🌴
Jambo.Travel
Hello from Anywhere
Login
🌴Privacy policy

Your data, handled with care

We only collect what we need to book great stays for you — and we tell you exactly what happens to it. Here is the plain-English version, plus every GDPR detail our lawyers insist on.

Last updated 9 July 2026
  1. 1

    Who is responsible for your data

    The controller of your personal data is Goomla B.V., trading as Jambo.Travel, with registered office at P.J. Oudweg 5, Almere, the Netherlands (Chamber of Commerce 39101067, VAT NL818542366B01). References to "Jambo", "we", "our" or "us" in this policy mean Goomla B.V.

    For any privacy question, request or complaint you can reach us at hello@jambo.travel. We aim to reply within five working days and always within the one-month legal deadline set by the GDPR.

  2. 2

    Scope of this policy

    This policy applies to all personal data we process when you visit jambo.travel, create an account, search for hotels, make a booking, contact support, subscribe to marketing emails or otherwise interact with our services. It does not cover websites of third parties (for example the hotel you book) that have their own privacy notices.

  3. 3

    What data we collect

    We only collect what we need to run the service:

    • Account data — email address, password hash and, when you sign in with Google, your name and profile picture.
    • Booking data — guest names, dates of birth or ages of children, citizenship, contact email and phone, arrival and departure dates, hotel and room selection, pricing and any special requests you submit.
    • Payment data — card details are entered directly into our payment provider's hosted tokenization form and are never stored on Jambo systems. We keep only a transaction reference, the last four digits and card brand for reconciliation.
    • Communication data — the content of emails, chat or phone conversations you have with our support team.
    • Technical data — IP address, device and browser, approximate location derived from IP, language, currency and residency preferences, referral source and pages viewed.
    • Marketing preferences — whether you have opted in to newsletters and which emails you have opened or clicked.
  4. 4

    Why we use it and on what legal basis

    Under Article 6 of the GDPR, we process your personal data on one of the following bases:

    • Performance of a contract (Art. 6(1)(b)) — to run the search, take your booking, transmit it to the supplier and hotel, issue vouchers and invoices, handle changes, cancellations and refunds.
    • Legitimate interests (Art. 6(1)(f)) — to secure our platform against fraud and abuse, debug problems, improve the product, and send transactional service notifications (for example a check-in reminder or a price-change alert on a rate you already booked).
    • Consent (Art. 6(1)(a)) — for optional cookies, marketing newsletters and any use of your data beyond what is described here. You can withdraw consent at any time from the preferences link in every marketing email or from your account settings.
    • Legal obligation (Art. 6(1)(c)) — to comply with tax, accounting and anti-money-laundering rules.
  5. 5

    Who we share it with

    To deliver your booking we share the strictly necessary data with a limited group of recipients:

    • Emerging Travel Group (Ratehawk), our wholesale supplier, which forwards the booking to the accommodation.
    • The accommodation provider you selected, which receives your name, stay dates and any special requests.
    • Payment providers that process card payments and perform 3-D Secure authentication.
    • Infrastructure processors — hosting, database, email delivery, error monitoring and analytics — all bound by a data processing agreement.
    • Authorities where we are legally required to disclose information, for example on a valid court order.

    We do not sell your personal data, and we do not share it with advertisers.

  6. 6

    International transfers

    Some of our processors and hotel suppliers operate outside the European Economic Area. In those cases we rely on one of the transfer mechanisms recognised by the GDPR:

    • An adequacy decision issued by the European Commission for that country.
    • The European Commission's Standard Contractual Clauses (2021/914), combined with additional safeguards where a transfer impact assessment shows they are needed.

    A copy of the safeguards in place for a specific transfer is available on request at hello@jambo.travel.

  7. 7

    How long we keep your data

    • Booking and invoice records — 7 years after the stay, as required by Dutch tax law.
    • Account data — until you delete your account, or after 3 years of inactivity we invite you to reconfirm; without a reply we delete the account.
    • Support tickets — 3 years after closure.
    • Technical and security logs — up to 12 months, then aggregated or deleted.
    • Marketing data — until you unsubscribe or after 24 months of no engagement.
  8. 8

    How we protect your data

    We apply administrative, technical and physical safeguards proportionate to the risk, including:

    • TLS 1.2+ encryption in transit and encryption at rest for the production database and backups.
    • Role-based access, single sign-on and least-privilege for all employees, with access reviewed at least twice a year.
    • Hosted payment tokenization so full card numbers never touch our servers.
    • Continuous monitoring, rate limiting, secret rotation and a documented incident-response procedure. In case of a personal data breach we notify the Dutch Data Protection Authority within 72 hours where required, and affected users without undue delay.
  9. 9

    Your rights

    Under the GDPR you have the right to:

    • Access a copy of the personal data we hold about you.
    • Rectify data that is inaccurate or incomplete.
    • Erase your data ("right to be forgotten"), unless we have to keep it for legal reasons.
    • Restrict or object to processing based on legitimate interests, including for direct marketing.
    • Portability — receive your data in a machine-readable format or have it transmitted to another controller.
    • Withdraw consent at any time without affecting the lawfulness of prior processing.
    • Lodge a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl) or the supervisory authority in your country of residence.

    To exercise any right, email hello@jambo.travel. We may ask for reasonable identity verification before we act.

  10. 10

    Cookies and similar technologies

    We group cookies into three categories:

    • Strictly necessary — session, authentication and security. Always active; they cannot be switched off.
    • Functional — remember your currency, language and residency selection so search results are relevant.
    • Analytics and marketing — only set after you give explicit consent through the cookie banner. You can change your choice at any time via the "Cookie preferences" link in the footer.
  11. 11

    Children

    Jambo.Travel is not intended for children under 16. We do not knowingly create accounts for minors. Children can of course be listed as guests on a booking made by an adult; in that case we only process the ages that hotels require in order to price the stay correctly.

  12. 12

    Automated decisions and profiling

    We do not take decisions producing legal or similarly significant effects on you based solely on automated processing. Our fraud checks may flag a booking for manual review, but a human at Jambo makes the final decision before any booking is refused.

  13. 13

    Changes to this policy

    We may update this policy to reflect changes in our services or the law. When we make material changes we notify you by email or with a prominent notice in the app at least 14 days before they take effect. The version in force at the time of your booking applies to that booking.

Questions or a data request? Email hello@jambo.travel — we reply within five working days.