep it secure.
| Service | Provider | What they do | Where |
|---|---|---|---|
| Website hosting and analytics | Vercel | Runs the website, keeps short-term server logs and counts page visits in aggregate (Vercel Web Analytics, no cookies) | United States, with servers in other regions including the European Union |
| Database | Neon (part of Databricks) | Stores accounts, bookings, orders, messages and uploaded payment proofs | European Union (Frankfurt, Germany) |
| Email delivery | Resend | Sends sign-in links, notifications and other emails from our no-reply address | United States |
| AI model provider for Ask Portal and staff drafting tools | OpenAI | Generates answers and drafts | United States |
We may also use everyday business tools, such as email and document software, to run our business. These providers process information only on our behalf.
7.2 Travel suppliers. To deliver your journey we share the necessary details (usually name, travel dates, room arrangements and, if needed, contact details) with the airline(s), hotels, ground transport, excursion operators and partner travel agencies who provide the services you booked. They use it under their own privacy policies. We share only what each supplier needs. We do not send them your private messages or your payment proofs.
7.3 Festival organisers. We do not sell festival tickets. If you buy a festival ticket, you deal with the festival directly under its own terms and privacy policy.
7.4 Delivery partners. For shop orders delivered to you, we share your name and delivery address with the delivery service.
7.5 Professional advisers and authorities. Our accountants, auditors, lawyers and insurers where needed, and public authorities (for example the Mauritius Revenue Authority, the police or a court) where the law requires it.
7.6 If the business changes hands. If all or part of our business is sold or reorganised, your information may be transferred to the new owner, who must continue to protect it in line with this policy.
8. Transfers outside Mauritius
Some of the providers above store or process information outside Mauritius, including in the European Union and the United States. Section 36 of the Data Protection Act 2017 allows such transfers in specific situations. We rely on:
- the transfer being necessary to perform your contract, for example sending your name to a hotel in Portugal or an airline, or storing your booking with our database provider; and
- appropriate safeguards with our service providers, such as their data processing agreements and, where offered, the European Commission's standard contractual clauses or the EU-U.S. Data Privacy Framework.
The level of protection in other countries may differ from Mauritius. You can ask us for more information about the safeguards for a particular transfer.
9. How long we keep your information
We keep personal information only for as long as we need it for the purpose we collected it for, then delete it or make it anonymous. In practice:
- Mailing list and interest registrations are kept until you unsubscribe or ask us to delete them, and we remove contacts who have not engaged with us for a long time.
- Enquiries that do not become a booking are deleted once they are no longer needed to answer you.
- Bookings, orders, messages and payment records are kept for as long as Mauritian law requires us to keep accounting, tax and business records, and for as long as needed to deal with any claim.
- Proof-of-payment files are kept only as long as needed to confirm your payment and deal with any dispute about it.
- Health or accessibility information you choose to give us is deleted after the journey.
- Security and rate-limiting records are kept for a short time only.
10. Your rights
Under the Data Protection Act 2017 you have the right to:
- Access: ask whether we hold information about you and receive a copy of it, free of charge;
- Correction: have inaccurate or incomplete information corrected;
- Erasure: ask us to delete your information where it is no longer needed, where you withdraw consent and no other legal ground applies, where you object and there is no overriding reason to keep it, or where it was processed unlawfully;
- Restriction: ask us to pause using your information while a question about it is resolved;
- Objection: object to our use of your information based on our legitimate interests and, at any time and without giving a reason, to direct marketing;
- Withdraw consent at any time, where we rely on consent. This does not affect anything we did before you withdrew it;
- Not be subject to a decision made only by automated means that has legal or similarly significant effects on you. We do not make any such decisions;
- Complain to the Data Protection Office (details below).
Some rights have limits. For example, we may need to keep booking and payment records for legal and accounting reasons even if you ask us to delete them, and we cannot delete information about a journey that is still going ahead without cancelling your place. We will explain if that is the case.
How to make a request. Use the contact form on our Contact page, message us through the Traveller portal, or write to the address in section 1. We may ask you to confirm your identity before we act. We will reply in writing within one month. If your request is complex we may extend this by one further month and will tell you why.
Complaints. We would like the chance to resolve any concern first. You also have the right to complain to the Data Protection Commissioner, Data Protection Office, Mauritius (https://dataprotection.govmu.org).
11. How we protect your information
We use measures appropriate to the risk, including: encrypted connections (HTTPS) for the whole website; sign-in by single-use, time-limited email links instead of passwords; sign-in tokens stored only in coded (hashed) form; separation so that each customer sees only their own bookings, orders and private messages; staff access limited to authorised people; and records of important actions.
No system is perfectly secure. If a personal data breach occurs we will notify the Data Protection Commissioner without undue delay and, where feasible, within 72 hours, and we will tell you directly where the breach is likely to put your rights and freedoms at high risk.
12. Links to other websites
Our website links to other sites, such as the festival's website, our suppliers, WhatsApp and social media. We are not responsible for how those sites handle your information. Please read their privacy policies.
13. Changes to this policy
We may update this policy when our services or the law change. The date at the top shows the latest version. If a change significantly affects how we use information you have already given us, we will tell you by email or in your Traveller portal before it takes effect.
14. Contact
Questions about this policy or your information: use the contact form on our Contact page, message us through the Traveller portal, or write to Data protection, Selectro Ltd, C2 Bonne Terre, Vacoas, Mauritius.
This policy is also available in French. If there is any difference between the English and French versions, the English version prevails.
