Legal

Privacy policy.

Last updated · 20 July 2026

How we collect, use, and protect your personal data when you contact us through this site.

This Privacy Policy explains how D'Bro Sri Lanka Travels ("we", "us", "our") collects, uses, and protects your personal data when you use our website at dbrosrilankatravels.com or contact us about a trip. We respect your privacy and are committed to protecting your data in line with the EU General Data Protection Regulation (GDPR) and the Sri Lankan Personal Data Protection Act (PDPA, 2022).

Who we are

D'Bro Sri Lanka Travels is a small private driver-guide service based in Sri Lanka. The data controller for any personal data submitted through this site is D'Bro Sri Lanka Travels. You can reach us at hello@dbrosrilankatravels.com.

What data we collect

We only collect personal data you actively give us — plus, if and only if you accept the analytics banner, the anonymous usage analytics described in the "Analytics" section below. There are no advertising pixels and no marketing cookies on this site.

When you submit an enquiry through the "Plan a trip" form, we collect:

  • Your name (optional)
  • Your email address (required)
  • Your phone or WhatsApp number (optional)
  • Number of travellers (optional)
  • Approximate travel dates (optional)
  • The tour you are interested in or your message (optional)
  • Your IP address and browser user-agent (collected automatically, used only for spam protection and abuse prevention)
  • The page you submitted the form from

Why we use your data

We use your data only to reply to your enquiry, plan your trip, and follow up if you book a tour. The lawful basis under GDPR is your consent (by submitting the form you ask us to contact you back) and our legitimate interest in running our business and responding to enquiries.

We do not send marketing emails, newsletters, or promotional content unless you explicitly opt in to them in a separate communication.

Where your data is stored and who processes it

Your data is stored and processed by the following sub-processors, all of whom offer GDPR-compliant Data Processing Agreements:

  • TiDB Cloud (PingCAP) — primary database, AWS Frankfurt, EU
  • Resend — sends us the enquiry notification email; based in the United States, transfers governed by Standard Contractual Clauses
  • Brevo — contact CRM, Paris, EU
  • Cloudflare — website CDN and edge security; data is served from the closest edge location to you
  • Fly.io — API server hosting, Frankfurt, EU
  • PostHog (EU Cloud) — opt-in usage analytics and session replay, hosted in the EU (Frankfurt). Only active if you accept the analytics banner
  • Microsoft (Clarity) — opt-in session recordings and heatmaps; transfers outside the EU are governed by Standard Contractual Clauses. Only active if you accept the analytics banner

How long we keep your data

We keep enquiry records for 2 years from the date of submission, then they are deleted, unless you have booked a tour with us — in which case we keep records for 7 years for tax and accounting purposes per Sri Lankan law.

If you do not wish for your enquiry to remain on file, just email us and we will delete it.

Cookies

By default we use only strictly necessary cookies required for the site to work and stay secure:

  • Cloudflare security cookies (__cf_bm, occasionally cf_clearance) — used by Cloudflare to distinguish humans from bots and protect against abuse

On top of that there are optional analytics cookies — but only if you accept the analytics banner. If you do, PostHog and Microsoft Clarity store small cookies/local-storage entries in your browser to recognise your session. If you decline — or never answer the banner — these are never set. We do not use marketing or tracking pixels, or third-party advertising cookies.

Your choice itself is remembered in your browser's local storage so we don't ask on every visit.

Analytics — only if you say yes

We'd like to understand which pages help travellers plan and where the site falls short. For that we use two analytics tools — both stay completely off (no scripts loaded, no cookies set, nothing collected) until you accept the analytics banner:

  • PostHog (EU Cloud) — pageviews, clicks, and enquiry-funnel events, plus session replay. Hosted in the EU (Frankfurt). Anything you type into forms is masked in replays — we never see it.
  • Microsoft Clarity — session recordings and heatmaps that show how pages are actually used.

We use this data only to improve the site. It is never used for advertising, never sold, and never joined with your enquiry details. The admin area and the chat page are excluded from analytics entirely.

You can withdraw your consent at any time — analytics stops and its cookies are removed:

The same banner can be reopened via the "Cookies" link in the footer of every page.

Your rights under GDPR

You have the right to:

  • Access — ask for a copy of the personal data we hold on you
  • Rectification — ask us to correct inaccurate data
  • Erasure — ask us to delete your data
  • Restriction — ask us to stop processing your data while we resolve a query
  • Portability — receive your data in a machine-readable format
  • Object to processing on grounds related to your particular situation
  • Lodge a complaint with your local supervisory authority — for example the Dutch Autoriteit Persoonsgegevens or the Belgian Gegevensbeschermingsautoriteit

To exercise any of these rights, email us at hello@dbrosrilankatravels.com. We will reply within 30 days as required by GDPR.

Children

Our service is intended for adults planning travel to Sri Lanka. We do not knowingly collect personal data from children under 16.

Changes to this policy

We may update this policy from time to time. The "last updated" date at the top reflects the most recent change. For material changes we will note it on this page.

Contact

For any privacy questions or to exercise your rights, contact us at hello@dbrosrilankatravels.com.

See also our Terms of service.