Viaquo
EN ES
Sign in

Where your data lives, and who can see it

Tenant isolation, what we store, what we never store, and how traveller data is handled.

Updated 25 July 2026

Where your data lives, and who can see it

Isolation

Every record — trips, travellers, segments, documents, conversations — carries the ID of the agency that owns it, and every query is filtered by it at the data layer rather than by each feature remembering to. One agency cannot read or write another's data, and that boundary is covered by tests.

What we store

What we do not do

Access

Access to an agency is by membership, with roles: owner, admin, member. Destructive actions are restricted to owners and admins, and every write through the API is recorded in an audit log.

Traveller rights

Travellers can set their own notification level, and can ask to be removed. Travellers set their level themselves; the options are listed in what the concierge sends, and when. Removing a traveller from a trip deletes their access and stops all messaging to them. For a full erasure request, contact us and we will handle it across trips and message history.

More on account & billing

Inviting your team and what each role can do

Send invitations, understand the owner, admin and member roles, and know which actions are restricted to owners and admins.