Privacy Policy
Last updated: 16 June, 2026
This policy explains how Archipelago collects, uses, stores and protects personal information, along with the rights individuals have over that information. It applies to the website, newsletter and any other digital services operated by Archipelago (together referred to as the "Services").
Archipelago is a UK-based travel publication and acts as the data controller for the personal information described here. This means responsibility for how that information is handled rests with Archipelago.
This policy is written to meet UK data protection law, including the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR), as amended by the Data (Use and Access) Act 2025.
1. Approach to personal data
It is worth being clear from the outset because many privacy policies are written for businesses that trade in personal data. Archipelago does not operate in that way.
Archipelago is funded primarily through affiliate links rather than advertising. Personal information is never sold or rented, advertising networks that profile users are not operated, and only the minimum amount of information reasonably required is collected.
In practice, this generally means an email address where a newsletter subscription is requested, a message where contact is initiated, and anonymous or aggregated information regarding how the site is used.
Where personal information is required, the purpose is explained clearly, a lawful basis is relied upon, and meaningful control is provided.
2. Who this policy covers
This policy applies to:
Visitors to the website
Newsletter subscribers
Archipelago+ members
Individuals who contact Archipelago, enter surveys or competitions, or participate in activities organised by Archipelago
Customers purchasing products or services, if these are offered in future
This policy does not apply to third-party websites or services linked from the Services but not controlled by Archipelago. When leaving the Services and visiting another site, that organisation's own privacy policy applies.
3. Information collected
Information provided directly
Most areas of the website can be used without providing personal information. Information is provided voluntarily in situations such as:
Subscribing to the newsletter (email address)
Contacting Archipelago (name, email address and information contained within a message)
Entering surveys, competitions or promotions
Subscribing to paid services or subscriptions
Depending on the interaction, this information may include names, email addresses and details necessary to fulfil purchases.
Payments are handled through secure third-party payment providers. Full card details are not stored by Archipelago.
Where information about another person is provided, appropriate permission should be obtained beforehand.
Information collected automatically
When the site is used, Archipelago and the services relied upon may collect certain technical information, including:
IP address
Browser type
Device type and operating system
Pages viewed and links clicked
Approximate location based on IP address
Most of this information is collected through cookies and similar technologies, which are explained further in the Cookie Policy.
Sensitive information
Sensitive personal information, including health information, race or ethnicity, political opinions, religious beliefs or criminal records, should not be submitted through the site.
This information is not requested and is generally unnecessary. If such information is shared voluntarily, for example within a message, this will be treated as consent for handling that information in order to respond.
Information from other sources
Information may occasionally be received from other sources, such as social media platforms where interactions take place. Any information obtained in this way is kept to a minimum and used only for the purposes described within this policy.
4. How information is used and lawful bases
Under UK data protection law, a lawful basis is required for processing personal information.
Information may be used for:
Sending newsletters where a subscription has been requested
Lawful basis: Consent, which can be withdrawn at any time.
Responding to messages and providing support
Lawful basis: Legitimate interests or taking steps requested by an individual.
Operating and improving the Services, including maintaining security, fixing issues and understanding usage patterns in aggregate
Lawful basis: Legitimate interests, together with consent for any non-essential analytics cookies where required.
Fulfilling purchases where products or services are offered
Lawful basis: Performance of a contract.
Running surveys, competitions and promotions
Lawful basis: Consent or performance of the terms relating to the promotion.
Meeting legal and regulatory obligations
Lawful basis: Compliance with legal obligations.
Where legitimate interests are relied upon, those interests are balanced against individual rights and expectations.
The right to object to processing based on legitimate interests remains available at any time.
5. Marketing and newsletters
Newsletters and marketing communications are only sent where requested.
Every marketing email includes an unsubscribe link, and subscriptions can be cancelled at any time through that link or by contacting Archipelago. Requests are actioned promptly.
Even where marketing communications are declined, essential communications may still need to be sent, such as service confirmations or important changes relating to a service being used.
6. Cookies and similar technologies
Cookies and similar technologies are used to operate the site, understand usage patterns in aggregate and support affiliate links that help fund the publication.
They are not used to build advertising profiles.
The Cookies Policy explains the types of cookies used and how preferences can be accepted, rejected or changed.
7. Sharing information
Personal information is never sold.
Information is shared only where necessary, including with:
Service providers supporting website hosting, email delivery, analytics and payment processing. These providers operate under instructions and are subject to confidentiality and data protection obligations.
Affiliate networks, where interactions through affiliate links are handled under the network's own privacy terms. Archipelago receives only anonymous or aggregated information regarding whether a referral resulted in a sale.
Authorities or professional advisers where required by law, to establish or defend legal rights, or to protect safety.
Buyers or successor organisations if Archipelago is sold or reorganised, in which case information would remain protected under equivalent safeguards.
Aggregated or anonymised information that can no longer identify individuals may also be shared.
8. Sending data outside the UK
Some service providers may operate outside the United Kingdom, often in the United States.
Where personal information is transferred internationally, approved safeguards are used, including UK adequacy regulations, the UK International Data Transfer Agreement or other lawful mechanisms.
9. Retention of information
Personal information is retained only for as long as necessary for the purposes set out in this policy before being deleted or anonymised.
Retention periods depend on the type of information and the reason it is held. For example, newsletter subscription information is retained until unsubscribing, while purchase records may need to be retained for legal, tax or accounting requirements.
10. Security
Appropriate technical and organisational measures are used to protect information against loss, misuse and unauthorised access. No website or system can ever be completely secure, but reasonable steps are taken to reduce risks and respond appropriately if issues arise.
11. Individual rights
Under UK data protection law, individuals have the right to:
Request a copy of personal information held
Request correction of inaccurate or incomplete information
Request deletion of information
Request restrictions on use
Object to processing based on legitimate interests and to direct marketing
Request transfer of information where applicable
Withdraw consent where consent is relied upon
Requests can be made through the Contact page.
Responses will be provided within legal timeframes, usually within one month, and there is generally no charge.
If concerns exist regarding the handling of information, Archipelago encourages those concerns to be raised directly so they can be addressed.
Complaints can also be submitted to the Information Commissioner's Office (ICO), the UK's data protection regulator.
12. Automated decisions
Decisions producing legal effects or similarly significant impacts are not made solely through automated processing.
13. Children
The Services are intended for adults planning travel and are not directed at children. Personal information from children under the age of 13 is not knowingly collected. Where information from a child is believed to have been provided, Archipelago should be contacted so it can be deleted.
14. Links and affiliate links to other sites
Articles may contain links to external websites, including affiliate links to booking sites, retailers and travel providers. Archipelago is not responsible for the privacy practices of those sites, and this policy does not apply to them. Further information regarding affiliate links can be found in the Affiliate Marketing Disclosure.
15. Changes to this policy
This policy may be updated when practices or legal requirements change. The "last updated" date shown at the top of the page always reflects the current version, and material changes affecting individuals will be highlighted clearly.
Change Log:
no changes yet
16. Contact and complaints
Questions, requests or concerns regarding personal information or this policy can be submitted by contacting Archipelago.
Concerns regarding handling of personal information are taken seriously and will be investigated appropriately.
If concerns cannot be resolved, complaints may also be submitted to the Information Commissioner's Office (ICO), the UK's data protection regulator.