Travafa Privacy Policy

Version 2.0 — Last updated: 23 August 2026 Effective date: 23 August 2026

This policy explains what Travafa collects, why, who receives it, how long we keep it, and what you can do about it. It is written against what the Travafa app, website and backend actually do — every category below maps to code that runs in production.

Controller / Data Fiduciary: Pirtztel Technologies Private Limited CIN: U62099TN2024PTC171339 Registered office: 3/1256 AB, Transport Nagar 6th, Karaikudi Southstreet, Karaikudi, Sivaganga - 630002, Tamil Nadu, India Contact: support@travafa.com

Quick summary — the short version, which does not replace the detail below:

  • We collect your phone number and/or email to create your account, and we verify both with a one-time code.
  • Device permissions (location, contacts, photos, calendar, camera, microphone) are all optional and each powers one specific feature.
  • We do not sell your personal information and we do not share it for cross-context behavioural advertising.
  • Your data is processed in the United States, and by the sub-processors listed in §7.
  • You can delete your account and your data from inside the app.

1. Scope

This policy applies to the Travafa mobile app (iOS and Android), the Travafa website, and the backend services behind them (the "Service").

It does not apply to third-party sites or services you reach through Travafa — for example an airline's own booking page, or a hotel's website. Those have their own policies.


2. Information we collect

2.1 Information you give us

DataCollected whenPurpose
Phone number, country and ISO codeSign-up, sign-inAccount identifier; verified by one-time code
Email addressEmail sign-up or added to profileAccount identifier, sign-in, verification, password reset, service email
PasswordEmail sign-up onlyStored only as a salted hash
First and last name, username / handleProfile creationIdentifying you to friends and trip companions
Date of birthProfileAge-appropriate content; bookings that require it
GenderProfile (optional)Personalisation; may be left blank
Profile photo, banner imageProfile (optional)Displayed on your profile
Home location — country, state, city, area, postal codeProfileLocal recommendations, currency and region defaults
Travel preferences — activity types, destination types, budget, travel classOnboarding, profileRecommendations and trip generation
Trips, itineraries, dates, companions, checklistsProduct useDelivering the product
Ratings, reviews, blogs, discussion postsProduct usePublishing what you chose to publish
Peer badges given and receivedProduct useSocial features
Visited places and wishlist ("travelog")Product useYour profile map and recommendations
Traveller and passport detailsOnly for bookings that require themCompleting the booking with the supplier
Support correspondenceWhen you contact usAnswering you; service quality

2.2 Device permissions

Each permission is optional, requested in context, and independently revocable in your device settings. Refusing one disables only the feature it powers.

PermissionFeature it powersNotes
Location — approximate and preciseNearby recommendations, place searchUsed while you are using the app
Location — backgroundLive location sharing with trip participantsCollected only while an active share is running. Turning the share off stops collection.
ContactsContacts Sync — finding which contacts already use TravafaOpt-in; see §3
Photos and mediaUploading photos and video to trips and profile
Media location (photo geotags)Photo Farming — proposing a trip built from photos you selectReads the date and geotag embedded in photos you choose
Camera, microphoneTaking photos and recording video in-app
Calendar — read and writeShowing your commitments while planning; adding confirmed trips
NotificationsTrip updates, messages, booking status
NFC, phone stateDevice capability checks and supported payment/boarding flows
Apple Music (iOS)Soundtrack features for trip media

2.3 Collected automatically

  • Device and app: device identifier, device type, platform, app version, session identifier.
  • Network: IP address — used for security controls (rate-limiting sign-in and one-time-passcode attempts) and coarse region defaults.
  • Push token: Firebase messaging token.
  • Usage and diagnostics: screens viewed, features used, API timings, crashes, error traces.

2.4 We do not collect

  • Your password in readable form.
  • Card numbers, CVV, or UPI credentials — these go directly to our payment processor (§7) and never reach our servers.
  • Biometric identifiers.
  • Precise location when no live share is running.

3. Contacts Sync — stated plainly

This is the most sensitive permission we request, so we are explicit:

  • Contacts Sync is opt-in and never runs unless you start it.
  • We use contact phone numbers to determine which are existing Travafa accounts.
  • We do not sell, rent, or market to your contacts.
  • We do not message non-users on your behalf without telling you first.
  • Revoking the permission stops all further reads. To have previously synced contact data deleted, write to support@travafa.com.
  • Only sync an address book you have permission to use.

4. Live location sharing — stated plainly

  • Off by default. It runs only when you start a share.
  • Visible only to the trip participants you select.
  • Stops when you end the share, when the trip ends, or when you revoke the permission.
  • We retain location share history per §8.

5. Legal bases for processing (EEA / UK)

Where the GDPR or UK GDPR applies, we rely on:

PurposeLegal basis
Creating and operating your account; delivering trips, itineraries, bookingsContract — Art 6(1)(b)
Verifying your phone and emailContract and legal obligation — Art 6(1)(b), 6(1)(c)
Processing payments; keeping tax and accounting recordsLegal obligation — Art 6(1)(c)
Security, fraud prevention, rate limiting, abuse investigationLegitimate interests — Art 6(1)(f) (keeping the Service safe)
Product analytics and crash reportingLegitimate interests — Art 6(1)(f), or consent where required by local law
Contacts Sync, precise/background location, photo and calendar accessConsent — Art 6(1)(a); withdrawable at any time
Marketing emailConsent — Art 6(1)(a); withdrawable at any time
Defending legal claimsLegitimate interests — Art 6(1)(f)

Special-category data: we do not intentionally collect it. If you volunteer health or dietary information in a trip note or a booking request, we process it on the basis of your explicit consent — Art 9(2)(a).


6. How we use your information

  1. Run your account — create, authenticate, verify, recover.
  2. Deliver the product — plan and store trips, generate recommendations, publish what you publish, share live location with people you choose, deliver notifications.
  3. Process bookings and payments — pass a supplier the details it requires.
  4. Keep the Service secure — rate-limit sign-in and passcode attempts, detect abuse, investigate incidents.
  5. Improve the product — understand feature usage, find and fix crashes.
  6. Communicate — verification codes, booking confirmations, service notices. Marketing is separate and opt-out.
  7. Comply with law — tax, accounting, lawful requests.

6.1 Automated processing, AI, and profiling

Travafa uses third-party AI services to generate itineraries, recommendations and in-app assistance. When you use those features, the trip details you supply — destinations, dates, preferences — are sent to the AI provider to produce the result.

  • We do not send your password, payment details, or contact list to AI providers.
  • These features assist your planning. They do not produce legal effects or similarly significant effects about you, so they are not "solely automated decision-making" under GDPR Art 22.
  • AI output can be wrong. Verify anything you will rely on.

We build a preference profile from your stated preferences and product activity to rank recommendations. You can change your preferences at any time in the app.


7. Who receives your information

We do not sell your personal information. We do not share it for cross-context behavioural advertising.

7.1 Sub-processors

ProviderPurposeData receivedPrimary location
Google Firebase / Google CloudAuthentication, storage, push, crash reporting, analytics, remote config, app integrity, hostingAccount and device identifiers, auth tokens, uploaded media, crash and usage dataUnited States
TwilioSMS one-time passcodesPhone number, message contentUnited States
TextlocalSMS one-time passcodes (India)Phone number, message contentIndia
PostHogProduct analyticsPseudonymous account and device identifiers, in-app eventsUnited States / EU
SentryCrash and error monitoringError traces, device and app version, account identifierUnited States
RazorpayPayment processingName, contact details, amount, order referenceIndia
RevenueCatSubscription managementAccount identifier, purchase and entitlement statusUnited States
OpenAIAI itinerary generation and assistancePrompt and trip content needed for the resultUnited States
AnthropicAI assistancePrompt and trip content needed for the resultUnited States
Google Maps / PlacesLocation search, maps, place detailSearch terms, approximate locationUnited States
Email delivery providerVerification, transactional and marketing emailEmail address, message contentUnited States / EU
Airlines, hotels, activity and transfer suppliersCompleting a booking you requestedTraveller details that supplier requiresVaries by supplier
Insurance providers and intermediariesIssuing travel insurance you requestedTraveller details required to issue the policyVaries by insurer

We keep this list current. Material additions will be reflected here.

7.2 Other disclosures

  • Legal: where required by law, court order, or a valid governmental request, and to establish or defend legal claims.
  • Safety: to protect the rights, property or safety of users, the public, or Travafa.
  • Corporate transactions: to an acquirer in a merger, acquisition or asset sale, subject to this policy.

7.3 What other users can see

  • Your profile, handle and photo.
  • Anything you publish — ratings, reviews, blogs, discussion posts — according to that item's visibility.
  • Travelog entries carry their own visibility: Only me, Friends, or Public.
  • Live location, only to trip participants, only while sharing is on.

8. Retention

DataRetained
Account profile and contentWhile the account is active
Account data after deletionRemoved on deletion, except items below
Booking and payment recordsAs long as tax and accounting law requires (typically 7–8 years in India)
Security and access logsUp to 12 months for abuse investigation
One-time passcodesExpire in 10 minutes; erased on use
Password reset and email verification codesExpire per their stated validity; erased on use
Crash and error reportsPer the provider's retention (typically 90 days)
Product analytics eventsPseudonymised; retained per provider settings
Live location share historyDeleted with the trip, or on account deletion
BackupsCycle out on a rolling schedule; deleted data may persist briefly in backups

Deleting your account: in-app under Profile → Settings, or by writing to support@travafa.com. Deletion removes your profile, social connections, and account-linked content. Records we must keep by law are retained as above.


9. International transfers

Our infrastructure runs on Google Cloud Platform in the United States (us-central1). If you use Travafa from India, the EEA, the UK or elsewhere, your information is transferred to and processed in the United States and in the locations listed in §7.1.

Where required, transfers rely on appropriate safeguards — the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent mechanisms with our sub-processors. You can request a copy of the relevant safeguards at support@travafa.com.


10. Cookies and similar technologies (website)

Cookie / storagePurposeType
tvfuidYour user identifier for the sessionStrictly necessary
tvfTokenFirebase ID token (stored in localStorage; too large for a cookie)Strictly necessary
access_tokenServer-side session tokenStrictly necessary
tvfUserAuthLogin session referenceStrictly necessary
tvfDeviceIdDevice identifier for security and rate limitingStrictly necessary
GuestNationalityRegion defaults for guest browsingFunctional
Google AnalyticsAggregate site usageAnalytics
PostHogProduct analyticsAnalytics
SentryError monitoringAnalytics / diagnostics

10.1 Your choices

Analytics cookies load only after you agree. Until you make a choice, no analytics runs — neither Google Analytics nor our own product analytics. You can change your decision at any time using Cookie settings in the site footer, which is as easy to use as the original banner.

Strictly necessary cookies cannot be switched off — the site cannot sign you in without them. You can also block or delete cookies in your browser; doing so may break sign-in.

Do Not Track / Global Privacy Control: if your browser sends a GPC or DNT signal we treat it as a standing refusal of non-essential tracking. We do not show you the banner and we do not load analytics. We do not sell or share personal information for advertising in any case.


11. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing, to data portability, to withdraw consent, and to not be discriminated against for exercising these rights.

How to exercise them: use the in-app controls (most profile fields are directly editable, and deletion is self-service), or write to support@travafa.com. We respond within the period applicable law requires — 30 days in most jurisdictions. We may need to verify your identity first, and we will not charge you unless a request is manifestly unfounded or excessive.

11.1 India — Digital Personal Data Protection Act, 2023

Travafa is a Data Fiduciary. As a Data Principal you may access a summary of your data and our processing, seek correction or erasure, nominate another person to exercise your rights in the event of death or incapacity, and raise a grievance.

Grievance Officer: reachable at support@travafa.com. We acknowledge grievances within 48 hours and resolve them within 30 days. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India.

11.2 EEA / UK — GDPR

You may lodge a complaint with your local supervisory authority.

Travafa is established in India and does not currently have an establishment in the EEA or UK. We have not appointed an Article 27 representative or a Data Protection Officer, as we do not believe our processing currently triggers those requirements. This is kept under review as we grow, and this section will be updated if that changes. In the meantime, EEA and UK users can exercise every right in this section directly at support@travafa.com, and we will respond within one month.

11.3 California — CCPA / CPRA

In the preceding 12 months we collected these categories: identifiers (name, email, phone, device and account IDs); customer records (name, contact details, payment-related records); protected classifications (age/date of birth, gender — optional); commercial information (bookings, subscriptions); internet activity (app and site usage); geolocation; audio/visual (photos and video you upload); and inferences (travel preferences). We disclosed these for business purposes to the sub-processors in §7.1.

We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the preceding 12 months.

We do not use or disclose sensitive personal information for purposes requiring a right to limit under the CPRA.

You may request to know, delete, or correct, and may use an authorised agent. Submit requests to support@travafa.com. We will not discriminate against you for exercising these rights.

11.4 Other US states

Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah and Texas) have equivalent rights of access, correction, deletion, portability and opt-out, and a right to appeal a refused request. To appeal, reply to our decision or write to support@travafa.com with "Appeal" in the subject.


12. Security

  • Authentication tokens and credentials are held in platform secure storage — iOS Keychain, Android EncryptedSharedPreferences.
  • Passwords are stored only as salted hashes.
  • All traffic between clients and our servers uses TLS.
  • Sign-in, one-time-passcode, password-reset and password-change endpoints are rate-limited.
  • One-time passcodes expire after 10 minutes and are burned on use.
  • Access to production data is restricted to personnel who need it.

No system is perfectly secure. If a breach affecting your personal information occurs, we will notify the relevant supervisory authority without undue delay and within 72 hours where the GDPR applies, notify the Data Protection Board of India as the DPDP Act requires, and notify affected users where the law requires or the risk warrants it.

Reporting a vulnerability: support@travafa.com. We will not pursue good-faith researchers who report privately and do not access other users' data.


13. Children

Travafa is not directed to children under 13, or under the higher age local law sets (16 in much of the EEA; 18 for independent consent under India's DPDP Act). We do not knowingly collect their personal information.

Where the DPDP Act applies, processing a child's data requires verifiable parental consent, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children.

If you believe a child has provided us personal information, write to support@travafa.com and we will delete it.


14. Changes

We will post any change here and update the version and date. For material changes we will give notice in the app or by email before the change takes effect, and where the law requires it, seek your consent.


15. Contact

AddressUse it for
support@travafa.comPrivacy and data rights, Grievance Officer (India), security and vulnerability reports, and general support
corporate@travafa.comLegal and copyright

Postal: 3/1256 AB, Transport Nagar 6th, Karaikudi Southstreet, Karaikudi, Sivaganga - 630002, Tamil Nadu, India


Document control

EntityPirtztel Technologies Private Limited
CINU62099TN2024PTC171339
Registered office3/1256 AB, Transport Nagar 6th, Karaikudi Southstreet, Karaikudi, Sivaganga - 630002, Tamil Nadu, India
Version2.0
Effective23 August 2026

Revisit within ~1 month (as agreed at launch): whether EEA/UK user volume now requires an Article 27 representative, and whether to name an individual Grievance Officer in place of the role mailbox.