Privacy Policy

Introduction

Welcome to Discover Sri Lanka. We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services.

By using our website, you agree to the collection and use of information in accordance with this Privacy Policy.

1. Information We Collect

1.1 Personal Information You Provide

When you submit an experience or interact with our website, we may collect:

Experience Submission Form:

  • Name (optional)
  • Email address (optional)
  • Phone number (optional)
  • Country of origin (required)
  • Driver/Guide/Travel company name (optional)
  • Your experience story
  • Photos and images you upload

Contact Forms:

  • Name
  • Email address
  • Message content
  • Any other information you choose to provide

1.2 Information from Third Parties

We may receive information about you from:

  • Social media platforms (if you interact with us there)
  • Analytics providers
  • Advertising partners

2. How We Use Your Information

We use the collected information for the following purposes:

2.1 To Provide Our Services

  • Display your submitted experiences on our website
  • Respond to your inquiries and support requests
  • Send you notifications about your submission status
  • Improve our website and user experience

2.2 To Communicate With You

  • Send approval notifications for submitted experiences
  • Respond to your questions and comments
  • Send updates about our website (if you opted in)
  • Contact you regarding featured stories or follow-ups

2.3 To Improve Our Services

  • Analyze website usage and trends
  • Conduct research and analytics
  • Develop new features and services
  • Enhance user experience and website performance

2.4 To Protect Our Rights

  • Prevent fraud and abuse
  • Enforce our Terms and Conditions
  • Comply with legal obligations
  • Protect the rights and safety of our users

3. Legal Basis for Processing (GDPR)

If you are in the European Economic Area (EEA), our legal basis for collecting and using your personal information includes:

  • Consent: You have given clear consent for us to process your personal information
  • Contract: Processing is necessary for a contract we have with you
  • Legal Obligation: Processing is necessary to comply with the law
  • Legitimate Interests: Processing is necessary for our legitimate interests

4. How We Share Your Information

4.1 Public Display

Approved Experience Submissions:
When your experience is approved and published, the following information becomes publicly visible:

  • Your name (if provided) or “Anonymous”
  • Your country
  • Your experience story
  • Images you uploaded
  • Guide/Driver/Company name (if provided)

NOT Publicly Displayed:

  • Your email address
  • Your phone number
  • Unapproved or pending submissions

4.2 Third-Party Service Providers

We may share your information with trusted third parties who assist us in operating our website:

  • Web hosting providers
  • Analytics services (e.g., Google Analytics)
  • Email service providers
  • Content delivery networks
  • Security services

These third parties are obligated to protect your information and use it only for the purposes we specify.

4.3 Legal Requirements

We may disclose your information if required by law or if we believe such action is necessary to:

  • Comply with legal processes or government requests
  • Enforce our Terms and Conditions
  • Protect our rights, property, or safety
  • Protect the rights, property, or safety of our users or the public

4.4 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

5. Cookies and Tracking Technologies

5.1 What Are Cookies?

Cookies are small text files stored on your device that help us improve your browsing experience.

5.2 Types of Cookies We Use

Essential Cookies:

  • Necessary for website functionality
  • Enable core features like security and accessibility
  • Cannot be disabled

Analytics Cookies:

  • Help us understand how visitors use our website
  • Provide statistics on website performance
  • Example: Google Analytics

Functional Cookies:

  • Remember your preferences and settings
  • Enhance user experience
  • Example: Language preferences

Advertising Cookies:

  • May be used to show relevant advertisements
  • Track effectiveness of marketing campaigns

5.3 Managing Cookies

You can control cookies through your browser settings:

  • Block all cookies
  • Delete existing cookies
  • Allow cookies from specific websites

Note: Disabling cookies may affect website functionality.


6. Data Security

We implement appropriate technical and organizational security measures to protect your personal information:

  • SSL/TLS encryption for data transmission
  • Secure servers and databases
  • Regular security updates and patches
  • Access controls and authentication
  • Regular security audits

However, no method of transmission over the Internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

7. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy:

  • Experience Submissions: Retained indefinitely while published on our website
  • Contact Inquiries: Retained for up to 2 years
  • Analytics Data: Typically retained for 26 months
  • Cookies: As specified in cookie settings

You can request deletion of your information at any time (see Your Rights section).

8. Your Rights

Depending on your location, you may have the following rights:

8.1 Access and Portability

  • Request a copy of your personal information
  • Receive your data in a portable format

8.2 Correction

  • Request correction of inaccurate information
  • Update your submitted information

8.3 Deletion

  • Request deletion of your personal information
  • “Right to be forgotten” (GDPR)

8.4 Objection

  • Object to processing of your information
  • Opt-out of marketing communications

8.5 Restriction

  • Request restriction of processing
  • Limit how we use your information

8.6 Withdraw Consent

  • Withdraw consent at any time
  • Does not affect previously processed information

To Exercise Your Rights:
Contact us at: [heshantha.l@gmail.com]

We will respond to your request within 30 days.

9. Children’s Privacy

Our website is not intended for children under 13 years of age (or 16 in the EEA).

We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately, and we will delete it.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your own. These countries may have different data protection laws.

We ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (EU)
  • Privacy Shield Framework (where applicable)
  • Other legally recognized transfer mechanisms

11. Third-Party Links

Our website may contain links to third-party websites. We are not responsible for the privacy practices of these websites. We encourage you to read their privacy policies.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated “Last Updated” date.

Significant changes will be notified through:

  • Prominent notice on our website
  • Email notification (if we have your email)

Your continued use of the website after changes constitutes acceptance of the updated Privacy Policy.

13. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:

Discover Sri Lanka
Email: [heshantha.l@gmail.com]

14. Dispute Resolution

If you have concerns about our privacy practices:

  1. Contact us first using the details above
  2. We will investigate and respond within 30 days
  3. If unsatisfied, you may file a complaint with your local data protection authority

EU Residents:
You have the right to lodge a complaint with your local supervisory authority.

15. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights:

  • Right to Know: What personal information we collect and how we use it
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt-out of the sale of personal information
  • Non-Discrimination: We will not discriminate against you for exercising your rights

Note: We do not sell personal information.

To exercise your California privacy rights, contact us at: [your-email@example.com]

Summary

We are committed to:

  • ✅ Transparency in data collection and use
  • ✅ Protecting your personal information
  • ✅ Respecting your privacy rights
  • ✅ Complying with applicable laws
  • ✅ Giving you control over your data

Thank you for trusting Discover Sri Lanka with your information.

This Privacy Policy is provided for informational purposes and should be reviewed by a legal professional before publication.