Legal
Privacy Policy
This policy explains what Travia collects, why, who else sees it, how long we keep it, and what you can do about it. It describes the system as it actually works — the tables below are generated from an audit of the platform itself.
Last verified against the platform on 2026-10-07.This document was written by Travia's engineering team to describe accurately how the system works. It has not yet been reviewed by legal counsel, and it is not legal advice.
Travia is an AI-powered travel platform. We compare flights, stays, tours, car rentals, real estate and events across providers, and we host business pages for the operators who list with us. We also run Travia Marg, which records the outdoor activity you choose to track — that involves precise location and, if you connect a sensor, heart-rate data, so it is set out in its own row in the table below.
Travia AI Pvt. Ltd. is the data controllerfor the personal data described here — we decide what is collected and why. This policy covers travia.ai, the Travia API, and the business and platform dashboards. It does not cover a partner's own website: when you follow a link out to an airline, hotel or partner booking site to complete a booking, that company's privacy policy governs what happens there.
Privacy questions go to support@travia.ai.
This table is the complete list. Each row names the actual fields involved, the reason we hold them, the lawful basis under Article 6 GDPR, and what causes the data to go away.
| Category | What it includes | Why | Lawful basis | How long |
|---|---|---|---|---|
| Profile basics | Name, email address, profile photo, bio, account type. Travia has no passwords — you sign in with a one-time code or link sent to your address, so there is no credential to store. | To create and operate your account, sign you in, and show you as the author of things you post. | Contract | Until you delete your account. Deletion anonymises the record immediately (see “Deleting your account”). |
| Contact and profile details | Phone number (and whether it is verified), date of birth, gender, citizenship, street address, city, state, postcode, preferred currency, appearance settings, the activities and travel goals you chose during setup, and your separate analytics and advertising consent decisions. | To complete bookings, meet traveller-identification requirements, and show prices and the interface the way you chose. | Contract | Until you change or delete them, or delete your account. |
| Travel documents | Passport number, names and expiry date. Optionally, a scanned copy of the data page — off by default, and only kept if you explicitly choose to keep it. | To pre-fill booking forms that legally require passport details, so you do not retype them for every trip. | Consent | Until you remove them or delete your account. Encrypted at rest with AES-256-GCM (helper/crypto.helper.js); a scan you did not opt to keep is processed in memory and never written to storage. |
| Bookings and transactions | Bookings, enquiries, viewings, commission and tax ledger entries, subscription and deposit records. | To provide the booking itself, to support you afterwards, and to meet accounting and tax obligations. | Contract | Kept after account deletion, in anonymised form: the transaction is retained for statutory accounting purposes, but it is no longer linked to an identifiable person. |
| Content you create | Reviews, journal entries, trips, guides, events you organise, photos, event memories, messages and support tickets. | To publish or deliver the thing you created, and to run the features you used it in. | Contract | Until you delete the item, or delete your account. |
| Activity | Search history, recently viewed listings, saved searches, saved items, visited places. | To show you your own history and to make results relevant to you. | Legitimate interest | Capped at the 200 most recent entries per type, and clearable at any time from Profile → Your activity. |
| Security and sign-in records | Sign-in history (device, browser, approximate location derived from IP), a random per-browser device identifier that lets Security → Devices sign out one browser without touching your others, and an append-only audit log of security-relevant actions on your account. | To detect and investigate unauthorised access, and to let you see and revoke your own sessions. | Legitimate interest | Security events are retained for up to 5 years and authentication events for 1 year, then removed automatically (modules/audit/auditLogSchema.js). |
| Approximate location (for “near you”) | A city-level location derived from your IP address, or a precise location if — and only if — you grant your browser’s location permission. | To show what is near you instead of a default city. | Legitimate interest (IP-derived) / Consent (precise device location) | The IP-derived lookup is cached for 24 hours and never written to your profile. A precise fix used for these “near you” sections is stored in your own browser and is not sent to us unless you act on it. Recording an activity in Travia Marg is separate and is described in its own row below. |
| Recorded outdoor activity (Travia Marg) | For each activity you record or upload: the full route as a list of coordinates with timestamps, start and end points, distance, duration, elevation gain and speed, the activity type and any tags, plus your own title, notes and photos. If you connect a heart-rate sensor or a fitness account (for example Strava, Garmin or Wahoo), also average and maximum heart rate, time in each heart-rate zone, and the individual heart-rate samples. Gear you record, and your challenge progress. | To give you the activity back — its map, splits and statistics — to verify Himalayan Challenge progress and the Miles it earns, and to show the activity to whoever you chose to share it with. | Contract (the recording is the feature you asked for). Heart-rate and other health-related figures are processed on Consent — they arrive only if you deliberately connect a sensor or a fitness account, and disconnecting stops it. | Until you delete the activity or your account. A deleted activity is recoverable from “Recently deleted” for a limited window and is then removed. Visibility is yours to set per activity, and an activity is not public unless you publish it. |
| Reservations from a business’s connected channels | When a hotel or other business connects its listings on other booking sites to Travia’s channel manager, reservations made on those sites are sent to Travia for that business: the guest’s name and contact details as the booking site provides them, dates, room and number of guests, and price. Calendar (iCal) connections carry dates only — no guest details. | So the business can see every booking in one calendar and avoid selling the same room twice. Travia processes this data on the business’s behalf; it is not used for anything else, including marketing. | Contract (with the business, which is the controller of its guests’ data) | For as long as the business keeps the booking or the connection, or until the business deletes it. The calendar feed Travia publishes back to those sites contains blocked dates only, never guest data. |
| Communications | Support tickets and replies, contact-form enquiries, and emails you send to support@travia.ai. | To answer you and to keep a record of what was agreed. | Contract / Legitimate interest | Until the enquiry is resolved and no longer needed for reference. |
We do not sell personal data. We do not use your bookings, messages or travel documents to train AI models.
Passport details are optional. You can use Travia without ever entering them; they exist so that bookings which legally require them do not make you retype the same details for every trip.
- Passport number and names are encrypted at rest with AES-256-GCM. They are decrypted only for you, on your own profile.
- A scan of your passport page is discarded by default. When you use the scan feature, the image is read in memory and never written to storage unless you explicitly tick the option to keep a copy.
- A kept copy is stored encrypted, is never returned in ordinary profile responses, and is destroyed when you remove it or delete your account.
- Travel documents are never part of your public profile and are never shared with AI providers.
When you create an account, a public profile page is created by default. It can show your display name, photo, bio, country, follower and connection counts, and reviews you have written after a completed booking or viewing.
Your email address, phone number, date of birth, home address, travel documents, bookings, saved items and messages are never part of your public profile, whatever its visibility setting.
You can make your profile private at any time in Preferences → Privacy, which removes the public page immediately. Business pages are always public — that is what makes them findable by travellers.
We use the services below to run Travia. Each is bound by a data-processing agreement and may only process your data on our instructions. Services we call for public reference data only — currency rates, encyclopaedia lookups, timetable data — are not listed, because none of your personal data reaches them.
| Service | What it does | What it receives | Where |
|---|---|---|---|
| MongoDB Atlas | Primary database — everything described above is stored here. | All account and content data. | India (Mumbai) |
| Vercel | Hosting for the website and the API. | Request metadata, including IP address, as part of serving pages. | India (Mumbai) / global edge |
| Cloudflare R2 | Object storage for photos, documents and other uploads. | Files you upload, including any travel document you chose to keep. | Global |
| Resend | Sending and receiving email (account emails, support replies, support@travia.ai). | Your email address and the contents of the messages exchanged. | United States / EU |
| Upstash Redis | Caching and rate limiting. | Short-lived technical identifiers such as IP-derived location lookups. | Global |
| Pusher | Real-time updates (messages and notifications appearing without a refresh). | Notification and message events addressed to you. | Global |
| Google (Maps, Analytics, Tag Manager) | Maps and place search; website analytics. | Map and place queries. Analytics only when you consent — analytics and advertising storage are denied by default until you choose otherwise. | Global |
| AI provider (Anthropic, OpenAI or Google, depending on configuration) | Travia Atlas answers, itinerary drafting, passport scanning and support-reply drafting. | The text of your request and, where relevant, the item you are asking about. Personalisation using your profile, saved items and bookings can be switched off entirely in Preferences → Atlas personalization; payment and security data are never sent. | United States |
| Duffel / SerpApi / Travelpayouts | Live flight search results and fares. | The search itself (route, dates, passenger counts). Not your identity. | United States / EU |
Travia is operated from Nepal. Its database and API run in India (Mumbai), and some processors listed above operate in the United States or globally. If you are in the EU/EEA or the UK, your personal data is transferred outside your region.
Those transfers rely on the Standard Contractual Clauses adopted by the European Commission, incorporated into our agreements with each processor listed above, together with the technical measures described in this policy — encryption in transit (TLS) and at rest, access control, and audit logging.
Under the GDPR and comparable laws you have the rights below. Most of them are self-service — you do not need to ask us, and you do not need to wait.
| Right | How to exercise it |
|---|---|
| Access and portability (Art. 15, 20) | Preferences → Privacy → “Download my data” returns a machine-readable JSON copy of everything linked to your account. |
| Rectification (Art. 16) | Edit your details directly in your Profile page and in Preferences. |
| Erasure (Art. 17) | Profile → Delete account. Your record is anonymised immediately, sessions are revoked and any kept travel document is destroyed. |
| Restriction and objection (Art. 18, 21) | Turn off Atlas personalisation (Preferences → Ads & personalization), make your profile private (Preferences → Privacy), or clear your activity (Profile → Your activity). For anything else, write to support@travia.ai. |
| Withdraw consent (Art. 7) | Cookie settings in the footer, or Preferences → Ads & personalization, changes your choice at any time. Removing a travel document withdraws consent for it. |
| Complain to a supervisory authority (Art. 77) | If you are in the EU/EEA or UK you may complain to your national data protection authority. We would rather you told us first. |
Where you do need to write to us, send the request to support@travia.ai. We respond within one month, as Article 12(3) requires.
Deleting your account from Profile → Delete account does all of the following immediately:
- Your name, email, phone, address, date of birth and profile photo are overwritten.
- Any kept travel document is destroyed, in the database and in object storage.
- Every active session is revoked and any connected Google Calendar is disconnected.
- Your public profile disappears.
Financial records of completed transactions are kept in anonymised form. We are legally required to retain accounting records, but they no longer identify you. Security audit entries expire on their own schedule (1–5 years) and are not linked to a live account after deletion.
- All traffic is encrypted in transit with TLS. Session cookies are HttpOnly and Secure.
- There are no passwords. Sign-in is a one-time code or link sent to your address, stored only as a keyed hash, single-use, and expiring within minutes — so there is no reusable credential to steal, phish or reuse from another site’s breach.
- Travel-document fields are encrypted at rest with AES-256-GCM under a separate key.
- State-changing requests carry a CSRF token, so another website cannot act as you.
- Rate limiting and bot traps protect sign-in, registration, contact and support forms.
- Security-relevant actions are written to an append-only audit log, which you can see for your own account under Your activity.
- Access to production data is role-based and enforced server-side, never only in the interface.
Travia is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us their data, write to support@travia.ai and we will delete it.
When we change how we handle personal data, we update this page and the review date at the top. For changes that materially affect your rights we will tell you directly — by email or an in-app notice — before they take effect, rather than relying on you re-reading this page.