Privacy Policy

Draft for review. This is a starting outline, not final legal wording. It must be reviewed and approved before the platform goes live.

This policy explains how Travelgenix handles personal data in Travelgenix Trips. We take the privacy of operators and travellers seriously.

Who is responsible for what

When a traveller books a trip, the operator is the controller of that traveller’s data. Travelgenix is the processor, handling the data on the operator’s behalf to provide the platform. For operator account data, Travelgenix is the controller.

What we collect

  • Operator account details: name, company, email and team access.
  • Traveller booking data: the details, answers and documents a traveller provides when booking and registering, as configured by the operator.
  • Usage data needed to run and secure the service.

Sensitive documents

Where an operator collects documents such as passports or ID, they are stored in a private, access-controlled store, not in email. They are available only to the operator that collected them.

Payments

Card payments are handled by Stripe under the operator’s own Stripe account. Travelgenix does not store card numbers.

Sharing

We do not sell personal data. We share it only with the processors needed to run the service, such as our hosting and email providers, under appropriate terms.

Retention

Data is kept for as long as needed to provide the service and to meet legal obligations, then deleted or anonymised.

Your rights

Travellers should contact the operator they booked with to exercise their data rights. Operators can contact Travelgenix about their own account data. The full detail of rights and lawful bases is to be completed on legal review, in line with UK GDPR.

Contact

Data questions can be raised through the contact page.