这是为方便起见提供的译文。英文版本为具有法律约束力的权威版本。
01 — The short version
- We collect what's needed to book your trip and run our business — name, contact, payment, booking details. That's most of it.
- We share your name and contact with the guide who's leading your experience, so they can find you on the day. We don't share with anyone else for marketing.
- We use cookies. You can turn off the non-essential ones on the banner we show you. See our Cookie Policy for the full list.
- If you're in the EU, UK, or somewhere with similar laws, you have rights to access, correct, delete, or move your data. We honour them.
- The fastest way to ask anything about your data is WhatsApp. We answer in 15 minutes.
02 — Who is responsible
The data controller for personal information collected through orchao.com is:
Brother Tours Co., Ltd. (trading as Orchao) Vientiane, Lao People's Democratic Republic Registration No. [BT-REG-NUMBER] Email: privacy@orchao.com
Orchao is a division of Brother Tours Co., Ltd. — a Lao-owned tour operator licensed in the Lao People's Democratic Republic. References to "Orchao" throughout this policy refer to Brother Tours Co., Ltd. operating under the Orchao brand for the activities described.
03 — What data we collect
You give us
- Account & booking — name, email, phone number, country of residence, WhatsApp number (if you provide it), date of birth (where required for a specific experience), passport details (only when required for transport tickets that demand passport identity, e.g. Laos-China Railway)
- Travel companions — names and ages of other travelers on your booking, if you book on their behalf
- Special requirements — dietary, accessibility, medical conditions you choose to share so we can adapt the experience for you
- Messages — what you tell us via WhatsApp, email, the contact form, or in-platform messaging
- Reviews & photos — any content you submit after an experience
Collected automatically
- Technical — IP address, browser type, device type, operating system, referring URL
- Behavioural — pages visited, search queries, items viewed, time on page, click patterns
- Cookies — see our Cookie Policy for the full list
From third parties
- Payment processors — confirmation of payment status, masked card information (the last four digits and card type), and any fraud-screening signals from Stripe, BCEL Payment Gateway, LOCA Pay, EZyKip, U-Money
- OTA partners — if you book an Orchao supplier through Viator, GetYourGuide, or another OTA, we receive your booking details from the OTA for the purpose of fulfilling the experience
- Identity verification — for select services that require it (long-stay journeys, group bookings over a certain size), we may verify your identity through a third-party service
We do not collect or store your full payment card number. All card data is processed directly by our payment provider (Stripe and/or BCEL Payment Gateway), which is PCI-DSS compliant. We see only the masked card number and processor status.
04 — Why we collect it
| Purpose | What we use |
|---|---|
| Process your booking | Name, contact, payment, booking details, passport (where required) |
| Connect you to your guide | Name, WhatsApp, special requirements shared with the specific guide |
| Customer support | All your communications with us, booking history |
| Fraud prevention | IP, device, payment signals, behavioural patterns |
| Improve the Platform | Aggregated behavioural data, performance metrics |
| Send service emails | Email, booking history (confirmations, reminders, post-trip review request) |
| Send marketing (opt-in only) | Email, country, travel preferences — only if you've opted in |
| Comply with Lao law & tax | Booking records, financial records |
05 — Legal basis (for EU/UK travelers)
Under the GDPR (EU) and UK GDPR, we need a lawful basis to process your data. Ours are:
- Performance of a contract — when you book through Orchao, we process the data needed to fulfill that booking
- Consent — for marketing emails and non-essential cookies, we only act if you've opted in. You can withdraw consent at any time.
- Legitimate interests — for security, fraud prevention, and analytics that improve the Platform. We balance our interests against your privacy and offer opt-outs where appropriate.
- Legal obligation — for tax, accounting, and records the Lao Ministry of Industry and Commerce or other competent authorities may require
06 — Who we share it with
Your supplier
When you book an experience, we share your name, WhatsApp number, group size, special requirements, and booking reference with the supplier who will deliver the experience. They need this to find you on the day and adapt the experience to your needs. We do not share your payment details or your full booking history with the supplier.
Service providers we use
- Payment processing — Stripe (US/Ireland), BCEL Payment Gateway (Laos), LOCA Pay (Laos), EZyKip (Laos), U-Money (Laos)
- Hosting & infrastructure — our hosting provider (currently AWS, Singapore region)
- Email delivery — our transactional email provider
- Customer messaging — WhatsApp (Meta), for our support thread
- Analytics — Google Analytics 4 (anonymised) for understanding site usage
- SMS & phone notifications — Twilio, where used
OTA distribution partners
If a guide on Orchao also distributes through Viator, GetYourGuide, Klook, or other OTAs, your booking remains with the platform you booked through. We do not share Orchao-direct bookings with OTA partners.
Law enforcement & regulators
We may share data with the Lao Ministry of Industry and Commerce, tax authorities, or law enforcement if legally required. We will not share data on request unless we are obligated to.
Business transfers
If Orchao is acquired, merged, or restructured, your data may transfer to the successor entity. We will notify you in advance, and the new entity must honor this policy or give you the option to delete your data.
We never sell your personal data. Not to advertisers, not to brokers, not to anyone.
07 — How long we keep it
| Data type | Retention period |
|---|---|
| Booking records | 7 years (Lao tax law) |
| Account profile | Until you delete the account, plus 90 days |
| Marketing preferences | Until you unsubscribe, plus 1 year for suppression list |
| Support messages | 3 years from last contact |
| Analytics data | 26 months (Google Analytics default) |
| Cookies | Per the Cookie Policy — most expire within 12 months |
08 — International transfers
Orchao is headquartered in Laos. Some of our service providers — payment processors, hosting providers, analytics — operate from Singapore, Ireland, the United States, and other jurisdictions. When we transfer your data outside its country of origin, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable
- Adequacy decisions where they exist
- Provider-specific safeguards (e.g., Stripe and Google operate under recognized data transfer frameworks)
If you have specific questions about how a particular transfer is protected, ask us — we'll show you the relevant agreement.
09 — Your rights
Depending on your location, you have some or all of the following rights:
- Access — request a copy of the data we hold about you
- Correction — ask us to fix anything inaccurate
- Deletion ("right to be forgotten") — ask us to delete your data, subject to legal retention requirements (e.g., we can't delete a paid booking record before 7 years)
- Restriction — limit how we process your data
- Portability — receive your data in a structured, machine-readable format and transfer it elsewhere
- Objection — object to processing based on legitimate interests, including marketing
- Withdraw consent — for anything you previously consented to
- Complaint — lodge a complaint with your local data protection authority. For UK residents, that's the ICO. For EU residents, your national supervisory authority.
To exercise any of these rights, email privacy@orchao.com or message us on WhatsApp. We respond within 30 days and almost always within 48 hours.
10 — Cookies & tracking
We use cookies for essential site functions (keeping you logged in, remembering your booking), analytics (understanding which pages help you and which don't), and — only with your consent — marketing (showing you Orchao on other websites you visit). See our Cookie Policy for the full breakdown.
11 — Security
We protect your data with industry-standard measures:
- HTTPS / TLS encryption on every page
- Payment data processed only by PCI-DSS compliant providers — we never store full card numbers
- Access to personal data is limited to staff who need it for their role
- Two-factor authentication on all internal admin systems
- Regular security reviews of our hosting infrastructure
No system is perfectly secure. If a data breach affects your personal information, we will notify you within 72 hours of becoming aware, as required by GDPR and applicable Lao law.
12 — Children
Orchao is for travelers aged 18 and over. We do not knowingly collect personal data from children under 13. If a parent or guardian is booking on behalf of a minor (e.g., a family tour), the adult is the account holder and is responsible for the minor's data. If you believe we have inadvertently collected data from a child, please contact us and we will delete it.
13 — Changes to this policy
If we change this Privacy Policy, we will update the "Last updated" date at the top and, for material changes, notify you by email or a notice on the website at least 30 days before the changes take effect.
14 — Contact us
Email: privacy@orchao.com WhatsApp: +856 20 7895 9598 Post: Brother Tours Co., Ltd. (trading as Orchao), Vientiane, Lao PDR
The shortest version of this whole policy: we collect what we need to run your booking, we share what we need to share to make the trip happen, we don't sell your data, and you can ask us to delete it at any time. Anything unclear, ask.
© 2026 Orchao, a division of Brother Tours Co., Ltd. · Reg. No. [BT-REG-NUMBER] · Vientiane, Lao PDR
