Legal

VEYA Privacy Policy

How we collect, use and protect personal information.

Effective 10 June 2026
Privacy at a glance

VEYA uses personal information to provide membership, travel-booking and support services; process payments; administer VEYA Coins and benefits; keep the Platform secure; and send communications according to your choices. We do not sell mobile numbers or SMS consent information for third-party marketing.

1. About this Policy

This Privacy Policy explains how VEYA collects, uses, shares, stores and protects personal information when you visit veyaprive.com or related VEYA websites and applications, create or use an account, buy a membership, make or manage a booking, use VEYA Coins or member benefits, contact us, or receive communications from us (together, the “Services”).

The VEYA entity identified when you join, renew or book is the controller responsible for the relevant personal information. In this Policy, “VEYA”, “we”, “us” and “our” refer to that entity. Independent travel suppliers and benefit providers may also act as separate controllers under their own privacy notices.

This Policy should be read with the VEYA Terms & Conditions, the cookie controls presented on the Platform, and any booking-specific or benefit-provider privacy information.

2. How to contact us

For privacy questions or to exercise a privacy right, email membersupport@veyaprive.com with “Privacy Request” in the subject line. Active members may also use the contact channels shown after signing in. We may ask for information reasonably necessary to verify your identity and protect your account.

If a VEYA entity is required to appoint a data protection officer or representative, its details will be displayed on the Platform or provided in response to a privacy request.

3. Personal information we collect

The information we collect depends on how you interact with the Services. It may include:

  • Identity and contact information: name, title, date of birth where needed, postal address, email address, telephone number, country of residence and preferred language.
  • Account and membership information: login and verification information, membership tier, subscription and renewal status, membership history, preferences, saved travellers, benefits and VEYA Coin balance and transactions.
  • Traveller and booking information: traveller names, dates of birth, nationality, passport or travel-document details where required, itinerary, accommodation, transport, activities, accessibility or assistance requests, special requests, loyalty programme numbers and supplier communications.
  • Payment and transaction information: billing address, payment method, payment status, transaction identifiers, refunds and chargebacks. Payment-card details are normally collected and processed by authorised payment providers rather than stored directly by VEYA. Cryptocurrency transactions may include wallet addresses and public blockchain transaction information.
  • Communications and support information: emails, calls, live-chat or WhatsApp messages, survey responses, complaints, requests and other correspondence. Calls or chats may be recorded or monitored where permitted and disclosed.
  • Marketing and consent information: communication preferences, email and SMS opt-ins or opt-outs, consent records, promotion entries and engagement with messages.
  • Device, usage and technical information: IP address, device and browser type, operating system, identifiers, approximate location derived from IP, log-in activity, pages viewed, searches, clicks, referral source, session information, diagnostic data and cookie or similar-technology data.
  • Fraud, safety and compliance information: identity-verification results, risk indicators, suspected misuse, sanctions or legal-compliance checks where appropriate, and information needed to protect travellers, suppliers, VEYA and other users.
  • Information about other people: information you provide about another traveller, companion or beneficiary. You must be authorised to provide it and should make this Policy available to them.

4. How we obtain information

We collect information directly from you, automatically through the Platform, and from other sources. Other sources may include a person booking on your behalf; travel suppliers; payment, identity-verification and fraud-prevention providers; benefit and loyalty partners; customer-support and communications providers; analytics and advertising partners according to your cookie choices; public sources; and authorities where lawful.

If we receive your information from someone else, we provide privacy information as required by applicable law unless an exception applies.

5. How and why we use personal information

We use personal information only where we have an appropriate legal basis. The lawful basis depends on the activity and applicable law.

PurposeExamplesTypical lawful basis
Provide membership and bookingsCreate accounts; manage subscriptions, bookings, benefits and VEYA Coins; send confirmations; provide support.Contract; legitimate interests
Take payment and manage transactionsAuthorise payments; reconcile funds; process refunds; prevent chargebacks and accounting errors.Contract; legal obligation; legitimate interests
Personalise and improve ServicesRemember preferences; analyse use; test and improve features; develop products.Legitimate interests; consent where required
Security, fraud prevention and complianceVerify accounts; investigate misuse; protect systems; meet tax, accounting, sanctions and law-enforcement duties.Legal obligation; legitimate interests
Service communicationsSend booking, account, security, payment, membership and benefit messages.Contract; legitimate interests; legal obligation
Marketing and advertisingSend offers; measure campaigns; personalise advertising according to choices.Consent where required; legitimate interests where permitted
Claims and business administrationResolve disputes; enforce terms; audit; obtain professional advice; manage a sale or reorganisation.Legal obligation; legitimate interests

Where we rely on legitimate interests, those interests include operating and improving a secure travel-membership business, serving members, preventing fraud, protecting legal rights, and understanding service performance. We balance those interests against your rights and reasonable expectations. Where processing relies on consent, you may withdraw consent at any time without affecting earlier lawful processing.

6. Special-category and sensitive information

Some travel requests may reveal health, disability, dietary, religious or other sensitive information. Please provide only information needed for the requested service. Where required, we process it with explicit consent or another lawful condition, and share it only with relevant suppliers or providers. Passport, payment and authentication information is also treated with heightened care even where it is not legally classified as special-category data.

7. Who we share information with

We share personal information only as reasonably necessary for the purposes described in this Policy. Recipients may include:

  • airlines, hotels, property managers, cruise lines, car-hire companies, rail and transfer operators, tour and activity providers, and other travel suppliers needed to search, book or service travel;
  • membership-benefit, lounge, loyalty and reward partners when you activate or use a benefit;
  • payment processors, banks, card networks, cryptocurrency payment providers and fraud-prevention services;
  • cloud hosting, software, analytics, identity, cybersecurity, customer-support, communications, email and SMS providers acting for us;
  • professional advisers, auditors, insurers and corporate transaction parties subject to appropriate confidentiality;
  • regulators, courts, law-enforcement bodies, tax authorities and other parties where disclosure is required or permitted by law; and
  • another person or organisation at your direction or with your permission.

Independent suppliers determine how they use information needed to provide their services. Review their privacy notices before booking or activating a benefit. We do not sell mobile numbers or SMS opt-in or consent information, and we do not share it with third parties or affiliates for their own marketing or promotional purposes. SMS information may be provided to service providers solely to operate the messaging programme and meet legal requirements.

8. International transfers

VEYA provides global travel services. Your information may therefore be accessed, processed or stored in countries outside your home country, including where a travel supplier, technology provider or VEYA service operation is located. Privacy laws in those countries may differ.

Where UK or European data-transfer rules apply, we use an approved safeguard where required, such as an adequacy regulation or decision, approved contractual clauses together with the UK addendum or international data transfer agreement, or another lawful transfer mechanism. You may request further information about the safeguard relevant to your information.

9. How long we keep information

We retain personal information only for as long as reasonably necessary for the purpose collected, including providing Services, meeting legal, tax and accounting obligations, handling complaints, preventing fraud and establishing or defending legal claims. The precise period varies by record and jurisdiction.

Typical criteria include the life of the account or membership; completion of travel and support; applicable limitation periods; supplier and payment requirements; consent status; security needs; and mandatory record-keeping periods. We may retain a minimal suppression record after a marketing opt-out so that we continue to respect the choice. When information is no longer required, we delete, anonymise or securely isolate it in accordance with our retention procedures.

10. Cookies and similar technologies

The Platform uses cookies, pixels, local storage and similar technologies. Strictly necessary technologies support functions such as authentication, security, booking and preferences. With consent where required, analytics technologies help us understand performance, and advertising technologies help measure or personalise campaigns.

The cookie banner or preference centre describes the available categories and lets you accept, reject or change optional choices. Browser settings may also block cookies, but some Services may not work correctly. Third-party technologies are also subject to the provider’s privacy information. The preference centre identifies the cookies and providers currently in use.

11. Email, SMS and other communications

We send necessary service communications about membership, security, payments, bookings and requested benefits. These are not marketing and may continue while needed to provide the Services.

We send marketing email, SMS, WhatsApp or similar messages according to your choices and applicable law. You can use the unsubscribe link in an email, reply STOP to an SMS, adjust available account preferences, or contact us. Reply HELP to an SMS for assistance. Message frequency varies and carrier message or data rates may apply. Withdrawing marketing consent does not stop necessary service messages.

12. Advertising and analytics

Subject to your cookie choices, we may use analytics and advertising providers to understand use of the Platform, measure campaigns and show more relevant advertising. These providers may receive online identifiers, device information, IP address and interaction data. We do not describe data as “anonymous” merely because it does not include a name; online identifiers may still be personal information.

The Platform’s cookie preference centre identifies the active providers. We update our disclosures if the providers or technologies in use change.

13. Automated processing and profiling

VEYA and its providers may use automated tools to detect fraud, protect accounts, rank search results, recommend offers, personalise experiences or assess payment and security risk. Unless we tell you otherwise, VEYA does not make a decision based solely on automated processing that produces legal or similarly significant effects on you. If such processing is introduced, we will provide the information and safeguards required by applicable law, including any right to request human review.

14. Your privacy rights

Depending on where you live and the applicable law, you may have the right to:

  • receive information about how your personal information is used;
  • request access to your personal information and a copy of it;
  • correct inaccurate or incomplete information;
  • request deletion of information in certain circumstances;
  • restrict or object to certain processing, including a clear right to object to direct marketing;
  • receive certain information in a portable, machine-readable format;
  • withdraw consent at any time where processing relies on consent;
  • request safeguards relating to certain automated decisions; and
  • complain to the relevant data-protection authority.

To exercise a right, contact membersupport@veyaprive.com. We normally respond within the period required by applicable law. We may verify identity, clarify the request, or refuse or charge for a request only where the law permits. Rights are not absolute; for example, legal or security obligations may require us to retain some information. We will not discriminate against you for exercising an applicable privacy right.

15. UK and European complaints

Please contact VEYA first so we can try to resolve your concern. If UK data-protection law applies, you may complain to the UK Information Commissioner’s Office at ico.org.uk. If EU or EEA law applies, you may complain to the supervisory authority in the country where you live or work, or where you believe an infringement occurred. This does not affect any other legal remedy.

16. Security

We use appropriate technical and organisational measures designed to protect personal information. Measures may include encryption in transit, access controls, authentication, monitoring, secure development and vendor assessment. No system or transmission method is completely secure, and we cannot guarantee absolute security.

Keep account credentials confidential and contact us promptly if you suspect unauthorised access. If a personal-data breach occurs, we will assess it and notify affected people and authorities where required by law.

17. Children

VEYA membership and account registration are intended for adults aged 18 or over. We do not knowingly invite children to create accounts. A member may provide information about a child traveller when necessary for a booking and when authorised to do so. If you believe a child has provided personal information directly without appropriate authorisation, contact us.

18. Third-party websites and services

The Platform may link to independent websites, apps and services. Their operators control their own privacy practices. VEYA is not responsible for those practices, and this Policy does not govern information collected directly by them. Review their privacy notices before providing information.

19. Changes to this Policy

We may update this Policy to reflect changes in law, technology, providers or the Services. We will post the revised Policy with a new effective date and provide additional notice where required. If a new use requires consent, we will request it rather than treating continued use alone as consent. We encourage you to review this Policy periodically.

20. Contact and requests

Privacy requests, questions and complaints may be sent to membersupport@veyaprive.com with “Privacy Request” in the subject line. Current telephone, live-chat and WhatsApp details are available to active members through the Platform.