This policy explains what we collect, why we use it, who may receive it and the choices available to you.
We use the information you submit to handle your enquiry, prepare a quotation, communicate with you and, if you choose to proceed, arrange travel services.
ShiftUp UG (haftungsbeschränkt), trading as Rose Voyage, is responsible for the personal data processed through rosevoyage.de and rosevoyage.in. Address: Kolpingstraße 74, 52078 Aachen, Germany. For privacy requests, email iamkiran@rosevoyage.de or contact +91 81083 81308.
We process account, enquiry and booking data to take steps at your request, provide quotations, perform a booking contract and comply with tax, accounting and legal duties. We use limited security data for our legitimate interest in preventing abuse and protecting accounts. Service messages about an enquiry or booking are not marketing. Promotional email or future-offer marketing is sent only when you make a separate affirmative choice, and you can withdraw that choice from your dashboard or by contacting us.
To arrange travel services, we transfer relevant traveler information to operating airlines, consolidators, reservation systems, and payment providers. We only share information strictly required to facilitate your bookings and do not sell details to advertising networks.
We also use the following third-party services to run this website and process enquiries:
Website fonts are self-hosted on our own server and are not loaded from Google or any other third party, so no data is shared with anyone for that purpose.
Airlines and travel providers operate globally. Booking information may be transferred to destinations outside the European Economic Area where necessary to arrange the travel you request. Where service providers transfer data internationally, we use the provider's applicable transfer safeguards and contractual protections.
Some of the service providers listed in Section 4 above (Google, Meta) are based in or transfer data to the United States. Where this occurs, we rely on those providers' Standard Contractual Clauses or other GDPR-recognized safeguards for the transfer.
Unconverted enquiries are reviewed for deletion or anonymisation after 24 months. Expired website sessions are removed after seven days. Marketing contacts remain subscribed until consent is withdrawn; after withdrawal we keep a minimal suppression record so the choice is respected. Booking, payment and tax records may be retained for the statutory period, and passport data should be deleted or restricted when no longer needed for the booking or a legal claim.
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent without affecting earlier lawful processing. You may also complain to a competent data-protection authority. Contact iamkiran@rosevoyage.de; we may need to verify identity before acting.
Measures include HTTPS transport, salted password hashing with a server-held secret, expiring hashed session tokens, failed-login lockouts, owner checks on booking records, private file storage, restricted administrator credentials and an audit log. No website can promise absolute security; use a unique password and contact us promptly if you suspect misuse.
We use browser storage for the login session, region and language preference, referral attribution and consent choice. These entries support functions requested by the visitor. The optional live airport-search service activates only after the visitor accepts optional services; otherwise the built-in airport list is used. Clearing site data signs you out and removes local preferences.
Our concierge services are not intended for use by minors. We do not knowingly collect information from children under 18 unless provided by a parent or legal guardian to secure a family flight booking.
We may update this policy to reflect legal or operational changes. Material changes will be shown on this page. Last updated: 1 September 2026. For privacy inquiries, email iamkiran@rosevoyage.de.