Here is the updated, unified Privacy Policy & Terms of Service incorporating the Archie Mobile Application Disclosures into both the Data Collection and Third-Party sections, as well as updating the document header and contact details.

Privacy Policy & Terms of Service for VistaOneTravels.com & Archie App

Effective Date: August 18, 2026 | Last Updated: August 18, 2026

At VistaOneTravels.com (“VistaOne Travels,” “we,” “us,” or “our”), we respect your privacy and are committed to protecting the Personally Identifiable Information (PII) you share with us. This document outlines how we collect, use, store, share, and safeguard your data across our website, cruise booking services, communications, and mobile applications (including the Archie travel application), as well as the terms governing your use of our travel advisor services.

Part 1: Privacy Policy & Data Protection

1. Data Controller Information

For the purposes of the EU General Data Protection Regulation (GDPR) and global data protection laws, VistaOne Travels acts as the Data Controller for personal information collected directly through our website, mobile applications, contact forms, and travel planning consultations.

  • Website: VistaOneTravels.com

  • Data Protection Contact: Privacy & Data Operations Desk

  • Contact Email: privacy@vistaonetravels.com

2. What Personal Data (PII) We Collect

Because planning and executing cruise travel and providing interactive travel recommendations require coordinating with suppliers and technology platforms, we collect several categories of personal data:

A. Data Provided Directly by You

  • Contact & Identity Information: Full legal names (matching government ID/passport), birthdates, gender, email addresses, physical mailing addresses, and telephone numbers.

  • Travel & Identity Documentation: Passport numbers, citizenship, passport expiration dates, emergency contact details, and frequent flyer/loyalty program numbers.

  • Financial & Payment Details: Credit/debit card numbers, billing addresses, and expiration dates. (Note: Payment data is processed securely through PCI-DSS compliant booking gateways and is never stored on unencrypted local servers).

  • Special Category / Health Data: Dietary requirements, mobility needs, medical accommodation requests, or pregnancy status required for cruise line manifest compliance.

B. Data Collected via the Archie Mobile Application

  • Location Data: With your explicit consent, we access precise or approximate device location data (via GPS or network triangulation) to provide real-time dining, activity, and travel recommendations near you.

  • App Usage & Diagnostics: We collect crash logs, performance metrics, and interaction data to improve app functionality and user experience.

  • Saved Preferences & Itineraries: Places, dining spots, or trip itineraries you bookmark or customize within the app.

C. Data Collected Automatically (Technical & Usage Data)

  • Device & Connection Data: IP addresses, browser types, operating systems, referring URLs, and language preferences.

  • Usage Patterns: Pages viewed, links clicked, time spent on specific guides, and interaction with our web forms.

  • Cookies & Tracking: Data collected through cookies, web beacons, and analytics tools (e.g., Google Analytics). You can manage or disable cookies at any time through your web browser settings.

3. Lawful Basis for Processing Data (GDPR Compliance)

Under the GDPR, every instance of personal data processing must rest on an explicit legal foundation. We process your data under the following legal bases:

  • Fulfilling Cruise Reservations: Names, Birthdates, Passports, Payment Details — Contractual Necessity (Required to book travel)

  • Mobile App Location & Features: Precise Location, App Preferences — Consent (Opt-in required via device settings)

  • Sending Booking Confirmations & Updates: Email, Phone Number, Reservation Codes — Contractual Necessity / Legitimate Interest

  • Processing Payment Transactions: Credit Card Info, Billing Address — Contractual Necessity

  • Responding to Inquiries & Quote Requests: Contact Form Entries, Travel Preferences — Consent / Pre-Contractual Steps

  • Email Newsletters & Promotions: Name, Email Address — Consent (Opt-in required; easily revoked)

  • Website & App Performance Analytics: IP Address, Cookies, Device Logs — Legitimate Interest / Consent

4. How We Share Your Data (Third-Party Suppliers & Technology Partners)

To complete your travel bookings and power our digital tools, VistaOne Travels shares relevant data with third-party service providers. We do not sell, rent, or trade your personal data to third parties for marketing purposes.

We share data strictly with:

  1. Cruise Lines & Tour Operators: (e.g., Royal Caribbean, Disney Cruise Line, Celebrity, Viking River Cruises) to generate official bookings, stateroom manifests, and passenger records.

  2. Host Agencies & Global Distribution Systems (GDS): Travel management platforms used to process reservation nodes and access group contract rates.

  3. Location & API Services (Archie App): Third-party mapping and venue platforms (such as the Google Places API) to locate nearby venues and calculate routing. Location queries are processed securely and are never sold or leveraged for advertising.

  4. Travel Insurance Providers: To issue requested travel protection quotes and policies.

  5. Payment Gateways & Financial Institutions: PCI-compliant processors that execute secure credit card transactions.

  6. Legal & Regulatory Authorities: When required by law, court order, customs/border protection agencies, or maritime security mandates.

5. Managing Mobile App Permissions

You can manage or revoke location tracking and notification permissions for the Archie app at any time through your device’s native settings:

  • iOS: Settings > Privacy & Security > Location Services > Archie

  • Android: Settings > Location > App Permissions > Archie

Disabling location permissions will limit the application’s ability to provide real-time, location-aware dining and activity recommendations.

6. International Data Transfers & GDPR Safeguards

Because cruise vacations involve global itineraries, your personal data may be transferred to and processed by cruise suppliers, port agents, and local tour operators located outside the European Economic Area (EEA) or your home country.

When transferring data internationally, VistaOne Travels ensures appropriate legal safeguards are applied, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.

  • Direct necessity to execute your travel contract (Article 49(1)(b) of the GDPR).

7. Data Security Measures

We maintain robust administrative, technical, and physical security measures to safeguard your personal information against unauthorized access, loss, alteration, or disclosure:

  • Encryption: All website traffic, mobile app API calls, and data transmission forms use standard HTTPS / TLS 1.3 encryption.

  • Access Controls: Strict role-based access policies ensure that only authorized personnel handle sensitive client information (such as passport details).

  • PCI-DSS Compliance: Payment card numbers are submitted directly to tokenized merchant gateways; we do not store raw credit card CVV codes.

Data Breach Protocol: In the event of a security incident that compromises your personal data, VistaOne Travels will notify affected individuals and relevant supervisory authorities within 72 hours of verification, as mandated by GDPR.

8. Data Retention Policy

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting obligations:

  • Active Booking Records: Retained for the duration of your trip + 7 years (for legal, tax, and insurance auditing requirements).

  • Archie App Account & Preferences: Retained as long as your account remains active or until you request account deletion.

  • Marketing Subscriptions: Retained until you withdraw consent or click “Unsubscribe.”

  • Technical Analytics Data: Anonymized or deleted automatically after 26 months.

9. Your Privacy Rights (GDPR, CCPA & US State Laws)

Depending on your geographic location, you hold specific legal rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you.

  • Right to Rectification: Request that we correct inaccurate or incomplete PII.

  • Right to Erasure (“Right to be Forgotten”): Request that we delete your personal data (subject to legal retention mandates).

  • Right to Restrict or Object: Object to data processing based on legitimate interests or direct marketing.

  • Right to Data Portability: Request a machine-readable transfer of your personal data.

  • Right to Withdraw Consent: Revoke marketing consent at any time using the “Unsubscribe” link in our emails or by updating your mobile app settings.

California Privacy Rights (CCPA / CPRA Disclosure)

Under the California Consumer Privacy Act (CCPA) as amended by the CPRA, California residents have specific rights regarding their personal information:

  • Notice of Collection: We collect identity, contact, financial, travel documentation, and precise location data as specified in Section 2 above.

  • No Sale or Sharing of Personal Data: VistaOne Travels does not sell your personal information or share it with third parties for cross-context behavioral advertising.

  • Right to Limit Use of Sensitive Personal Information: We only use sensitive PII (such as passport details or precise GPS location) to fulfill travel reservations or deliver requested mobile app features.

  • Non-Discrimination: We will not discriminate against you (e.g., by denying services or charging different rates) for exercising any of your privacy rights.

To exercise any of these rights, submit a written request to privacy@vistaonetravels.com. We respond to all verified requests within 30 days free of charge.

Part 2: Terms of Service & Advisor Disclaimers

By accessing VistaOneTravels.com, using the Archie mobile app, or engaging our services, you agree to the following operational terms:

1. Role as an Independent Travel Advisor

VistaOne Travels acts solely as an intermediary agent between you (the client) and third-party travel suppliers (including cruise lines, airlines, hotels, and excursion operators).

  • We do not own, operate, or control the cruise ships, hotels, or transport vehicles.

  • All bookings are subject to the specific terms, conditions, contract of carriage, and cancellation policies imposed by the respective travel supplier.

2. Client Responsibilities (Passports, Visas, & Health)

  • Identification: Passengers are strictly responsible for obtaining and carrying valid government identification. For international cruises, passports must generally be valid for at least 6 months beyond your scheduled return date.

  • Visas & Entry Protocols: Travelers are responsible for securing any required entry visas, travel authorizations (e.g., ESTA, ETIAS), or health declarations for ports of call.

  • Boarding Refusal: VistaOne Travels is not liable if a cruise line or border authority denies you boarding due to improper documentation.

3. Travel Protection & Insurance Warning

Highly Recommended: Cruise fares, shore excursions, and air travel carry strict non-refundable cancellation penalties. VistaOne Travels strongly advises every client to purchase a comprehensive Travel Protection Policy covering trip cancellation, interruption, medical evacuation, and flight delays.

Part 3: Policy Updates & Contact Information

We may update this Privacy Policy & Terms of Service periodically to reflect changes in privacy laws, maritime regulations, mobile app updates, or agency operations. Revisions will be posted on this page and within the Archie app settings with an updated “Last Updated” date.

How to Contact Us

If you have questions, concerns, or legal requests regarding this Privacy Policy or your personal data, please reach out to us at:

  • Agency Name: Vista One Travels

  • Mailing Address: [Insert Full Business Street / PO Box Address, City, State, Zip Code]

  • Data Protection Contact: Privacy & Data Operations Desk

  • Privacy Email: privacy@vistaonetravels.com

  • General Inquiries: info@vistaonetravels.com

Archie, by Vista One Travels — last updated August 10, 2026

This policy explains what information Archie (“the app,” “we,” “us”) collects, why, and who it’s shared with. It covers the mobile app and the backend service it talks to.

Information we collect

Account & profile

  • Required: name, email address, and a password (stored as a one-way hash — we never store or can retrieve your actual password).
  • Optional, if you choose to add them: phone number, profile photo, mailing address, birth month and day, travel interests, and food preferences. These personalize recommendations; nothing about them is required to use the app.

Trip information

Trips can be added two ways, and both involve reading booking-confirmation content you provide:

  • Pasting an email: you copy the subject and body of a confirmation email into the app.
  • Forwarding an email: each account gets a personal forwarding address; forwarding a confirmation there (only from your registered email address) adds the trip automatically. We keep the email’s subject line and the trip details extracted from it (dates, confirmation number, hotel/cruise/ship name, etc.) — we do not retain the full email body after it’s been processed.

Cruise itineraries you type in, or a cruise itinerary PDF you upload, are handled the same way — we extract and store trip details, not the original file, once it’s been read.

Location

With your permission, we use your device’s location only while the app is open to show nearby dining, activities, and shopping. We never collect location in the background, and location isn’t required to use the app — you can decline and still use every other feature.

Photos

If you choose to add a profile picture or a photo of a port of call, the app can access your camera or photo library. Photos you add are stored with your account; we never access your camera roll except when you actively choose to pick or take a photo.

Device & diagnostic data

If crash reporting is enabled, basic device and crash information is sent to our error-monitoring provider (Sentry) when the app encounters a bug, so we can fix it. This does not include your trip content, messages, or profile details.

In-app assistant

Questions you type to Archie’s built-in travel assistant, along with relevant context about your current trip (destination, dates, hotel/cruise name), are sent to our AI provider (Anthropic) to generate a response. Recommendation curation for a destination works the same way, using the destination name only.

Biometric sign-in

If you turn on Face ID/fingerprint sign-in, authentication happens entirely on your device using your OS’s own biometric system. Your biometric data itself is never sent to us or stored by the app — we only ever receive a yes/no confirmation from your device’s operating system.

Who we share information with

ServiceWhat it’s used forWhat it receives
Google (Gmail API)Reading forwarded booking-confirmation emailsEmail content you forward, matched to your account by sender address
Anthropic (Claude)The in-app travel assistant and destination recommendation curationYour questions, relevant trip context, and destination names
SentryCrash/error reportingDevice info and crash logs — never trip content or messages
Unsplash / WikipediaDestination and hero photos shown in the appNothing of yours — we only fetch publicly available photos by destination name
Weather / geocoding providersForecast, local time, and travel-advisory data for your destinationDestination name/coordinates only, never tied to your identity

We do not sell your information, and we do not share it with advertisers.

Data retention

We keep your account and trip data for as long as your account is active. You can delete individual trips at any time in the app. To delete your account entirely, contact us at the address below.

Security

Passwords are hashed, never stored in plain text. Data in transit between the app and our servers is encrypted.

Your choices

  • Location, camera, and photo-library access can all be declined or revoked any time in your device’s system settings — the app keeps working without them, just without the features that depend on them.
  • You can delete individual trips, packing-list items, and your profile photo directly in the app.
  • To request a full copy or deletion of your data, contact us below.

Children’s privacy

Archie is not directed at children under 13, and we do not knowingly collect information from them.

Changes to this policy

If this policy changes materially, we’ll update the date at the top of this page.

Contact us

Questions about this policy or your data: derek@vistaonetravels.com