Security Policy
This policy explains the website, account, payment, booking and personal data security practices used for Trendy Holiday Destinations in a clear and user-friendly format.
HTTPS
Website traffic should be protected through secure connections.
Payment Security
Card transactions are handled by bank or payment provider infrastructure.
Data Protection
Access, retention and sharing processes are controlled.
Incident Reports
Suspicious transactions or access attempts are reviewed promptly.
Responsible Business and Contact
Website and Connection Security
- Users should verify the correct domain name and secure connection before entering personal or payment information.
- The website may use technical controls to reduce unauthorized access, spam, misuse and automated attack risks.
- If a suspicious link, fake email or impersonating website is noticed, users should contact the business before making payment.
- Users are encouraged to use strong, unique passwords and not share account credentials with third parties.
Virtual POS and PCI DSS Approach
Payment pages and virtual POS integrations should be operated through bank or payment provider infrastructure designed for secure card processing. PCI DSS, published by the PCI Security Standards Council, provides a baseline of technical and operational security requirements for protecting payment account data.
PCI DSS v4.0.1 is among the current payment security resources. Payment page security, third-party script controls, e-skimming risk reduction and payment provider controls should be verified before live POS use.
Personal Data and Booking Security
Booking, contact, payment status, invoice and support records should be accessible only for authorized purposes. TRNC Personal Data Protection Law No. 89/2007 principles such as lawful and fair collection, specified and legitimate processing purposes, and limited retention are considered.
User Security Responsibilities
- Accurate, current and personally owned information should be used on booking and payment screens.
- Passwords, SMS codes, bank verification codes and card details must not be shared with third parties.
- When using shared computers or public networks, users should log out and review browser records.
- If unauthorized activity is suspected, the user should contact the bank/payment provider and Sevener Travel without delay.
Security Incident Reporting
For suspicious payment activity, unauthorized account access, fake emails, impersonating websites, suspected data incidents or vulnerability reports, contact info@sevenertravel.com or call (+90) 533 830 0881.
Including the incident date, booking number, screenshots, email/phone used and a short description helps speed up review.
Policy Updates
This security policy may be updated according to payment provider rules, legislation, technical infrastructure and operational needs. The update date will be revised for material changes.