Privacy Policy
We hold money on behalf of people we have usually never met, so we hold as little about them as the job allows. This page says exactly what that is.
Contents
Who is responsible
The controller of the personal data described here is OnwardTrust S.a.r.l., Rue du puits Romain 33-39, 8070 Bertrange, Luxembourg. Full identifying details are on our legal notice.
For anything about your data, including any of the requests in section 11, write to help@onwardtrust.com.
This policy covers our website, the payment pages at onwardtrust.com/pay/ and the correspondence we exchange with you. It does not cover the travel agency you booked with, which decides for itself what to do with the data it holds and is a separate controller for that.
Where your data comes from
Most of what we hold about a traveller did not come from the traveller. It came from one of three places:
- From the agency, when it creates a payment: the traveller's name, email address, preferred language, the booking it relates to and the amount payable.
- From the bank, when a transfer arrives: the name on the sending account, its IBAN, the amount, the value date and the free-text reference line the sender wrote.
- From you, if you write to us, use the payment page, or send us evidence in support of a request or a dispute.
What we hold
- Identification and contact data — name, email address, and any postal address or telephone number you choose to give us in correspondence.
- Payment data — the payment reference, the amount, the currency, the state the payment is in, the times it changed state, and the bank details of the account the money came from.
- Booking data — the agency's own booking identifier, and, in the proof of issuance an agency submits, the ticket number and the passenger name for the booking.
- Correspondence — the messages you send us and our replies, including anything you attach.
- Technical data — our web server records the IP address, the request, the time and the browser identification string for each request, as almost every web server does. Separately, our own application logs record the processing of a payment, which includes its reference.
We do not ask for and do not want a card number, a card security code, an online banking password or a one-time code. We have no card acceptance of any kind, so there is no circumstance in which we would need one. If anybody asks you for these in our name, see section 9 of our Terms and Conditions.
Why, and on what legal basis
- To run the escrow: receiving the money, matching it to a booking, telling the agency it is held, and releasing or returning it
- Performance of a contract (Article 6(1)(b) of the GDPR), and our legitimate interest in performing the contract we have with the agency where the traveller is not directly our counterparty (Article 6(1)(f)).
- To tell you what is happening to your money
- Performance of a contract, and our legitimate interest in a traveller not being left uninformed about money they have sent (Article 6(1)(f)).
- To prevent, detect and investigate fraud, impersonation and misuse of the service
- Our legitimate interest, and the legitimate interest of every other user of the service, in a payment system that is not used to defraud people (Article 6(1)(f)).
- To meet our obligations against money laundering and terrorist financing, and to screen against sanctions
- Compliance with a legal obligation (Article 6(1)(c)).
- To keep accounting and tax records
- Compliance with a legal obligation (Article 6(1)(c)).
- To establish, exercise or defend legal claims, including in a dispute over a booking
- Our legitimate interest in being able to evidence what happened (Article 6(1)(f)), and compliance with a legal obligation where a court or authority requires it.
- To keep the service secure and available
- Our legitimate interest in operating the service safely (Article 6(1)(f)).
We do not sell personal data, we do not share it for anybody's marketing, and we do not send marketing email to travellers.
Where it is stored
Our servers are located in the European Union, and personal data described in this policy is stored there. We do not routinely transfer it outside the European Economic Area. If that ever changes, we will use a transfer mechanism recognised under Chapter V of the GDPR, such as the European Commission's standard contractual clauses, and we will say so here first.
How long we keep it
- The record of a payment, and its status page — 24 months from the date the payment was completed or returned, so that both sides of a booking can still consult the same record if something is questioned later.
- Accounting records, including the underlying transaction data — ten years, which is the period Luxembourg commercial law requires us to keep them for.
- Records kept to meet anti-money-laundering obligations — five years after the end of the business relationship or the transaction, as that legislation requires.
- Correspondence — 24 months, or longer where it relates to a dispute that is still open or to a legal claim.
- Web server request logs — 14 days.
- Application logs, which record the handling of a payment rather than a web request — 8 weeks.
Where two of these apply to the same data, the longer period governs, because we cannot delete something the law requires us to retain.
Automated decisions
No decision about your money is made automatically. Matching a transfer to a booking, verifying proof of issuance, releasing funds and returning funds are each decided by a member of our staff, and above a threshold a release requires a second person as well. There is no automated profiling and no decision producing legal effects that is taken without a human being.
How we protect it
Connections to this site and to the payment pages are encrypted in transit. Access to payment records is restricted to named members of staff, each with their own account, and the permission to release money is held by fewer people than the permission to read a record.
Every change to a payment is written to an append-only audit log recording what changed, when, and who caused it. That log cannot be edited or deleted by the people whose actions it records.
A payment page can be reached by anyone holding its address, which is how a traveller reaches it without registering. The address contains a long random reference that cannot be guessed or enumerated, and the page is excluded from search engines. Treat the link as you would treat the payment details themselves.
Your rights
Under the GDPR you may ask us to:
- give you a copy of the personal data we hold about you, and tell you what we do with it;
- correct anything that is wrong or incomplete;
- delete it, where we no longer have a reason to hold it;
- restrict what we do with it while a dispute about its accuracy or our grounds is resolved;
- give you, or another controller, a portable copy of the data you provided to us, where we hold it on the basis of a contract; and
- stop processing it where we rely on legitimate interests — we will do so unless we have grounds that override yours, and we will explain which.
Write to help@onwardtrust.com. We answer within one month. We may need to check who you are before we act, particularly where a request concerns money — we will ask for the least we can manage with.
Some of these rights have limits. We cannot delete a record we are required by law to keep, and we cannot restrict processing so far that we are unable to return money we are holding for you.
Complaining to the regulator
We would rather you told us first, at help@onwardtrust.com, so that we can put it right. You do not have to.
You may complain to the Luxembourg data protection authority, the Commission nationale pour la protection des données (CNPD), whose contact details are published at cnpd.lu. You may also complain to the supervisory authority of the country you live or work in.
Changes to this policy
The date at the top of this page is the date of the version you are reading. Where a change materially affects how we use data we already hold, we will tell affected people directly rather than relying on this page having been re-read.