ARR HOLIDAYS · PRIVACY AT A GLANCE
Your trip and access details
Last updated: 30 August 2026. ARR Holidays uses only the information needed for the action you choose. Signing in, preparing a WhatsApp draft, sending an enquiry and paying are separate actions.
Direct enquiries to ARR
When you choose Send enquiry to ARR, ARR uses your name, contact number, party details, travel date, package and request type only to respond to that enquiry. It does not subscribe you to marketing.
ARR records the enquiry-only consent notice version and time, an operational request ID and the source page with the request. WhatsApp authentication proof and unrelated chat content are not added to the enquiry. Authorised sales or trip-design staff may receive the enquiry through ARR’s customer-management system.
WhatsApp drafts and secure sign-in
A WhatsApp draft is prepared in your browser. Nothing is sent to ARR automatically. When you choose Open WhatsApp draft, the displayed name, phone and trip details are included in a link sent to WhatsApp/Meta so WhatsApp can show the draft. ARR receives the message only if you press Send in WhatsApp.
Secure WhatsApp sign-in creates a one-time approval phrase. ARR forwards only bounded campaign fields from the page URL—source, medium, campaign, content and term—to its login service. After the registered ARR WhatsApp account receives the exact phrase from the expected number, ARR creates a secure first-party session cookie for up to ten days. The cookie is not readable by page scripts. Signing in does not create a CRM enquiry or subscribe you to marketing.
Information kept in this browser
Your optional Genie name and guest-wish count remain only for the current browser tab. Selected trip preferences may be remembered on this device for up to 30 days so the page can restore your planning context. You can remove them by clearing ARR Holidays site data in your browser; closing the tab clears session-only details.
ARR Genie
In this test release, the three guest quick wishes use local product guidance and do not call the live AI provider. Free-text personal planning requires verified WhatsApp access. ARR does not keep a browser Genie chat history.
After secure sign-in, you may explicitly choose Remember my choices. ARR then keeps only your preferred name, selected region, released package code, party type and travel pace for up to 90 days so those choices can follow you across signed-in devices. This optional memory is not used for marketing, is never created automatically, and excludes chat text, contact, identity, health and payment data. Choose Forget everywhere in Genie to withdraw consent and remove the remembered choices from ARR’s active memory as well as this device.
Genie removes common email, phone, payment-number and credential patterns before any enabled provider request. Do not enter passport, card, health, contact or password information. Genie cannot book, pay, sign you in, send WhatsApp messages or write to ARR’s CRM; those remain separate actions you choose.
Payments
Live PayU checkout and fulfilment are off in this release. If ARR enables a controlled hosted-checkout test, ARR may hold the entered first name, email and phone with the transaction record for up to seven days. Card or bank credentials must be entered only on PayU’s hosted page and are not accepted by ARR’s website. A booking is not confirmed until ARR independently verifies the payment.
Retention, sharing and your choices
ARR restricts access to authorised staff and service providers needed for the selected action, such as Bitrix for enquiry handling, Meta/WhatsApp for WhatsApp actions and PayU for an enabled hosted payment. ARR retains enquiry and booking information only for service delivery and applicable operational, financial or legal obligations; test authentication and payment records use short expiry periods.
You may continue browsing without signing in, decide not to open or send a WhatsApp draft, or withdraw an enquiry. For access, correction, deletion or privacy assistance, email corp@arrholidays.com and include the request ID when available.