Privacy Policy

Last updated: June 3, 2026

Best Vacation Deals (“we,” “our,” or “us”) respects your privacy. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have under laws including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA). If you have any questions about this policy or your data, contact us at [email protected].

1. Who we are

Best Vacation Deals is an editorial publication operated by MV3 Marketing, located at 7283 NC Hwy 42 West, Suite 102-317, Raleigh, NC 27603, United States. We are the data controller for the personal information collected through bestvacationdeals.com and bestvacationdeals.com.

2. Information we collect

2.1 Information you provide directly

  • Newsletter signups: When you subscribe, we collect your email address and any optional fields (first name, travel preferences).
  • Contact form submissions: When you message us via the contact form, we collect your name, email address, and the contents of your message.
  • Partnership and press inquiries: Business contact details, company name, and any additional context you provide.

2.2 Information collected automatically

  • Log data: IP address, browser type and version, operating system, referring URL, pages viewed, and timestamps.
  • Cookies and similar technologies: See our Cookie Policy for a complete breakdown.
  • Analytics data: Aggregated, pseudonymized usage data via Google Analytics 4.
  • Affiliate click data: When you click an outbound affiliate link, our partners may receive a referrer tag, your IP address, and basic browser data so they can attribute the booking.

3. How we use your information

We use the information we collect to:

  • Send you deal alerts, newsletters, and editorial updates (only if you’ve subscribed)
  • Respond to your questions, partnership inquiries, or press requests
  • Improve the site, measure content performance, and understand reader interests
  • Detect fraud, abuse, and security threats
  • Comply with legal obligations
  • Enable affiliate attribution so partners can credit us for referred bookings

Legal bases (GDPR): consent (newsletter, marketing cookies), legitimate interest (analytics, site improvement, fraud prevention), and legal obligation (tax/compliance records).

4. Who we share information with

We do not sell your personal information. We share data only with the following categories of recipients:

  • Resend — our transactional and newsletter email provider. They process subscriber emails to send our messages.
  • Travel booking partners (Booking.com, Viator, GetYourGuide, Hotellook, Agoda, DiscoverCars, Stay22, and 90+ other affiliate partners) — when you click an outbound link, they may receive referral attribution data.
  • Google Analytics 4 — for aggregated traffic and engagement analytics, with IP anonymization enabled where required.
  • Cloudflare — our CDN and security provider; they process limited connection metadata to protect the site from abuse.
  • WP Engine — our hosting provider, which stores site data and server logs.
  • Legal and regulatory authorities — only when required by law or to enforce our rights.

Each of these providers is contractually bound to handle data securely and consistent with applicable law.

5. Cookies and tracking

We use four categories of cookies: strictly necessary, functional, analytics, and marketing/affiliate. You can control non-essential cookies via our consent banner, your browser settings, or by visiting the third party’s opt-out page (links provided in our Cookie Policy).

6. Data retention

We retain personal data only as long as needed for the purposes described above:

  • Newsletter subscriber data: until you unsubscribe, plus 30 days for record-keeping
  • Contact form messages: 24 months, then deleted
  • Analytics data: 14 months (GA4 default)
  • Server logs: 90 days
  • Legal/financial records: as required by U.S. law (typically 7 years)

7. International data transfers

We are based in the United States. If you access the site from the EU, UK, or other regions, your data will be transferred to and processed in the U.S. Where required, we rely on Standard Contractual Clauses (SCCs) and the EU-U.S. Data Privacy Framework to protect cross-border transfers.

8. Your rights

8.1 GDPR (EU/UK residents)

You have the right to access, correct, delete, restrict processing, or port your personal data; the right to object to processing based on legitimate interest; and the right to withdraw consent at any time. You may also lodge a complaint with your local data protection authority.

8.2 CCPA/CPRA (California residents)

California residents have the right to know what personal information we collect, to request deletion, to correct inaccurate information, to opt out of “sale” or “sharing” (we do not sell personal information), and to non-discrimination for exercising any of these rights.

8.3 How to exercise your rights

To make any rights request, email [email protected] with the subject line “Privacy Request.” We will verify your identity and respond within 30 days (45 days for CCPA requests; we may extend by an additional 45 days when reasonably necessary).

9. Children’s privacy

Best Vacation Deals is not directed to children under 13 (or under 16 in the EU/UK). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at [email protected] and we will delete it promptly.

10. Security

We use commercially reasonable administrative, technical, and physical safeguards to protect your information, including TLS encryption in transit, hardened hosting, access controls, and regular security review. No system is perfectly secure, however, and we cannot guarantee absolute security of data transmitted over the internet.

11. Do Not Track

Our site does not currently respond to “Do Not Track” browser signals, as there is no industry-standard interpretation. We do honor Global Privacy Control (GPC) signals where required by California law.

12. Third-party links

Our site contains links to third-party websites — most prominently our affiliate booking partners. We are not responsible for the privacy practices of those sites. We encourage you to read their privacy policies before providing any personal information.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top and, where appropriate, notify subscribers by email. Continued use of the site after changes take effect constitutes acceptance of the revised policy.

14. Marketing communications and your choices

If you subscribe to our newsletter, we will send you periodic emails containing curated travel deals, editorial picks, and occasional updates about Best Vacation Deals. Every marketing email we send includes a one-click unsubscribe link in the footer. Clicking it removes you from our list within 10 business days, as required by the U.S. CAN-SPAM Act of 2003. You may also email [email protected] with the subject line “Unsubscribe” to be removed manually.

We do not send unsolicited marketing email to addresses that have not opted in. We do not sell, rent, lease, or otherwise transfer email addresses to third parties for their own marketing purposes. Transactional emails (such as a response to a contact form submission) are not “marketing” under CAN-SPAM and are sent regardless of subscription status.

15. How our partners use your data

When you click an outbound affiliate link from our site, you leave Best Vacation Deals and arrive on a partner’s website (for example, Booking.com or Viator). At that point, the partner becomes the data controller for any information you provide them — name, payment details, travel preferences, identity documents, and so on. We never see, store, or process your payment information; all bookings happen entirely on partner sites under their privacy and security frameworks. Before completing a booking, we strongly encourage you to review the partner’s own privacy policy, terms of service, and cancellation policy.

The only data shared between our site and our affiliate partners is referral attribution — a small tag in the URL that tells the partner you arrived through Best Vacation Deals. This allows them to credit any subsequent booking back to us for commission purposes. It does not include any personally identifying information that you have provided to us.

16. Automated decision-making

We do not engage in automated decision-making that produces legal or similarly significant effects about you. We do not use algorithmic profiling to make decisions about access, pricing, or eligibility. Any personalization we apply to the site (for example, ordering deals by category) is non-individualized and does not depend on profiling personal data.

17. Notice for residents of Virginia, Colorado, Connecticut, Utah, and other U.S. state privacy laws

Residents of U.S. states with comprehensive consumer privacy laws — including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and others — have rights similar to those described under CCPA/CPRA: the right to access, correct, delete, and (in some states) opt out of targeted advertising and the sale of personal data. We treat all U.S. consumer rights requests under a uniform process; to exercise any such right, email [email protected] with the subject line “Privacy Request.”

18. Contact us

For any privacy questions, rights requests, or complaints:

Email: [email protected]
Mail: Best Vacation Deals — Privacy, c/o MV3 Marketing, 7283 NC Hwy 42 West, Suite 102-317, Raleigh, NC 27603, USA

We will respond to every legitimate request as quickly as possible — typically well inside the 30-day GDPR window and the 45-day CCPA window. If we ever need more time, we will tell you and explain why.