Privacy Policy

Privacy Policy. The World Travel Diary #twtd20 #theworldtraveldiary #instatravel #wanderlust #WorldTravel

Privacy Policy


Website: theworldtraveldiary.com
Brand: The World Travel Diary (TWTD)

1. Who We Are

The World Travel Diary (“TWTD”, “we”, “us”, or “our”) is operated from New South Wales, Australia. This Privacy Policy explains how we collect, use, store, and disclose your personal information when you visit our website (theworldtraveldiary.com), subscribe to our emails, download our resources, or interact with our content.

Contact: privacy@theworldtraveldiary.com
Postal Address: Shop 51, 260 Jersey Road, Plumpton NSW, Australia

2. Information We Collect

2.1 Information You Provide Directly

  • Email address — when you subscribe to our newsletter, download a free resource, or purchase a product
  • First name — required, used for personalisation
  • Last name — optional, used for personalisation
  • Purchase information — if you buy a digital product via Whop (handled by Whop’s payment system; we do not store payment details)
  • Communications — when you contact us via email or contact forms

2.2 Information Collected Automatically

  • Website usage data — pages viewed, time spent, referring website, device type, browser (via Google Analytics and CookieYes)
  • Cookie data — preferences, consent state, analytics identifiers (see our Cookie Policy)
  • Email engagement data — whether you open emails, click links (via MailerLite)

2.3 Information We Do NOT Collect

We do not knowingly collect sensitive information such as:

  • Children’s personal information (see Section 10)
  • Health, medical, or passport details
  • Payment card information (handled by Whop)
  • Precise location data

3. How We Use Your Information

We use your information for the following purposes:

  • To deliver requested resources — send you the free guide, checklist, or product you requested
  • Email marketing — send you TWTD newsletters, travel tips, product updates, and affiliate recommendations (only if you explicitly consented)
  • Website analytics — understand how visitors use our site to improve content and user experience
  • Customer support — respond to your inquiries and requests
  • Legal compliance — meet our obligations under Australian and international law
  • Security — protect our website and systems from fraud, spam, and malicious activity

4. Legal Basis for Processing (GDPR/UK GDPR)

If you are located in the European Union, United Kingdom, or other jurisdictions requiring a legal basis for data processing, we rely on:

  • Consent — for email marketing (you explicitly opted in)
  • Contractual necessity — to deliver products or services you requested
  • Legitimate interests — for website analytics, security, and improving our services (balanced against your rights)
  • Legal obligation — to comply with applicable laws

You may withdraw consent at any time by unsubscribing from emails or contacting us at privacy@theworldtraveldiary.com.

5. How We Share Your Information

We do not sell, rent, or trade your personal information. We only share your information with:

5.1 Service Providers (Data Processors)

  • MailerLite — email delivery and subscriber management (see Section 7)
  • Whop — payment processing and digital product delivery
  • Google — website analytics via GA4 (anonymised where possible)
  • CookieYes — cookie consent management
  • WordPress hosting provider — website infrastructure
  • Email delivery services — WP Mail SMTP for transactional emails

These providers are contractually obligated to protect your data and use it only for the purposes we specify.

5.2 Legal Requirements

We may disclose your information if required by law, court order, or government authority, or to protect our rights, safety, or property.

5.3 Business Transfers

If TWTD is sold, merged, or transferred, your information may be transferred as part of that transaction.

6. International Data Transfers

Your information may be transferred to and processed in countries outside Australia, including:

  • European Union — MailerLite stores subscriber data in EU data centers (GDPR-compliant)
  • United States — MailerLite, Inc. (USA) provides contractual management and participates in international data protection frameworks
  • Global — Google Analytics, WordPress, and other service providers may process data in various jurisdictions

We ensure appropriate safeguards are in place, including contractual protections and reliance on providers certified under international data protection frameworks.

By using our website and subscribing to our emails, you consent to these international transfers.

7. MailerLite & Email Security

Our Commitment to Your Privacy & Secure Email Management

Your trust is incredibly important to us, and we are committed to handling your personal information with care. To ensure your email updates are delivered reliably and securely, we partner with MailerLite to manage our subscriber lists.

Where Your Data is Safely Managed

To give your information the highest standard of protection, MailerLite physically stores all subscriber data in secure, certified data storage facilities located within the European Union (which operates under strict GDPR privacy frameworks). Contractual management is handled by MailerLite, Inc. (USA), which actively participates in international Data Privacy Frameworks.

Legal Responsibility and Liability

By subscribing to our updates, you acknowledge and consent to this secure cross-border transfer and storage of your personal data.

While we deliberately choose industry-leading partners who prioritise data security, our business operates independently from MailerLite. Therefore, to the maximum extent permitted by law (including the Privacy Act 1988 (Cth) and Australian Consumer Law), we cannot accept legal responsibility or liability for any data breaches, security incidents, or unauthorized access that occur within MailerLite’s proprietary systems, networks, or infrastructure. MailerLite maintains its own robust, independent security controls, and any claims or inquiries regarding the security of their platform must be directed solely to MailerLite, Inc.

8. Cookies & Tracking Technologies

We use cookies and similar technologies to:

  • Remember your preferences and consent choices
  • Analyse website traffic via Google Analytics
  • Manage cookie consent via CookieYes
  • Enable social sharing features

You can control cookie settings through your browser or our CookieYes consent banner. Disabling cookies may affect website functionality.

See our Cookie Policy for detailed information.

9. Your Rights

Depending on your location, you may have the following rights:

  • Access — request a copy of the personal information we hold about you
  • Correction — request correction of inaccurate or incomplete information
  • Deletion — request deletion of your personal information (subject to legal retention obligations)
  • Withdrawal of consent — unsubscribe from emails or withdraw consent for specific processing
  • Objection — object to certain processing activities (e.g., direct marketing)
  • Data portability — request transfer of your data to another provider (where technically feasible)
  • Complaint — lodge a complaint with a relevant privacy regulator

To exercise these rights, contact us at privacy@theworldtraveldiary.com. We will respond within 30 days.

Australian residents: You may also contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

EU/UK residents: You may contact your local data protection authority.

10. Children’s Privacy

The World Travel Diary is a family travel website, but our content and services are intended for adults (parents, guardians, and family travel planners). We do not knowingly collect personal information from children under 13 (or 16 in jurisdictions where this age is higher).

If you are a parent or guardian and believe your child has provided personal information to us, please contact us at privacy@theworldtraveldiary.com, and we will take steps to delete such information.

We encourage parents to:

  • Supervise their children’s online activities
  • Not allow children to submit personal information without parental consent
  • Teach children about online privacy and safety

11. Data Retention

We retain your personal information for as long as necessary to:

  • Provide our services and communicate with you
  • Comply with legal obligations
  • Resolve disputes and enforce our agreements

Email subscribers: We retain your information indefinitely while you remain subscribed. If you unsubscribe, we retain your email address and consent records for compliance purposes (to ensure you are not re-added accidentally) but cease marketing communications. You may request complete deletion at any time.

Website analytics: Google Analytics data is retained according to Google’s configured retention periods (typically 2-14 months for user-level data).

Purchase records: Transaction records are retained for tax and accounting purposes as required by law.

12. Security

We implement reasonable technical and organisational measures to protect your personal information, including:

  • Secure website hosting with regular updates
  • SSL encryption for data transmission
  • Access controls and authentication for administrative systems
  • Regular backups via WPvivid Backup Plugin
  • Spam and malware protection via Jetpack and other security tools

However, no internet transmission or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

13. Third-Party Links

Our website and emails may contain links to third-party websites (e.g., affiliate partners, travel providers, social media). We are not responsible for the privacy practices or content of these external sites. We encourage you to review their privacy policies.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or operations. When we do, we will post the revised policy on this page. We encourage you to review this Privacy Policy periodically.

15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Email: privacy@theworldtraveldiary.com

For general inquiries (not privacy-related), use our Contact page or email hello@theworldtraveldiary.com. Our preferred means of contact is via email.

16. Governing Law

This Privacy Policy is governed by the laws of New South Wales, Australia. Any disputes relating to this policy will be subject to the exclusive jurisdiction of the courts of New South Wales.

This Privacy Policy was last updated in September 2026.