Legal

Privacy Policy

Last updated: 30 June 2026

Mercury Travel ("Mercury", "we", "us", "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, hold, use, disclose and protect personal information about travellers, trade partners and website visitors.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and — where applicable — the Privacy Act 2020 (NZ) and the New Zealand Information Privacy Principles (IPPs). Where the EU/UK GDPR applies to a particular interaction, we will apply additional protections required by that law.

1. Who we are

Mercury Travel is a destination management and group travel specialist operating across Australia, New Zealand and the South Pacific Islands. References to "Mercury", "we", "us" or "our" in this policy mean the Mercury Travel trading entity that provides services to you.

If you need to contact us about privacy, see Section 13.

2. Personal information we collect

The types of personal information we collect depend on how you interact with us. They typically include:

  • Identity & contact details: full name, date of birth, passport number, nationality, postal and email address, phone number.
  • Travel details: itinerary preferences, dietary requirements, mobility needs, emergency contacts, frequent-flyer numbers, accommodation and room-share preferences.
  • Health and sensitive information: only where you provide it for the purpose of travel (for example, medical conditions, accessibility needs, dietary restrictions or insurance claims). Sensitive information is collected only with your consent.
  • Payment information: billing details and, where relevant, partial card details processed via PCI-compliant payment providers. We do not store full card numbers.
  • Trade partner information: business contact details, ABN/NZBN, IATA/TIDS numbers, and commercial correspondence.
  • Website and technical data: IP address, device and browser information, pages visited, referring URLs, and cookie identifiers (see Section 9).

3. How we collect personal information

We collect personal information:

  • directly from you, when you enquire, book, email, call or complete a form;
  • from trade partners (tour operators, travel agents, cruise lines, MICE buyers) who book on your behalf;
  • from suppliers (airlines, hotels, ground operators, insurers) in connection with your travel;
  • automatically through our website via cookies and analytics tools; and
  • from publicly available sources where relevant to a business relationship.

Where you provide personal information about another person (for example, a fellow traveller or emergency contact), you confirm you have their authority to do so.

4. Why we collect and use your information

We use personal information to:

  • respond to enquiries and prepare quotations;
  • plan, book, confirm and deliver travel arrangements;
  • communicate with you about your trip, including changes, cancellations and emergencies;
  • process payments and manage trade-partner accounts;
  • meet legal, regulatory, immigration and border-control obligations;
  • improve our services, website and marketing (with your consent where required); and
  • resolve disputes, handle complaints and protect our legal interests.

Under the Australian Privacy Act and the NZ Privacy Act, we will only use personal information for the purpose for which it was collected, a directly related secondary purpose you would reasonably expect, or another purpose with your consent or as permitted by law.

5. Disclosure of personal information

To deliver travel services, we share information with:

  • Travel suppliers: airlines, hotels, resorts, ground operators, cruise lines, restaurants, activity providers and insurers — many of whom are located in Australia, New Zealand and the South Pacific.
  • Trade partners: the tour operator, wholesaler or travel agent who arranged your booking.
  • Service providers: IT, hosting, payment processing, CRM, email and analytics providers that act on our instructions.
  • Government and regulators: where required by law, including immigration, customs, health and biosecurity authorities.
  • Professional advisers: lawyers, auditors and insurers.

We do not sell personal information.

6. Overseas disclosure

Because we operate across Australia, New Zealand and the South Pacific Islands, your personal information may be disclosed to recipients located in those countries and to other countries where our suppliers or service providers are based.

Where we disclose personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the APPs (APP 8) and the IPPs (IPP 12), including by relying on contractual protections. You acknowledge that, in some cases, the destination country may not have privacy laws equivalent to those in Australia or New Zealand.

7. Data security and retention

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. These include access controls, encryption in transit, use of vetted suppliers and staff training.

We retain personal information only for as long as needed for the purposes set out in this policy, to meet legal, accounting and tax requirements (typically 7 years for financial records in Australia and New Zealand), and to resolve disputes. When no longer required, we securely delete or de-identify it.

8. Your rights

Subject to limited exceptions, you have the right to:

  • Access the personal information we hold about you;
  • Correct information that is inaccurate, out of date, incomplete or misleading;
  • Withdraw consent to marketing communications at any time (use the unsubscribe link or contact us);
  • Complain to us about how we have handled your personal information (see Section 13); and
  • where the GDPR applies, request erasure, restriction, portability or object to certain processing.

We will respond to requests within a reasonable period (and within the timeframes required by law).

9. Cookies and analytics

Our website uses cookies and similar technologies to operate the site, remember preferences and measure performance. You can control cookies through your browser settings. Disabling cookies may affect site functionality.

We use analytics tools (which may include Google Analytics) to understand how visitors use our site. These tools may set cookies and process limited information such as IP address and pages viewed. Where required, we obtain your consent before non-essential cookies are set.

10. Direct marketing

We may send you newsletters or updates about destinations, itineraries and trade-partner news where you have opted in or where permitted under the Spam Act 2003 (Cth) and the Unsolicited Electronic Messages Act 2007 (NZ). Every marketing message includes a functional unsubscribe option.

11. Children

Our services are sold to adult trade partners and adult travellers. Where children travel with parents or guardians, we collect only the personal information necessary for their travel and rely on the parent or guardian's consent.

12. Data breaches

We maintain procedures to detect, respond to and report eligible data breaches. Where a breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme, and/or the Office of the New Zealand Privacy Commissioner under Part 6 of the Privacy Act 2020, as required.

13. Contact and complaints

To access or correct your information, withdraw consent, or make a privacy complaint, contact our Privacy Officer:

  • Email: info@mercury.travel
  • Post: Privacy Officer, Mercury Travel, PO Box 567, Christchurch 8542, New Zealand

We will acknowledge your complaint promptly and aim to resolve it within 30 days. If you are not satisfied with our response, you may contact:

  • Australia: Office of the Australian Information Commissioner — oaic.gov.au
  • New Zealand: Office of the Privacy Commissioner — privacy.org.nz

14. Changes to this policy

We may update this Privacy Policy from time to time. The current version is always available on this page with the "Last updated" date above. Material changes will be notified through our website or by email where appropriate.