Your information, handled thoughtfully

Privacy Policy

Travel planning is personal. This policy explains what information Ash Got Plans may collect, why it is needed, and how it is intended to be handled.

Last updated: 22 July 2026

Privacy by design

Personalized travel planning may involve information about where and when you plan to travel. Ash Got Plans aims to collect only what is reasonably needed, limit access to private travel materials, and build privacy protections into the client experience.

01

About this Privacy Policy

This Privacy Policy explains how Ash Got Plans collects, uses, stores, and shares personal information when you visit the website, submit a trip-planning inquiry, communicate with Ashley, purchase or use Ash Got Plans services, or access a personalized travel itinerary or private client travel portal.

Ash Got Plans is committed to collecting and using only the information reasonably needed to provide, protect, and improve its services.

02

Information You Provide

Depending on how you interact with Ash Got Plans, you may provide information including:

  • Your name
  • Your email address
  • Your phone number, if provided
  • Your destination and departure location
  • Your travel dates and date flexibility
  • The number of travelers in your group
  • Whether children are traveling, the number of children, and their ages at the time of travel
  • Your preferred planning package
  • Your trip type and travel style
  • Your interests and preferred pace
  • Your estimated trip budget
  • Your accommodation and transportation preferences
  • Details about reservations or bookings already made
  • Your travel goals, preferences, must-do activities, and dislikes
  • Dietary, accessibility, mobility, or other considerations that you choose to provide
  • How you heard about Ash Got Plans
  • Any other information you voluntarily include in a message or form

03

Information About Children

Ash Got Plans is intended for adults arranging travel and is not directed to children.

An adult customer may choose to provide limited information about children who will be part of a traveling party, such as the number of children and their ages. This information is used only to help create age-appropriate travel recommendations, pacing, activities, accommodation guidance, and transportation suggestions.

Please do not submit a child's full name, contact information, identification documents, medical records, school information, or other unnecessary personal information through the trip-planning questionnaire or general communications.

04

Sensitive or Special Information

Some travel-planning details you voluntarily provide may reveal information about health, mobility, accessibility, dietary needs, or similar personal circumstances.

Please provide only the information reasonably necessary for Ashley to plan the trip appropriately. Do not submit medical records, diagnoses, insurance records, passport numbers, government identification numbers, payment-card details, or other highly sensitive information through general website forms.

Where you voluntarily provide information about accessibility, mobility, dietary, or similar needs, Ash Got Plans will use it only as reasonably necessary to provide the requested planning service.

05

Private Client Itineraries and Travel Portals

Ash Got Plans may provide a personalized itinerary through a private online travel page or client travel portal created for a specific customer and the customer's intended traveling party.

Depending on the trip and the information provided by the customer, a private itinerary may contain the customer's name, travel destination, travel dates, accommodation or home-base information, scheduled activities, restaurant plans, transportation details, reservation information, confirmation references, provider contact details, booking links, map links, and other information relevant to the planned trip.

Ash Got Plans will use reasonable access controls and technical measures intended to limit access to private client itineraries. Customers should keep itinerary links, access codes, and other access credentials private and should share them only with members of their intended traveling party or another person they trust to assist with the trip.

Members of a traveling party who receive access from the customer may be able to view information included in the shared itinerary. The customer should consider the information visible in the itinerary before intentionally sharing access with another person.

Customers should not submit or request inclusion of passport numbers, government identification numbers, full payment-card information, medical records, or other unnecessary highly sensitive information in an online itinerary.

06

Downloaded Itineraries and Travel Documents

Ash Got Plans may provide downloadable itinerary PDFs, Quick Guides, Trip Command Centers, or other travel documents containing personalized trip information.

Once a customer downloads a travel document, a copy may be stored on the customer's phone, computer, tablet, cloud-storage account, email account, or another system selected or controlled by the customer. Ash Got Plans does not control the security settings of the customer's personal devices or third-party accounts.

Customers should take reasonable care when storing, forwarding, printing, or sharing personalized travel documents, particularly where the document includes travel dates, accommodation information, reservation references, or other trip-specific details.

07

How Information Is Used

Ash Got Plans may use personal information to:

  • Respond to trip-planning inquiries
  • Evaluate which planning package may be appropriate
  • Create personalized itineraries and recommendations
  • Create and operate private client travel pages
  • Generate personalized itinerary and Quick Guide documents
  • Manage access to private itinerary content
  • Communicate about a trip or planning service
  • Prepare quotes, invoices, and service information
  • Provide customer support
  • Maintain business and financial records
  • Improve website content and services
  • Prevent misuse, fraud, spam, or security issues
  • Comply with legal obligations

08

Legal Bases Where Applicable

Depending on the circumstances and applicable law, personal information may be processed because it is necessary to respond to your request, take steps before entering into a service agreement, perform a contract, comply with a legal obligation, pursue a legitimate business interest, or because you have provided consent.

Where consent is relied upon, you may withdraw that consent where permitted by law. Withdrawal does not affect processing that was lawful before consent was withdrawn.

09

How Information May Be Shared

Ash Got Plans does not sell personal information.

Personal information may be shared with service providers that help operate the business, such as providers for website hosting, form processing, email delivery, cloud storage, payment processing, invoicing, analytics, security, document generation, and other business functions.

Current providers include Resend for transactional email delivery, Google Workspace for business email, and Cloudflare for website security, traffic protection, and form-abuse prevention. These providers process information according to their roles in delivering and protecting the requested service.

Information may also be disclosed where reasonably necessary to comply with law, respond to valid legal process, protect rights or safety, investigate fraud or misuse, or complete a business reorganization or transfer.

10

Third-Party Travel Providers

Ash Got Plans may recommend or link to third-party websites, accommodations, airlines, restaurants, tour operators, transportation providers, or other travel services.

Private itineraries and travel documents may contain booking links, map links, phone numbers, addresses, or other information that allows a customer to interact directly with an independent travel provider.

If you choose to interact directly with a third party, that provider's own privacy policy and terms govern the information you provide to them.

Ash Got Plans does not control how independent third-party providers collect, use, or protect your personal information.

11

Website Data, Cookies and Access Security

The website may collect basic technical information needed to operate securely and reliably, such as browser type, device information, approximate location derived from an IP address, access times, pages visited, and diagnostic information.

Where private itinerary access is provided, Ash Got Plans may use security cookies or similar technical mechanisms to maintain an authorized session, reduce repeated access-code prompts, and protect private travel content. These mechanisms may be necessary for the requested service to function securely.

The trip-planning form uses Cloudflare Turnstile to distinguish legitimate submissions from automated abuse. Turnstile may process technical information about the browser, device, network, and form interaction for security purposes.

If Ash Got Plans later uses analytics, advertising, or non-essential cookies, this Privacy Policy and any required cookie notice or consent mechanism will be updated before those tools are enabled.

12

Payments

Ash Got Plans does not currently collect payment-card information through the trip-planning questionnaire.

If online payments are introduced, payment information will be processed through an appropriate third-party payment provider. Ash Got Plans does not intend to store full payment-card numbers on its own website systems.

This Privacy Policy will be updated to identify the applicable payment provider before online payments are accepted.

13

Data Retention and Itinerary Availability

Personal information will be retained only for as long as reasonably necessary for the purpose for which it was collected, including to provide services, respond to inquiries, maintain appropriate business and financial records, resolve disputes, and comply with legal obligations.

Private online itineraries may remain available during the planning process, before travel, during the trip, and for a reasonable period after the trip to support the customer and complete the service.

Ash Got Plans may later archive, restrict access to, or remove a private itinerary when continued online availability is no longer reasonably necessary. The retention period for underlying business records may differ from the period during which a client itinerary is available online.

Different categories of information may be retained for different periods depending on the nature of the information and the reason it is needed. More specific retention periods may be established as Ash Got Plans operational systems and service providers are finalized.

14

Data Security

Ash Got Plans uses reasonable administrative, technical, and organizational measures intended to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure.

Security measures for private travel content may include restricted itinerary access, access codes, server-side authorization checks, session controls, measures intended to discourage search-engine indexing, and restrictions on caching private responses.

No method of internet transmission or electronic storage can be guaranteed to be completely secure. Customers should avoid sending or requesting inclusion of unnecessary highly sensitive information and should protect access credentials and downloaded travel documents.

15

International Processing

Ash Got Plans may operate, communicate, or use service providers across more than one country. As a result, personal information may be processed or stored in a country different from the country where you live.

Where applicable law requires safeguards for international transfers of personal information, Ash Got Plans will take reasonable steps to use appropriate protections.

16

Your Privacy Rights

Depending on where you live and the law that applies, you may have rights relating to your personal information, including the right to request access, correction, deletion, restriction, portability, or objection to certain processing.

You may also have the right to withdraw consent where processing is based on consent and to lodge a complaint with an appropriate data protection or regulatory authority.

Ash Got Plans may need to verify your identity before completing a privacy request.

17

Marketing Communications

Ash Got Plans will not add you to promotional email marketing solely because you submit a trip-planning inquiry unless another lawful basis permits the communication.

Where marketing communications are offered, you will be given an appropriate way to unsubscribe from future promotional messages.

Service-related communications about an active inquiry, purchase, or trip may still be sent where necessary to provide the requested service.

18

Testimonials and Photographs

Ash Got Plans will not publish an identifiable testimonial, customer photograph, or personal travel content for marketing purposes without appropriate permission.

Customers may be asked separately whether they consent to the use of feedback, a first name, initials, trip information, location, or photographs in marketing materials.

19

Links to Other Websites

The Ash Got Plans website may contain links to third-party websites. Ash Got Plans is not responsible for the privacy practices or content of independent third-party websites.

You should review the privacy policy of any third-party service before providing personal information.

20

Changes to this Privacy Policy

Ash Got Plans may update this Privacy Policy as the website, services, technology providers, or legal requirements change.

The updated version will be posted on this page with a revised "Last updated" date.

21

Contact and Privacy Requests

Questions about this Privacy Policy or requests relating to personal information may be sent to:

hello@ashgotplans.com

Questions about your information?

You should know how your information is being used.

Contact Ash Got Plans with questions about this policy or a request relating to personal information.