Privacy Policy
Last Updated: 27 July 2026
This Privacy Policy explains how TravelCS collects, uses, discloses and safeguards personal information when you use our website at https://www.travelcs.ai, our platform, applications and services. It is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Meta Platform Terms and Developer Policies, the Google API Services User Data Policy (including Limited Use), and applicable Portuguese privacy law.
1. Data Controller
The data controller responsible for personal data processed through TravelCS is:
- Legal entity: Femke Irik, operating as a sole trader under the trading name "TravelCS".
- Country of establishment: Portugal.
- Contact email: info@travelcs.ai
- Privacy contact: info@travelcs.ai
If the legal form of the controller changes (for example, if TravelCS is later incorporated as a company), this section will be updated with the new legal entity, registration number and registered office, and the change will be communicated in accordance with section 15.
2. Personal Data Collected
TravelCS processes personal data provided directly by operators, personal data received through services that operators explicitly connect to TravelCS (such as WhatsApp Business, Gmail or booking channels), and personal data generated automatically when the platform is used.
2.1 Provided by operators (account and business data)
- Name and email address of the operator account holder
- Phone number (when provided)
- Business / company name and website
- Business address, timezone and operational settings
- Team member names and emails when invited to the workspace
- Booking information (guest name, contact, participants, dates, price)
- Uploaded documents (FAQs, brain content, experience descriptions, images)
- Customer-support communications sent to TravelCS
2.2 Received through connected services
- WhatsApp Business (via Meta): WhatsApp Business Account information, phone number ID, business profile information, message content and metadata, and profile pictures where available. See section 3.
- Gmail / Google Workspace (via Google): message headers, bodies and attachments, conversation metadata and read/unread state, connected account email and profile name. See section 4.
- Booking channels (e.g. GetYourGuide): booking references, guest contact details, itinerary and status.
- Website chat / email conversations: messages exchanged between guests and the operator through the TravelCS chat widget or email integration.
- Profile photos: when made available by Meta or another connected identity provider.
2.3 Generated automatically
- IP address (masked or nullified for landing leads after 48 hours — see section 10)
- Browser type and device information
- Log data and server timestamps
- Cookies and similar identifiers (see section 13)
- Usage analytics (feature usage, error events)
- AI-generated draft responses produced when an operator uses AI assistance
Where a data category is not needed to provide a requested feature, TravelCS does not collect it. The full Article 30 Record of Processing Activities is published at /ropa.
3. Meta Platform Data
When an operator connects a WhatsApp Business Account to TravelCS through Meta's Embedded Signup or another authorized flow, TravelCS may receive and process Platform Data from Meta as defined in the Meta Platform Terms.
Platform Data received may include:
- WhatsApp Business Account ID (WABA ID)
- Phone Number ID
- Business name and business profile information (address, description, category, website)
- WhatsApp message content and metadata (sender, recipient, timestamps, message status, template IDs)
- Profile pictures, where available
- Access tokens and other credentials strictly required to operate the WhatsApp integration
Platform Data is only accessed after the business explicitly authorizes the connection through Meta's official flow, and is used solely to provide the WhatsApp integration the operator has requested — receiving guest messages inside the TravelCS inbox, sending operator-approved replies and templates, and displaying delivery status.
TravelCS does not:
- access personal consumer WhatsApp accounts;
- sell, license or trade Meta Platform Data;
- use Meta Platform Data for advertising or ad targeting;
- use Meta Platform Data to train generalized artificial intelligence or machine-learning models;
- transfer Meta Platform Data to any party other than the sub-processors listed at /sub-processors, and only to the extent required to provide the WhatsApp integration or comply with law.
Access tokens are stored encrypted and scoped to the specific operator workspace. Operators may disconnect the WhatsApp integration at any time from Settings → Channels; on disconnect, TravelCS stops accessing new Platform Data and deletes the stored access tokens.
4. Google API Data
Google user data is only accessed after the user has explicitly consented through Google's OAuth flow. A reviewer-oriented summary is at /google-api-disclosure.
4.0 Gmail Access
When a user voluntarily connects their Gmail account, TravelCS uses Google OAuth to request only the permissions required for the Inbox functionality.
TravelCS uses Gmail permissions exclusively to:
- read Gmail messages, conversation threads, metadata and attachments;
- display customer conversations inside the TravelCS Inbox;
- send email replies that are explicitly initiated or approved by the operator.
TravelCS does not:
- create Gmail drafts;
- archive emails;
- delete emails;
- move emails to Trash;
- change read or unread state;
- apply or remove Gmail labels;
- access Gmail settings.
4.1 OAuth scopes we request
TravelCS requests only the minimum scopes required to deliver the feature — two Gmail scopes plus one identity scope:
https://www.googleapis.com/auth/gmail.readonly— read incoming guest email, conversation threads, metadata and attachments so they can appear in the operator's unified TravelCS inbox.https://www.googleapis.com/auth/gmail.send— send reply emails from the operator's Gmail account, only when the operator explicitly sends or approves the message. TravelCS never sends emails automatically.https://www.googleapis.com/auth/userinfo.email— identify which Google account was connected so we can display the connected mailbox in TravelCS settings.
TravelCS does not request gmail.modify, gmail.compose, gmail.insert, gmail.labels, gmail.metadata, any gmail.settings.* scope, the full-access https://mail.google.com/ scope, or any Google Drive or Google Calendar scope. TravelCS performs no Gmail writes other than sending an operator-approved email.
Sign-in with Google (when used to log in to TravelCS) additionally uses the standard openid, email and profile identity scopes to create or match your TravelCS account. These are identity scopes only and grant no access to Google Workspace data.
4.2 Data we access and why
| Data | Purpose |
|---|---|
| Message headers (From, To, Cc, Subject, Date, Thread ID, Message ID) | Thread guest conversations, deduplicate messages, route to the correct booking or lead. |
| Message bodies and attachments | Display the conversation to the operator and let our AI draft context-aware replies for operator review. |
Read/unread state (UNREAD label) | Read only: show whether a guest email is unread in the TravelCS inbox. TravelCS never changes the read/unread state or any label in Gmail, and never archives, trashes or deletes a message. |
| Connected account email address and profile name | Identify which account is connected; sign the outbound reply with the correct sender. |
4.3 Use of Google Workspace data
Google Workspace data is used exclusively to provide user-facing functionality explicitly requested by the user: displaying Gmail conversations inside the TravelCS Inbox, synchronizing customer emails, generating AI-assisted reply drafts inside TravelCS for operator review (these are TravelCS in-app drafts — no Gmail draft is ever created), and linking emails with the corresponding booking or lead.
4.3.1 Principle of Least Privilege
TravelCS follows the Principle of Least Privilege. Gmail permissions are limited to what is strictly necessary for the Inbox feature, and are reduced whenever a feature no longer requires broader access. TravelCS does not request gmail.modify, gmail.compose, gmail.insert, gmail.labels, gmail.metadata, any gmail.settings.* scope, the full-access https://mail.google.com/ scope, or any Google Drive or Google Calendar scope. TravelCS performs no Gmail writes other than sending an operator-approved email.
TravelCS affirms that:
- Google Workspace data is never sold.
- Google Workspace data is never shared with advertisers or used for advertising, ad personalization or ad targeting.
- Google Workspace APIs are not used to develop, improve or train generalized or foundation AI or machine-learning models.
- Google Workspace data is used only to provide features explicitly requested by the user.
4.4 Storage, security, human access, retention and deletion
Google-sourced data is stored in our EEA-hosted database (Supabase, EU region) and encrypted in transit (TLS) and at rest. OAuth refresh tokens are stored encrypted and scoped to the specific operator workspace. Humans (TravelCS staff) only access Google user data when: (a) you give us specific permission (e.g. a support request); (b) we need to for security, to prevent abuse, or to comply with applicable law; or (c) the data is aggregated in a manner consistent with the Google API Services User Data Policy.
You can at any time disconnect Gmail from Settings → Channels, revoke TravelCS's access at myaccount.google.com/permissions, or request deletion of stored Google-sourced data via our Data Subject Access Request form. We honor deletion requests within 30 days.
4.5 Limited Use affirmation
TravelCS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Questions about Google user data: info@travelcs.ai.
5. Purposes of Processing
TravelCS processes personal data for the following purposes:
- Providing customer support to operators and their guests
- Responding to enquiries received through connected channels
- Managing bookings and booking-related communications
- Sending transactional and operational notifications
- Generating AI-assisted draft replies for operator review
- Website chat functionality
- WhatsApp Business integration
- Email integration (Gmail, Microsoft Outlook)
- Product and usage analytics
- Fraud prevention and abuse detection
- Platform security, audit logging and incident response
- Compliance with legal obligations
- Billing and subscription management
6. Legal Basis (GDPR)
TravelCS relies on the following legal bases under Article 6 GDPR:
- Performance of a contract (Art. 6(1)(b)) — to provide the TravelCS service under our Terms and any operator agreement.
- Legitimate interests (Art. 6(1)(f)) — to secure the platform, prevent abuse, improve product reliability and communicate with operators about their account. Balancing tests are documented in our Record of Processing Activities.
- Legal obligations (Art. 6(1)(c)) — to comply with tax, accounting, and other legal duties applicable to TravelCS in Portugal and the EU.
- Consent (Art. 6(1)(a)) — where processing is based on user consent, such as connecting a Google or Meta account, enabling optional cookies, or opting into optional marketing communications. Consent can be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
7. AI Processing
TravelCS uses artificial intelligence to help operators draft replies to guests and to classify and route incoming messages.
- AI-generated responses are suggestions. They are presented for review and are not sent to a guest unless the operator approves them (or configures automatic sending for a specific, limited scenario).
- Operators remain responsible for all communications sent from their workspace, including AI-assisted messages.
- AI does not make legally binding decisions on behalf of operators or guests, and is not used for automated decision-making producing legal effects within the meaning of Article 22 GDPR.
- AI is used only to provide functionality explicitly requested by the operator.
- Customer data processed by TravelCS is not used to train public or generalized AI models.
AI features are provided through the Lovable AI Gateway, which routes requests to model providers (Google-family and OpenAI-family foundation models) under commercial API terms that prohibit training on TravelCS API traffic. The current list of AI sub-processors is at /sub-processors.
8. Data Processors
TravelCS uses the following categories of processors to operate the service. Each processor only processes personal data necessary to provide its service and is bound by contractual confidentiality and data-protection obligations (Article 28 GDPR).
- Supabase (EU region) — managed Postgres database, authentication and file storage.
- Lovable — application hosting and edge runtime for the TravelCS web application.
- OpenAI — AI drafting and classification (via the Lovable AI Gateway) when AI features are used, under API terms that prohibit training on TravelCS traffic.
- Google — Gmail / Google Workspace integration, when the operator connects a Google account.
- Meta Platforms — WhatsApp Business Platform, when the operator connects a WhatsApp Business Account.
- Stripe — payment processing, subscription billing and (where enabled) operator payouts.
- Resend — transactional email delivery for system notifications, when enabled.
The complete, up-to-date register — including hosting region, data categories and DPA references — is published at /sub-processors. Operators can sign our standard Article 28 GDPR Data Processing Agreement at /dpa. TravelCS does not sell personal information.
9. International Transfers
Personal data is hosted in the EEA by default. Some processors (for example Google, Meta, OpenAI and Stripe) may process data outside the European Economic Area, primarily in the United States. Where this occurs, TravelCS relies on appropriate safeguards under Chapter V GDPR, including the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914, Module 2 / Module 3), supplemented by the EU–US Data Privacy Framework where applicable and by encryption in transit and at rest. Details per sub-processor are at /sub-processors.
10. Data Retention
TravelCS retains personal data only as long as necessary to provide the service, comply with legal obligations, resolve disputes and enforce agreements. Data is deleted or anonymized when no longer necessary, unless a legal obligation requires longer retention. The full per-category retention schedule is at /retention.
- Operator account data: retained while the workspace is active; deleted or anonymized on account closure, subject to legal retention obligations.
- Conversations and messages (email, WhatsApp, chat): retained while the workspace is active and the relevant channel is connected; deleted on disconnect or on Data Subject Access Request, subject to the per-category schedule.
- Bookings: retained for the duration reasonably required for operational, tax and accounting purposes.
- Landing / marketing leads: maximum 30 days from capture, then automatically deleted (rule R2/R3).
- Online identifiers on landing leads (IP, User-Agent, Referrer): masked or nullified after 48 hours (rule R2-minimisation).
- Unconfirmed / unassigned admin accounts: automatically purged after 24 hours (rule R12).
- Operator deletion backups: kept for the documented restore window, then automatically purged (rule R11).
- Application and audit logs: retained for the period documented in the retention schedule, then rotated and deleted.
- Google Workspace data: retained only while the Gmail channel is connected; deleted on disconnect, on Data Subject Access Request, or on account deletion.
- Meta Platform Data: retained only while the WhatsApp channel is connected; access tokens deleted on disconnect.
11. User Rights
Under the GDPR, data subjects have the following rights:
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure / to be forgotten (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object to processing (Art. 21)
- Right to withdraw consent at any time, where processing is based on consent (Art. 7(3))
- Right to lodge a complaint with a supervisory authority — in Portugal, the Comissão Nacional de Proteção de Dados (CNPD), www.cnpd.pt
To exercise these rights, use our Data Subject Access Request form or email info@travelcs.ai. We respond within 30 days (Art. 12(3) GDPR).
See our Security Incident Response Plan for how we triage, contain and notify supervisory authorities within 72 hours (Art. 33 GDPR) and affected data subjects when required (Art. 34 GDPR).
12. Security
TravelCS implements administrative, technical and organizational safeguards appropriate to the risk, including:
- HTTPS / TLS encryption in transit
- Encryption at rest for the managed database and file storage
- Authenticated access for all operator surfaces
- Role-based access controls and per-workspace data isolation (row-level security)
- Least-privilege access for TravelCS staff
- Audit logging of privileged and sensitive actions
- EEA-hosted, encrypted cloud infrastructure
- OAuth tokens and secrets stored encrypted and scoped to the workspace that authorized them
No internet-based service can guarantee absolute security. TravelCS does not currently claim any third-party security certification (such as ISO 27001 or SOC 2) — if and when TravelCS obtains such certifications, this section will be updated.
13. Cookies
TravelCS uses cookies and similar technologies in the following categories:
- Essential cookies — required to sign in, keep you signed in, maintain your workspace context, and provide security (CSRF protection, session management). These cannot be disabled without breaking the service.
- Analytics cookies — used to understand how the platform is used so we can improve reliability and product decisions. Where required by law, these are only set after consent.
- Optional marketing cookies — only set if explicitly enabled by the visitor and only on our public marketing pages. TravelCS does not run cross-site advertising on operator surfaces.
Where a cookie banner is required, cookie preferences can be reviewed and changed through the banner or through your browser settings. A full inventory of cookies and online identifiers is at /cookies.
14. Children's Privacy
TravelCS is a B2B product intended for tour and activity operators. It is not directed to children and is not intended for use by children under 16. TravelCS does not knowingly collect personal information from children. If we become aware that a child has provided personal data, we will delete it.
15. Changes to this Policy
TravelCS may update this Privacy Policy from time to time. Updates are published on this page with a new "Last Updated" date. Material changes — including changes to how we access, use, store, share or delete Meta Platform Data or Google user data, changes to the identity of the data controller, or changes to sub-processors that materially affect operators — will be communicated to affected operators by email and via an in-product notice at least 14 days before they take effect, so operators can review the change and, if they wish, disconnect their account before it applies.
16. Contact
Femke Irik, operating as TravelCS
Country: Portugal
General: info@travelcs.ai
Privacy / data protection: info@travelcs.ai
Website: https://www.travelcs.ai