Info - Privacy & Terms

Your trust matters to us

Privacy Policy
Terms & Conditions

Effective Date: 25 June, 2025

At Travelity ("we," "us," or "our"), a platform developed and operated by BraveCrew Inc, we are committed to empowering travel agencies, tour operators, drivers, tour guides, and their teams with advanced tools to streamline operations, manage bookings, allocate resources, and coordinate communication across multiple channels. As a B2B software platform developed specifically for the travel service industry, we understand the significance of data security and privacy in managing business workflows, personnel information, and client records. This Privacy Policy outlines how we collect, use, disclose, and protect personal data shared with us by our business clients and their authorized users. We adhere to strict data protection regulations, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable international frameworks.

I. Introduction
This Privacy Policy describes Travelity's commitment to protecting the personal and organizational data shared by users of our platform, which is designed for professional use by agencies and personnel in the travel services sector. Our users include account-holding travel companies, operational staff, tour organizers, guides, and transportation partners who use our software to facilitate travel logistics. This policy informs you about the nature of the data we collect, the purposes for which we use it, and the rights and choices available to you under applicable data protection laws. By using the Travelity platform or any associated services, you acknowledge and agree to the terms set out in this Privacy Policy.
II. Information We Collect
A. Personal Information
We collect business-related personal information that is necessary for account management, operational coordination, and customer support. This includes:
  • Full name and role/title within the business
  • Business contact details such as email address and telephone number
  • Organization name and location
  • Login credentials and account activity
  • Payment and billing information for subscription or service transactions
In cases where the platform is used to process customer bookings on behalf of clients, agencies may enter limited end-customer data (e.g., name, contact info, tour preferences), in which case Travelity acts as a data processor on behalf of the agency.
B. Non-Personal Information
We also collect technical and behavioral data from users interacting with our platform:
  • IP addresses and access timestamps
  • Browser type and device configuration
  • Operating system and session duration
  • Navigation behavior and platform feature usage metrics
This information is used to maintain the functionality and performance of our services, diagnose issues, and support product development.
III. Legal Basis for Processing (GDPR)
Our processing of personal data is based on the following legal grounds:
  • Contractual necessity: When data processing is required to provide our software and fulfill service agreements with our clients.
  • Legitimate interest: When we use data to improve platform performance, prevent misuse, or maintain business continuity.
  • Consent: Where the user has provided explicit consent for specific purposes, such as receiving marketing updates.
  • Legal obligation: When we are required by law to retain or disclose certain information.
IV. How We Use Your Information
The information we collect is used primarily to operate and improve the Travelity platform. Use cases include:
  • Account provisioning and access management for agency teams, drivers, and guides
  • Managing real-time booking workflows and scheduling assignments
  • Providing customer support and resolving operational issues
  • Communicating updates, alerts, and service notifications to users
  • Facilitating billing and subscription management
  • Monitoring usage trends and optimizing system performance
We do not use your data for consumer marketing or profiling, unless explicitly agreed.
V. Sharing and Disclosure of Personal Information
We share information only when necessary and with appropriate safeguards in place:
  • Service Providers: Such as data hosting platforms, infrastructure providers, analytics vendors, and integrated CRM tools.
  • Authorized Partners: Where agencies connect their Travelity accounts with third-party services or OTAs.
  • Compliance and Legal Requests: To fulfill legal obligations or respond to valid government inquiries.
  • Corporate Events: In the event of a merger, restructuring, or acquisition.
We do not sell or monetize user data.
VI. Data Security Measures
We employ rigorous data protection practices:
  • Advanced Role-Based Access Control (RBAC)
    Access is governed through fine-grained, context-aware RBAC applied consistently across all services. The IDP we use manages user authentication and federated identity with dynamic access tokens and scopes tied to precise roles and permissions. Service-to-service communication is secured with identity-aware proxying and workload identity bindings within our cloud platform of choice, ensuring only authorized microservices can access protected APIs or resources.
  • Encryption at Rest and in Transit
    All data is encrypted in transit using TLS 1.2+ and at rest using AES-256, managed by our cloud platform of choice and database.
  • Secure Storage and Isolation
    Our database and storage are protected with signed URLs, IAM controls, reducing misconfiguration risk.
  • Secure Development Lifecycle (SDLC)
    Our development process integrates threat modeling, secure code reviews, static/dynamic analysis, and dependency scanning from design to deployment.
  • Incident Response and Business Continuity
    We have an actionable incident response plan that includes detection, triage, notification, and remediation.
  • Compliance and Governance
    All the 3rd party services of choice support compliance with industry standards such as SOC 2, ISO 27001 and GDPR. Access policies and logging ensure traceability and accountability across systems.
VII. Data Retention Policy
Data is retained only for as long as necessary to fulfill the intended business purpose, fulfill contractual obligations, or comply with applicable legal requirements.
Retention Principles:
  • User Data & Authentication Information
    Retained for the duration of the user's account activity and for a limited period thereafter, unless a longer retention period is required or justified.
  • Operational & Application Data
    Retained while it remains relevant for service functionality, analysis, or support purposes. We periodically review and securely dispose of data no longer required.
  • Logs, Backups, and System Data
    Retained for a reasonable period in line with operational continuity and auditing needs. These are automatically purged on a rolling basis or securely deleted after their usefulness has expired.
  • Data Subject Rights
    Individuals may request access to, correction of, or deletion of their personal data, and we respond in accordance with applicable data protection laws, including the GDPR.
  • Secure Disposal:
    When data is no longer needed, it is securely and permanently deleted using industry-standard methods to prevent unauthorized access or recovery.
VIII. Your Rights and Data Choices
Platform users and authorized client representatives have the right to:
  • Request access to the data associated with their user accounts
  • Correct inaccuracies or update contact information
  • Request data deletion or deactivation (where permitted)
  • Object to certain processing or revoke previously given consent
To exercise any of these rights, please contact us using the details provided in Section XV. We may require identity verification before fulfilling your request, and we will respond within the timeframes required by applicable law Agencies acting as data controllers for their clients are responsible for fulfilling requests related to end-customer data.
IX. International Data Transfers
If user or agency data is transferred outside the user's country (including to or from the EEA), we implement appropriate safeguards, including:
  • Standard Contractual Clauses (SCCs)
  • Hosting within compliant jurisdictions
  • Vendor assessments aligned with GDPR or equivalent data transfer principles
X. Children's Privacy
Travelity is intended for professional use only. Our services are not marketed to or intended for children under the age of 18, and we do not knowingly collect data from minors.
XI. Cookies and Tracking Technologies
Cookies and similar tools that may be used:
  • Essential Cookies
    These are necessary for the basic operation of our website or application. They support authentication, security, and core user functionality.
  • Performance and Analytics Cookies
    These cookies help us understand how users interact with our services, enabling us to improve performance and user experience over time.
  • Functionality Cookie
    These remember your preferences and settings to deliver a more personalized experience.
  • Third-Party Cookies and Technologies
    We may work with trusted third-party providers (such as analytics or identity services) who may set their own cookies or use similar technologies. These are subject to their own privacy policies.
Users may control cookie preferences through their browser settings.
XII. U.S. State Privacy Rights
For U.S. users subject to CCPA or other state-level privacy laws, we provide:
  • Transparency on what data is collected
  • A method to request access or deletion of data
  • A commitment not to sell personal data
Authorized users may submit requests through designated contact channels.
XIII. Notice of Financial Incentives
If we provide account-based incentives or early-access promotions, the terms will clearly explain the conditions, value, and user rights. Participation is always optional.
XIV. Updates to this Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, technical, or operational changes. We will notify users of material updates via email or platform notifications, and all changes will be reflected with an updated "Effective Date."
XV. Contacting Travelity
For any data privacy inquiries or user rights requests: Email: support@travelity.app Website: www.travelity.app This Privacy Policy applies to all organizational users of the Travelity platform, including agencies, subcontractors, and registered account holders. It governs the handling of all personal and business data processed through our systems on or after the effective date stated above.
Start Your 60-day Free Trial
no credit card required
Ready to Transform Your Tourism Business?

Join thousands of tourism professionals who have already optimized their operations with Travelity.