Data protection
Privacy policy
What data we collect when you buy a ticket or write to us, why, how long we keep it, who sees it and how to exercise your rights.
Who we are
The controller of your data is Lu-Na sh.p.k. (Luna Travel), NIPT K31412087P, with its address at Rruga e Durrësit 75, Tiranë, Albania.
For any matter relating to your data: info@luna.al.
We have not appointed a data protection officer. Data requests are handled directly by our office.
We apply Law no. 124/2024 “On Personal Data Protection” and, when we serve persons located in the European Union, Regulation (EU) 2016/679 (GDPR).
What we collect and why
When you buy a ticket. For each passenger: first name and surname, email and phone number. For the order: the line, the date and time of travel, the return journey if you choose one, the number of seats, the price and the site language. We use them to issue the named ticket, to send it to you, to check it on the vehicle and to notify you when something changes about the journey. The first name, surname, email and phone number are mandatory: without them the ticket cannot be issued. We use the phone number to contact you when there are changes or problems with the journey. Legal basis: performance of the travel contract and, for sales records, legal obligation under accounting law.
When you buy for other people. You provide us with the data of the other passengers. Provide only data that you are entitled to share, and inform them of this policy. Each passenger whose email differs from the buyer's receives only their own ticket by email. Legal basis: performance of the travel contract.
Customer summary. From the orders, the system keeps for each buyer, by email address, a summary with the name, phone number, language, and the number and value of orders, so that the office can see the history when you contact it. Legal basis: legitimate interest in customer service.
At the time of ordering. The IP address and browser data, as a measure against fraud and misuse. From the IP address we derive the country using a database located on our server, without sending the IP address to anyone. The IP address and browser data are automatically deleted from the order after 90 days; the country remains with the order. Legal basis: legitimate interest in fraud prevention.
When the ticket is scanned. The time of the scan, the employee who scanned it and the vehicle. This is the proof that the journey took place. Legal basis: performance of the travel contract.
When you request a cancellation or refund. The reason you select, the explanation you write and the IP address of the request. The reason is stored with the order so that the office's decision is traceable; the IP address is automatically deleted after 90 days. Legal basis: performance of the contract and, for refunds, legal obligation under accounting law.
When you send a transfer request. The type of transfer, the departure and arrival points, the dates, the number of passengers, the luggage, first name and surname, phone number, email, preferred contact method and your notes. The first name, surname, phone number and email are mandatory. The request is sent to the office by email so that it can make you an offer. Legal basis: steps taken at your request prior to entering into a contract.
When you write to us through the contact page. First name, surname, email, phone number, subject and message. The first name, surname, email and phone number are mandatory. The message is sent to the office by email so that it can reply to you. Legal basis: legitimate interest in answering your questions.
Visit statistics. For each page opened, we count the page, language, country, device type and the page you came from (e.g. a search engine). These counts are stored as totals per day and per hour, with no IP address, no cookies and no identifiers. The list of IP addresses we keep for security is described in the next point. Legal basis: legitimate interest in improving the site.
Server logs. The site's server logs every request with the IP address, the page address, the browser and the time. For each IP address that opens the site we also keep how many pages it opened each day, the country, the device type, the last page and the time. Error logs may contain the IP address, or the recipient's email address for an email that was not sent. Legal basis: legitimate interest in the security and maintenance of the service.
For card payment, see the section Card payment and POK.
Card payment and POK
The full card number and the CVC code never reach our server. The card form is displayed within our payment page, but the card details are captured by POK's payment software running in your browser: it encrypts them there and sends them directly to POK. The payment may require 3-D Secure verification by the bank that issued the card.
In the form you enter the card number, expiry date and CVC, the name on the card and the card's country; for cards from the United States and Canada, also the postcode and the state. The amount, the currency, the order description, the buyer's name and email, as well as technical browser data (screen size, time zone, language) required by card verification, are also passed to POK.
From POK we receive and store with the order: the payment status, the transaction identifier and reference number, the card brand and type, the last four digits, the name on the card and the billing details that POK returns to us. We use them to confirm the payment, for refunds and for accounting. Legal basis: performance of the contract and legal obligation under accounting law.
During payment, POK's software also loads into your browser services that POK uses for fraud prevention and card verification: ThreatMetrix, which creates a device fingerprint, and Cardinal Commerce for 3-D Secure. Your bank's verification page may open within the payment window. These services receive the IP address and technical data of your device.
For the data it collects during payment, POK is an independent controller and applies its own policy. Its main points, which we pass on to you for convenience, are:
- Who it is: RPAY sh.p.k., NIPT M11328018F, trading as POK, an electronic money institution licensed by the Bank of Albania (licence no. 50, dated 9.9.2021), Rruga “Frang Bardhi”, Godina Kristal Center, 2nd floor, entrance 33, Tiranë.
- What it collects: card or account data, transaction data, device identifier, IP address and security signals; for users with a POK account, also identification data.
- Why: to carry out the payment, for fraud prevention, for legal obligations against money laundering, for customer support, for security, for technical analysis and, when you so choose, for marketing.
- Legal basis: performance of a contract, legal obligations, legitimate interest and, where required, consent.
- Shared with: payment processors and card partners, card schemes and banks, identity verification and sanctions screening providers, hosting and cloud providers, Google Tag Manager, merchants and regulatory authorities, including the Bank of Albania and the Commissioner for the Right to Information and Personal Data Protection.
- Outside Albania: it may transfer them to countries of the European Economic Area or to other countries, with safeguards which, according to its policy, may include adequacy decisions, standard or equivalent contractual clauses, and technical measures.
- How long: for as long as necessary for the purpose and as required by the laws it applies.
- Cookies: POK declares that it does not use cookies on its website and app and that it may use Google Tag Manager for technical tags.
- Privacy contact: Akil Rajdho, Information Security Officer and Privacy Contact, arajdho@rpay.ai, +355 68 606 0063.
POK's full and up-to-date text: pokpay.io/privacy-policy. If our summary differs from POK's text, POK's text prevails.
The emails we send you
Only emails related to your order or request: the ticket with the QR code (as a PDF and as an image), confirmation of the cancellation request and of the cancellation, the new date when the office reschedules the journey, and the office's reply. We do not send advertising or newsletters, and we do not give your address to anyone.
Automated emails are sent from noreply@luna.al through our mail server. When sending fails, the system tries up to 8 times in total, within about 11 hours. The copy of the email is deleted 30 days after sending, or 30 days after creation if it cannot be sent; attachments are deleted as soon as the email is sent.
Who sees the data
Refund requests, transfer requests, contact messages and notifications about payments with problems are sent to our office by email.
Processors acting on our behalf: Hetzner Online GmbH, which provides the server on which the site runs and the database is stored, and the email hosting provider for luna.al. They process the data only to provide these services to us.
Independent controllers: POK for payment, Google when the map is displayed and WhatsApp when you write to us there, each under its own policy.
Public authorities, such as the tax administration, the courts or the police, receive data only when required by law. We do not sell your data and we do not give it to third parties for their own purposes.
Where the data is stored
The site, the database, the backups and the mail server are located in data centres in Germany, in the European Union. Under Law no. 124/2024 and Commissioner's Decision no. 01, dated 30.04.2025, the Member States of the European Union have an adequate level of protection, so this transfer does not require specific authorisation.
POK and Google may transfer the data they collect themselves outside Albania, in accordance with their own policies.
How long we keep them
| Data | Legal basis | Kept for |
|---|---|---|
| Orders, tickets, payments, refunds and scans, together with the passengers' name, email and phone number | Performance of a contract and statutory accounting duties | 10 years after the close of the accounting period (Law no. 25/2018, Article 8) |
| Customer summary | Legitimate interest: customer service | For as long as the customer's orders are kept |
| Unpaid orders | Steps prior to entering into a contract | Automatically deleted 5–10 minutes after expiry, when no payment is in progress |
| IP address and browser in the order, in cancellation requests and in the list of visits | Legitimate interest: fraud prevention and security | 90 days, then automatically deleted |
| Copies of emails in the sending queue, including transfer requests and contact messages | Performance of a contract; steps prior to entering into a contract; legitimate interest | 30 days after sending, or 30 days after creation if it cannot be sent |
| Requests and messages in the office mailbox | Steps prior to entering into a contract; legitimate interest | For as long as the communication lasts; if a contract is concluded, for the same period as the accounting records |
| Application error log | Legitimate interest: security and maintenance | 30 days |
| Server system log | Legitimate interest: security and maintenance | Up to 90 days |
| Web server request log (IP, page, browser, time) | Legitimate interest: security | Up to 53 days |
| Anti-abuse counters by IP address | Legitimate interest: security | Deleted about 24 hours after the limit expires |
| Database backups | Legitimate interest: continuity of the service | Up to 7 days; deleted data also disappears from the backups within this period |
| Visit statistics | Legitimate interest; they contain no personal data | As total counts, with no time limit |
Orders, tickets, payments, refunds and scans, together with the passengers' name, email and phone number
Legal basisPerformance of a contract and statutory accounting dutiesKept for10 years after the close of the accounting period (Law no. 25/2018, Article 8)Customer summary
Legal basisLegitimate interest: customer serviceKept forFor as long as the customer's orders are keptUnpaid orders
Legal basisSteps prior to entering into a contractKept forAutomatically deleted 5–10 minutes after expiry, when no payment is in progressIP address and browser in the order, in cancellation requests and in the list of visits
Legal basisLegitimate interest: fraud prevention and securityKept for90 days, then automatically deletedCopies of emails in the sending queue, including transfer requests and contact messages
Legal basisPerformance of a contract; steps prior to entering into a contract; legitimate interestKept for30 days after sending, or 30 days after creation if it cannot be sentRequests and messages in the office mailbox
Legal basisSteps prior to entering into a contract; legitimate interestKept forFor as long as the communication lasts; if a contract is concluded, for the same period as the accounting recordsApplication error log
Legal basisLegitimate interest: security and maintenanceKept for30 daysServer system log
Legal basisLegitimate interest: security and maintenanceKept forUp to 90 daysWeb server request log (IP, page, browser, time)
Legal basisLegitimate interest: securityKept forUp to 53 daysAnti-abuse counters by IP address
Legal basisLegitimate interest: securityKept forDeleted about 24 hours after the limit expiresDatabase backups
Legal basisLegitimate interest: continuity of the serviceKept forUp to 7 days; deleted data also disappears from the backups within this periodVisit statistics
Legal basisLegitimate interest; they contain no personal dataKept forAs total counts, with no time limit
Automated checks
We do not take decisions based solely on automated processing which produce legal effects concerning you or similarly significantly affect you, and we do not carry out profiling.
For security, the system automatically limits the number of orders from the same IP address and the number of card attempts for the same order; once the limit is reached, card payment for that order is closed. POK and your bank may decline a payment based on their own checks. If you believe you have been blocked in error, write to us and the office will review the case.
Minors
We do not collect passengers' age or date of birth. When you buy a ticket for a minor, you provide us with their data, as the parent, guardian or adult buying on their behalf. You may use your own email for their ticket.
Your rights
Under Law no. 124/2024, you have the following rights:
- Information: to know how your data is processed, as explained on this page.
- Access: to obtain a copy of your data. The first copy is free of charge.
- Rectification: to rectify inaccurate or incomplete data.
- Erasure: to request the erasure of data when there is no longer a legal reason to keep it.
- Restriction of processing: to request that the data be stored but not used, e.g. while its accuracy is being examined.
- Data portability: to receive the data you have provided to us in a commonly used electronic format or, where technically feasible, to have us send it directly to another controller.
- Automated individual decision-making: not to be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you.
- Withdrawal of consent: where processing is based on your consent, to withdraw it at any time, without affecting processing carried out before the withdrawal.
Right to object. When we process data on the basis of legitimate interest (security, fraud prevention, statistics, the customer summary, replying to messages), you may object at any time on grounds relating to your particular situation. We stop the processing unless we have compelling legitimate grounds which override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims. We do not use your data for direct marketing.
How to exercise them. Write to info@luna.al. To protect your data, we may ask you to write from the order email or to provide the order code. We respond free of charge within 30 days. When a request is complex or we have many requests, this period may be extended to up to 60 days, and we will inform you of this, with the reasons, within the first 30 days.
When you request erasure, order data that accounting law requires us to keep is not erased before the 10-year period expires. Until then, we keep it only for this obligation and do not use it for anything else.
Complaints. You have the right to lodge a complaint, free of charge, with the Commissioner for the Right to Information and Personal Data Protection: Rr. “Abdi Toptani”, Nd. 5, 1001 Tiranë; tel. +355 42 23 7200; toll-free line 0800 2050; info@idp.al; idp.al. You may also apply to the court. If you are located in the European Union, you may also lodge a complaint with the data protection authority in your country.
Security
The connection to the site is encrypted. The ticket QR code carries a cryptographic signature that the server verifies at every scan, so the ticket cannot be forged.
If a personal data breach occurs that puts your rights at risk, we notify the Commissioner within 72 hours of becoming aware of it, as required by Article 29 of Law no. 124/2024, and we notify you when the law requires it.
Changes to this policy
When the way we process data changes, we update this page and the date at the top of it. The version published here is the one in force.
For travel conditions and cancellation, see terms and conditions.

