Legal

Privacy Policy & End-User License Agreement (EULA)

Data Controller: Travel360 Technologies FZE (Sharjah Research, Technology and Innovation Park, UAE).

1. Who We Are, Scope, and White-Labeled Architecture

Travel360 Technologies FZE ("Travel360", "we", "us", or "our"), registered at Block B-B56-197, SRTIP, Sharjah University City, UAE, operates the Travel360.ai multi-tenant enterprise software platform and its native mobile applications distributed via iOS App Store and Google Play Store (including white-labeled partner applications and the consumer utility app, Pep Traveler).

White-Labeled Platform Clarification: Our mobile and web applications function as a multi-tenant, white-labeled software architecture. End-consumers interact with, view, and interface with the branding, logo, trade name, and customer service identities of their designated local travel company, Outbound Agent (OA), or Destination Management Company (DMC). Travel360 acts solely as the underlying software technology infrastructure provider and SaaS licensor. Travel360 does not directly contract as a travel agency or merchant of record for end-consumer travel itineraries unless expressly stated.

This Privacy Policy and Software End-User License Agreement ("EULA") applies to all platform users and mobile application installations across iOS and Android, including:

  • B2B Platform Users: Outbound Agents (OAs), Destination Agents/Suppliers (DAs), Hotel Partners, and their authorized personnel.
  • Travelers & Guests: Individual consumers who book travel packages, interact with our AI Concierge, or utilize our digital wallet services.
  • Referred Contacts: Individuals whose contact details are provided through our viral referral and contact-syncing features.

2. Categories of Personal Data We Collect

We collect personal data directly from you, automatically through platform usage, and via third-party B2B partners who manage your travel bookings.

  • A. Account & Business Verification Data: Full name, corporate email address, phone number, business registration details, trade license, job role, and identity verification credentials (e.g., Emirates ID, Passport details, National ID).
  • B. Booking & Traveler Profile Data: Passport details, nationality, date of birth, travel itineraries, flight and hotel preferences, special requests, family/group details (for Group Inclusive Tours - GIT and religious travel such as Umrah/Hajj), and emergency contact information.
  • C. Financial & Payment Data: Bank account numbers, payment card metadata, transaction history, digital wallet balances, and cross-border payment logs processed via our BaaS/FinTech partners.
  • D. Contact Sync & Referral Data: Where explicitly authorized by the user, contact numbers and names from mobile address books uploaded to enable cash discounts, viral referral tracking, and group travel coordination.
  • E. Platform Interaction & AI Analytics: Unstructured traveler intent input into our AI Engine, chat logs, platform usage records, security audit logs, IP addresses, device identifiers, and geolocation data.

4. How We Use Your Data

Your personal data is used exclusively for specified, explicit, and legitimate purposes:

  • Operational Fulfillment: Connecting OAs and DAs to build, price, and confirm travel packages via our automated reverse-auction marketplace.
  • AI Personalization & Concierge: Processing unstructured travel queries into structured API formats to curate custom itineraries and dynamic package offerings.
  • Fintech & Wallet Infrastructure: Managing stored value, processing cross-border FX settlements, and facilitating local payment methods (e.g., UPI, Mada, Apple Pay) via licensed financial partner rails.
  • Anti-Poaching & Attribution Integrity: Enforcing contractually bound, immutable customer attribution to lock referred travelers to their originating agency ledger (preventing unauthorized direct marketing or supplier poaching).
  • Viral Referral Programs: Verifying uploaded contacts to issue promotional credits, cash discounts, and group booking rewards.

5. Who Sees Your Data and Cross-Border Transfers

We do not sell, rent, or trade personal data to third-party data brokers. Personal data is disclosed only on a need-to-know basis as follows:

A. Operational Disclosures

  • Matched Destination Partners: When an OA submits a trip request, destination suppliers (DAs) see structured itinerary metrics (dates, hotel tiers, group size) without disclosing the traveler's personal identity during the reverse-bidding stage. Full guest manifests are shared only with the confirmed hotel, transport, and ground execution partners.
  • Originating Agencies: End-travelers booking via agent-referred links interface with white-labeled or agent-pegged interfaces where data routes back to the designated OA.

B. Third-Party Service Processors

We utilize vetted technical processors operating under strict data processing agreements (DPAs):

  • Cloud & Edge Infrastructure: Secure cloud hosting and edge networks located in data centers across Europe, Asia, and the GCC.
  • Fintech & Payment Rail Partners: Licensed financial institutions, payment service providers, and BaaS partners for cross-border settlements, local payment processing, and KYC verification.

C. International Data Transfers

Because Travel360 operates across the GCC, India, Southeast Asia, the Caucasus, and the EU, your data may be transferred to and processed in countries outside your country of residence. We ensure appropriate safeguards are in place:

  • International Transfer Safeguards: Implementation of appropriate contractual safeguards, standard data protection clauses, and security measures for international transfers.
  • GCC & Asian Compliance: Adherence to cross-border transfer rules mandated by the UAE Federal Decree-Law No. 45/2021, KSA PDPL, India DPDP Act 2023, and Singapore PDPA.

6. AI Processing and Automated Decision-Making

Travel360 utilizes automated algorithms and artificial intelligence to parse travel requests, calculate Guest Satisfaction Scores (GSS/GQS), and dynamically bundle supplier bids.

  • Automated processing is used solely to generate optimal booking options and operational efficiencies.
  • It does not produce legal or similarly significant effects on travelers without human oversight or agent confirmation.
  • Users maintain the right to request human review of any automated allocation or scoring outcome.

7. Mobile Application End-User License Agreement (EULA)

By downloading, installing, or accessing the Travel360 multi-tenant mobile software application (whether branded directly as Travel360, Pep Traveler, or via a white-labeled agent/partner application) from the Apple App Store or Google Play Store, both B2B platform users and end-consumers agree to the following license terms:

  • Limited Software License: Travel360 Technologies FZE grants you a revocable, non-exclusive, non-transferable, limited license to download, install, and use the mobile application on authorized Apple iOS and Android devices strictly in accordance with this agreement and applicable app store terms.
  • License Restrictions: You shall not reverse engineer, decompile, disassemble, attempt to derive the source code of, modify, or create derivative works of the multi-tenant mobile application software, network APIs, or underlying AI algorithms.
  • App Store & Platform Terms: You acknowledge that this agreement is concluded between you and Travel360 Technologies FZE only, and not with Apple Inc. or Google LLC. Apple and Google are third-party beneficiaries of this EULA and have the right to enforce its provisions as related to their respective operating system platforms.
  • White-Label Service Interface: Consumers acknowledge that app interface customization, logos, and local travel offers belong to the respective partner agent, while intellectual property rights in the application software and infrastructure remain exclusively with Travel360 Technologies FZE.

8. Data Retention, Security, and Wallet Inactivity

  • Retention Period: We retain personal data for as long as your account is active or as necessary to fulfill travel bookings. Post-account closure, data is retained for up to 7 years to meet statutory legal, tax, and AML requirements.
  • Security Standards: We implement bank-grade technical and organizational measures, including end-to-end encryption in transit (TLS 1.3) and at rest (AES-256), multi-tenant database isolation, strict role-based access controls, and periodic vulnerability audits.
  • Dormant Wallet Balances: Unspent digital wallet balances are held in ring-fenced safeguarding accounts. In accordance with applicable Central Bank regulations, accounts inactive for 365 days are designated as dormant. Maintenance fees or escheatment sweeps are executed strictly pursuant to local legal frameworks and user disclosures.

9. Your Legal Rights

Depending on your jurisdiction (e.g., UAE PDPL, KSA PDPL, India DPDP Act, Singapore PDPA, or relevant regional privacy laws across the GCC, Indian Subcontinent, Southeast Asia, and Caucasus), you hold the following rights regarding your personal data:

  • Right to Access & Portability: Request a copy of the personal data we hold about you in a structured, machine-readable format.
  • Right to Rectification: Correct inaccurate or incomplete personal records.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your data where processing is no longer necessary or legal consent is withdrawn.
  • Right to Object / Restrict Processing: Limit or opt-out of specific processing activities, including direct marketing and AI profiling.
  • Right to Withdraw Consent: Revoke previously granted consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact our Data Protection Officer (DPO) at [email protected] or via your platform workspace administrator.

10. Children’s Data

Given our specialized vertical coverage of family travel and religious tourism (such as Hajj and Umrah), we may process personal data of minors (under 18 years of age). Such processing is permitted strictly when provided by a parent, legal guardian, or authorized group booking coordinator with verifiable parental consent in compliance with regional laws (e.g., India DPDP Act and KSA PDPL).

11. Amendments and Updates

We may update this Privacy Policy from time to time to reflect changes in our legal obligations, organizational structure, or technical operations. Material changes will be notified via email, platform notifications, or a mandatory consent re-prompt upon your next sign-in.

12. Contact Us & Complaints

For questions, concerns, or privacy grievances, please contact us at:

  • Data Protection Officer (DPO): [email protected]
  • UAE Operating Entity:
    Travel360 Technologies FZE, Block B-B56-197, SRTIP, Sharjah University City, UAE
  • Operating Address:
    Sharjah Research, Technology and Innovation Park, Sharjah University City, UAE

If you feel your privacy rights have been violated, you also have the right to lodge a complaint with your competent local data protection supervisory authority.