Privacy Policy — how Joymira handles your data
The honest version of what we collect, why we collect it, and what we never do with it. Written to be read by humans, not just lawyers. Last updated: September 2026.
What we collect (and what we don't)
Only what a trip needs — nothing more. Here's the full list.
Your details
- Name and how to reach you (phone, email)
- Traveller details for bookings — dates of birth, passport info where a booking legally needs it
- Dietary, mobility and accessibility needs you tell us about
Trip details
- Itinerary preferences, dates, budgets and destinations
- Booking history with us — so trip number two is easier
- Feedback and reviews you choose to share
What we never collect
We don't buy marketing lists, don't scrape social profiles, and don't ask for data a trip doesn't need. If a field on a form feels pointless, it's because it is — we removed it.
How your information gets used
Three purposes, and only three. No mystery fourth one.
Building your trip
Passing the necessary details to airlines, hotels, tour operators and venues so your booking actually exists when you arrive.
Talking to you
Confirmations, itinerary updates, the "your driver is outside" texts, and replies when you write to us. No newsletters unless you ask.
Legal bits
Invoices, tax records and anything regulators require us to keep — held for the legal minimum period, then deleted.
One thing we never do: sell or rent your details to anyone. Not partners, not advertisers, not "trusted third parties". Never.
Who actually sees your information
A short list, on purpose.
Our planners
The Joymira team working on your trip — all employed, all trained on data handling, all in the Waterloo office.
Trip partners
Hotels, airlines and operators strictly need-to-know — a hotel gets your name and dates, never your email history.
Service providers
Our booking software and payment processor — vetted, contract-bound, and unable to use your data for their own purposes.
When the law says so
Court orders and regulators — rare, always challenged when overbroad, always documented.
Storage & security
Where it lives
Encrypted booking systems hosted in Australia. Paper documents are rare, locked, and shredded on schedule.
How long we keep it
Active bookings: until the trip ends plus a short tail. Financial records: the 7 years the ATO requires. Enquiries that never became trips: 12 months, then gone.
If something goes wrong
A breach that could harm you gets reported to you and to the OAIC, fast and in plain English — that's the law, and we'd do it anyway.
Your rights — use them freely
See what we hold
Ask and we'll send you everything we have on file within 30 days. Free, no forms, no fuss.
Fix or delete it
Wrong detail? We'll correct it. Want it gone? We'll delete what we legally can and tell you exactly what we couldn't and why.
Complain
Unhappy with how we've handled things? Tell us first — and you always have the right to go to the OAIC (oaic.gov.au) directly.
Cookies, tracking and the privacy officer
Cookies
We use a small set of functional and analytics cookies — the full breakdown lives on our cookie policy page.
Privacy officer
Questions, requests or complaints go to our privacy officer via joymira@gmail.com — mark it "Privacy" and it lands on the right desk.
Changes to this policy
When this page changes, the date at the top changes with it. Big changes get emailed to travellers with active bookings — everyone else can check back here. Also see our terms of service.

Questions about your data?
Write to us marked "Privacy" and a human — our privacy officer, not a bot — will get back to you within a day.