Wijesiri Tours
Wijesiri Tours is committed to protecting the privacy of its passengers. This policy sets out exactly what personal information we collect when you book a bus seat with us, why we collect it, who it is shared with, and what control you have over it. By creating an account or making a booking you consent to the practices described here.
Last updated: 5 August 2026
When you create an account we collect:
For each seat in a booking we collect the travelling passenger's:
You may book on behalf of another person. If you enter someone else's details, you confirm that you have their permission to share that information with us and with the bus operator.
We never see, receive or store your card details. Payments are handled entirely on the secure hosted payment page of our payment service provider, PayHere. Your card number, expiry date and CVV are submitted directly to them and never pass through our servers.
What we keep against a booking is limited to the transaction record we need in order to reconcile it and to support you: the amount, the currency, the payment status, and the reference identifiers issued by the payment provider for that transaction.
PayHere processes your payment data as an independent controller under its own privacy policy and its card-network security obligations.
To keep you signed in, we store your session tokens in your own browser's local storage. These stay on your device, are readable only by this website, and are erased when you sign out.
We do not use advertising cookies, analytics cookies, tracking pixels or third-party profiling tools. We do not build advertising profiles, and we do not track your activity across other websites. Our servers keep ordinary technical logs needed to operate and secure the service and to diagnose faults.
We use your information only to:
We do not sell your personal information, and we do not send marketing messages unrelated to a booking you have made.
We share your information only where it is necessary, and only with:
We do not sell, rent or trade your personal information to anyone, and we do not disclose it for anyone else's marketing purposes.
Passwords are stored only as one-way hashes. Access to the site is authenticated with signed, expiring tokens, and every request for booking data is checked against the signed-in account so that one passenger cannot read another's bookings. Traffic between your browser and our servers is encrypted in transit, as is the connection to our database.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please keep your password confidential and sign out on shared devices. Tell us promptly if you believe your account has been accessed by someone else.
We keep your account information for as long as your account is open. Booking and payment records are kept after travel for as long as we need them to handle disputes and to satisfy accounting and tax requirements. Expired sign-in tokens are removed.
You may at any time:
Contact us using the details below to make any of these requests. Note that we may need to keep certain booking and payment records even after an account is deleted, where the law requires us to retain them.
The service is not intended for children. You must be at least 18 years old to hold an account, as set out in our Terms and Conditions. We do not knowingly collect information from anyone below that age. An adult may of course book travel for a child as a passenger.
We may update this Privacy Policy from time to time. Any change is published on this page with a revised “last updated” date. Please check back occasionally to stay informed.
For any question about this Privacy Policy, or to exercise any of the rights in section 8, contact us at: