Travafa Privacy Policy
Version 2.0 — Last updated: 23 August 2026 Effective date: 23 August 2026
This policy explains what Travafa collects, why, who receives it, how long we keep it, and what you can do about it. It is written against what the Travafa app, website and backend actually do — every category below maps to code that runs in production.
Controller / Data Fiduciary: Pirtztel Technologies Private Limited CIN: U62099TN2024PTC171339 Registered office: 3/1256 AB, Transport Nagar 6th, Karaikudi Southstreet, Karaikudi, Sivaganga - 630002, Tamil Nadu, India Contact: support@travafa.com
Quick summary — the short version, which does not replace the detail below:
- We collect your phone number and/or email to create your account, and we verify both with a one-time code.
- Device permissions (location, contacts, photos, calendar, camera, microphone) are all optional and each powers one specific feature.
- We do not sell your personal information and we do not share it for cross-context behavioural advertising.
- Your data is processed in the United States, and by the sub-processors listed in §7.
- You can delete your account and your data from inside the app.
1. Scope
This policy applies to the Travafa mobile app (iOS and Android), the Travafa website, and the backend services behind them (the "Service").
It does not apply to third-party sites or services you reach through Travafa — for example an airline's own booking page, or a hotel's website. Those have their own policies.
2. Information we collect
2.1 Information you give us
| Data | Collected when | Purpose |
|---|---|---|
| Phone number, country and ISO code | Sign-up, sign-in | Account identifier; verified by one-time code |
| Email address | Email sign-up or added to profile | Account identifier, sign-in, verification, password reset, service email |
| Password | Email sign-up only | Stored only as a salted hash |
| First and last name, username / handle | Profile creation | Identifying you to friends and trip companions |
| Date of birth | Profile | Age-appropriate content; bookings that require it |
| Gender | Profile (optional) | Personalisation; may be left blank |
| Profile photo, banner image | Profile (optional) | Displayed on your profile |
| Home location — country, state, city, area, postal code | Profile | Local recommendations, currency and region defaults |
| Travel preferences — activity types, destination types, budget, travel class | Onboarding, profile | Recommendations and trip generation |
| Trips, itineraries, dates, companions, checklists | Product use | Delivering the product |
| Ratings, reviews, blogs, discussion posts | Product use | Publishing what you chose to publish |
| Peer badges given and received | Product use | Social features |
| Visited places and wishlist ("travelog") | Product use | Your profile map and recommendations |
| Traveller and passport details | Only for bookings that require them | Completing the booking with the supplier |
| Support correspondence | When you contact us | Answering you; service quality |
2.2 Device permissions
Each permission is optional, requested in context, and independently revocable in your device settings. Refusing one disables only the feature it powers.
| Permission | Feature it powers | Notes |
|---|---|---|
| Location — approximate and precise | Nearby recommendations, place search | Used while you are using the app |
| Location — background | Live location sharing with trip participants | Collected only while an active share is running. Turning the share off stops collection. |
| Contacts | Contacts Sync — finding which contacts already use Travafa | Opt-in; see §3 |
| Photos and media | Uploading photos and video to trips and profile | |
| Media location (photo geotags) | Photo Farming — proposing a trip built from photos you select | Reads the date and geotag embedded in photos you choose |
| Camera, microphone | Taking photos and recording video in-app | |
| Calendar — read and write | Showing your commitments while planning; adding confirmed trips | |
| Notifications | Trip updates, messages, booking status | |
| NFC, phone state | Device capability checks and supported payment/boarding flows | |
| Apple Music (iOS) | Soundtrack features for trip media |
2.3 Collected automatically
- Device and app: device identifier, device type, platform, app version, session identifier.
- Network: IP address — used for security controls (rate-limiting sign-in and one-time-passcode attempts) and coarse region defaults.
- Push token: Firebase messaging token.
- Usage and diagnostics: screens viewed, features used, API timings, crashes, error traces.
2.4 We do not collect
- Your password in readable form.
- Card numbers, CVV, or UPI credentials — these go directly to our payment processor (§7) and never reach our servers.
- Biometric identifiers.
- Precise location when no live share is running.
3. Contacts Sync — stated plainly
This is the most sensitive permission we request, so we are explicit:
- Contacts Sync is opt-in and never runs unless you start it.
- We use contact phone numbers to determine which are existing Travafa accounts.
- We do not sell, rent, or market to your contacts.
- We do not message non-users on your behalf without telling you first.
- Revoking the permission stops all further reads. To have previously synced contact data deleted, write to support@travafa.com.
- Only sync an address book you have permission to use.
4. Live location sharing — stated plainly
- Off by default. It runs only when you start a share.
- Visible only to the trip participants you select.
- Stops when you end the share, when the trip ends, or when you revoke the permission.
- We retain location share history per §8.
5. Legal bases for processing (EEA / UK)
Where the GDPR or UK GDPR applies, we rely on:
| Purpose | Legal basis |
|---|---|
| Creating and operating your account; delivering trips, itineraries, bookings | Contract — Art 6(1)(b) |
| Verifying your phone and email | Contract and legal obligation — Art 6(1)(b), 6(1)(c) |
| Processing payments; keeping tax and accounting records | Legal obligation — Art 6(1)(c) |
| Security, fraud prevention, rate limiting, abuse investigation | Legitimate interests — Art 6(1)(f) (keeping the Service safe) |
| Product analytics and crash reporting | Legitimate interests — Art 6(1)(f), or consent where required by local law |
| Contacts Sync, precise/background location, photo and calendar access | Consent — Art 6(1)(a); withdrawable at any time |
| Marketing email | Consent — Art 6(1)(a); withdrawable at any time |
| Defending legal claims | Legitimate interests — Art 6(1)(f) |
Special-category data: we do not intentionally collect it. If you volunteer health or dietary information in a trip note or a booking request, we process it on the basis of your explicit consent — Art 9(2)(a).
6. How we use your information
- Run your account — create, authenticate, verify, recover.
- Deliver the product — plan and store trips, generate recommendations, publish what you publish, share live location with people you choose, deliver notifications.
- Process bookings and payments — pass a supplier the details it requires.
- Keep the Service secure — rate-limit sign-in and passcode attempts, detect abuse, investigate incidents.
- Improve the product — understand feature usage, find and fix crashes.
- Communicate — verification codes, booking confirmations, service notices. Marketing is separate and opt-out.
- Comply with law — tax, accounting, lawful requests.
6.1 Automated processing, AI, and profiling
Travafa uses third-party AI services to generate itineraries, recommendations and in-app assistance. When you use those features, the trip details you supply — destinations, dates, preferences — are sent to the AI provider to produce the result.
- We do not send your password, payment details, or contact list to AI providers.
- These features assist your planning. They do not produce legal effects or similarly significant effects about you, so they are not "solely automated decision-making" under GDPR Art 22.
- AI output can be wrong. Verify anything you will rely on.
We build a preference profile from your stated preferences and product activity to rank recommendations. You can change your preferences at any time in the app.
7. Who receives your information
We do not sell your personal information. We do not share it for cross-context behavioural advertising.
7.1 Sub-processors
| Provider | Purpose | Data received | Primary location |
|---|---|---|---|
| Google Firebase / Google Cloud | Authentication, storage, push, crash reporting, analytics, remote config, app integrity, hosting | Account and device identifiers, auth tokens, uploaded media, crash and usage data | United States |
| Twilio | SMS one-time passcodes | Phone number, message content | United States |
| Textlocal | SMS one-time passcodes (India) | Phone number, message content | India |
| PostHog | Product analytics | Pseudonymous account and device identifiers, in-app events | United States / EU |
| Sentry | Crash and error monitoring | Error traces, device and app version, account identifier | United States |
| Razorpay | Payment processing | Name, contact details, amount, order reference | India |
| RevenueCat | Subscription management | Account identifier, purchase and entitlement status | United States |
| OpenAI | AI itinerary generation and assistance | Prompt and trip content needed for the result | United States |
| Anthropic | AI assistance | Prompt and trip content needed for the result | United States |
| Google Maps / Places | Location search, maps, place detail | Search terms, approximate location | United States |
| Email delivery provider | Verification, transactional and marketing email | Email address, message content | United States / EU |
| Airlines, hotels, activity and transfer suppliers | Completing a booking you requested | Traveller details that supplier requires | Varies by supplier |
| Insurance providers and intermediaries | Issuing travel insurance you requested | Traveller details required to issue the policy | Varies by insurer |
We keep this list current. Material additions will be reflected here.
7.2 Other disclosures
- Legal: where required by law, court order, or a valid governmental request, and to establish or defend legal claims.
- Safety: to protect the rights, property or safety of users, the public, or Travafa.
- Corporate transactions: to an acquirer in a merger, acquisition or asset sale, subject to this policy.
7.3 What other users can see
- Your profile, handle and photo.
- Anything you publish — ratings, reviews, blogs, discussion posts — according to that item's visibility.
- Travelog entries carry their own visibility: Only me, Friends, or Public.
- Live location, only to trip participants, only while sharing is on.
8. Retention
| Data | Retained |
|---|---|
| Account profile and content | While the account is active |
| Account data after deletion | Removed on deletion, except items below |
| Booking and payment records | As long as tax and accounting law requires (typically 7–8 years in India) |
| Security and access logs | Up to 12 months for abuse investigation |
| One-time passcodes | Expire in 10 minutes; erased on use |
| Password reset and email verification codes | Expire per their stated validity; erased on use |
| Crash and error reports | Per the provider's retention (typically 90 days) |
| Product analytics events | Pseudonymised; retained per provider settings |
| Live location share history | Deleted with the trip, or on account deletion |
| Backups | Cycle out on a rolling schedule; deleted data may persist briefly in backups |
Deleting your account: in-app under Profile → Settings, or by writing to support@travafa.com. Deletion removes your profile, social connections, and account-linked content. Records we must keep by law are retained as above.
9. International transfers
Our infrastructure runs on Google Cloud Platform in the United States (us-central1). If you use Travafa from India, the EEA, the UK or elsewhere, your information is transferred to and processed in the United States and in the locations listed in §7.1.
Where required, transfers rely on appropriate safeguards — the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent mechanisms with our sub-processors. You can request a copy of the relevant safeguards at support@travafa.com.
10. Cookies and similar technologies (website)
| Cookie / storage | Purpose | Type |
|---|---|---|
tvfuid | Your user identifier for the session | Strictly necessary |
tvfToken | Firebase ID token (stored in localStorage; too large for a cookie) | Strictly necessary |
access_token | Server-side session token | Strictly necessary |
tvfUserAuth | Login session reference | Strictly necessary |
tvfDeviceId | Device identifier for security and rate limiting | Strictly necessary |
GuestNationality | Region defaults for guest browsing | Functional |
| Google Analytics | Aggregate site usage | Analytics |
| PostHog | Product analytics | Analytics |
| Sentry | Error monitoring | Analytics / diagnostics |
10.1 Your choices
Analytics cookies load only after you agree. Until you make a choice, no analytics runs — neither Google Analytics nor our own product analytics. You can change your decision at any time using Cookie settings in the site footer, which is as easy to use as the original banner.
Strictly necessary cookies cannot be switched off — the site cannot sign you in without them. You can also block or delete cookies in your browser; doing so may break sign-in.
Do Not Track / Global Privacy Control: if your browser sends a GPC or DNT signal we treat it as a standing refusal of non-essential tracking. We do not show you the banner and we do not load analytics. We do not sell or share personal information for advertising in any case.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing, to data portability, to withdraw consent, and to not be discriminated against for exercising these rights.
How to exercise them: use the in-app controls (most profile fields are directly editable, and deletion is self-service), or write to support@travafa.com. We respond within the period applicable law requires — 30 days in most jurisdictions. We may need to verify your identity first, and we will not charge you unless a request is manifestly unfounded or excessive.
11.1 India — Digital Personal Data Protection Act, 2023
Travafa is a Data Fiduciary. As a Data Principal you may access a summary of your data and our processing, seek correction or erasure, nominate another person to exercise your rights in the event of death or incapacity, and raise a grievance.
Grievance Officer: reachable at support@travafa.com. We acknowledge grievances within 48 hours and resolve them within 30 days. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India.
11.2 EEA / UK — GDPR
You may lodge a complaint with your local supervisory authority.
Travafa is established in India and does not currently have an establishment in the EEA or UK. We have not appointed an Article 27 representative or a Data Protection Officer, as we do not believe our processing currently triggers those requirements. This is kept under review as we grow, and this section will be updated if that changes. In the meantime, EEA and UK users can exercise every right in this section directly at support@travafa.com, and we will respond within one month.
11.3 California — CCPA / CPRA
In the preceding 12 months we collected these categories: identifiers (name, email, phone, device and account IDs); customer records (name, contact details, payment-related records); protected classifications (age/date of birth, gender — optional); commercial information (bookings, subscriptions); internet activity (app and site usage); geolocation; audio/visual (photos and video you upload); and inferences (travel preferences). We disclosed these for business purposes to the sub-processors in §7.1.
We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the preceding 12 months.
We do not use or disclose sensitive personal information for purposes requiring a right to limit under the CPRA.
You may request to know, delete, or correct, and may use an authorised agent. Submit requests to support@travafa.com. We will not discriminate against you for exercising these rights.
11.4 Other US states
Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah and Texas) have equivalent rights of access, correction, deletion, portability and opt-out, and a right to appeal a refused request. To appeal, reply to our decision or write to support@travafa.com with "Appeal" in the subject.
12. Security
- Authentication tokens and credentials are held in platform secure storage — iOS Keychain, Android EncryptedSharedPreferences.
- Passwords are stored only as salted hashes.
- All traffic between clients and our servers uses TLS.
- Sign-in, one-time-passcode, password-reset and password-change endpoints are rate-limited.
- One-time passcodes expire after 10 minutes and are burned on use.
- Access to production data is restricted to personnel who need it.
No system is perfectly secure. If a breach affecting your personal information occurs, we will notify the relevant supervisory authority without undue delay and within 72 hours where the GDPR applies, notify the Data Protection Board of India as the DPDP Act requires, and notify affected users where the law requires or the risk warrants it.
Reporting a vulnerability: support@travafa.com. We will not pursue good-faith researchers who report privately and do not access other users' data.
13. Children
Travafa is not directed to children under 13, or under the higher age local law sets (16 in much of the EEA; 18 for independent consent under India's DPDP Act). We do not knowingly collect their personal information.
Where the DPDP Act applies, processing a child's data requires verifiable parental consent, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
If you believe a child has provided us personal information, write to support@travafa.com and we will delete it.
14. Changes
We will post any change here and update the version and date. For material changes we will give notice in the app or by email before the change takes effect, and where the law requires it, seek your consent.
15. Contact
| Address | Use it for |
|---|---|
| support@travafa.com | Privacy and data rights, Grievance Officer (India), security and vulnerability reports, and general support |
| corporate@travafa.com | Legal and copyright |
Postal: 3/1256 AB, Transport Nagar 6th, Karaikudi Southstreet, Karaikudi, Sivaganga - 630002, Tamil Nadu, India
Document control
| Entity | Pirtztel Technologies Private Limited |
| CIN | U62099TN2024PTC171339 |
| Registered office | 3/1256 AB, Transport Nagar 6th, Karaikudi Southstreet, Karaikudi, Sivaganga - 630002, Tamil Nadu, India |
| Version | 2.0 |
| Effective | 23 August 2026 |
Revisit within ~1 month (as agreed at launch): whether EEA/UK user volume now requires an Article 27 representative, and whether to name an individual Grievance Officer in place of the role mailbox.
