





Personal Information Protection Policy
Date of Release: / / 2025
Effective Date: / / 2025
Introduction
Welcome to the DidaTravel Platform! Shenzhen DidaTravel Technology Co., Ltd. (hereinafter referred to as "DidaTravel "), as a technology-driven travel distribution service provider, is dedicated to connecting the supply and demand sides through technological solutions. Leveraging a one-stop procurement platform and industry-leading information technology, DidaTravel Tech provides global tourism resources to over 23,000 travel buyers worldwide.
DidaTravel (hereinafter also referred to as "we") fully recognizes the importance of your personal information and places the highest priority on protecting your privacy and personal data. In compliance with applicable laws and regulations, and through this DidaTravel Personal Information Protection Policy (hereinafter referred to as the "Policy"), we aim to transparently explain how we process your personal information when you use the products/services on the DidaTravel Platform, as well as the methods we provide for you to access, update, delete, and safeguard such information.
【Special Notice】
Before accessing or using the products/services on the DidaTravel Platform, please read this Policy carefully and ensure you fully understand its contents, particularly the terms highlighted in bold font, which require your focused attention. Only after confirming your full understanding and agreement should you proceed to use the products/services. If you or your legal guardian (if you are a minor) disagree with any part of this Policy, you will be unable to log in and access the DidaTravel Platform’s products/services. For any questions, feedback, or suggestions regarding this Policy, please contact us using the methods provided in [Article VIII ] of this Policy.
Please pay special attention to the scope of application of this Policy:
- This Policy applies to all products and services provided by the DidaTravel Platform. If our products/services utilize DidaTravel Platform offerings that do not have a standalone personal information protection policy, such portions shall also be governed by this Policy. For products/services with independent personal information protection policies, those standalone policies shall take precedence. Any matters not addressed in the standalone policies but stipulated herein shall be subject to this Policy.
- This Policy does not apply to third-party information/services (including third-party applications, websites, etc.) embedded within or linked to the DidaTravel Platform’s products/services. Such information/services are operated by third parties and must comply with the respective third party’s personal information protection policies or similar regulations.
Part I Definition
1. DidaTravel Platform: Refers to the webpages and clients (including WeChat Mini Programs) primarily accessible via the domains dida.com, with client applications compatible with terminal devices such as PCs, tablets, mobile phones, and others.
2. DidaTravel/We: Includes both the developer and operator of the DidaTravel Platform, Shenzhen DidaTravel Technology Co., Ltd.(registered at Room 1005-01, Aokangde Group Building, 2010 Shennan East Road, Chengdong Community, Dongmen Street, Luohu District, Shenzhen).
3. Affiliated Companies: All subsidiaries, affiliates, and related entities under Shenzhen DidaTravel Technology Co., Ltd. , including but not limited to:
Shenzhen GoodluckTrip International Travel Service Co.,Ltd.
Shenzhen Youdao Travel Co., Ltd.
Caring(Shenzhen) Travel Service Co.,Ltd.
Zhejiang GoodluckTrip International Travel Service Co.,Ltd.
DidaTravel International Limited.
DIDA TECHNOLOGY SINGAPORE PTE.LTD.
4. Client/You:Refers to any natural person or legal entity that accesses or uses the products/services provided by the DidaTravel Platform, including but not limited to registered and unregistered users.
5. Personal Information: Any information recorded by electronic or other means that relates to an identified or identifiable natural person.
6. Sensitive Personal Information: Personal information that, if leaked, illegally disclosed, or misused may endanger personal and property safety, easily lead to personal reputation, physical and mental health damage or discriminatory treatment of personal information. Sensitive personal information covered in this policy includes biometrics, religious beliefs, specific identities, medical and health information, financial accounts, whereabouts and other information, as well as personal information of minors under 14 years of age.
7. Deletion of Personal Information: The act of removing personal information from systems involved in daily business operations, rendering it irretrievable and inaccessible.
8. Children: Minors under the age of 14.
9. Minor: A natural person under the age of 18. A minor aged 16 or older who primarily relies on their own labor income for livelihood shall be deemed to have full civil capacity.
10. API: API (Application Programming Interface) refers to a predefined set of rules, protocols, and tools for building software applications.
Part II: Personal Information Protection Policy
This Policy outlines the following key aspects:
I.How We Collect and Use Your Personal Information
II. How We Use Cookies
III. How We Share, Transfer, Entrust Processing, and Publicly Disclose Your Personal Information
IV. How We Store and Cross-Border Transfer Your Personal Information
V. How We Protect the Security of Your Personal Information
VI. How We Protect Minors’ Personal Information
VII. Amendments and Notifications of This Policy
VIII. How to Contact Us
I. How We Collect and Use Your Personal Information
When using our products/services, you may need to authorize us to collect and use personal information under the following circumstances:
Essential Functionality: To provide basic features of our products/services, you must authorize us to collect and use necessary information. If you refuse to provide such information, you will be unable to use our products/services normally.
Additional Functionality: To access enhanced features of our products/services, you may voluntarily authorize us to collect and use information. Refusal to provide such information will restrict your access to these additional features or limit their intended effects, but will not impact your use of core functionalities.
Note:
As we offer diverse products/services, we collect and use your personal information strictly under the principles of legitimacy, fairness, and necessity, based on the specific products/services you select.
To enhance our offerings, we may introduce new or optimized features that require changes to the purposes, scope, or methods of personal information collection. In such cases, we will notify you via updated policies, pop-ups, or in-platform messages, clearly explaining the changes and seeking your explicit consent before implementation. For questions or feedback, contact us using the methods in [Article VIII] of this Policy.
(A) Providing Search and Browsing Functionality
Under normal circumstances, you may search and browse various products on the DidaTravel Platform after accepting the Privacy Policy and logging into your account.
After you agree to this policy, in order to ensure the realization of search and browsing functions, we will collect the search keywords you enter on the web page, the pages or links you click in order to return the corresponding pages or results to you on the service side of the Tao Travel platform. In addition, we also collect your log information for the purposes described above.
Please note that log information alone or search keyword information alone cannot identify you and is not your personal information, only when your log information alone or search keyword information is used in combination with other information about you and can identify you; During the combined use, we will treat your log information or search keyword information as your personal information, which will be processed and protected in accordance with this policy.
(B) Assisting with DidaTravel Account Registration and Management
If you want to use the products/services of the DidaTravel Platform, you first need your employer to register a Tao Travel account to become a DidaTravel Platform user. We will complete the account registration based on the company name, employee name, mobile number and email address provided by your employer.
In order to ensure the security of your account during the registration process, we will send a verification message to your registered email address to verify registration or login. During the login process, we will send verification information to your registered mobile phone number or to your registered email address according to the login method you choose to ensure your login security.
In order to protect the security of your account, we will send a verification code to your mobile phone number to verify that it is your operation when you extend a credit line, cancel an order, redeem points, top up, make a payment or any other action related to money operations on the DidaTravel Platform. When you query or modify account information (such as creating sub-accounts under the main account, modifying sub-account information under the main account, deleting sub-accounts, etc.), in order to ensure the security of your account, we will send a verification code to your mobile phone number to verify whether it is your operation. If you refuse to provide the corresponding information, please contact your employer, you will not be able to create an account and use the products/services of the DidaTravel platform.
(C)Displaying, Recommending, and Promoting Products/Services
1.Providing Products and Services
When providing products and services to you, it is necessary to use your personal information or the actual user of the product/service. When providing hotel products, we usually need to collect the name and nationality of the check-in person, and the hotel will require the collection of the phone number, passport number or other ID number of the check-in person in order to confirm the check-in information. In order to assist guests in determining the room type and completing the booking and check-in, the hotel will ask to collect the name and age of children when they are brought to the hotel. When providing ticket products, we need to collect the passenger's name, document type and document number, mobile phone number, and email address if necessary.
Please note that DidaTravel provides distribution services for travel products and is not the ultimate provider of travel products, so we may also provide products or services through third parties such as business partners and affiliates, so we may also share information collected with suppliers, third-party payment financial institutions, business partners, and related affiliates.
2.Market Research and Promotions
In order to better provide you with products or services, we may periodically send you information about new products, special offers or other information that we think may be of interest to you to the email address you have provided. We will also invite you to participate in market research through the contact information you provide from time to time to fully understand your interest and opinions on our products and services.
3.Understanding Your API Collaboration Intentions
In order to better understand your cooperation intention and cooperation mode, and improve the communication efficiency of cooperation intention, we set up an API cooperation intention collection interface on the DidaTravel platform. If you are interested in API cooperation, you can fill in the cooperation intention on our platform. In order to provide you with services and communication, we need to collect the company name of your employer, the country where the company is located, the type of business of the company and the address of the company's website on the Intention to cooperate interface. In order to contact you or your employer, we need to collect your employer's company phone number and company email address, your name and your title at your employer.
In order to provide you with products or services more accurately, we may need to know whether your company type is a travel agent or travel agency, your company's travel turnover profile in the previous year, your company's hotel room night turnover profile in the previous year, and whether your company has a history of API integration. In order to optimize our products or services, we also need to understand why your company is interested in working with us.
(D)Providing Bookmarking Functionality
While using the DidaTravel Platform’s products/services, you may choose to bookmark hotels of interest. To enable this functionality and other purposes explicitly disclosed to you, we will collect at least the log information generated during your bookmarking activity (e.g., timestamps, hotel IDs).
(E)Providing Order Inquiry and Account Management Functionality
When you place an order for products/services on the DidaTravel Platform, the system generates an order record. During the ordering and management process, we may collect the following information:
(1) Information required by the specific product/service you select.
(2) Contact details: Name and mobile number of the contact person.
(3) Order information generated during your use of the Platform.
Purpose of Collection:
(1) To facilitate transaction confirmation, payment settlement, notifications, order management, and client support/after-sales services.
(2) To monitor transaction anomalies and ensure your transaction security.
Special Requirements for Travel Products/Services
Due to the nature of travel services, the following products require additional mandatory information to complete bookings. You must provide this information directly or authorize us to assist in its entry. Please review details during the booking process:
1.Flight Bookings:
- Domestic flights: At minimum, passenger’s name, ID type, ID number, and mobile number.
- International flights: At minimum, passenger’s name (including phonetic spelling), gender, nationality, date of birth, ID type, ID number, ID expiration date, and contact mobile number. Additional fields (e.g., contact email) may apply depending on the product.
2. Hotel Reservations:
- At minimum, guest’s name and mobile number. Additional fields (e.g., ID number, email) may apply depending on the product.
3.Airport Transfers/Chartered Car Services:
- Passenger’s name, contact phone/email.
- For airport transfers: Flight number (to ensure punctuality).
- For chartered services: Travel date (to confirm scheduling).
4.Minors in Travel Groups:
- Name, ID type, and ID number of minors, provided with consent from their legal guardian.
5.Bank Card Binding:
- Name, bank card number, mobile number, ID type, and ID number.
Additional Requirements:
Other products/services may require further information as specified during the booking process. Please review prompts and authorizations carefully.
(F) Facilitating Payment Completion
When purchasing products through the DidaTravel Platform, third-party payment platforms may collect relevant information to ensure successful payment processing for your order. If you use an international bank card, depending on the requirements of your selected payment provider, we may collect your billing address details, including:
- Country
- Contact address
- Email address
This information is necessary to comply with cross-border payment regulations and complete the transaction securely.
(G) Facilitating Delivery of Products/Services
To ensure the secure delivery of your purchased products/services, we will collect and use at minimum your order information during this process.
For Redemption via Points Mall:
- If you redeem points for digital vouchers or mailing services (e.g., invoices, physical goods), we require:
(1) Recipient’s phone number and email address.
(2) For physical goods: Delivery address, recipient’s phone number, and recipient’s title (e.g., Mr./Ms.).
- For digital vouchers: Your mobile number is required for online redemption.
For Invoicing:
- If you request paper or electronic invoices for purchased products/services, we collect:
(1) Billing information: Invoice title, email address.
(2) Delivery details (as specified above).
(H) Contacting You
We may contact you via website notifications, email, phone, or postal mail to address order-related issues or other product/service inquiries.
(I) Providing Client Support and Resolving Disputes
- In order to ensure the security of your account, our telephone and online client service will use your user information and order information to verify your identity. When you take the initiative to ask us to provide client service related to your order, we may inquire your relevant order information in order to give you appropriate help and treatment. If you voluntarily ask client Service to assist you in modifying the information (such as shipping address, contact person, or contact number), you may need to provide additional information in addition to the above information to complete the modification
- When you contact us, we may save the communication/call records and content with you, or the contact information and related information you left, in order to contact you or help you solve the problem, or record the solution and result of the relevant problem.
- In order to protect your information security, transaction security and service quality, to deal with possible disputes in the future, when you contact our client service consultation, we may save the call record and content between you. Such call records and contents are automatically deleted after the minimum necessary storage period as required by law, unless retained for compliance requirements or legitimate interests. In addition, due to the network status, call environment, policies and regulations, the recording/storage failure cannot be ruled out.
- If you consult, complain or provide suggestions regarding our services or specific orders, we will use your account information, order information, and page operation records of related orders to facilitate the clarification of facts and settlement of disputes, and provide them to administrative regulatory authorities, judicial departments and our litigants within the scope permitted by law.
(J) Enhancing DidaTravel Platform Products/Services
We may use your de-identified data for research, statistical analysis, and predictive modeling to improve the Platform’s content, layout, support business decision-making, and refine our offerings.
(K)Special Notes on Personal Information Collection and Use
1. If the information you provide contains the personal information of other users, for example, you need to submit the personal information of the actual subscriber when ordering products/services for others through the DidaTravel Platform, or the personal information of other users is involved in the information uploaded, published or shared by you through the DidaTravel Platform, in the foregoing circumstances, before providing such personal information to the DidaTravel Platform, You must ensure that you have obtained your consent and that you are aware of and accept this Policy. If a child's personal information is involved, you need to obtain the consent of the child's guardian in advance.
2. Unless there are authorized consent exceptions (see "I, How We Collect and Use your Personal Information" in this Policy), we will, in accordance with the requirements of laws and regulations and national standards, obtain your individual consent in a reasonable way for the processing of sensitive personal information in certain scenarios. The specific individual consent method is subject to the display of the specific function page. You understand and understand that if you do not handle sensitive personal information properly, your personal dignity may be violated or your personal and property safety may be jeopardized. We will try our best to de-identify your sensitive personal information on the basis of ensuring the availability of information.
3. If we use the information for other purposes not specified in this policy, or use the information collected for a specific purpose for other purposes, we will re-obtain your consent.
4. We may obtain information about you collected by third parties such as affiliated companies and business partners that provide services to you. For example, when you book through our affiliates, business partner websites and their mobile apps, the booking information you provide to them may be transferred to us so that we can process your order and ensure that your booking is smooth. According to the agreement with the third party, we will ask the third party to explain the source of your personal information before collection, and confirm the legal compliance of these personal information sources, and understand the scope of authorization and consent of the third party to collect your personal information. If we collect and use your information for purposes beyond the scope of authorization granted to a third party, we will process your personal information ourselves or require the third party to obtain your consent separately.
5. Exceptions to authorized consent
You are fully aware that according to the requirements of laws and regulations, we do not need to obtain your authorization to collect and use your personal information in the following circumstances:
- Necessary for the performance of the statutory duties or statutory obligations of DidaTravel;
- Related to national security and national defense security;
- Related to public security, public health and major public interests;
- In connection with criminal investigation, prosecution, trial and execution of judgments;
- Necessary for the conclusion and performance of a contract to which you are a party;
- In case of emergency, to protect the life, health and property of you or other individuals;
- The personal information collected is the personal information subject's own disclosure to the public or other personal information that has been legally disclosed;
- Your personal information collected from legally publicly disclosed information, such as legitimate news reports, government information disclosure and other channels;
- Conduct news reporting, public opinion supervision and other acts in the public interest, and process personal information within a reasonable scope;
- Other circumstances stipulated by laws, regulations and national standards.
Please be aware that, in accordance with applicable law, if we process personal information with technical measures and other measures necessary to make it impossible for the recipient of the data to re-identify a particular individual and to recover it, the use of such processed data does not require further notice to you and your consent.
II. How We Use Cookies
To enhance your browsing experience, when you visit the DidaTravel Platform or use our services, we may store small data files called Cookies on your device or system to recognize your identity. These Cookies help:
Simplify repeated logins by saving registration details.
Optimize ad preferences and interactions.
Assess your account security status.
Managing Cookies:
You may clear all Cookies stored on your computer or mobile device.
You have the right to accept or reject Cookies. If your browser automatically accepts Cookies, you can modify its settings to block them.
Note: If you choose to reject Cookies, some features of our services may be limited or unavailable.
For detailed information about our use of Cookies, please refer to the [Cookie Policy].
III. How We Share, Transfer, Entrust Processing, and Publicly Disclose Your Personal Information
(A)Sharing and Provision
1.Principles of Processing
We may share your order information, account details, device data, and location information with third parties (e.g., partners) to ensure the successful delivery of services. However, we will only share your personal information for lawful, legitimate, necessary, specific, good faith, and explicit purposes, and only to the extent strictly required to provide such services.
- Third-Party Assessments: We evaluate the legality, legitimacy, and necessity of third parties’ data collection practices.
- Data Handling Requirements: Third parties must:
Process your personal information within the scope of your authorized consent.
Implement necessary administrative and technical measures to prevent unauthorized access, loss, alteration, or leakage of your data.
- Usage Restrictions: Third parties are prohibited from using shared data for purposes beyond the agreed scope. If they intend to alter the purpose or method of processing, they must re-obtain your explicit consent.
2.Separate Consent
Unless there are authorized consent exceptions (see "I, How We Collect and Use your Personal Information" in this policy), we will, in accordance with the requirements of laws and regulations and national standards, take reasonable ways to obtain your separate consent for the sharing and provision of personal information in certain scenarios other than those described above. However, regardless of whether we need to obtain your separate consent, we will explicitly inform you in a reasonable manner about the third-party supplier information that specifically provides you with the products/services involved and the purpose, method and type of processing your personal information. For example, when you are preparing to order some products/services of the Travel Platform, We may explicitly inform you of the above information through the order filling page or the order confirmation page before you place an order, and obtain your separate consent to authorize Tao Travel to provide your personal information to suppliers or service providers if necessary. For specific individual consent forms, please refer to the specific product/service order page.
3.Our Partners Include the Following Types (Domestic and International Entities):
(1) Your Employer:
As a client of DidaTravel, your employer may receive necessary personal information from us based on contractual agreements and operational needs. This data sharing enables purposes such as reconciliation, data analysis, and statistical reporting. Information may also be shared with individuals authorized by your employer.
(2) Suppliers:
Includes but not limited to hotels, airlines, car rental services, travel agencies, attraction and activity providers, and agents to fulfill your bookings. We share:
- Basic personal details (e.g., name, nationality).
- Identity information (e.g., passport/ID number).
- Contact details (e.g., phone number, email).
Suppliers may contact you directly to finalize travel arrangements.
(3) Financial Institutions & Third-Party Payment Providers:
- When placing orders or requesting refunds, we share specific order details (e.g., transaction amount, booking dates).
- For fraud detection and prevention, we may share additional data (e.g., IP address) with relevant institutions.
(4) Business Partners:
We collaborate with partners to deliver services such as:
- Logistics (e.g., courier services).
- Communication (e.g., SMS providers for notifications).
- Customer support, marketing, technical services, identity verification, and consulting.
- For example, SMS providers receive your mobile number and message content for service updates.
(5) Affiliated Companies:
We share personal information with DidaTravel’s affiliates to offer travel-related or complementary products/services. These affiliates adhere to protection measures no less stringent than those outlined in this Policy.
Important Note:
To prevent and detect fraud, we may prudently share necessary personal information with partners and affiliates. Such sharing undergoes rigorous internal security assessments and approvals, with strict agreements limiting data usage to specified purposes.
4. We may share your personal information in accordance with laws and regulations, litigation dispute resolution needs, relevant agreements signed between you and us (including online electronic agreements and platform rules) or legal documents, or when required by administrative, judicial and other competent authorities according to law.
5. In addition to the above instructions or otherwise provided by laws and regulations, if we share your personal information with any other company, organization or individual, we will seek your authorization again according to law.
(B) Information Transfer
We will not transfer your personal information to any company, organization, or individual, except in the following circumstances:
- With your explicit prior consent or authorization.
- To comply with applicable laws, regulations, legal proceedings, or mandatory administrative/judicial requirements.
- In the event of mergers, divisions, acquisitions, asset transfers, or similar transactions:
- If personal information transfer is involved, we will:
Notify you in advance of the name and contact details of the receiving entity.
Ensure the new entity continues to be bound by this Policy and assumes the original personal information processing obligations.
- If the new entity cannot comply, we will require them to re-obtain your authorization and consent.
(D) Public Disclosure
We will only publicly disclose your personal information under the following circumstances:
1.At Your Request:
- With your separate consent, we will disclose your specified personal information in the manner you approve.
2.Legal or Judicial Obligations:
- To comply with laws, regulations, mandatory administrative enforcement actions, or judicial orders, we may disclose your personal information as required, including the type of data and method of disclosure.
- In compliance with legal requirements, we will demand proper legal documentation (e.g., subpoenas, investigation letters) before responding to such requests.
IV. How We Store Your Personal Information
(A) Storage Location
1.Principles of Processing
In compliance with laws and regulations, we store personal information collected within the People’s Republic of China on servers located within China.
2.Cross-Border Transfers
If your personal information is transferred from China to overseas, we will strictly adhere to legal requirements.
Scenarios requiring cross-border transfers include:
- Your explicit authorization.
- Involvement of overseas service providers in marketing activities.
- Your proactive actions (e.g., booking international hotels/flights through the DaoTrip Platform that involve overseas suppliers).
- Legal or regulatory mandates.
Unless exempt under consent exceptions (see Section I), we will seek your separate consent through reasonable methods for cross-border transfers beyond the above scenarios. Regardless of consent requirements, we will clearly inform you about:
- Domestic/overseas service providers involved.
- Purpose, methods, and categories of data processing.
- For example, when ordering overseas products/services, this information will be disclosed on the order entry or confirmation page, and your separate consent will be sought if required.
Legal Compliance:
- We will fulfill obligations such as security assessments, personal information protection certifications, and executing standard contracts with overseas recipients as prescribed by authorities.
- Overseas entities must maintain confidentiality and uphold equivalent data protection obligations.
(B) Retention Period
We retain your information only for the shortest period necessary to fulfill the purposes outlined in this Policy or as required by laws and regulations. Our criteria for determining retention periods include:
- Achieving transaction-related purposes.
- Maintaining transaction and business records to address potential inquiries or complaints.
- Ensuring service security and quality.
- Complying with statutes of limitations.
- Adhering to legal retention requirements or specific agreements.
After exceeding the retention period, or upon your request to delete data or close your account, we will delete or anonymize your personal information.
Exceptions for Extended Retention:
We may adjust retention periods under the following circumstances:
- Legal Compliance: To meet statutory obligations (e.g., the E-Commerce Law mandates retaining product/service and transaction records for at least three years from the transaction date).
- Judicial Requirements: To comply with court judgments, rulings, or legal proceedings.
- Government or Regulatory Requests: To fulfill demands from authorized governmental or regulatory bodies.
- Public or Individual Interests: To safeguard public interests or protect the safety, property, or legal rights of DidaTravel Platform users, our company, affiliated entities, employees, or other stakeholders.
(C) Cessation of Operations
If we cease operations of the DidaTravel Platform or its services:
- We will immediately halt further collection of your personal information.
- Notify you via individual notifications or public announcements.
- Securely delete or anonymize all retained personal information.
V. How We Protect the Security of Your Personal Information
- DidaTravel attaches great importance to information security and has set up a dedicated team responsible for the supervision of personal information processing activities and protection measures taken. We strive to provide you with information protection, take appropriate management, technical and physical security measures, with reference to domestic and foreign information security standards and best practices to establish an information security assurance system suitable for business development, has obtained ISO27001 information security management system standard certification, PCI-DSS payment card industry data security standard certification..
- From the perspective of data life cycle, we have established security protection measures in various aspects of data collection, storage, display, processing, use, destruction, etc., and adopted different control measures according to the level of information sensitivity. This includes but is not limited to access control, SSL encrypted transmission, encrypted storage using an AES256bit or higher encryption algorithm, and desensitized display of sensitive information.
- We also strictly manage employees who may have access to your information, monitor their operations, establish an approval mechanism for data access, internal and external transmission and use, desensitization, decryption and other important operations, and sign confidentiality agreements with the above employees. At the same time, we also regularly conduct information security training for employees, requiring them to form good operating habits in their daily work and enhance their awareness of data protection.
- Despite the aforementioned security measures, please understand that there are no "perfect security measures" on the network. We will provide appropriate security measures according to existing technology to protect your information, provide reasonable security, we will do our best to ensure that your information is not leaked, damaged or lost.
- Your account has a security protection function. Please keep the device you use to log in to the DidaTravel Platform, as well as your account name and password information, and do not provide the device to others for logging in to the DidaTravel Platform or inform others of your password. If you find your personal information leaked, especially your account name and password leaked, please contact our customer service immediately. So that we can take corresponding measures.
- please save or back up your text, pictures and other information in a timely manner, you need to understand and accept that your access to our services in the system and communication network, there may be problems due to factors beyond our control.
- When using the service of Tao Travel Platform for online transactions, please properly protect your personal information (including but not limited to the traveler's name, contact information or contact address), and only provide it to others when necessary. Please use a complex password to help us keep your account secure. We will do our best to ensure the security of any information you send us. In order to prevent unauthorized use of your password or use of your computer, mobile device or SIM card, if you find that your personal information, especially your account or password, has been leaked, please contact our customer service immediately so that we can verify and take appropriate measures according to your application.
- In the event of an unfortunate personal information security incident, we will inform you in accordance with the requirements of laws and regulations: the basic situation and possible impact of the security incident, the disposal measures we have taken or will take, the suggestions you can independently prevent and reduce risks, and the remedial measures for you. We will inform you by email, letter, telephone, push notification, etc. When it is difficult to inform the personal information subject one by one, we will take a reasonable and effective way to release the announcement. At the same time, we will also report the disposal of personal information security incidents in accordance with the requirements of the regulatory authorities.
VI. How We Protect Minors’ Personal Information
1. DidaTravel attaches great importance to the protection of minors' personal information. If you are a minor under the age of 18, you should obtain the prior consent of your legal guardian before using our services. We protect the personal information and privacy of minors in accordance with the requirements of the Law of the People's Republic of China on the Protection of Minors and other relevant national laws and regulations.
2. No Direct Collection from Minors
DidaTravel。does not actively or directly collect personal information from minors. For information collected with guardian consent, we will use, share, transfer, or disclose such data only when:
- Permitted by laws and regulations.
- Necessary to protect the minor’s interests.
- Explicit guardian consent is obtained
3. Children Under 14
For personal information of children under the age of 14, we adhere to the principles of legitimacy, necessity, informed consent, purpose limitation, and security, in compliance with the Regulations on the Cyber Protection of Children’s Personal Information and other applicable laws.
Guardian Responsibilities:
- When using DidaTravel Platform services for a child under your guardianship, we may collect the child’s information as necessary to fulfill the service.
- Failure to provide such information will result in inability to access related services.
- Guardians must fulfill their responsibilities diligently to ensure the child’s information security.
4. Feedback and Complaints
For questions, suggestions, or complaints regarding children’s personal information, please contact us using the methods outlined in [Section VIII: How to Contact Us] of this Policy.
VII. Policy Revisions and Notifications
We may update this Personal Information Protection Policy as necessary. Please note that we reserve the right to amend this Policy periodically, with the latest revision date clearly indicated. Revisions will take effect after being published. We will not diminish your rights under this Policy without your explicit consent. For material changes, we will provide prominent notice (e.g., email notifications detailing specific revisions for certain services). We encourage you to review this Policy regularly to stay informed of updates.
Material changes include, but are not limited to:
1. Significant changes to our service model, such as:
- Purposes of processing personal information.
- Types of personal information processed.
- Methods of using personal information.
2. Major changes in ownership or organizational structure, such as:
- Business restructuring.
- Changes in ownership due to bankruptcy, mergers, or acquisitions.
3. Changes to primary recipients of personal information sharing, transfers, or public disclosures.
4. Material changes to your rights regarding personal information processing and how to exercise them.
5. Changes to the department responsible for personal information security, contact details, or complaint channels.
6. High-risk findings identified in a personal information security impact assessment report.
VIII. How to Contact Us
1. For any questions, feedback, or suggestions regarding personal information protection or privacy, please contact DidaTravel ’s client service at [+86-13986004209]. If you disagree with any terms of this Policy, you may choose to discontinue access to the Platform. Continued use will be deemed as your acknowledgement, acceptance, and binding agreement to this Policy.
Company Name: Shenzhen DidaTravel Technology Co., Ltd.
Registered Address: Room 1005-01, Aokangde Group, No. 2010, Shennan East Road, Chengdong Community, Dongmen Street, Luohu District, Shenzhen
2. We have established a dedicated Personal Information Protection Department. You may reach our Head of Personal Information Protection via email at [james@dida.com].
- We generally respond within 5 business days after verifying your identity and related information.
个人信息保护政策
发布日期:2025年 月 日
生效时间:2025年 月 日
引言
欢迎您访问道旅平台!深圳市道旅旅游科技股份有限公司(以下简称“道旅科技”)作为一家以科技驱动的旅游分销服务商,致力于用科技手段链接供应端和需求端。道旅科技通过一站式的采购平台及行业领先的信息技术,为全球超过23,000家旅游买家提供来自全球的旅游资源。
道旅(以下也称“我们”)深知个人信息对您的重要性,因此我们非常重视保护您的隐私和个人信息。我们将按照法律法规要求并通过《道旅个人信息保护政策》(以下简称“本政策”)向您说明我们在您使用道旅平台的产品/服务时如何处理您的个人信息,以及我们为您提供的访问、更新、删除和保护这些信息的方式。
【特别提示】在您使用道旅平台的产品/服务之前,请您务必仔细阅读、充分理解本政策,特别是以字体加粗的条款,您应当重点阅读,在确认充分理解并同意后开始使用道旅平台的产品/服务。如果您或您的监护人(如果您是未成年人)不同意本政策的任何内容,您将无法登录,即您将无法使用道旅平台的产品/服务。如对本政策内容有任何疑问、意见或建议,您可通过本政策第【八】条提供的联系方式与我们联系。
请您特别注意本政策的适用范围:
1、本政策适用于道旅平台提供的所有产品和服务。如我们的产品/服务中使用了道旅平台提供的产品/服务但未设独立个人信息保护政策的,则该部分产品/服务同样适用于本政策。如我们的产品/服务已设独立个人信息保护政策的,则独立的个人信息保护政策优先适用,该等独立的个人信息保护政策中未提及而本政策有约定的内容,适用本政策。
2.本政策不适用于道旅平台的产品/服务中包含的或链接至第三方提供的信息/服务(包括任何第三方应用、网站等),该等信息/服务由第三方负责运营,须遵循该第三方的个人信息保护政策或类似规定。
第一部分 定义
1.道旅平台:域名为didatravel.com及dida.com为主的网页及客户端(包括微信小程),客户端适用的终端设备包括但不限于PC、平板电脑、手机等。
2.道旅/我们:包括道旅平台的开发者和运营者深圳市道旅旅游科技股份有限公司(注册地址为深圳市罗湖区东门街道城东社区深南东路2010号奥康德集团1005-01室)。
3、关联公司:深圳市道旅旅游科技股份有限公司旗下所有公司及其附属、关联公司,包括但不限于深圳市幸游国际旅行社有限公司、深圳市友道旅游有限公司、贴心(深圳)旅行社有限公司,浙江幸游旅游服务有限公司、道旅国际有限公司、DidaTravel Technology Singapore Pte.Ltd.等。
4、用户/您:指访问或使用道旅平台所提供的产品/服务的自然人或法人,包括但不限于注册用户及未注册用户。
5、个人信息:以电子或者其他方式记录的与已识别或者可识别的自然人有关的各种信息。
6、敏感个人信息:一旦泄露、非法提供或滥用可能危害人身和财产安全,极易导致个人名誉、身心健康受到损害或歧视性待遇等的个人信息。本政策中涉及的敏感个人信息包括生物识别、宗教信仰、特定身份、医疗健康、金融账户、行踪轨迹等信息,以及不满十四周岁未成年人的个人信息。
7、个人信息删除:在实现日常业务功能所涉及的系统中去除个人信息的行为,使其保持不可被检索、访问的状态。
8、儿童:不满十四周岁的未成年人。
9.未成年人:不满十八周岁的自然人为未成年人。十六周岁以上的未成年人,以自己的劳动收入为主要生活来源的,视为完全民事行为能力人。
第二部分 个人信息保护政策
本政策将帮助您了解以下内容:
一、我们如何收集和使用您的个人信息
二、我们如何使用Cookie
三、我们如何共享、转移、委托处理和公开披露您的个人信息
四、我们如何存储和跨境传输您的个人信息
五、我们如何保护您的个人信息安全
六、我们如何保护未成年人的个人信息
七、本政策的修订和通知
八、如何联系我们
一、我们如何收集和使用您的个人信息
在您使用我们的产品/服务时,您需要/可以选择授权我们收集和使用个人信息的情形包括:
1、为了向您提供我们产品/服务的基本功能,您需要授权我们收集、使用必要信息的情形。如您拒绝提供前述必要信息,您将无法正常使用我们的产品/服务;
2、为了向您提供我们产品/服务的附加功能,您可以选择授权我们收集、使用信息的情形。如您拒绝提供前述信息,您将无法正常使用相关附加功能或无法实现我们拟达到的功能效果,但并不会影响您正常使用我们产品/服务的基本功能。
请您注意,因我们向您提供的产品和服务种类众多,我们将根据您选择使用的具体产品/服务范围,遵循“合理、正当、必要”原则收集和使用您的个人信息。除此之外,您理解并同意,基于向您提供更好的产品和服务的目的,我们可能会不时推出新的或优化后的功能,可能增加或变更收集和使用个人信息的目的、范围和方式。对此,我们将通过更新本政策、弹窗或站内信等通知方式另行向您说明收集和使用对应信息的目的、范围和方式,并为您提供同意与否的选项,且在征得您的明示同意后收集、使用对应信息。在此过程中,如您有任何疑问、意见或建议,您可通过本政策第【八】条提供的联系方式与我们联系。
(一)为您提供搜索、浏览功能
通常情况下,您可以在同意隐私政策后且已登录状态下在道旅平台上搜索和浏览各类产品。
在您同意本政策后,为保障搜索、浏览功能的实现,我们会收集您在网页输入的搜索关键字、您点击的页面或链接以便在道旅平台的服务端向您返回相应的页面或结果。此外,为实现前述目的,我们也会收集您的日志信息。
请您注意,单独的日志信息或仅搜索关键词信息无法单独识别您的身份,不属于您的个人信息,只有当您的单独的日志信息或搜索关键词信息与您的其他信息相互结合使用并可以识别您的身份时;则在结合使用期间,我们会将您的日志信息或搜索关键词信息作为您的个人信息,按照本政策对其进行处理与保护。
(二)帮助您注册与管理道旅账户
若您想使用道旅平台的产品/服务,您首先需要您的雇主注册一个道旅账户成为道旅平台用户。我们将基于您雇主提供的企业名称、员工姓名、手机号、邮箱来完成账户注册。
在注册过程中为了保障您的账户安全,我们会向您的注册邮箱发送验证信息以验证注册或登录。在登录过程中,我们会依据您选择的登录方式来向您的注册手机号码发送验证信息或向您的注册邮箱发送验证信息,以保障您的登录安全。
当您在道旅平台中进行授信额度、取消订单、积分兑换、充值、付款或其他与金钱操作相关的行为时,为了保障您的账户安全,我们会向您的手机号码发送验证码以验证是否为您的操作。当您查询或修改账户信息时(如:在主账号下创建子账号、主账号修改子账号信息、删除子账号等行为),为了保障您的账户安全,我们会向您的手机号码发送验证码以验证是否为您的操作。如您拒绝提供对应信息请联系您的雇主,您将无法在道旅平台创建账户并使用道旅平台的产品/服务。
(三)为您提供产品/服务信息的展示、推荐与推送
1.为您提供产品及服务
在向您提供产品和服务时,需要使用到您或产品/服务实际使用者的个人信息,提供酒店产品时,通常我们需要收集入住人的姓名、国籍,酒店端为了确认入住信息还会要求收集入住人的电话号码、护照号或其他证件号码;为了协助入住人确定房型及完成预定和入住,在涉及携带儿童入住时酒店会要求收集儿童的姓名和年龄。提供机票产品时,我们需要收集乘机人的姓名、证件类型及证件号码、手机号码,必要时还需要提供电子邮箱。
请注意,道旅科技提供旅游产品的分销服务,道旅科技非旅游产品的最终提供方,因此我们也可能通过业务合作伙伴、关联公司等第三方提供产品或服务,因此我们可能也会与供应商、第三方支付金融机构、业务合作伙伴、相关关联公司共享收集到的信息。
2.市场调研与营销活动
为了更好地向您提供产品或服务,我们可能会向您所提供的电子邮件地址定期发送有关新产品、特别优惠或其他我们认为您可能会感兴趣的信息。我们亦会不定期通过您所提供的联系方式邀请您参与市场调研,以充分了解您对我们的产品及服务的兴趣及意见。
(四)为您提供收藏功能
在您使用道旅平台的产品/服务过程中,您可以选择对感兴趣的酒店进行收藏,我们至少需要收集您在收藏过程中产生的日志信息,用于实现上述功能以及其他我们明确告知的目的。
(五)为您提供订单查询及账户管理功能
当您准备订购道旅平台的产品/服务时,道旅平台系统会生成您订购该产品/服务的订单。在下单和订单管理过程中,我们可能会收集如下信息:
(1)您所选择的不同产品/服务所要求提供的信息;
(2)您的联系人姓名、手机号;
(3)您在使用道旅平台的产品/服务过程中产生的订单信息。
我们收集这些信息是为了帮助您确定交易、支付结算、获得通知、帮助您查询和管理订单信息,以及提供客服与售后服务; 我们还会使用您的订单信息来判断您的交易是否存在异常,以保护您的交易安全。
因旅行产品/服务的特殊性,您所选择的以下产品/服务,需要您进一步提交必要的信息才能完成预订,这些信息您需要自行填写,或者授权我们以其他方式帮助您完成信息录入,我们同时也提请您在具体预订过程中予以关注:
(1)当您预订境内外机票时,视不同的服务类型,您可能需要提供不同的信息类型。当您预订境内机票时,您至少需要提供乘客姓名、证件类型、证件号、手机号信息。当您预订境外机票时,您至少需要提供乘客姓名(含拼音)、性别、国籍、出生日期、证件类型、证件号、证件有效期以及联系人手机号信息,视产品不同还可能需要您提供联系人邮箱信息。
(2)当您预订酒店时,您至少需要提供入住人姓名、手机号信息;视产品不同可能还需要您提供证件号、邮箱信息。
(3)当您预订接送机、包车服务时,您提供乘车人的姓名、联系电话或邮箱;为了确保接送机的准确性与及时性,您可能需要提供乘车人航班号码;为了确保包车服务的准确性与及时性,您可能需要提供乘车人的出行日期。
(4)当您的出行人中包含未成年人时,我们需要您作为监护人或在取得监护人的同意下提供出行的未成年人的姓名、证件类型、证件号。
(5)当您使用绑定银行卡服务时,您需要提供姓名、银行卡号、手机号、证件类型、证件号。
其他需要您进一步提供必要信息才能完成产品/服务的预订的,具体以预订流程中的展示、提示或授权内容为准,请注意仔细阅读。
(六)帮助您完成支付
您通过道旅平台购买的产品需要进行支付结算时,视服务的不同,第三方支付平台需要收集相应的信息以便于您的订单能够顺利完成支付。当您使用境外银行卡时,基于您选择的不同的支付机构的要求,我们可能会收集您的账单地址信息(包括国家、联系地址、邮箱)。
(七)帮助向您完成产品/服务的交付
为向您完成产品/服务的交付,我们在此过程中至少需要收集和使用您的订单信息以保证您的订购的产品/服务能够安全完成交付。
若您有积分可在积分商城使用电子兑换券或邮寄(发票、商品)服务的,您至少需要提供产品/服务的使用人或收件人的电话号码、邮箱地址。如积分兑换为实体商品时,可能需要收件人的收件地址、收件手机号码、收件人称谓,以便您的发票、产品/服务能够兑换或送达。
如卡券类线上兑换的,则需要您的手机号码。
若您就订购的产品/服务需要开具纸质或电子发票的,我们至少需要收集发票抬头、邮箱在内的开票信息以及上述配送信息。
(八)与您取得联系
我们可能会因为订单或其他产品及服务问题通过网站、电子邮件、电话或信件的方式与您取得联系或反馈相关问题。
(九)为您提供客户服务与处理争议
1、为保证您的账户安全,我们的电话客服和在线客服会使用您的用户信息和订单信息,以验证您的身份。当您主动要求我们提供与您订单相关的客户服务时,我们可能会查询您的相关订单信息以便给予您适当的帮助和处理。如您主动要求客服协助您修改有关信息(如配送地址、联系人或联系电话),您可能还需要提供上述信息外的其他信息以便完成修改
2、当您与我们联系时,我们可能会保存与您的通信/通话记录和内容,或您留下的联系方式及相关信息,以便与您联系或帮助您解决问题,或记录相关问题的处理方案及结果。
3、为了保障您的信息安全、交易安全及服务质量,处理未来可能的争议,当您联系我们的客服咨询时,我们可能会保存与您之间的通话记录和内容。上述通话记录和内容在法律规定的最短必要存储时间后会自动删除,除非由于合规要求或合法利益需要而保留。此外,受网络状态、通话环境、政策法规等因素的影响,不排除会出现录音/存储失败的情形。
4、如果您针对我们的服务或具体订单进行咨询、投诉或提供建议的,为便于厘清事实、解决争议,我们会使用您的账户信息、订单信息、相关订单的页面操作记录,并在法律允许的范围内提供给行政监管部门、司法部门和我们的诉讼代理人。
(十)改进道旅平台的产品/服务
我们可能会使用您的信息进行去标识化地研究、统计分析和预测,用于改善道旅平台的内容和布局,为商业决策提供产品或服务支撑,以及改进我们的产品和服务。
(十一)收集和使用您的个人信息的特别说明
1、若您提供的信息中含有其他用户的个人信息,例如,您通过道旅平台为他人订购产品/服务时需要提交实际订购人的个人信息,或您通过道旅平台主动上传、发布或共享的信息中涉及其他用户的个人信息的,在前述情形下,在向道旅平台提供这些个人信息之前,您须确保您已经取得本人的同意,并确保其已知晓并接受本政策。若其中涉及儿童个人信息的,您需要事先取得对应儿童监护人的同意。
2、除非符合征得授权同意的例外情形(见本政策“一、我们如何收集和使用您的个人信息”),否则我们将会按照法律法规及国家标准的要求,针对某些场景下的敏感个人信息的处理,通过合理的方式征得您的单独同意。具体单独同意方式,以具体的功能页面显示为准。您理解并知晓,如果非适当地处理敏感个人信息,可能导致您的人格尊严受到侵害或者人身、财产安全受到危害。我们会在保证信息可用性的基础上尽量去标识化处理,以保障您的敏感个人信息安全。
3、若我们将信息用于本政策未载明的其他用途,或者将基于特定目的收集而来的信息用于其他目的,均会重新获得您的授权同意。
4、我们可能从为您提供服务的关联公司、业务合作伙伴等第三方处获得其所收集的您的相关信息。例如,您通过我们关联公司、业务合作伙伴网站及其移动应用软件等预订时,您向其提供的预订信息可能会转交给我们,以便我们处理您的订单,确保您顺利预订。我们将依据与第三方的约定,在收集前要求第三方说明您的个人信息来源,并对这些个人信息来源的合法合规性进行确认,了解第三方所收集您的个人信息的授权同意范围。如果我们收集和使用您的信息的目的,超出了第三方已获得的授权范围,我们会自行或要求该第三方另行征得您的同意后再处理您的个人信息。
5、征得授权同意的例外
您充分知晓,根据法律法规要求,以下情形中我们收集、使用您的个人信息无需征得您的授权同意:
为履行道旅法定职责或者法定义务所必需;
与国家安全、国防安全有关的;
与公共安全、公共卫生、重大公共利益有关的;
与犯罪侦查、起诉、审判和判决执行等有关的;
为订立、履行您作为一方当事人的合同所必需;
在紧急状况下,出于维护您或其他个人的生命健康和财产安全;
所收集的个人信息是个人信息主体自行向社会公众公开的或其他已经合法公开的个人信息;
从合法公开披露的信息中收集的您的个人信息的,如合法的新闻报道、政府信息公开等渠道;
为公共利益实施新闻报道、舆论监督等行为,在合理的范围内处理个人信息;
法律法规以及国家标准规定的其他情形。
请知悉,根据适用的法律,若我们对个人信息采取技术措施和其他必要措施进行处理,使得数据接收方无法重新识别特定个人且不能复原,则此类处理后数据的使用无需另行向您通知并征得您的同意。
二、我们如何使用Cookie
为了让您获得更轻松便捷的访问体验,您访问道旅平台或使用我们提供的服务时,我们可能会在您的设备终端或系统上存储名为Cookie的小型数据文件用来识别您的身份,这样可以帮您省去重复输入注册信息的步骤,帮您优化对广告的选择与互动及其帮助判断您的账户安全状态。您可以清除计算机或移动设备上保存的所有Cookie,您有权接受或拒绝Cookie,如果浏览器自动接受Cookie,您可以根据自己的需要修改浏览器的设置以拒绝Cookie。请注意,如果您选择拒绝Cookie,那么您可能无法更好地体验我们提供的服务。
如您想进一步了解Cookie使用情况,详见《Cookie政策》。
三、我们如何共享、转移、委托处理和公开披露您的个人信息
(一)共享与提供
1、处理原则
我们可能会向合作伙伴等第三方共享您的订单信息、账户信息、设备信息以及位置信息,以保障为您提供的服务顺利完成。但我们仅会出于合法、正当、必要、特定、诚信、明确的目的共享您的个人信息,并且只会共享提供服务所必要的个人信息。我们将评估第三方收集您的个人信息的合法性、正当性、必要性,同时,要求第三方在您的授权同意范围内处理您的个人信息,采取必要的信息管理措施与技术手段,防止您的个人信息发生泄露、损毁、丢失、篡改等后果。第三方无权将所共享的您的个人信息用于任何其他用途,如要改变个人信息的处理目的、处理方式的,将重新您的授权同意。
2、单独同意
除非符合征得授权同意的例外情形(见本政策“一、我们如何收集和使用您的个人信息”),否则我们将会按照法律法规及国家标准的要求,针对除前述情形之外的某些场景下的个人信息的共享与提供,采取合理的方式另外征得您的单独同意。但不论是否需要征得您的单独同意,我们均会以合理的方式向您明示告知具体向您提供所涉产品/服务的第三方供应商信息及其处理您个人信息的目的、方式和种类,例如,在您准备订购部分道旅平台的产品/服务时,我们可能会在您下单前通过订单填写页面或订单确认页面向您明示告知上述信息,并在必要时征得您授权道旅向供应商或服务商提供您的个人信息的单独同意。具体的单独同意形式,请以具体产品/服务订单页面为准。
3、我们的合作伙伴包括以下类型(包含中国境内和中国境外实体):
(1)您的雇主:您的雇主作为道旅的客户,我们将基于您的雇主与道旅的合同及您的雇主的相应需求提供必要的个人信息给您的雇主及其授权的个人,用于实现对账、数据统计等目的。
(2)供应商:包括但不限于为了满足您预订需求的酒店、航空公司、汽车租赁、旅行社、景区和活动提供商和代理商,我们将向供应商共享个人基本资料、个人身份信息、联系人信息。这些供应商可能根据需要与您联系,以完成旅行产品或服务。
(3) 金融机构和第三方支付机构:当您预订订单、申请退款时,我们会与金融机构或第三方支付机构共享特定的订单信息,当我们认为用于欺诈检测和预防目的实属必要时,我们将进一步和相关金融机构共享其他必要信息,如IP地址等。
(4) 业务合作伙伴:我们可能与合作伙伴一起为您提供产品或者服务,将向合作伙伴共享相关个人信息,用于包括快递业务、通讯服务、客户服务、市场推广、技术服务、实名认证服务、咨询服务。例如,为向您提供服务信息之目的,我们会向短信服务商提供您的手机号及拟推送的信息内容。
(5)关联公司:我们可能会与我们的关联公司共享您的相关个人信息,使我们能够向您提供与旅行相关的或者其他产品或服务,他们会采取不低于本政策同等严格的保护措施。
请您注意,基于业务合作伙伴和关联公司防范和检测欺诈的目的,我们可能也会审慎地提供您的必要个人信息,这些个人信息的提供会经过严格的内部安全评估和审批并通过签署相应的协议限定这些信息的使用目的。
5、根据法律法规的规定、诉讼争议解决需要、您与我们签署的相关协议(包括在线签署的电子协议及平台规则)或法律文件,或行政、司法等有权机关依法提出要求时,我们可能会共享您的个人信息。
6.除了上述说明或法律法规另有规定外,我们如果对其他任何公司、组织和个人共享您的个人信息,会依法再次征求您的授权。
(二)信息转移
我们不会将您的个人信息转移给任何公司、组织和个人,但以下情况除外:
(1)事先获得您的明确同意或授权;
(2)根据适用的法律法规、法律程序的要求、强制性的行政或司法要求;
(3)在涉及合并、分立、收购、资产转让或类似的交易时,如涉及到个人信息转移,我们会在正式进行信息转移前,向您告知接收信息公司、组织的名称和联系方式,并要求新的持有您个人信息的公司、组织继续受本政策的约束,继续履行原先由我们承担的个人信息处理义务。否则,我们将要求该公司、组织重新向您征求授权同意。
(三)委托处理
为了提升信息处理效率,降低信息处理成本或提高信息处理准确性,我们可能会委托有专业技术能力的关联公司或道旅以外的外部服务供应商处理您的个人信息。我们会与受托方签署委托处理协议,并要求受托方按照委托处理协议、本政策以及其他任何相关的保密和安全措施来处理个人信息。委托关系不生效、无效或被撤销或者终止时,我们会要求受托方返还、删除您的个人信息(包括但不限于因委托处理获取到的原始信息或副本、摘要等),不得保留。未经您的授权同意,我们禁止受托方转委托他人处理您的个人信息。
(四)公开披露
我们仅会在以下情形,公开披露您的个人信息:
(1)根据您的需求,在您单独同意的前提下,根据您认可的披露方式下披露您所指定的个人信息;
(2)根据法律、法规的要求、强制性的行政执法或司法要求所必须提供您个人信息的情况下,我们可能会依据所要求的个人信息类型和披露方式披露您的个人信息。在符合法律法规的前提下,当我们收到上述披露信息的请求时,我们会要求必须出具与之相应的法律文件,如传票或调查函。
四、我们如何存储您的个人信息
(一)存储地点
1、处理原则
我们会按照法律法规规定,将中华人民共和国境内收集的用户个人信息存储于中国境内。
2、跨境传输
如果您的个人信息存储地点从中国境内转移到境外的,我们将严格依照法律的规定执行。
需要将您的个人信息传输至境外的场景包括:
(1)获得您的明确授权;
(2)当营销场景涉及到境外服务提供商时;
(3)当您通过道旅平台进行跨境交易(如预订境外酒店,预订境外机票涉及境外供应商提供服务时)等个人主动行为;
(4)法律法规的明确要求。
除非符合征得授权同意的例外情形(见本政策“一、我们如何收集和使用您的个人信息”),否则我们将会按照法律法规及国家标准的要求,针对除前述情形之外的个人信息跨境传输情形,采取合理的方式另外征得您的单独同意。但不论是否需要征得您的单独同意,我们均会以合理的方式向您明示告知所涉产品/服务的境内外服务商信息及其处理您个人信息的目的、方式和种类,例如,在您准备订购道旅平台的部分境外产品/服务时,我们将会在您下单前通过订单填写页面或订单确认页面向您明示告知上述信息,并在必要时就道旅向境外供应商提供您的个人信息征得您的单独同意。具体的单独同意形式,以具体产品/服务订购页面为准。
我们将按照法律、行政法规和国家网信主管部门规定(如履行安全评估义务、个人信息保护认证、按照主管部门制定的标准合同与境外接收方签订协议)条件执行,并要求境外机构对所获得的您的个人信息保密并履行相应的个人信息保护义务。
(二)存储期限
我们仅在本政策所述目的所必需且最短的期间内,或法律法规要求的时限内保留您的信息。我们判断个人信息的存储期限主要参考以下标准:实现与您相关的交易目的、维护相应交易及业务记录,以应对您可能的查询或投诉;保证我们为您提供服务的安全和质量;根据诉讼时效的相关需要;是否存在关于保留期限的法律规定或其他特别约定。在超出上述存储期限后,或在您行使个人信息删除权、注销账户的情况下,我们会对您的个人信息进行删除或匿名化处理。
但在下列情况下,我们可能调整个人信息的保留时间:
(1)为遵守适用的法律法规等有关规定(例如:《电子商务法》规定:商品和服务信息、交易信息保存时间自交易完成之日起不少于三年);
(2)为遵守法院判决、裁定或其他法律程序的规定;
(3)为遵守相关政府机关或法定授权组织的要求;
(4)为维护社会公共利益,为保护道旅平台的用户、我们或我们的关联公司、其他用户或雇员的人身财产安全或其他合法权益所合理必需的用途。
(三)停止运营
如我们停止运营道旅平台产品或服务,我们将及时停止继续收集您个人信息的活动,将停止运营的通知以逐一送达或公告的形式通知您,对所持有的个人信息进行删除或匿名化处理。
五、我们如何保护您的个人信息安全
1、道旅非常重视信息安全,成立了专门的负责团队,负责对个人信息处理活动以及采取的保护措施进行监督。我们努力为您提供信息保护,采取了合适的管理、技术以及物理安全措施,参照国内外信息安全标准及最佳实践建立了与业务发展相适应的信息安全保障体系,已获得ISO27001信息安全管理体系标准认证、PCI-DSS支付卡行业数据安全标准认证。
2、我们从数据的生命周期角度出发,在数据收集、存储、显示、处理、使用、销毁等各个环节建立了安全防护措施,根据信息敏感程度的级别采取不同的控制措施,包括但不限于访问控制、SSL加密传输、AES256bit或以上强度的加密算法进行加密存储、敏感信息脱敏显示等。
3、我们对可能接触到您信息的员工也采取了严格管理,可监控他们的操作情况,对于数据访问、内外部传输使用、脱敏、解密等重要操作建立了审批机制,并与上述员工签署保密协议等。与此同时,我们还定期对员工进行信息安全培训,要求员工在日常工作中形成良好操作习惯,提升数据保护意识。
4、尽管有前述的安全措施,但同时也请您理解在网络上不存在“完善的安全措施”。我们会按现有的技术提供相应的安全措施来保护您的信息,提供合理的安全保障,我们将尽力做到使您的信息不被泄露、损毁或丢失。
5、您的账户均有安全保护功能,请妥善保管您用于登录道旅平台的设备以及您的账户名及密码信息,切勿将设备提供他人用于登录道旅平台或将密码告知他人,如果您发现自己的个人信息泄露,特别是您的账户名和密码发生泄露,请您立即与我们的客服联系,以便我们采取相应的措施。
6、请您及时保存或备份您的文字、图片等其他信息,您需理解并接受,您接入我们的服务所用的系统和通讯网络,有可能因我们可控范围外的因素而出现问题。
7、在使用道旅平台服务进行网上交易时,请您妥善保护自己的个人信息(包括但不限于出行人姓名、联络方式或联系地址),仅在必要的情形下向他人提供。请使用复杂密码,协助我们保证您的账户安全。我们将尽力保障您发送给我们的任何信息的安全性。为防止他人未经授权使用您的密码或使用您的计算机、移动设备或SIM卡,如您发现自己的个人信息尤其是您的账户或密码发生泄露,请您立即联络道旅平台客服,以便我们核实后根据您的申请采取相应措施。
8、在不幸发生个人信息安全事件后,我们将按照法律法规的要求向您告知:安全事件的基本情况和可能的影响、我们已采取或将要采取的处置措施、您可自主防范和降低风险的建议、对您的补救措施等。事件相关情况我们将以邮件、信函、电话、推送通知等方式告知您,难以逐一告知个人信息主体时,我们会采取合理、有效的方式发布公告。同时,我们还将按照监管部门要求,上报个人信息安全事件的处置情况。
六、我们如何保护未成年人的个人信息
1、道旅非常重视对未成年人个人信息的保护。若您是18周岁以下的未成年人,在使用我们的服务前,应事先取得您法定监护人的同意。我们根据《中华人民共和国未成年人保护法》等国家相关法律法规的要求对未成年人的个人信息及隐私进行保护。
2、道旅不会主动直接向未成年人收集其个人信息。对于经监护人同意而收集未成年人个人信息的情况,我们仅在法律法规允许、监护人同意或保护未成年人所必要的情况下使用、共享、转移或披露此类信息。
3、对于不满14周岁的儿童个人信息,我们还会遵循正当必要、知情同意、目的明确、安全保障、依法利用的原则,按照《儿童个人信息网络保护规定》等法律法规的要求进行收集、存储、使用、转移、披露等处理儿童个人信息。
当您作为监护人为被监护的儿童选择使用道旅平台相关旅行服务时,我们可能需要向您收集被监护的儿童个人信息,用于向您履行相关服务之必要。如果您不提供前述信息,您将无法享受我们提供的相关服务。您作为监护人应当正确履行监护职责,保护儿童个人信息安全。
5、如您对儿童个人信息相关事宜有任何意见、建议或投诉,请联系我们,具体联系方式详见本政策“八、如何联系我们”。
七、本政策的修订和通知
我们会在必要时修改个人信息保护政策,请您理解,我们可能会适时修订本政策,我们将标注本政策最近更新的日期,并经公示后生效。未经您明确同意,我们不会削减您按照本政策所应享有的权利。对于重大变更,我们还会提供更为显著的通知(包括对于某些服务,我们会通过电子邮件发送通知,说明个人信息保护政策的具体变更内容)。请您经常回访本政策,以阅读最新版本。本政策所指的重大变更包括但不限于:
1、我们的服务模式发生重大变化。如处理个人信息的目的、处理的个人信息类型、个人信息的使用方式等;
2、我们在所有权结构、组织架构等方面发生重大变化。如业务调整、破产并购等引起的所有者变更等;
3、个人信息共享、转移或公开披露的主要对象发生变化;
4、您参与个人信息处理方面的权利及其行使方式发生重大变化;
5、我们负责处理个人信息安全的责任部门、联络方式及投诉渠道发生变化时;
6、个人信息安全影响评估报告表明存在高风险时。
八、如何联系我们
1、如您有任何与个人信息保护或隐私保护相关的问题、意见或建议,您可以通过拨打【+86-13986004209】联系道旅客服与我们联系。如您不同意本个人信息保护政策中的任何条款,您可选择停止访问,否则将视为您知悉并同意本隐私政策,且愿意受其约束。
公司名称:深圳市道旅旅游科技股份有限公司
注册地址:深圳市罗湖区东门街道城东社区深南东路2010号奥康德集团1005-01室
2、我们还设立了个人信息保护专职部门,您可以发送邮件至我们个人信息保护负责人的邮箱james@didatravel.com与我们取得联系。