1. Who we are
Travelboost Inc. is the data controller for the personal data described in this policy. Our registered office is 251 Little Falls Drive, Wilmington, DE 19808, United States. You can contact our Data Protection Officer at [email protected].
2. Data we collect
2.1 Data you give us
- Account data: name, email address, phone number, agency name, password (hashed).
- Billing data: billing address, VAT number, payment method (processed by our payment provider, not stored by us).
- Content you upload: leads, customers, bookings, invoices, files, notes, messages — collectively “Customer Data”.
- Communications: support tickets, sales enquiries, feedback, survey responses.
2.2 Data we collect automatically
- Usage data: pages visited, features used, timestamps, errors, performance metrics.
- Device data: IP address, browser type, operating system, device identifiers, language.
- Cookies and similar technologies: see our Cookie Policy.
2.3 Data from third parties
- Authentication providers (Google, Microsoft) if you sign in with them.
- Payment providers (Stripe, PayPal) for billing status.
- Marketing tools (analytics, ad platforms) if you clicked one of our campaigns.
3. Why we use your data (legal bases)
Under GDPR and similar laws, we process personal data on the following bases:
| Purpose | Legal basis |
|---|---|
| Provide and operate the Service | Contract (Article 6(1)(b) GDPR) |
| Bill you and collect payments | Contract + legal obligation |
| Send service, security, and legal notices | Legal obligation + legitimate interest |
| Improve the Service; fix bugs; monitor abuse | Legitimate interest |
| Send marketing about our own products | Consent (opt-out anytime) |
| Comply with tax, accounting, and law-enforcement obligations | Legal obligation |
| Establish, exercise, or defend legal claims | Legitimate interest |
4. Sharing your data
We do not sell personal data. We share data only in these limited cases:
- Sub-processors: service providers who process data on our behalf under written contracts — hosting (DigitalOcean, AWS), transactional email (SendGrid, Amazon SES), payments (Stripe, PayPal), analytics (privacy-preserving providers). The current list is available on request from [email protected].
- Affiliates: group companies bound by the same privacy standards.
- Legal: when required by law, court order, or to protect our rights and the safety of users.
- Successors: in connection with a merger, acquisition, or sale of assets, subject to equivalent protections.
5. International transfers
We are based in the United States. If you access the Service from outside the US, your data may be transferred to and processed in the US or other countries where we or our sub-processors operate. When we transfer personal data out of the EEA, UK, or Switzerland, we rely on the Standard Contractual Clauses published by the European Commission (2021/914) and, where applicable, the UK International Data Transfer Addendum.
6. Data retention
- Account data: retained for the life of your account. Deleted 30 days after termination; backups purge within 90 days.
- Customer Data: same as above. Full export is available on request.
- Billing records: retained for 7 years to meet accounting and tax obligations.
- Support communications: retained for 3 years after the last interaction.
- Marketing data: until you unsubscribe or we notice you're inactive for 24 months.
7. Your rights
Depending on your jurisdiction, you may have the following rights over your personal data:
- Access — request a copy of the data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion, subject to legal retention obligations.
- Restriction — limit how we process your data.
- Portability — receive your data in a machine-readable format.
- Object — object to processing based on legitimate interest, including marketing.
- Withdraw consent — where processing is based on consent, at any time.
- Lodge a complaint — with your local supervisory authority (e.g. ICO in the UK, CNIL in France).
To exercise any of these rights, email [email protected] from the email address on your account. We respond within 30 days.
8. California residents (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we collect, sell, or share; to delete personal information; to correct inaccurate personal information; to opt out of sale or sharing (we do not sell); and to limit use of sensitive personal information. We do not discriminate against you for exercising these rights. Contact [email protected].
9. Security
We employ industry-standard technical and organisational measures to protect your personal data — TLS 1.3 encryption in transit, AES-256 at rest, isolated tenants, principle of least privilege, and 24/7 monitoring. See the Security Policy for details.
10. Children
The Service is not directed to individuals under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified via email or in-app notice at least 30 days before they take effect. The “Effective” date at the top of this page indicates the current version.
12. Contact
For any privacy question, or to exercise any of your rights:
Data Protection Officer
Travelboost Inc.
251 Little Falls Drive
Wilmington, DE 19808
United States
Email: [email protected]
