Skip to main content

Legal

Privacy Policy

This policy explains what Travia collects, why, who else sees it, how long we keep it, and what you can do about it. It describes the system as it actually works — the tables below are generated from an audit of the platform itself.

Last verified against the platform on 2026-10-07.This document was written by Travia's engineering team to describe accurately how the system works. It has not yet been reviewed by legal counsel, and it is not legal advice.

Travia is an AI-powered travel platform. We compare flights, stays, tours, car rentals, real estate and events across providers, and we host business pages for the operators who list with us. We also run Travia Marg, which records the outdoor activity you choose to track — that involves precise location and, if you connect a sensor, heart-rate data, so it is set out in its own row in the table below.

Travia AI Pvt. Ltd. is the data controllerfor the personal data described here — we decide what is collected and why. This policy covers travia.ai, the Travia API, and the business and platform dashboards. It does not cover a partner's own website: when you follow a link out to an airline, hotel or partner booking site to complete a booking, that company's privacy policy governs what happens there.

Privacy questions go to support@travia.ai.

This table is the complete list. Each row names the actual fields involved, the reason we hold them, the lawful basis under Article 6 GDPR, and what causes the data to go away.

CategoryWhat it includesWhyLawful basisHow long
Profile basicsName, email address, profile photo, bio, account type. Travia has no passwords — you sign in with a one-time code or link sent to your address, so there is no credential to store.To create and operate your account, sign you in, and show you as the author of things you post.ContractUntil you delete your account. Deletion anonymises the record immediately (see “Deleting your account”).
Contact and profile detailsPhone number (and whether it is verified), date of birth, gender, citizenship, street address, city, state, postcode, preferred currency, appearance settings, the activities and travel goals you chose during setup, and your separate analytics and advertising consent decisions.To complete bookings, meet traveller-identification requirements, and show prices and the interface the way you chose.ContractUntil you change or delete them, or delete your account.
Travel documentsPassport number, names and expiry date. Optionally, a scanned copy of the data page — off by default, and only kept if you explicitly choose to keep it.To pre-fill booking forms that legally require passport details, so you do not retype them for every trip.ConsentUntil you remove them or delete your account. Encrypted at rest with AES-256-GCM (helper/crypto.helper.js); a scan you did not opt to keep is processed in memory and never written to storage.
Bookings and transactionsBookings, enquiries, viewings, commission and tax ledger entries, subscription and deposit records.To provide the booking itself, to support you afterwards, and to meet accounting and tax obligations.ContractKept after account deletion, in anonymised form: the transaction is retained for statutory accounting purposes, but it is no longer linked to an identifiable person.
Content you createReviews, journal entries, trips, guides, events you organise, photos, event memories, messages and support tickets.To publish or deliver the thing you created, and to run the features you used it in.ContractUntil you delete the item, or delete your account.
ActivitySearch history, recently viewed listings, saved searches, saved items, visited places.To show you your own history and to make results relevant to you.Legitimate interestCapped at the 200 most recent entries per type, and clearable at any time from Profile → Your activity.
Security and sign-in recordsSign-in history (device, browser, approximate location derived from IP), a random per-browser device identifier that lets Security → Devices sign out one browser without touching your others, and an append-only audit log of security-relevant actions on your account.To detect and investigate unauthorised access, and to let you see and revoke your own sessions.Legitimate interestSecurity events are retained for up to 5 years and authentication events for 1 year, then removed automatically (modules/audit/auditLogSchema.js).
Approximate location (for “near you”)A city-level location derived from your IP address, or a precise location if — and only if — you grant your browser’s location permission.To show what is near you instead of a default city.Legitimate interest (IP-derived) / Consent (precise device location)The IP-derived lookup is cached for 24 hours and never written to your profile. A precise fix used for these “near you” sections is stored in your own browser and is not sent to us unless you act on it. Recording an activity in Travia Marg is separate and is described in its own row below.
Recorded outdoor activity (Travia Marg)For each activity you record or upload: the full route as a list of coordinates with timestamps, start and end points, distance, duration, elevation gain and speed, the activity type and any tags, plus your own title, notes and photos. If you connect a heart-rate sensor or a fitness account (for example Strava, Garmin or Wahoo), also average and maximum heart rate, time in each heart-rate zone, and the individual heart-rate samples. Gear you record, and your challenge progress.To give you the activity back — its map, splits and statistics — to verify Himalayan Challenge progress and the Miles it earns, and to show the activity to whoever you chose to share it with.Contract (the recording is the feature you asked for). Heart-rate and other health-related figures are processed on Consent — they arrive only if you deliberately connect a sensor or a fitness account, and disconnecting stops it.Until you delete the activity or your account. A deleted activity is recoverable from “Recently deleted” for a limited window and is then removed. Visibility is yours to set per activity, and an activity is not public unless you publish it.
Reservations from a business’s connected channelsWhen a hotel or other business connects its listings on other booking sites to Travia’s channel manager, reservations made on those sites are sent to Travia for that business: the guest’s name and contact details as the booking site provides them, dates, room and number of guests, and price. Calendar (iCal) connections carry dates only — no guest details.So the business can see every booking in one calendar and avoid selling the same room twice. Travia processes this data on the business’s behalf; it is not used for anything else, including marketing.Contract (with the business, which is the controller of its guests’ data)For as long as the business keeps the booking or the connection, or until the business deletes it. The calendar feed Travia publishes back to those sites contains blocked dates only, never guest data.
CommunicationsSupport tickets and replies, contact-form enquiries, and emails you send to support@travia.ai.To answer you and to keep a record of what was agreed.Contract / Legitimate interestUntil the enquiry is resolved and no longer needed for reference.

We do not sell personal data. We do not use your bookings, messages or travel documents to train AI models.

Passport details are optional. You can use Travia without ever entering them; they exist so that bookings which legally require them do not make you retype the same details for every trip.

  • Passport number and names are encrypted at rest with AES-256-GCM. They are decrypted only for you, on your own profile.
  • A scan of your passport page is discarded by default. When you use the scan feature, the image is read in memory and never written to storage unless you explicitly tick the option to keep a copy.
  • A kept copy is stored encrypted, is never returned in ordinary profile responses, and is destroyed when you remove it or delete your account.
  • Travel documents are never part of your public profile and are never shared with AI providers.

When you create an account, a public profile page is created by default. It can show your display name, photo, bio, country, follower and connection counts, and reviews you have written after a completed booking or viewing.

Your email address, phone number, date of birth, home address, travel documents, bookings, saved items and messages are never part of your public profile, whatever its visibility setting.

You can make your profile private at any time in Preferences → Privacy, which removes the public page immediately. Business pages are always public — that is what makes them findable by travellers.

We use the services below to run Travia. Each is bound by a data-processing agreement and may only process your data on our instructions. Services we call for public reference data only — currency rates, encyclopaedia lookups, timetable data — are not listed, because none of your personal data reaches them.

ServiceWhat it doesWhat it receivesWhere
MongoDB AtlasPrimary database — everything described above is stored here.All account and content data.India (Mumbai)
VercelHosting for the website and the API.Request metadata, including IP address, as part of serving pages.India (Mumbai) / global edge
Cloudflare R2Object storage for photos, documents and other uploads.Files you upload, including any travel document you chose to keep.Global
ResendSending and receiving email (account emails, support replies, support@travia.ai).Your email address and the contents of the messages exchanged.United States / EU
Upstash RedisCaching and rate limiting.Short-lived technical identifiers such as IP-derived location lookups.Global
PusherReal-time updates (messages and notifications appearing without a refresh).Notification and message events addressed to you.Global
Google (Maps, Analytics, Tag Manager)Maps and place search; website analytics.Map and place queries. Analytics only when you consent — analytics and advertising storage are denied by default until you choose otherwise.Global
AI provider (Anthropic, OpenAI or Google, depending on configuration)Travia Atlas answers, itinerary drafting, passport scanning and support-reply drafting.The text of your request and, where relevant, the item you are asking about. Personalisation using your profile, saved items and bookings can be switched off entirely in Preferences → Atlas personalization; payment and security data are never sent.United States
Duffel / SerpApi / TravelpayoutsLive flight search results and fares.The search itself (route, dates, passenger counts). Not your identity.United States / EU

Travia is operated from Nepal. Its database and API run in India (Mumbai), and some processors listed above operate in the United States or globally. If you are in the EU/EEA or the UK, your personal data is transferred outside your region.

Those transfers rely on the Standard Contractual Clauses adopted by the European Commission, incorporated into our agreements with each processor listed above, together with the technical measures described in this policy — encryption in transit (TLS) and at rest, access control, and audit logging.

Analytics and advertising storage are denied by default. Nothing in those categories is set until you make a choice, and you can change that choice at any time via Cookie settings in the footer.

NameTypeCategoryWhat it doesDuration
authCookieStrictly necessaryKeeps you signed in. HttpOnly, so it cannot be read by scripts.Matches your session token (7 days by default, never less than 24 hours); renewed by travia_refresh.
travia_refreshCookieStrictly necessaryRenews your sign-in silently so you are not logged out while you are using Travia. HttpOnly; an opaque random value, stored only as a hash on our side.30 days from your last visit, and never more than 90 days from when you signed in.
travia_didCookieStrictly necessaryA random identifier for this browser, set when you sign in, so Security → Devices can sign out one browser without signing out your others. Used for nothing else.400 days
travia_g_stateCookieStrictly necessaryA one-time value that ties a “Continue with Google” sign-in to the browser that started it, so another site cannot complete a sign-in on your behalf.10 minutes
travia_csrfCookieStrictly necessaryA random token used to prove a request came from Travia and not from another website. It identifies nothing and is not a credential on its own.30 days
sessionCookieStrictly necessaryShort-lived server session used during sign-in flows such as Google and SSO.24 hours
travia_consentCookieStrictly necessaryRecords your cookie choice so it can be applied before any tag loads on your next visit. Without it we would have to ask you every time.180 days
atlas_guest_nCookieStrictly necessaryCounts free Atlas messages for signed-out visitors so the limit can be enforced.Session
travia-preferencesLocal storagePreferencesYour chosen display currency and language.Until you clear your browser storage.
travia-auth-v2Local storageStrictly necessaryYour active profile (personal or business) so the right one is loaded on return.Until you sign out or clear browser storage.
travia-primary-color / travia-primary-vars / themeLocal storagePreferencesYour appearance settings, so the page renders in your theme before it loads.Until you clear your browser storage.
travia-i18n-v1:<language>Local storagePreferencesTranslations already fetched for your chosen language, so pages do not have to be re-translated on every visit.Until you clear your browser storage.
travia:rv / travia:shLocal storagePreferencesRecently viewed listings and recent searches, kept on your device when you are signed out.Until you clear them from Profile → Your activity, or clear browser storage.
travia_loc_prompt_v1 / travia_consent_dismissedLocal storagePreferencesRemembers that you dismissed a prompt, so we do not ask again immediately.Until you clear your browser storage.
_ga, _ga_*CookieAnalyticsGoogle Analytics — how the site is used in aggregate. Only set if you accept analytics cookies.Up to 2 years
Advertising cookiesCookieAdvertisingSet by Google to measure campaign performance. Only set if you accept advertising cookies.Varies by provider

The full explanation, including what happens if you decline, is on the Cookie Policy page.

Under the GDPR and comparable laws you have the rights below. Most of them are self-service — you do not need to ask us, and you do not need to wait.

RightHow to exercise it
Access and portability (Art. 15, 20)Preferences → Privacy → “Download my data” returns a machine-readable JSON copy of everything linked to your account.
Rectification (Art. 16)Edit your details directly in your Profile page and in Preferences.
Erasure (Art. 17)Profile → Delete account. Your record is anonymised immediately, sessions are revoked and any kept travel document is destroyed.
Restriction and objection (Art. 18, 21)Turn off Atlas personalisation (Preferences → Ads & personalization), make your profile private (Preferences → Privacy), or clear your activity (Profile → Your activity). For anything else, write to support@travia.ai.
Withdraw consent (Art. 7)Cookie settings in the footer, or Preferences → Ads & personalization, changes your choice at any time. Removing a travel document withdraws consent for it.
Complain to a supervisory authority (Art. 77)If you are in the EU/EEA or UK you may complain to your national data protection authority. We would rather you told us first.

Where you do need to write to us, send the request to support@travia.ai. We respond within one month, as Article 12(3) requires.

Deleting your account from Profile → Delete account does all of the following immediately:

  • Your name, email, phone, address, date of birth and profile photo are overwritten.
  • Any kept travel document is destroyed, in the database and in object storage.
  • Every active session is revoked and any connected Google Calendar is disconnected.
  • Your public profile disappears.

Financial records of completed transactions are kept in anonymised form. We are legally required to retain accounting records, but they no longer identify you. Security audit entries expire on their own schedule (1–5 years) and are not linked to a live account after deletion.

  • All traffic is encrypted in transit with TLS. Session cookies are HttpOnly and Secure.
  • There are no passwords. Sign-in is a one-time code or link sent to your address, stored only as a keyed hash, single-use, and expiring within minutes — so there is no reusable credential to steal, phish or reuse from another site’s breach.
  • Travel-document fields are encrypted at rest with AES-256-GCM under a separate key.
  • State-changing requests carry a CSRF token, so another website cannot act as you.
  • Rate limiting and bot traps protect sign-in, registration, contact and support forms.
  • Security-relevant actions are written to an append-only audit log, which you can see for your own account under Your activity.
  • Access to production data is role-based and enforced server-side, never only in the interface.

Travia is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us their data, write to support@travia.ai and we will delete it.

When we change how we handle personal data, we update this page and the review date at the top. For changes that materially affect your rights we will tell you directly — by email or an in-app notice — before they take effect, rather than relying on you re-reading this page.