Traveloop
Last Updated: 19 August 2026
Traveloop (“we”, “us”, “our” or “the Platform”) operates the peer-to-peer secondary marketplace available at https://www.traveloopmarket.com. Traveloop enables users to safely list, transfer, buy and sell non-refundable travel bookings, hotel stays and yacht/boat charters under escrow protection.
Traveloop is the Data Controller within the meaning of Article 4(7) of Regulation (EU) 2016/679 (General Data Protection Regulation – “GDPR”) and is responsible for determining the purposes and means of the processing of personal data described in this Privacy Policy.
This Privacy Policy explains:
By creating an account, using the Platform or otherwise providing personal data to us, you acknowledge that you have read and understood this Privacy Policy.
We collect and process the following categories of personal data:
Important clarification: Traveloop does not collect, store or process raw credit-card or debit-card numbers, CVV codes or full cardholder data on its own servers. All payment-card processing, cardholder-data handling and escrow fund holding are performed exclusively by our payment-service provider, Stripe, Inc., acting as an independent Data Controller or Processor (as applicable) under its own privacy terms.
We do not intentionally collect special categories of personal data (Article 9 GDPR) except where a passport or ID document contains such data and is strictly necessary for a booking transfer; in that case processing is limited to the minimum required for the contractual purpose.
We engage the following carefully selected third-party service providers who act as Data Processors under Article 28 GDPR and process personal data solely on our documented instructions:
| Processor | Purpose | Location / Safeguards |
|---|---|---|
| Stripe, Inc. | Payment processing, KYC verification of sellers, escrow holding, automated payouts | United States – SCCs + additional safeguards |
| Supabase, Inc. | Database infrastructure, authentication and user-account services (EU-region hosting) | European Union |
| Resend, Inc. | Transactional email delivery and booking-status notifications | United States – SCCs |
| Google Analytics / PostHog | Aggregated, anonymised website analytics and product telemetry (only with consent) | United States / EU – SCCs + anonymisation |
We maintain written data-processing agreements with all Processors that impose the obligations required by Article 28 GDPR. A current list of subprocessors is available upon request at the contact details below.
We process personal data only where a valid legal basis exists:
Performance of a contract (Art. 6(1)(b)) – Facilitating the creation and management of listings, matching buyers and sellers, operating the escrow mechanism, executing booking transfers and communicating transaction status.
Compliance with a legal obligation (Art. 6(1)(c)) – Retention of tax, accounting, anti-money-laundering (AML) and dispute-related records as required under Greek and EU law.
Legitimate interests (Art. 6(1)(f)) – Ensuring platform security, preventing fraud, detecting abuse, maintaining system integrity and improving service reliability. We have balanced these interests against your rights and freedoms and concluded that they do not override them.
Consent (Art. 6(1)(a)) – Placement of non-essential analytical cookies and any voluntary profile customisation or marketing communications. Consent may be withdrawn at any time without affecting the lawfulness of processing based on consent before its withdrawal.
You have the following rights under the GDPR:
Right of access (Art. 15) – Obtain confirmation whether we process your personal data and receive a copy of that data.
Right to rectification (Art. 16) – Have inaccurate or incomplete personal data corrected without undue delay.
Right to erasure / “Right to be Forgotten” (Art. 17) – Request deletion of your personal data. You may exercise this right directly via the self-service “Delete Account” function available in your Profile Settings. Deletion will be completed without undue delay, subject only to any legally mandatory retention periods for financial, tax or dispute records.
Right to restriction of processing (Art. 18) – Request that we temporarily limit processing under the conditions set out in the GDPR.
Right to data portability (Art. 20) – Receive the personal data you have provided to us in a structured, commonly used and machine-readable format and transmit it to another controller.
Right to object (Art. 21) – Object at any time to processing based on legitimate interests (including profiling) or to direct marketing.
To exercise any of these rights, please contact us at the email address indicated in Section 8. We will respond within one month (extendable by two further months in complex cases) and will not charge a fee unless the request is manifestly unfounded or excessive.
You also have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects you (Art. 22). Traveloop does not currently take such fully automated decisions.
We implement appropriate technical and organisational measures in accordance with Article 32 GDPR, including:
Where personal data is transferred outside the European Economic Area (for example to Stripe or Resend in the United States), we rely on the European Commission’s Standard Contractual Clauses (SCCs) pursuant to Commission Implementing Decision (EU) 2021/914, supplemented by additional technical and organisational safeguards. You may obtain a copy of the relevant SCCs by contacting us.
We use cookies and similar technologies in accordance with the ePrivacy Directive and GDPR:
Strictly necessary cookies – Essential for authentication, session management, security and the core functioning of the Platform. These cookies do not require consent.
Analytical / performance cookies – Used (only after you give explicit consent via our cookie banner) to collect aggregated, anonymised statistics about Platform usage (Google Analytics / PostHog). You may withdraw consent at any time through the cookie-preference centre or your browser settings.
You can manage cookie preferences at any time via the cookie-settings link on the Platform or by adjusting your browser settings. Blocking strictly necessary cookies may impair the functionality of the service.
For any privacy-related requests, questions or complaints, please contact us at:
You also have the right to lodge a complaint with the competent supervisory authority. In Greece this is:
You may alternatively contact the supervisory authority of your habitual residence, place of work or place of the alleged infringement within the European Union.
Traveloop reserves the right to update this Privacy Policy from time to time to reflect changes in law, technology or our processing activities. Material changes will be notified via email or a prominent notice on the Platform. The “Last Updated” date at the top of this document indicates the most recent revision.
This Privacy Policy is governed by the laws of Greece and the applicable provisions of European Union law.