Overview
TravOps AI ("we", "us", "our") operates the website https://travopsai.com (the "Website") and the TravOps AI platform — an AI-powered ERP for travel agencies, tour operators, Umrah companies, OTAs, and corporate travel businesses (the "Service").
This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the rights you have. It is written to comply with the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA), and applicable Pakistani law.
1. Who Is Responsible for Your Data
The data controller is:
[Registered legal entity name]
[Registered address], Pakistan
Email: hello@travops.ai · Phone: +92 42 3123 4567
2. Data We Collect
2.1 Data you give us directly
- Demo request form: name, company name, phone number, email address, country, and any message you include.
- Communications: emails, calls, or messages you send to us (e.g., to hello@travops.ai or support@travops.ai).
- Account data (platform users): login credentials, role, branch, and profile details created when your organization is onboarded to the Service.
2.2 Data collected automatically
- Usage data: pages visited, time on page, referral source, clicks, and general interaction with the Website.
- Device data: IP address, browser type, operating system, device identifiers, and approximate location derived from IP.
- Cookies and pixels: via Google Analytics, Meta Pixel, and Google Ads tags — see our Cookie Policy for details.
2.3 Customer business data (platform)
When your organization uses the Service, it may enter data about its own customers, bookings, PNRs, passengers, invoices, employees, and accounts ("Customer Data"). For Customer Data, your organization is the data controller and we act as a data processor, handling it only on your organization's instructions. You own your data and can export or audit your records at any time.
3. How and Why We Use Your Data
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Responding to demo requests and inquiries | Form and contact data | Legitimate interests / pre-contract steps |
| Providing and operating the Service | Account data, Customer Data | Contract performance |
| Improving the Website and Service | Usage and device data | Legitimate interests / consent |
| Marketing and advertising measurement | Cookie and pixel data | Consent |
| Sending service updates and marketing emails | Contact data | Consent / legitimate interests (with opt-out) |
| Security, fraud prevention, audit trails | Account, device, usage data | Legitimate interests / legal obligation |
| Complying with legal obligations | As required | Legal obligation |
We do not use your personal data for automated decisions that produce legal or similarly significant effects about you. AI features in the Service (such as lead scoring or quotation drafting) only assist your team — humans review and approve before any action is taken.
4. Who We Share Data With
We do not sell personal data for money. We share data only with:
- Service providers: hosting, email delivery, analytics (Google), and advertising platforms (Meta, Google), under appropriate contractual safeguards.
- Professional advisers: lawyers, accountants, auditors where necessary.
- Authorities: where required by law, court order, or to protect rights and safety.
- Business transfers: if we merge, are acquired, or sell assets, data may transfer as part of that transaction, subject to this policy.
California note: The use of advertising cookies/pixels may qualify as "sharing" personal information for cross-context behavioral advertising under the CCPA/CPRA. You may opt out at any time (see Section 8).
5. International Transfers
We are based in Pakistan, and our service providers (including Google and Meta) may process data in the United States and other countries. Where we transfer data of EU/EEA or UK residents internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or equivalent mechanisms.
6. Data Retention
We keep personal data only as long as needed for the purposes described above:
- Demo/inquiry data: up to 24 months after last contact, unless you become a customer.
- Account data: for the life of your organization's account plus a reasonable period for legal and audit purposes.
- Customer Data: for as long as your organization uses the Service; on termination, your organization may export its data, after which it is deleted in line with our deletion schedule.
- Analytics/advertising data: per the durations in our Cookie Policy.
7. Security
We use administrative, technical, and organizational safeguards appropriate to the risk, including role-based access controls, audit trails, multi-branch data isolation, and encrypted connections. No system is 100% secure, but we work to protect your data against unauthorized access, loss, or misuse.
8. Your Rights
8.1 If you are in the EU/EEA or UK (GDPR)
You have the right to: access your data; rectify inaccurate data; erase your data; restrict or object to processing; data portability; and withdraw consent at any time (without affecting prior processing). You may also lodge a complaint with your local supervisory authority.
8.2 If you are a California resident (CCPA/CPRA)
You have the right to: know what personal information we collect and how it is used; access and receive a copy of it; correct inaccurate information; delete your personal information; opt out of the "sale" or "sharing" of personal information (including via advertising cookies); limit use of sensitive personal information; and not be discriminated against for exercising these rights. You may use an authorized agent to submit requests.
8.3 If you are in Pakistan
You may request access to, correction of, or deletion of your personal data, and object to its use for direct marketing, consistent with applicable Pakistani data protection law.
To exercise any right, email hello@travops.ai with the subject "Privacy Request". We will verify your identity and respond within the timeframe required by applicable law (generally 30 days under GDPR, 45 days under CCPA).
9. Children's Privacy
The Website and Service are intended for businesses and are not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
10. Third-Party Links
The Website may link to third-party sites (e.g., our social media pages). We are not responsible for their privacy practices; review their policies separately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date shows the latest revision. Material changes will be notified on the Website or by email where appropriate.