Privacy policy
Last updated: 11 August 2026
This policy explains how we handle personal data. It covers two different relationships, and the difference matters.
- For agencies using the platform, we are the controller of your account data.
- For travellers whose details an agency loads, we are a processor acting on that agency's instructions. The agency is the controller. If you are a traveller and want your data changed or removed, your agency is the fastest route — though you can also contact us directly and we will act on it.
What we hold
Account data (agencies). Names, work email addresses, the organisation, roles, and authentication records. We use it to run your account, secure it, and contact you about the service.
Traveller data (on behalf of agencies). Names, contact details, languages, itinerary records, documents uploaded to a trip, notification preferences, and message history with the concierge. Some of this may include data a jurisdiction treats as sensitive — a passport, a medical form — because a travel file sometimes needs it.
Technical data. Logs, IP addresses and timestamps, kept to operate and secure the service.
Why we hold it
To provide the service under our contract with the agency; to keep the service secure and diagnose problems; and to meet legal obligations. We do not use traveller data for advertising, and we do not sell it.
AI processing
Messages and itinerary data are processed by AI models to interpret bookings and answer traveller questions. Two commitments:
- Traveller conversations are not used to train models.
- The model interprets, it does not invent. Times, locators and policies come from the structured record your agency approved.
Sub-processors
We use a small number of infrastructure providers — hosting, database and object storage, email delivery, AI model providers and messaging platforms. Each is bound by a data processing agreement. We will give a current list on request and give notice of material changes.
Product analytics. Microsoft Clarity and PostHog record how our own interfaces are used. On the marketing site they run only where the law allows it without asking, or where a visitor has accepted — see the Cookie policy. In the console they run under our agreement with the agency, with the content area masked, so what reaches them is which screens were used and how, plus unhandled errors — not traveller names, documents, passport details or message threads. Console sessions are identified by user id, never by email.
Retention
We keep trip and message data for as long as the agency's account is active, plus a wind-down period after termination for export. An agency can delete a traveller at any time, which removes their access and stops all messaging to them. A full erasure request is honoured across trips and message history.
Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or erase your data, and to object to processing. Contact us and we will respond; where we act as processor, we will pass the request to the agency and support them in answering it.
Transfers
Our infrastructure is in the European Union. Where a sub-processor moves data outside it, that transfer is covered by the appropriate safeguards.
Security
Tenant isolation is enforced at the data layer rather than by each feature remembering to filter, documents are served through short-lived signed links that expire, agency credentials are never included in the public payloads travellers' pages read, and administrative actions are recorded in an audit log.
Contact
Write to us at the address on the contact page with anything about this policy or a specific request.