Skip to content
Legal

Privacy Policy

Last Updated: April 13, 2026Effective Date: April 13, 2026

Introduction

Travify (Pvt) Ltd (Registration No. PV00360275) ("Travify," "we," "our," or "us") is a cloud-based travel operations management platform designed for destination management companies ("DMCs"). This Privacy Policy ("Policy") describes how we collect, use, disclose, retain, and safeguard information when you access or use our platform, website (travify.app), application programming interfaces ("APIs"), and all related services, features, content, and applications (collectively, the "Services").

This Policy applies to all users of the Services, including but not limited to registered account holders, authorized users within a Customer organization, website visitors, and any individual whose personal data is processed through the Services (e.g., travelers whose information is uploaded by a Customer).

By accessing or using the Services, you acknowledge that you have read, understood, and agree to be bound by this Policy. If you do not agree with this Policy, you must not access or use the Services.

We process personal data in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation ("UK GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), Sri Lanka's Personal Data Protection Act No. 9 of 2022 ("PDPA"), and all other applicable data protection and privacy laws.

1. Definitions

For the purposes of this Policy:

  • "Customer" means the entity or individual that has entered into a subscription agreement with Travify to use the Services.
  • "Authorized User" means any individual granted access to the Services by a Customer, including employees, contractors, or agents of the Customer.
  • "Customer Content" (also "Customer Data") means any data, content, information, or materials that a Customer or Authorized User uploads, submits, stores, transmits, or otherwise provides to or through the Services, including but not limited to traveler profiles, itineraries, booking records, financial data, documents, images, and communications.
  • "Personal Data" means any information relating to an identified or identifiable natural person, as defined by applicable data protection law.
  • "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
  • "Sub-processor" means any third party engaged by Travify to process Customer Content or Personal Data on Travify's behalf.
  • "Traveler Data" means Personal Data relating to end travelers whose information is processed through the Services by or on behalf of a Customer.

2. Data Controller and Data Processor Roles

2.1 Travify as Data Controller

Travify acts as the data controller with respect to:

  • Account registration and profile information of Customers and Authorized Users;
  • Website visitor data (e.g., cookies, analytics, IP addresses);
  • Billing and payment information;
  • Communications between you and Travify (e.g., support requests); and
  • Any Personal Data collected directly by Travify for its own business purposes.

2.2 Travify as Data Processor

Travify acts as the data processor (or "service provider" under the CCPA) with respect to Customer Content, including Traveler Data, uploaded or submitted by Customers or Authorized Users to the Services.

In this capacity, Travify processes Customer Content solely on behalf of and in accordance with the Customer's documented instructions, these Terms, and any applicable Data Processing Agreement ("DPA"). Customers are responsible for ensuring that they have a lawful basis to process and transfer Traveler Data to Travify and for providing any required notices or obtaining any required consents from data subjects.

2.3 Data Processing Agreement

Enterprise and business Customers may request a DPA that supplements this Policy and governs the processing of Personal Data in Customer Content. To request a DPA, contact us at legal@travify.app.

3. Information We Collect

3.1 Information You Provide Directly

CategoryExamples
Account InformationFull name, email address, phone number, password (hashed), job title, company name, business address, and billing information
Customer ContentTraveler profiles, itineraries, booking records, hotel and supplier data, pricing information, invoices, vouchers, documents, images, and any other data uploaded or input into the Services
Payment InformationCredit/debit card details, bank account information, billing address (processed and stored by our PCI-DSS-compliant third-party payment processor; Travify does not store full payment card numbers)
CommunicationsContents of emails, support tickets, chat messages, feedback, and any attachments sent to Travify
Third-Party Account CredentialsOAuth tokens and associated profile data when you connect third-party services (e.g., Google, Microsoft)

3.2 Information Collected Automatically

CategoryExamples
Usage DataFeatures accessed, pages viewed, click-stream data, time spent on pages, search queries, actions taken within the platform, error logs, and performance metrics
Device and Connection DataIP address, browser type and version, operating system, device type, unique device identifiers, screen resolution, language preferences, time zone, and referring URLs
Geolocation DataApproximate location (city, country, coordinates) derived from your IP address using third-party geolocation services to provide localized features such as weather forecasts and currency defaults
Cookies and Similar TechnologiesSession cookies, persistent cookies, web beacons, pixels, and local storage objects (see Section 12 — Cookie Policy)
Log DataServer logs recording access times, pages viewed, system activity, hardware settings, and crash data

3.3 Information from Third-Party Sources

We may receive information about you from third-party sources, including:

  • Authentication Providers: When you sign in using Google or Microsoft, we receive profile information as described in Sections 5 and 6.
  • Payment Processors: Transaction confirmation and fraud-prevention data from Stripe or other payment processors.
  • Maps and Location Services: Place data, coordinates, distances, and geocoding results from Google Maps, Mapbox, OpenStreetMap, and Open-Meteo.
  • Weather Services: Weather forecast data for destinations via the Google Weather API.
  • Publicly Available Sources: Business registration data and publicly available professional information.

Where the GDPR or UK GDPR applies, we rely on the following legal bases for processing Personal Data:

Legal BasisApplicable Processing Activities
Performance of a Contract (Art. 6(1)(b))Processing necessary to provide the Services, manage your account, process payments, and fulfill our contractual obligations
Legitimate Interests (Art. 6(1)(f))Analytics and service improvement, fraud detection and prevention, security monitoring, enforcing our Terms, and direct marketing to existing customers (with opt-out)
Consent (Art. 6(1)(a))Connecting third-party accounts (Google, Microsoft), use of non-essential cookies, receiving marketing communications (where required), and use of the AI Chat Assistant
Legal Obligation (Art. 6(1)(c))Compliance with applicable laws, regulations, court orders, or governmental requests; tax and accounting obligations

You may withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

5. Google User Data

Travify accesses certain Google user data through Google APIs. This section describes the specific Google data we access, the purpose of such access, and the applicable restrictions.

5.1 Data Accessed

  • Google Sign-In: When you authenticate using Google, we receive your email address, display name, and profile photo. This data is used solely to create, authenticate, and maintain your Travify account.
  • Gmail (Send-Only Access): If you elect to connect your Gmail account, we request the gmail.send OAuth scope exclusively. This permits Travify to send emails on your behalf (e.g., quotes, invoices, vouchers, booking confirmations, and reminders) that you initiate through the platform. We do not request, receive, or have access to read, search, modify, or delete your emails, contacts, calendar, or any other Gmail data.

5.2 Use of Google Data

Google user data obtained through Google APIs is used exclusively to provide and improve the user-facing features of the Services. Specifically:

  • Google Sign-In data is used only for authentication, identity display, and account management.
  • Gmail send access is used only to transmit emails that you expressly initiate through the Travify platform.

5.3 Restrictions on Google Data Use

Travify's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for:

  • Serving, personalizing, or targeting advertisements;
  • Selling, licensing, or sharing data with third parties for advertising, data brokerage, or any unrelated purpose;
  • Training, fine-tuning, or evaluating artificial intelligence or machine learning models;
  • Profiling or automated decision-making unrelated to the Services; or
  • Any purpose other than providing or improving the user-facing functionality of Travify.

5.4 Token Security and Revocation

OAuth tokens are encrypted at rest using AES-256-GCM and transmitted exclusively over TLS 1.2 or higher. You may disconnect your Gmail integration at any time from your Travify account settings, which will trigger immediate and permanent deletion of the associated OAuth tokens. You may also revoke access directly through your Google Account permissions.

6. Microsoft User Data

Travify accesses certain Microsoft user data through Microsoft Graph APIs. This section describes the specific Microsoft data we access, the purpose of such access, and the applicable restrictions.

6.1 Data Accessed

  • Microsoft Sign-In: When you authenticate using a Microsoft account, we receive your email address, display name, and profile photo. This data is used solely to create, authenticate, and maintain your Travify account.
  • Outlook Email (Send-Only Access): If you elect to connect your Outlook account, we request the Mail.Send permission via Microsoft Graph API. This permits Travify to send emails on your behalf that you initiate through the platform. We additionally request User.Read solely to retrieve your email address for sender identification. We do not request or have access to read, search, modify, or delete your emails, calendar events, contacts, files, or any other Microsoft data.

6.2 Use of Microsoft Data

Microsoft user data obtained through Microsoft APIs is used exclusively to provide and improve the user-facing features of the Services:

  • Microsoft Sign-In data is used only for authentication, identity display, and account management.
  • Outlook send access is used only to transmit emails that you expressly initiate through the Travify platform.

6.3 Restrictions on Microsoft Data Use

Travify's use of information received from Microsoft APIs complies with the Microsoft APIs Terms of Use. We do not use Microsoft user data for:

  • Advertising, marketing, retargeting, or ad-based profiling;
  • Selling, redistributing, sublicensing, or sharing data with third parties for unrelated purposes;
  • Training, fine-tuning, or evaluating artificial intelligence or machine learning models;
  • Profiling or automated decision-making unrelated to the Services; or
  • Any purpose other than providing or improving the user-facing functionality of Travify.

6.4 Token Security and Revocation

OAuth tokens are encrypted at rest using AES-256-GCM and transmitted exclusively over TLS 1.2 or higher. You may disconnect your Outlook integration at any time from your Travify account settings, which will trigger immediate and permanent deletion of the associated OAuth tokens. You may also revoke access directly at https://myapps.microsoft.com.

7. Artificial Intelligence Features

7.1 Overview

The Services include optional AI-powered features designed to assist with booking management, itinerary generation, content creation, and general platform tasks. These features rely on third-party AI providers to process your queries and generate responses.

7.2 AI Providers and Data Transmitted

Travify uses third-party AI services provided by Google, Anthropic, and OpenAI to power AI features within the platform. When you use AI-powered features, contextual data necessary to process your request — such as booking details, itinerary content, traveler names, dates, and pricing information — may be transmitted to one or more of these providers solely for the purpose of generating a response.

Travify may change, add, or remove AI providers at any time. We will update this Policy to reflect any material changes to the providers used.

7.3 No AI Training

Travify does not use Customer Content, Traveler Data, or AI interactions to train, fine-tune, evaluate, or improve any artificial intelligence or machine learning models. Data transmitted to third-party AI providers is processed solely to generate a response to your request and is governed by those providers' applicable terms and privacy policies:

7.4 Opt-Out

Use of AI-powered features is entirely optional. No functionality critical to core platform operations requires their use. If you prefer that your Customer Content not be processed through third-party AI services, you may choose not to use these features.

8. How We Use Your Information

We use the information we collect for the following purposes:

8.1 Service Delivery and Operations

  • Providing, operating, maintaining, and improving the features and functionality of the Services;
  • Processing transactions, sending invoices, and managing billing;
  • Authenticating users, managing accounts, and administering access controls;
  • Providing customer support and responding to inquiries.

8.2 Service Improvement and Analytics

  • Analyzing aggregated and de-identified usage patterns to understand feature adoption, identify bugs, and improve the user experience;
  • Conducting internal research and development to enhance the reliability, performance, and security of the Services.

8.3 Communications

  • Sending transactional communications, including confirmations, technical notices, security alerts, and support messages;
  • Sending product updates, feature announcements, and, where permitted, marketing communications (with opt-out).

8.4 Security and Fraud Prevention

  • Monitoring for, detecting, investigating, and preventing fraudulent, unauthorized, or illegal activity;
  • Enforcing our Terms of Service and other applicable policies;
  • Protecting the rights, property, and safety of Travify, our Customers, and the public.

8.5 Legal and Compliance

  • Complying with applicable laws, regulations, legal processes, or enforceable governmental requests;
  • Establishing, exercising, or defending legal claims.

8.6 No Sale of Personal Data; No AI/ML Training

  • We do not sell, rent, or lease your Personal Data to third parties.
  • We do not use your Personal Data or Customer Content to train artificial intelligence or machine learning models.

9. Sharing and Disclosure of Information

We do not sell your Personal Data. We may share your information only in the following limited circumstances:

9.1 Service Providers and Sub-processors

We engage trusted third-party service providers and Sub-processors to perform functions on our behalf. These parties are contractually obligated to process Personal Data only as instructed by Travify, to maintain appropriate security measures, and not to use such data for their own purposes.

The following Sub-processors and third-party services may process your data:

Sub-processorPurposeData Categories
Google Cloud (Firebase)Cloud infrastructure, database, authentication, file storageAccount data, Customer Content, authentication credentials
StripePayment processing (PCI-DSS compliant; Travify does not store full card numbers)Billing and payment information
Google (Gmail API)User-connected email sendingEmail content and recipient addresses for emails you initiate
Microsoft (Graph API)User-connected email sendingEmail content and recipient addresses for emails you initiate
Amazon Web ServicesTransactional email deliveryContact form submissions
GoogleAI-powered platform featuresCustomer Content relevant to AI feature requests
AnthropicAI-powered platform featuresCustomer Content relevant to AI feature requests
OpenAIAI-powered platform featuresCustomer Content relevant to AI feature requests
Google MapsMaps, location search, distance calculationLocation coordinates, place names
MapboxGeocoding and map imageryLocation coordinates
OpenStreetMapReverse geocodingLocation coordinates
Open-MeteoLocation searchLocation queries
Google (Weather API)Weather forecasts for destinationsLocation coordinates
Google AnalyticsUsage analytics and platform improvementPage views, session data, device information
Google reCAPTCHABot protection and abuse preventionUser interaction signals, IP address
ip-api.comIP-based geolocation for localizationIP address
Google FontsFont deliveryFont requests (implicit IP logging)

A detailed Sub-processor register with additional technical and contractual information is available upon request by contacting privacy@travify.app.

We will update this list when we engage new Sub-processors. If you have subscribed to Sub-processor change notifications, we will notify you of any additions or replacements.

9.2 Legal Obligations and Law Enforcement

We may disclose information where we believe in good faith that disclosure is necessary to: (a) comply with applicable law, regulation, legal process, or enforceable governmental request; (b) enforce our Terms of Service or other agreements; (c) detect, prevent, or address fraud, security, or technical issues; or (d) protect the rights, property, or safety of Travify, our Customers, or the public, as required or permitted by law.

9.3 Business Transfers

In connection with any merger, acquisition, reorganization, sale of assets, financing, or similar corporate transaction (including during due diligence), your information may be transferred to or shared with the acquiring or successor entity, subject to confidentiality obligations and this Policy. We will notify you of any such transfer via email or prominent notice on our website.

9.4 With Your Consent or at Your Direction

We may share information with third parties when you have provided explicit consent or at your documented direction. For example, if you instruct the Services to send an email via a connected third-party email provider, necessary data will be transmitted to that provider.

9.5 Aggregated and De-identified Data

We may share aggregated or de-identified data that cannot reasonably be used to identify you for any purpose, including industry benchmarking, research, and marketing.

10. Data Retention

10.1 General Retention Principles

We retain Personal Data only for as long as reasonably necessary to fulfill the purposes for which it was collected, including to satisfy legal, regulatory, tax, accounting, or reporting requirements. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the data, and applicable legal requirements.

10.2 Specific Retention Periods

Data CategoryRetention Period
Account InformationDuration of the active account plus 90 days after account deletion to facilitate reactivation requests, after which it is permanently deleted or anonymized
Customer ContentDuration of the active subscription. Upon termination, Customer Content is available for export for 30 days, after which it is permanently deleted within 60 days
Billing and Transaction Records7 years from the date of the transaction, as required by applicable tax and accounting laws
Usage and Log Data24 months from collection, after which it is aggregated, anonymized, or deleted
OAuth TokensRetained only while the third-party account is connected; permanently deleted upon disconnection or account deletion
Support Communications3 years from the date of resolution
Backup CopiesRetained for up to 90 days in encrypted backup systems, after which they are purged in accordance with our backup rotation schedule

10.3 Deletion Requests

Upon receipt of a valid deletion request, we will delete or anonymize the applicable Personal Data within 30 days, except where retention is required or permitted by applicable law.

11. Security

11.1 Security Measures

We implement and maintain reasonable administrative, technical, and organizational security measures designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, theft, alteration, or disclosure. These measures include, but are not limited to:

  • Encryption: Data encrypted in transit using TLS 1.2+ and at rest using AES-256-GCM;
  • Access Controls: Role-based access controls, multi-factor authentication for administrative access, and principle of least privilege;
  • Infrastructure: Hosting on SOC 2 Type II-certified cloud infrastructure with redundancy and disaster recovery capabilities;
  • Monitoring: Continuous security monitoring, intrusion detection, vulnerability scanning, and penetration testing;
  • Personnel: Background checks, confidentiality agreements, and mandatory security awareness training for all personnel with access to Personal Data;
  • Incident Response: Documented incident response plan with defined roles, escalation procedures, and post-incident review processes.

11.2 Data Breach Notification

In the event of a confirmed Personal Data breach that poses a risk to the rights and freedoms of affected individuals, we will:

  • Notify affected Customers without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach (in accordance with GDPR Article 33);
  • Provide details of the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address the breach;
  • Cooperate with Customers in fulfilling their own breach notification obligations to data subjects and supervisory authorities.

11.3 No Absolute Guarantee

While we strive to use commercially reasonable means to protect your Personal Data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security and shall not be liable for unauthorized access, hacking, data loss, or other breaches of security beyond our reasonable control.

12. Cookie Policy

12.1 What Are Cookies

Cookies are small text files stored on your device when you visit a website. We use cookies and similar technologies (web beacons, pixels, local storage) to operate and improve the Services.

12.2 Categories of Cookies

CategoryPurposeConsent Required
Strictly NecessaryEssential for platform functionality, authentication, security, and load balancingNo (required for operation)
Performance and AnalyticsAggregate usage statistics to understand feature adoption and diagnose issuesYes
FunctionalRemembering preferences, language settings, and display configurationsYes

12.3 Third-Party Cookies and Scripts

The following third-party services may set cookies or process data when you use the Services:

ServicePurposeData Collected
Google AnalyticsUsage analytics and trackingPage views, user interactions, session data, device information
Google reCAPTCHABot and abuse protectionUser interaction signals, IP address, browser characteristics
Google FontsIcon font delivery (Material Symbols)Font requests (implicit IP logging by Google)
FirebaseAuthentication and platform operationSession tokens, authentication state

These services are governed by the Google Privacy Policy. We configure Google Analytics with IP anonymization where feasible.

12.4 Managing Cookies

You may manage cookie preferences through our cookie consent mechanism displayed upon first visit, or through your browser settings. Disabling certain cookies may affect the functionality of the Services. For more information on managing cookies, visit aboutcookies.org.

13. International Data Transfers

13.1 Transfer Mechanisms

Travify is headquartered in Sri Lanka and utilizes Google Cloud Platform (Firebase) as its primary cloud infrastructure, with data centers located in the United States. Additionally, certain Sub-processors — including Anthropic, OpenAI, Stripe, and Amazon Web Services — may process data in the United States or other jurisdictions. Where Personal Data is transferred from the European Economic Area ("EEA"), the United Kingdom ("UK"), or Switzerland to a country that has not received an adequacy decision, we implement appropriate safeguards including:

  • Standard Contractual Clauses ("SCCs") as adopted by the European Commission (Decision 2021/914);
  • UK International Data Transfer Agreement or UK Addendum to the EU SCCs, as applicable;
  • Supplementary measures (e.g., encryption, access controls, data minimization) where required by applicable guidance.

13.2 Customer Responsibility

Customers transferring Traveler Data or other Personal Data to Travify from jurisdictions with data transfer restrictions are responsible for ensuring that such transfer complies with applicable law, including by entering into appropriate data transfer agreements with Travify.

14. Your Data Rights

14.1 Rights Under the GDPR and UK GDPR (EEA/UK Residents)

If you are located in the EEA or UK, you have the following rights under applicable data protection law:

  • Right of Access (Art. 15): To obtain confirmation of whether we process your Personal Data and to receive a copy of such data.
  • Right to Rectification (Art. 16): To request correction of inaccurate or incomplete Personal Data.
  • Right to Erasure (Art. 17): To request deletion of your Personal Data where there is no compelling reason for continued processing.
  • Right to Restriction of Processing (Art. 18): To request that we restrict processing of your Personal Data in certain circumstances.
  • Right to Data Portability (Art. 20): To receive your Personal Data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
  • Right to Object (Art. 21): To object to processing based on legitimate interests or for direct marketing purposes.
  • Right to Withdraw Consent (Art. 7(3)): To withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
  • Right to Lodge a Complaint: To lodge a complaint with your local supervisory authority. A list of EEA supervisory authorities is available at edpb.europa.eu.

14.2 Rights Under the CCPA/CPRA (California Residents)

If you are a California resident, you have the following rights:

  • Right to Know: To request disclosure of the categories and specific pieces of Personal Data we have collected, the sources, the business or commercial purposes, and the categories of third parties with whom we share it.
  • Right to Delete: To request deletion of your Personal Data, subject to legal exceptions.
  • Right to Correct: To request correction of inaccurate Personal Data.
  • Right to Opt-Out of Sale/Sharing: We do not sell or share (as defined under the CCPA/CPRA) your Personal Data. No opt-out is required.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights.

Verification: We may need to verify your identity before processing your request. We will not fulfill requests from unauthorized agents unless they provide a power of attorney or the consumer separately confirms authorization.

14.3 Rights Under Sri Lanka's PDPA

If you are a data subject under the Sri Lanka Personal Data Protection Act No. 9 of 2022, you have rights including the right of access, rectification, erasure, restriction of processing, and objection to processing. To exercise these rights, contact us at privacy@travify.app.

14.4 How to Exercise Your Rights

To exercise any of the rights described above, please submit a request to:

We will respond to all verified requests within 30 days (or within the timeframe required by applicable law). If we require an extension, we will inform you of the reason and the extended period within the initial 30-day window.

15. Children's Privacy

The Services are designed for business use and are not directed to individuals under the age of 16 (or the applicable age of digital consent in the relevant jurisdiction). We do not knowingly collect Personal Data from children. If we become aware that we have collected Personal Data from a child without appropriate parental or guardian consent, we will take immediate steps to delete such information. If you believe that a child has provided us with Personal Data, please contact us at privacy@travify.app.

16. Third-Party Links and Services

The Services may contain links to third-party websites, services, or applications that are not owned or controlled by Travify. This Policy does not apply to any third-party services. We are not responsible for the privacy practices of any third party. We encourage you to read the privacy policies of any third-party services you access.

17. Google reCAPTCHA

Certain parts of the Services are protected by Google reCAPTCHA to prevent automated abuse. Use of reCAPTCHA is subject to the Google Privacy Policy and Google Terms of Service. reCAPTCHA may collect hardware and software information, such as device and application data, to verify that interactions are from a legitimate user.

18. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. If we make material changes, we will:

  • Update the "Last Updated" date at the top of this Policy;
  • Provide notice through the Services (e.g., an in-application banner or notification); and
  • Where required by applicable law, seek your consent to material changes.

We encourage you to review this Policy periodically. Your continued use of the Services after the effective date of any updated Policy constitutes your acceptance of the revised Policy.

19. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:

Travify (Pvt) Ltd
Registration No: PV00360275

General Inquiriesinfo@travify.app
Privacy and Data Rightsprivacy@travify.app
Supportsupport@travify.app
Legallegal@travify.app

For GDPR-related matters, you may also contact our designated data protection representative at privacy@travify.app.

© 2026 Travify (Pvt) Ltd. All rights reserved.