1. Scope
This policy applies to personal information handled directly by Witcher Travel Deals through this website, Telegram, email, booking support, and related customer service. Third-party services have their own privacy practices.
2. Information we collect
Depending on how you use the service, we may receive:
- Contact details, including your Telegram user and chat identifiers, Telegram display name, username and profile-photo file identifier where available, email address, phone number, and internal customer tags.
- Quote and booking information submitted through the website or bot, including names, dates of birth, gender, destinations, travel dates, product links, passenger or guest counts, preferences, and special requests where relevant to the requested service.
- A request reference, confirmation and workflow status, reminder timestamps, and message-routing identifiers used to keep each bot conversation connected to the correct request.
- Telegram conversation content and attachment metadata needed to display customer service history in the private customer-management panel. Telegram file identifiers may be retained so an authorized administrator can retrieve an attachment through the server without exposing the bot token.
- Internal service notes, follow-up tasks, and status history created while managing a customer request.
- Administrator Telegram allowlist identifiers, hashed and expiring one-time-code challenge records, secure session records, and audit events used to restrict and monitor access to the private panel. Plaintext sign-in codes are not stored.
- Transaction information, such as payment confirmation, amount, currency, and transaction reference. We do not ask you to send passwords or full payment account credentials.
- Basic technical data made available by hosting providers or third-party resources, such as IP address, browser type, and referring page. Rate limiting may temporarily process an IP address in server memory to prevent automated abuse.
Please do not send passport details, identification documents, health information, or other sensitive data unless it is necessary for an agreed booking and you have confirmed the official communication channel.
3. How we use information
- Prepare quotes and check availability.
- Arrange, confirm, manage, and support requested bookings or orders.
- Communicate about requests, status changes, reminders, refunds, and customer service.
- Prevent fraud, abuse, and unauthorized transactions.
- Maintain records, resolve disputes, and comply with applicable legal obligations.
- Improve the website and service.
5. Retention
Unclaimed website quote requests are normally deleted after seven days. Requests connected to Telegram but not confirmed normally expire after 24 hours. Confirmed requests with no activity are normally closed after 30 days. Closed or cancelled request records, stored conversation history, attachment metadata, and message-routing links are normally deleted after 90 days. Customer profiles, internal notes, and tasks are normally deleted after no associated request remains and the profile has been inactive for 90 days. Administrator one-time codes expire after five minutes, and challenge records are retained for at least one day for abuse prevention before scheduled removal. Administrator sessions expire after the configured short session period, and security audit events are normally deleted after one year. Longer retention may apply where reasonably necessary for accounting, fraud prevention, dispute resolution, supplier support, or legal obligations. Deleting server records does not automatically remove messages already stored by Telegram in a chat.
6. Your rights and choices
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or a portable copy of personal information. You may also withdraw consent where processing relies on consent. These rights may be limited by legal obligations and legitimate recordkeeping needs.
To make a request, email support@witchertraveldeals.com. Identity verification may be required before a request is completed.
7. Security and account safety
Reasonable administrative and technical safeguards are used, including an administrator allowlist, bot-delivered single-use sign-in codes, hashed challenge records, strict expiry and attempt limits, short-lived server-side sessions, anti-forgery controls, access auditing, and restricted database networking. No internet transmission or storage method is completely secure. The official Telegram bot is linked from witchertraveldeals.com and accepts request details directly in its private chat; the official support email is support@witchertraveldeals.com. Never share administrator one-time codes, passwords, or wallet seed phrases.
Children
The service is intended for adults. Do not submit information about a child unless you are the parent or legal guardian and the information is necessary for an agreed booking.
8. Contact and updates
Questions or privacy requests can be sent to support@witchertraveldeals.com. This policy may be updated when the service, technology, or legal obligations change. The date above identifies the latest version.