1. Introduction
TripVeer is a cloud-based customer relationship management and operations platform built for travel agencies and tour operators. This Privacy Policy explains how TripVeer (“TripVeer”, “we”, “us”, or “our”) collects, uses, shares, protects, and retains personal data when people visit our website, contact us, create an account, or use our software and related services (the “Service”).
We believe privacy information should be understandable. This Policy therefore explains both the data TripVeer handles for its own business operations and the data our customers place in their TripVeer workspaces. TripVeer does not sell Customer Data or personal data.
2. Scope of this Privacy Policy
This Policy applies to the TripVeer website, applications, APIs, subscription services, support interactions, demo requests, and communications that link to it. It applies to account holders, authorised users, website visitors, prospective customers, and individuals whose information is processed through the Service.
Our role depends on the context. For Account administration, billing, security, website analytics, and our own communications, TripVeer generally decides why and how personal data is used and acts as a data controller under the GDPR or data fiduciary under India’s Digital Personal Data Protection framework.
For traveller, lead, customer, supplier, booking, and quotation data entered by a Customer, that Customer generally decides the purposes and means of processing. TripVeer processes the data on the Customer’s instructions and generally acts as a processor. Questions from a traveller or lead about data entered by a travel agency may therefore need to be directed to that agency.
This Policy does not govern independent third-party websites, suppliers, payment gateways, or integrations. Their own privacy terms apply.
3. Information We Collect
The information we collect depends on how the Service is used. We apply data-minimisation principles and ask Customers to enter only information reasonably needed for their travel and CRM operations.
3.1 Account Information
We may collect names, work email addresses, telephone numbers, passwords in protected form, profile photographs, roles, authentication records, user preferences, and account status. If an administrator invites a team member, we receive the invitation details and permissions selected by that administrator.
3.2 Organisation Information
We collect agency or business names, addresses, tax and registration details, logos, branding, websites, business types, team structure, plan information, subscription status, and administrative contacts. Customers may also configure payment accounts, document branding, workflows, mark-ups, and operational preferences.
3.3 Customer & Traveller Data
Customers may enter information about their leads, travellers, corporate customers, suppliers, and contacts. This can include names, email addresses, telephone numbers, addresses, travel preferences, destinations, passenger categories, notes, communications, follow-up history, identity-document details, or other information needed to arrange travel.
Travel records can sometimes contain sensitive or high-risk information. Users should avoid uploading unnecessary sensitive personal data, government identifiers, health information, payment credentials, or children’s information. Where such data is genuinely required, the Customer is responsible for having a lawful basis and applying appropriate access restrictions.
3.4 Booking & Quotation Data
The Service may process enquiries, quotations, package options, itineraries, destinations, travel dates, accommodation, transport, activities, passenger counts, prices, taxes, discounts, mark-ups, booking status, supplier references, payment schedules, vouchers, invoices, and customer responses. These records may identify or relate to travellers and employees.
3.5 Documents Uploaded by Users
Users may upload hotel tariffs, rate sheets, images, PDFs, spreadsheets, word-processing files, identity or travel documents, logos, contracts, and supporting material. Files may be stored, converted, scanned, extracted, or transmitted as needed to provide requested functionality, such as hotel-rate extraction, quotation generation, itinerary assistance, vouchers, and document creation.
3.6 Payment & Billing Information
We collect billing contacts, invoice details, plan, payment status, transaction references, tax information, and limited payment-method metadata. Payments are processed by secure third-party payment gateways. TripVeer does not store complete payment-card numbers, CVV codes, or full online-banking credentials.
3.7 Communication Data
We process demo requests, emails, support messages, meeting details, feedback, survey answers, notification preferences, and records of communications sent through or about the Service. Calls or meetings are recorded only where disclosed and permitted.
3.8 Usage Analytics
We may collect feature interactions, page views, clicks, navigation, session times, error events, usage volumes, AI-credit consumption, integration activity, and performance measurements. We use this information to understand adoption, improve usability, administer limits, and maintain reliable operations.
3.9 Device Information and System Logs
We may collect IP address, browser type, operating system, device type, language, approximate location derived from IP, request timestamps, authentication events, API activity, and diagnostic identifiers. System and audit logs are collected for security, troubleshooting, fraud prevention, service monitoring, and compliance.
3.10 Cookies & Tracking Technologies
We use cookies, local storage, pixels, and similar technologies for authentication, session continuity, security, preferences, analytics, and performance improvement. More detail appears in Section 15.
4. How We Collect Information
We collect information:
- directly from you, when you register, request a demo, subscribe, configure an Account, contact support, or upload information;
- from Customer administrators and users, when they invite team members or enter lead, traveller, supplier, and booking information;
- automatically, through logs, cookies, analytics, device information, and interactions with the Service;
- from connected services, where an authorised user enables an email, calendar, meeting, payment, storage, messaging, AI, or other integration; and
- from lawful business sources, such as referrals, events, publicly available business information, and sales enquiries.
Customers must ensure that information they upload was collected lawfully and that required notices or consents have been provided.
5. How We Use Your Information
We use personal data to:
- create, authenticate, administer, and secure Accounts;
- provide CRM, lead, quotation, itinerary, booking, supplier, hotel rate, customer, workflow, reporting, document, and integration features;
- process subscriptions, billing, payments, and plan limits;
- respond to enquiries, demos, support requests, and feedback;
- send service notices, security alerts, product messages, and permitted communications;
- personalise settings and improve functionality, accessibility, reliability, and performance;
- detect abuse, fraud, security threats, errors, and violations of our Terms;
- comply with law, enforce agreements, protect rights, and resolve disputes; and
- create aggregated or de-identified insights that do not reasonably identify an individual or Customer.
We do not use Customer Data for unrelated advertising, and we never sell it.
6. Legal Basis for Processing (GDPR)
Where the GDPR or similar law applies, TripVeer relies on one or more of these legal bases:
- Contract: processing needed to create an Account, provide subscribed features, deliver support, and administer billing.
- Legitimate interests: securing and improving the Service, preventing fraud, understanding business usage, responding to business enquiries, and operating TripVeer efficiently, where those interests are not overridden by individual rights.
- Consent: optional cookies, certain communications, recorded calls, or other activities where consent is required. Consent may be withdrawn without affecting earlier lawful processing.
- Legal obligation: tax, accounting, regulatory, court, law-enforcement, and compliance requirements.
- Protection of vital interests or public interest:only where applicable in exceptional circumstances.
For Customer Data processed on a Customer’s instructions, the Customer determines the applicable lawful basis. TripVeer assists as required by the applicable agreement and law.
7. AI Features & Data Processing
AI and automated features may process prompts, itinerary context, hotel tariffs, uploaded files, quotations, destinations, and other submitted content to generate requested outputs. Depending on the feature, relevant content may be sent securely to an AI provider that temporarily processes it solely to generate the requested output, maintain security, and provide its contracted service.
We seek to limit submitted content to what the feature requires. Users should remove unnecessary names, contact details, passport information, financial information, health information, and other sensitive data before using AI features. Customers remain responsible for deciding whether information may lawfully be submitted.
AI-generated itineraries, quotations, hotel-rate extractions, summaries, and recommendations may be inaccurate. Users must review outputs before relying on or sharing them. Information about provider processing, retention, or optional AI controls may also be provided within the relevant feature or commercial documentation.
9. Third-Party Service Providers
TripVeer uses carefully selected providers for cloud hosting, databases, storage, authentication, email delivery, meetings, analytics, customer support, AI processing, payment processing, error monitoring, and related infrastructure. These providers process only the information reasonably required for their function and are subject to contractual, confidentiality, and security obligations where appropriate.
When a Customer independently enables Google or another integration, data exchanged with that provider is also governed by the Customer’s account settings and the provider’s terms. Administrators should review requested permissions and disable integrations they no longer use.
Providers and their locations may change as the Service develops. We remain responsible for selecting providers appropriate to our role, but we do not control an independent provider’s service or privacy practices.
10. International Data Transfers
TripVeer and its providers may process information in India and other countries where they operate. Those countries may have privacy laws different from the laws in your location.
Where GDPR transfer rules apply, we use a recognised transfer mechanism when required, such as an adequacy decision, Standard Contractual Clauses, or another lawful safeguard, together with supplementary measures where appropriate. Transfers under India’s DPDP framework are subject to restrictions notified by the Indian Government. Customers must also ensure their instructions comply with applicable localisation or transfer requirements.
11. Data Retention
We retain personal data only as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, maintain security and audit trails, comply with legal and accounting duties, resolve disputes, and enforce agreements.
Retention varies by data type. Active Account and Customer Data is generally retained during the subscription. Billing, tax, security, consent, and transaction records may be retained longer where law or legitimate compliance needs require. Logs are generally kept for a limited operational period unless an incident requires preservation.
Backups may retain deleted information for a limited disaster- recovery cycle. Backup data is isolated from normal use and removed or overwritten according to backup schedules. Legal holds, fraud investigations, or disputes may require longer retention.
12. Data Security
We use reasonable technical, organisational, and administrative safeguards designed to protect information from accidental loss, unauthorised access, alteration, disclosure, and misuse. Measures may include access controls, authentication, encryption in transit, monitoring, logging, backups, secure development practices, provider reviews, and incident-response procedures.
No system is completely secure. Customers share responsibility by using strong credentials, limiting permissions, protecting devices and API keys, reviewing integrations, and removing former users promptly. Please report suspected unauthorised access immediately.
If a personal-data breach occurs, we will investigate and provide notifications to affected Customers, individuals, or authorities as required by applicable law and our role in the processing.
13. Customer Data Ownership
All customer, traveller, lead, supplier, quotation, itinerary, booking, and business data entered into a Customer workspace remains the property of that Customer as between TripVeer and the Customer. Using TripVeer does not transfer ownership of that data to us.
Customers grant TripVeer a limited permission to host, process, transmit, back up, and display Customer Data only to provide, secure, support, and improve the Service, follow Customer instructions, and comply with law. We may create aggregated or de-identified information that does not reasonably identify an individual or Customer.
14. User Rights
Depending on your location and our role, you may have rights to:
- receive information about processing;
- access personal data and obtain a copy;
- correct inaccurate or incomplete data;
- request deletion or erasure;
- restrict or object to certain processing;
- receive portable data where applicable;
- withdraw consent for future processing;
- object to direct marketing and certain uses based on legitimate interests;
- request information about grievance handling and, where applicable, nominate another person to exercise rights; and
- complain to a competent privacy authority, including the relevant European supervisory authority or India’s Data Protection Board where applicable.
Rights are not absolute and may be limited by identity verification, another person’s rights, contractual necessity, security, legal privilege, retention law, or other lawful grounds.
For data entered by a travel agency or employer, contact that organisation first because it generally controls the data. We will assist our Customer as required. For data controlled by TripVeer, email info@tripveer.com. We may ask for information needed to verify identity and authority. We will respond within the period required by applicable law.
16. Children’s Privacy
TripVeer Accounts are intended for business users aged 18 or older. We do not knowingly market the Service to children or permit children to create Accounts.
Travel agencies may need to process information about child travellers to arrange family travel. The Customer is responsible for obtaining verifiable parental or guardian consent and complying with laws governing children’s data. Users should collect only what is necessary and apply restricted access. Contact us if you believe a child has provided Account information directly without appropriate permission.
17. Third-Party Links
The Service may link to hotel, airline, supplier, payment, mapping, government, visa, meeting, or other third-party websites. A link does not mean TripVeer controls or endorses that party’s privacy practices. Information submitted to a third party is governed by its policy. Review third-party terms before providing personal data.
18. Account Deletion
An authorised administrator may request Account deletion by using available Account controls or contacting us. We may verify identity, authority, outstanding subscription obligations, and whether the request affects other users before proceeding.
After deletion, active access is removed and Customer Data is deleted or de-identified according to our retention process, subject to legal obligations, security records, disputes, and legitimate fraud prevention. Complete removal from encrypted backups may take a reasonable additional period until backup copies expire or are overwritten. Backup copies are not returned to normal use except for authorised recovery.
Deleting an individual user does not necessarily delete the organisation’s workspace or records created for that organisation. The organisation’s administrator controls those records.
19. Data Export
Customers may export supported data and documents using available features. An authorised administrator may also request a reasonable export in an available standard format, subject to identity verification, technical feasibility, plan limits, another person’s rights, and legal restrictions.
Before cancellation or termination, Customers should export business-critical records. Where applicable, we normally provide a limited post-termination period for an administrator to request an export, as described in our Terms & Conditions. Export does not require TripVeer to provide proprietary software, internal security information, or data belonging to another Customer.
20. Changes to this Privacy Policy
We may update this Policy when the Service, providers, laws, or privacy practices change. The latest version will appear on this page with an updated effective date. Where a change materially affects how we use personal data, we will provide additional notice through the Service, email, or website where required.
We encourage you to review this Policy periodically. Earlier versions may be made available where legally required or reasonably practicable.
21. Contact Information
For privacy questions, rights requests, concerns about Customer Data, or suspected unauthorised access, contact:
Please describe your relationship with TripVeer, the relevant Account or organisation, the information concerned, and the right you wish to exercise. Do not send passwords or unnecessary identity documents by email. If we cannot resolve a concern, you may have the right to contact the privacy authority in your jurisdiction.
