Privacy Policy

Last updated: June 2025

Travesy ("we", "us", or "our") is committed to protecting your privacy. This policy explains what data we collect, why we collect it, and how we handle it. Please read it carefully.

1. Who we are

Travesy is a B2B SaaS platform operated by Travesy Technologies Private Limited, a company registered in India. We provide travel agents with tools to create and share branded trip portals for their clients.

Contact: privacy@Travesy.in

Last updated: June 2025

2. Information we collect

Account information: When you sign up, we collect your name, email address, agency name, and password (stored as a bcrypt hash — never in plaintext).

Trip and portal data: We store all trip content you create — itineraries, hotel descriptions, flight details, images, and other portal content. This content is associated with your account and is yours.

Usage analytics: We collect anonymised data about how you use Travesy — pages visited, features used, and session duration. This helps us improve the product.

Portal view analytics: When your clients view a portal you've shared, we log the view event (timestamp, device type, general geographic region). We do not collect client personal data beyond what you explicitly enter into the portal.

Cookies: We use essential cookies for session management and authentication. We may use analytics cookies (with your consent) to understand product usage.

Payment information: Payments are processed by Razorpay. We receive transaction confirmations but never store card numbers, CVVs, or bank account details.

3. How we use your information

We use the information we collect to:

Provide, operate, and maintain the Travesy platform
Process your subscription payments
Send you product updates, security notices, and support communications
Improve and personalise your experience
Analyse usage patterns to improve product features
Comply with legal obligations
Prevent fraud and ensure platform security

We do not sell your personal data to third parties. We do not use your data for advertising purposes or share it with ad networks.

4. Data sharing and third parties

We share data with the following third-party service providers, only to the extent necessary to provide the service:

Neon PostgreSQL: Our primary database provider. Account data and trip content is stored on Neon's infrastructure (AWS ap-south-1, Mumbai). Neon is bound by a Data Processing Agreement.

Cloudflare R2: Media assets (images, documents) uploaded to Travesy are stored on Cloudflare R2. Files are served via Cloudflare's global CDN.

Anthropic (Claude AI): When you use the AI content writer, your input is sent to Anthropic's API for processing. Anthropic's privacy policy applies to this data. We do not use AI-generated content to train our models.

Razorpay: Payment processing. Subject to Razorpay's privacy policy and PCI-DSS compliance.

Resend: Transactional email delivery (account confirmations, notifications).

We do not share your data with any other third parties except as required by law.

5. Data retention

We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required by law to retain it longer.

Portal view analytics are retained for 12 months. Anonymised, aggregated analytics may be retained indefinitely for product improvement purposes.

Backup data may persist in encrypted backups for up to 90 days after deletion.

6. Your rights

You have the following rights regarding your personal data:

Right of access: You can request a copy of the personal data we hold about you.

Right to rectification: You can correct inaccurate data through the account settings, or by contacting us.

Right to erasure: You can request deletion of your account and all associated data.

Right to data portability: You can export your trip data from the dashboard at any time.

Right to object: You can opt out of non-essential communications at any time.

To exercise any of these rights, email privacy@Travesy.in with your request. We will respond within 30 days.

7. Cookies

We use the following cookies:

Essential cookies: Required for authentication and session management. These cannot be disabled without breaking the service.

Analytics cookies: Help us understand how users interact with Travesy. These are set only with your consent and can be disabled in your browser.

You can manage cookies through your browser settings. Disabling essential cookies will prevent you from logging in.

8. Security

We implement industry-standard security measures including TLS 1.3 encryption in transit, AES-256 encryption at rest, and bcrypt password hashing. For details, see our Trust Center.

No system is 100% secure. If you believe your account has been compromised, contact security@Travesy.in immediately.

9. Children's privacy

Travesy is a B2B platform intended for travel professionals. We do not knowingly collect personal data from persons under the age of 18. If you believe a minor has created an account, please contact us and we will delete the account promptly.

10. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and/or by placing a notice on the dashboard. The date at the top of this document reflects the most recent update.

Continued use of Travesy after changes constitutes acceptance of the updated policy.

11. Contact

For privacy-related enquiries, contact:

Email: privacy@Travesy.in

Response time: Within 5 business days

Travesy Technologies Private Limited

Remote-first, India