Last updated: July 18, 2026
1. Who we are and the scope of this policy
SmartVision Limited Company, doing business as Galapagos Dream Travel ("Galapagos Dream Travel," "we," "us," or "our"), is a Virginia company located at 13800 Coppermine Rd, Herndon, VA 20171 USA. This policy applies to personal information handled through galapagosdreamtravel.com, our website assistant, contact and reservation inquiry forms, newsletter, and our related communications and booking-support services.
This policy does not govern a travel supplier's, payment processor's, or other third party's independent handling of information. Their own privacy notices apply when they determine how and why to use your information.
2. Information we collect
The information we collect depends on how you interact with us and may include:
- Contact and inquiry information: your name, email address, telephone or WhatsApp number, preferred contact method, travel window, party size, trip or cabin interests, and the contents of your message.
- Booking-support information: traveler names, ages, rooming preferences, itinerary choices, and information needed by a travel supplier to evaluate or fulfill a booking. If you voluntarily disclose mobility, health, accessibility, dietary, or religious requirements, we use that information only as needed to respond to your request and coordinate the requested arrangements.
- Newsletter information: your name, email address, signup source, page path, referring page, browser user-agent, subscription status, and unsubscribe preference.
- Website and device information: IP address, hashed network identifiers used for abuse prevention, browser and device information, referring page, page path, server logs, and information stored locally in your browser to remember selected trips, pricing data, or the current assistant session.
- Payment and transaction information: payer name, billing address, payment amount, transaction identifier, status, fraud-screening results, booking confirmations, invoices, and refunds. Complete card numbers and card security codes are sent directly to our payment processor and are not sent to or stored on our servers.
- Communications records: emails, call or message records, and related customer-service records when you communicate or book with us.
We collect information directly from you, automatically from your browser or device, from travel suppliers and other people included in your booking, and from service providers that help us operate the website and respond to requests. If you provide information about another person, you must have authority to do so and should make this policy available to them.
3. How and why we use information
We use personal information to:
- respond to inquiries, check trip and cabin availability, prepare quotes, and provide booking support;
- communicate with you and the travelers in your party about requested services, changes, payments, safety, and customer support;
- send promotional email when you subscribe, and record and honor unsubscribe requests;
- operate, secure, troubleshoot, and improve the website, forms, and assistant; prevent spam, fraud, and abuse; and maintain business records;
- comply with legal obligations, respond to lawful requests, enforce our agreements, and establish or defend legal claims; and
- create aggregated or de-identified information that does not reasonably identify you.
Where a law requires a legal basis for processing, we rely as appropriate on your request or our contract with you, our legitimate interests in operating and securing our business, your consent, and compliance with legal obligations. You may withdraw consent at any time, but withdrawal does not affect processing already completed or processing supported by another lawful basis.
4. How we disclose information
We may disclose the relevant information to the following categories of recipients:
- Travel suppliers and booking partners, such as cruise operators, local operators, hotels, transportation providers, insurers, and other principals needed to quote, reserve, or provide your requested arrangements. These parties may be located outside the United States and may use information under their own privacy notices.
- Technology and business service providers that host or support our website, database, forms, security, communications, and customer service. Our current providers include Supabase for database and server-function infrastructure, Cloudflare Turnstile for bot and abuse prevention, Resend for contact-form email notifications, OpenAI for the website assistant, and providers of web fonts and interface assets.
- Authorize.net, our payment processor, which receives card details directly from your browser and processes transaction and fraud-screening information under its own privacy and security obligations.
- Professional advisers and authorities, including lawyers, accountants, insurers, regulators, law enforcement, courts, customs, immigration, or other government bodies when reasonably necessary or legally required.
- Corporate transaction recipients in connection with an actual or proposed merger, financing, reorganization, sale of assets, or similar transaction, subject to appropriate confidentiality protections.
We do not sell personal information for money, and we do not use or share personal information for cross-context behavioral advertising. If those practices change, we will update this policy and provide any legally required choices before beginning them.
5. Payments
Online card payments are processed by Authorize.net. Card details are exchanged in your browser for a short-lived payment token and are sent directly to Authorize.net. Our payment function receives the token, payer and billing-address information, amount, transaction identifier, status, and fraud-screening results. Complete card numbers and card security codes are not sent to or stored on our servers.
Do not send card numbers, bank credentials, or security codes through our contact form, website assistant, email, text message, or WhatsApp.
6. Marketing communications
If you subscribe to our newsletter, we may send limited-time sales, new sailing dates, cabin releases, and related travel updates. You can unsubscribe at any time using the link in a marketing email or by contacting us. We may retain the minimum information needed to record and honor your opt-out. Even after you opt out of marketing, we may send non-promotional messages concerning an inquiry, booking, payment, safety issue, or other ongoing business relationship.
7. Cookies, measurement, local storage, and third-party resources
The site uses browser session storage, local storage, and IndexedDB for necessary or functional purposes, such as keeping selected expedition details, caching public trip data, applying usage limits, and preserving the current assistant conversation in your browser. Cloudflare Turnstile may use cookies or similar signals to distinguish people from automated traffic. The site also requests fonts from Google Fonts and interface assets from unpkg; those providers receive technical request information such as your IP address and browser details when your browser connects to them.
If Google measurement is configured and you select "Allow analytics," the site uses Google Analytics and Google Ads conversion measurement to understand visits, contact requests, calls initiated from the site, cart activity, and completed payments. Google may receive the page URL, browser and device information, interaction details, conversion value, and an advertising click identifier when one is present. Advertising personalization is disabled. If you continue without analytics, analytics and advertising storage remain denied.
Your measurement choice is saved in local storage so the site can respect it on later visits. You can clear browser storage to reset that choice. Clearing other browser storage may also reset saved selections or prevent some features from working. Because we do not sell personal information or use it for cross-context behavioral advertising, we do not currently offer a separate "Do Not Sell or Share" link.
8. Website assistant
Our optional website assistant answers questions using information published on this website and current public trip data. When you submit a question, it is processed through our Supabase-hosted server function and OpenAI so that an answer can be generated and checked against the website sources. Please do not enter passport numbers, payment details, login credentials, phone numbers, email addresses, or other sensitive personal information in the assistant.
We do not use assistant conversations for marketing, visitor profiling, reservation follow-up, or our own model training. The current conversation is kept in your browser's session storage so that follow-up questions work and is cleared when that browser session ends or when you select "Clear conversation." Our application database does not store the raw question. A generated answer and its public sources may be cached without the raw question for up to 24 hours (or up to five minutes for live trip data), and limited operational records such as an anonymous request identifier, hashed network and session identifiers, response status, retrieval score, timing, model names, error codes, and token counts may be retained for up to 30 days for security, usage limits, abuse investigation, and reliability monitoring.
If the assistant cannot support an answer from the website, it will direct you to our contact form. Information entered on the contact form is handled under the other sections of this policy and is not automatically copied from the assistant unless you choose the contact link and submit the prefilled message.
9. Data retention
We retain personal information only for as long as reasonably necessary for the purposes described in this policy, including to respond to inquiries, administer bookings, honor marketing choices, maintain security, comply with tax, accounting, supplier, and other legal obligations, and resolve disputes. Retention periods vary by record type, the status of the inquiry or booking, supplier requirements, applicable limitation periods, and legal obligations. When information is no longer needed, we delete, de-identify, or securely dispose of it. Backup copies may remain for a limited period before being overwritten.
10. Security
We use reasonable administrative, technical, and organizational safeguards designed for the nature of the information we handle, including access controls and service providers that support encrypted transmission. No website, transmission, or storage system can be guaranteed completely secure. You are responsible for using secure communication methods and for not sending sensitive credentials through general-purpose forms or messages.
11. International data transfers
We are based in the United States, and our service providers and travel suppliers may process information in the United States, Ecuador, the destination country, or other countries whose privacy laws may differ from those where you live. Where required, we use appropriate contractual or other safeguards for international transfers. Information may also be transferred when necessary to perform the travel arrangements you request.
12. Children
Our website and online forms are intended for adults and are not directed to children under 13. We do not knowingly collect personal information online directly from a child under 13. A parent, legal guardian, or adult booking contact should provide information needed for a minor's travel. If you believe a child has submitted personal information directly to us without appropriate permission, contact us so we can review and delete it as required.
13. Your privacy choices and rights
Depending on where you live and the law that applies, you may have the right to request access to, correction of, deletion of, or a portable copy of personal information; to withdraw consent; to restrict or object to certain processing; and to opt out of certain sales, targeted advertising, or profiling. You may also have the right not to receive discriminatory treatment for exercising a privacy right and to appeal a decision we make about your request.
To make a request or appeal a decision, email reservation@galapagosdreamtravel.com with the subject line "Privacy Request," or write to: SmartVision Limited Company (DBA Galapagos Dream Travel), 13800 Coppermine Rd, Herndon, VA 20171 USA. Describe your request and the email address or phone number you used with us. We may need to verify your identity and authority before acting. Authorized agents may submit requests where permitted by law, but we may require proof of authorization. We will respond within the period required by applicable law. If we deny an appeal and applicable law provides a regulator complaint process, we will explain how to contact the relevant regulator.
You may unsubscribe from marketing email at any time using the unsubscribe link in the message. Rights are subject to legal exceptions, including where information must be retained to complete a requested transaction, protect security, comply with law, or establish or defend legal claims.
14. Changes to this policy and contact
We may update this policy to reflect changes in our services, providers, or legal obligations. We will post the revised policy here and update the date above. If required by law, we will provide additional notice or obtain consent before a material change takes effect.
For questions about this policy or our privacy practices, contact us at reservation@galapagosdreamtravel.com, call 571-645-5886, or write to the address above.