← Back to home

Privacy Policy

Last Updated: 27 July 2026

This Privacy Policy explains how TravelCS collects, uses, discloses and safeguards personal information when you use our website at https://www.travelcs.ai, our platform, applications and services. It is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Meta Platform Terms and Developer Policies, the Google API Services User Data Policy (including Limited Use), and applicable Portuguese privacy law.

1. Data Controller

The data controller responsible for personal data processed through TravelCS is:

If the legal form of the controller changes (for example, if TravelCS is later incorporated as a company), this section will be updated with the new legal entity, registration number and registered office, and the change will be communicated in accordance with section 15.

2. Personal Data Collected

TravelCS processes personal data provided directly by operators, personal data received through services that operators explicitly connect to TravelCS (such as WhatsApp Business, Gmail or booking channels), and personal data generated automatically when the platform is used.

2.1 Provided by operators (account and business data)

2.2 Received through connected services

2.3 Generated automatically

Where a data category is not needed to provide a requested feature, TravelCS does not collect it. The full Article 30 Record of Processing Activities is published at /ropa.

3. Meta Platform Data

When an operator connects a WhatsApp Business Account to TravelCS through Meta's Embedded Signup or another authorized flow, TravelCS may receive and process Platform Data from Meta as defined in the Meta Platform Terms.

Platform Data received may include:

Platform Data is only accessed after the business explicitly authorizes the connection through Meta's official flow, and is used solely to provide the WhatsApp integration the operator has requested — receiving guest messages inside the TravelCS inbox, sending operator-approved replies and templates, and displaying delivery status.

TravelCS does not:

Access tokens are stored encrypted and scoped to the specific operator workspace. Operators may disconnect the WhatsApp integration at any time from Settings → Channels; on disconnect, TravelCS stops accessing new Platform Data and deletes the stored access tokens.

4. Google API Data

Google user data is only accessed after the user has explicitly consented through Google's OAuth flow. A reviewer-oriented summary is at /google-api-disclosure.

4.0 Gmail Access

When a user voluntarily connects their Gmail account, TravelCS uses Google OAuth to request only the permissions required for the Inbox functionality.

TravelCS uses Gmail permissions exclusively to:

TravelCS does not:

4.1 OAuth scopes we request

TravelCS requests only the minimum scopes required to deliver the feature — two Gmail scopes plus one identity scope:

TravelCS does not request gmail.modify, gmail.compose, gmail.insert, gmail.labels, gmail.metadata, any gmail.settings.* scope, the full-access https://mail.google.com/ scope, or any Google Drive or Google Calendar scope. TravelCS performs no Gmail writes other than sending an operator-approved email.

Sign-in with Google (when used to log in to TravelCS) additionally uses the standard openid, email and profile identity scopes to create or match your TravelCS account. These are identity scopes only and grant no access to Google Workspace data.

4.2 Data we access and why

DataPurpose
Message headers (From, To, Cc, Subject, Date, Thread ID, Message ID)Thread guest conversations, deduplicate messages, route to the correct booking or lead.
Message bodies and attachmentsDisplay the conversation to the operator and let our AI draft context-aware replies for operator review.
Read/unread state (UNREAD label)Read only: show whether a guest email is unread in the TravelCS inbox. TravelCS never changes the read/unread state or any label in Gmail, and never archives, trashes or deletes a message.
Connected account email address and profile nameIdentify which account is connected; sign the outbound reply with the correct sender.

4.3 Use of Google Workspace data

Google Workspace data is used exclusively to provide user-facing functionality explicitly requested by the user: displaying Gmail conversations inside the TravelCS Inbox, synchronizing customer emails, generating AI-assisted reply drafts inside TravelCS for operator review (these are TravelCS in-app drafts — no Gmail draft is ever created), and linking emails with the corresponding booking or lead.

4.3.1 Principle of Least Privilege

TravelCS follows the Principle of Least Privilege. Gmail permissions are limited to what is strictly necessary for the Inbox feature, and are reduced whenever a feature no longer requires broader access. TravelCS does not request gmail.modify, gmail.compose, gmail.insert, gmail.labels, gmail.metadata, any gmail.settings.* scope, the full-access https://mail.google.com/ scope, or any Google Drive or Google Calendar scope. TravelCS performs no Gmail writes other than sending an operator-approved email.

TravelCS affirms that:

4.4 Storage, security, human access, retention and deletion

Google-sourced data is stored in our EEA-hosted database (Supabase, EU region) and encrypted in transit (TLS) and at rest. OAuth refresh tokens are stored encrypted and scoped to the specific operator workspace. Humans (TravelCS staff) only access Google user data when: (a) you give us specific permission (e.g. a support request); (b) we need to for security, to prevent abuse, or to comply with applicable law; or (c) the data is aggregated in a manner consistent with the Google API Services User Data Policy.

You can at any time disconnect Gmail from Settings → Channels, revoke TravelCS's access at myaccount.google.com/permissions, or request deletion of stored Google-sourced data via our Data Subject Access Request form. We honor deletion requests within 30 days.

4.5 Limited Use affirmation

TravelCS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Questions about Google user data: info@travelcs.ai.

5. Purposes of Processing

TravelCS processes personal data for the following purposes:

6. Legal Basis (GDPR)

TravelCS relies on the following legal bases under Article 6 GDPR:

7. AI Processing

TravelCS uses artificial intelligence to help operators draft replies to guests and to classify and route incoming messages.

AI features are provided through the Lovable AI Gateway, which routes requests to model providers (Google-family and OpenAI-family foundation models) under commercial API terms that prohibit training on TravelCS API traffic. The current list of AI sub-processors is at /sub-processors.

8. Data Processors

TravelCS uses the following categories of processors to operate the service. Each processor only processes personal data necessary to provide its service and is bound by contractual confidentiality and data-protection obligations (Article 28 GDPR).

The complete, up-to-date register — including hosting region, data categories and DPA references — is published at /sub-processors. Operators can sign our standard Article 28 GDPR Data Processing Agreement at /dpa. TravelCS does not sell personal information.

9. International Transfers

Personal data is hosted in the EEA by default. Some processors (for example Google, Meta, OpenAI and Stripe) may process data outside the European Economic Area, primarily in the United States. Where this occurs, TravelCS relies on appropriate safeguards under Chapter V GDPR, including the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914, Module 2 / Module 3), supplemented by the EU–US Data Privacy Framework where applicable and by encryption in transit and at rest. Details per sub-processor are at /sub-processors.

10. Data Retention

TravelCS retains personal data only as long as necessary to provide the service, comply with legal obligations, resolve disputes and enforce agreements. Data is deleted or anonymized when no longer necessary, unless a legal obligation requires longer retention. The full per-category retention schedule is at /retention.

11. User Rights

Under the GDPR, data subjects have the following rights:

To exercise these rights, use our Data Subject Access Request form or email info@travelcs.ai. We respond within 30 days (Art. 12(3) GDPR).

See our Security Incident Response Plan for how we triage, contain and notify supervisory authorities within 72 hours (Art. 33 GDPR) and affected data subjects when required (Art. 34 GDPR).

12. Security

TravelCS implements administrative, technical and organizational safeguards appropriate to the risk, including:

No internet-based service can guarantee absolute security. TravelCS does not currently claim any third-party security certification (such as ISO 27001 or SOC 2) — if and when TravelCS obtains such certifications, this section will be updated.

13. Cookies

TravelCS uses cookies and similar technologies in the following categories:

Where a cookie banner is required, cookie preferences can be reviewed and changed through the banner or through your browser settings. A full inventory of cookies and online identifiers is at /cookies.

14. Children's Privacy

TravelCS is a B2B product intended for tour and activity operators. It is not directed to children and is not intended for use by children under 16. TravelCS does not knowingly collect personal information from children. If we become aware that a child has provided personal data, we will delete it.

15. Changes to this Policy

TravelCS may update this Privacy Policy from time to time. Updates are published on this page with a new "Last Updated" date. Material changes — including changes to how we access, use, store, share or delete Meta Platform Data or Google user data, changes to the identity of the data controller, or changes to sub-processors that materially affect operators — will be communicated to affected operators by email and via an in-product notice at least 14 days before they take effect, so operators can review the change and, if they wish, disconnect their account before it applies.

16. Contact

Femke Irik, operating as TravelCS
Country: Portugal
General: info@travelcs.ai
Privacy / data protection: info@travelcs.ai
Website: https://www.travelcs.ai