1 Who We Are
Hop On Hop Off Bus Tickets Worldwide ("we", "us", "our") is a travel technology company that operates https://www.hopon-hopoff-bus-tickets.com/ — a booking platform helping travellers discover and book city sightseeing experiences, hop-on hop-off bus tours, and attraction tickets worldwide.
Registered address: 111 Dudley Road West, Tividale, Oldbury, England, B69 2HU , United Kingdom.
As a data controller under UK GDPR and EU GDPR, we are responsible for your personal data. If you have questions about this policy, contact our Data Protection Officer at help@activity-crest.com.
2 Data We Collect
Information you provide directly
- Name, email address, and password when you create an account
- Payment details — processed securely by Stripe (we never store card numbers or CVVs)
- Booking details: travel dates, passenger names, and special requirements
- Messages sent via contact forms, live chat, or email to our support team
- Reviews and ratings you submit for tours you have completed
Automatically collected data
- IP address, browser type, device type, and operating system
- Pages visited, time spent on pages, clicks, and referral source (how you found us)
- Cookie identifiers and session data (see Section 4)
- Approximate geolocation (country/city level, derived from IP address)
We never collect sensitive personal data (health, religion, political views, biometric data) and we never sell your personal data to third parties.
3 How We Use Your Data
We process your data only when we have a lawful basis — primarily contractual necessity, legitimate interest, or your consent. We use your data to:
- Process your tour bookings and deliver e-tickets to your inbox
- Manage your account and communicate about your reservations
- Provide customer support before, during, and after your trip
- Send booking confirmation, reminders, and post-trip review requests
- Personalise your experience (currency, language, saved tours)
- Send marketing emails and offers — only with your explicit consent, opt-out anytime
- Improve our platform via analytics and A/B testing
- Detect and prevent fraud and abuse
- Comply with legal obligations (accounting, anti-money-laundering)
4 Cookies
We use cookies and similar tracking technologies. You can manage your cookie preferences via our cookie banner at any time.
Essential cookies
Required for the site to function: session management, shopping cart, security tokens. These cannot be disabled.
Functional cookies
Remember your preferences: currency selection, language, and login status. Disabled by default — enabled when you adjust settings.
Analytics cookies
Google Analytics 4 (anonymised IP, no cross-site tracking). Helps us understand how people use the site so we can improve it. You may opt out via our cookie banner or the Google Analytics opt-out.
We never use advertising or retargeting cookies without your explicit consent.
5 Third-Party Services
We share the minimum necessary data with these GDPR-compliant partners to deliver our service:
- Ventrata, Prio, TourCMS, City Sightseeing — tour operators and ticketing platforms (booking fulfilment)
- Stripe — payment processing (card data is never stored by us)
- Google Analytics — anonymised site analytics
- Mailchimp — newsletter emails (opt-in only, unsubscribe anytime)
- Cloudways (AWS) — hosting infrastructure (EU data centres)
Each partner has signed a Data Processing Agreement (DPA) with us. We do not allow them to use your data for their own purposes.
6 Your Rights (GDPR / UK GDPR)
Under UK and EU data protection law, you have the following rights:
To exercise any right, email help@activity-crest.com. We respond within 30 days. You also have the right to lodge a complaint with the ICO (UK): ico.org.uk.
7 Data Retention
- Booking records: 7 years after the booking date (legal and tax obligations)
- Account data: deleted within 30 days of account closure on request
- Support messages: 2 years
- Marketing preferences: until you withdraw consent
- Analytics data: 26 months (Google Analytics default)
8 Security
We take data security seriously. Our measures include:
- All data in transit is encrypted using TLS 1.3
- All data at rest is encrypted using AES-256
- PCI-DSS Level 1 compliance for payment processing (via Stripe)
- Annual third-party security audits and penetration testing
- Multi-factor authentication for all staff with data access
- Automated breach detection and a 72-hour ICO breach notification process
9 Changes to This Policy
We may update this privacy policy from time to time. When we make material changes, we will notify you by email (if you have an account) and update the "Last updated" date at the top of this page. Continued use of our services after changes means you accept the updated policy.
10 Contact Us
For any privacy-related queries, concerns, or to exercise your rights:
- Email:help@activity-crest.com
- Response time: Within 30 days as required by GDPR