Skip to content
+373 79 611 511 Mon-Fri 9-18 · Sat 10-14
Privacy · last updated 1 January 2026

Privacy policy.

Find your holiday

Start here.

1. The data controller

VicTravel Prim SRL, office in Chisinau, Bd. Ștefan cel Mare 182, of. 227. DPO email: gdpr@victoriatravel.md. Phone: +373 79 611 511.

2. What data we collect

  • Identification data: surname, first name, date of birth, personal ID number, passport copy;
  • Contact data: phone, email, address;
  • Payment data: we don't store card details — all payments go through PCI-DSS certified processors;
  • Usage data: cookies, IP address, browser, device;
  • Optional data: dietary preferences, medical restrictions, account password.

3. Why we process it

  • To provide the services you've booked;
  • To process payment and issue fiscal documents;
  • To communicate before and after your trip;
  • To meet legal obligations (5-year retention);
  • Direct marketing, only with explicit consent.

4. Legal basis

Performance of the contract (GDPR art. 6.1.b), legal obligation (art. 6.1.c), explicit consent (art. 6.1.a — marketing), legitimate interest (art. 6.1.f — site security).

5. Who we share data with

  • Tour operators (Anex, Coral, TEZ, Pegas, Join Up and others) — to make the booking;
  • Airlines (FlyOne, Turkish Airlines and others) — to issue the ticket;
  • Hotels — for check-in;
  • Payment processors (Moldindconbank, Stripe) — for transactions;
  • Embassies & consulates — for visa applications;
  • Vercel (US hosting) — with safeguards under GDPR art. 46.

6. Your rights

You have the right to: (a) access, (b) rectification, (c) erasure, (d) restriction, (e) portability, (f) objection, (g) withdrawal of consent, (h) complaint to the CNPDCP. To exercise any of these, write to gdpr@victoriatravel.md — we reply within 30 days.

7. How long we keep it

  • Contract data: 5 years after completion;
  • User account: until deletion, plus a 6-month grace period;
  • Newsletter: until you unsubscribe;
  • Cookies: 24 months at most.

8. Data security

We use TLS 1.3, encryption at rest for the Supabase database, bcrypt password hashing, 2FA for administrators, audit logging, and regular GDPR training for staff.

9. Cookies

We use essential cookies, analytics cookies (anonymised GA4, Plausible) and marketing cookies (FB Pixel, Google Ads) — all with granular consent. Details: cookie policy.

10. International transfers

Some services (Vercel US, Resend US, the Cloudflare CDN) involve transfers outside the EU and Moldova. All of them have appropriate safeguards (GDPR Standard Contractual Clauses).

11. Complaints

To gdpr@victoriatravel.md or the CNPDCP in Moldova.

Before you go

Search real offers.