Privacy Notice
How TravelBookingWidgets collects, uses, shares and protects personal data — for subscribing tour operators and their staff, visitors to our website, guests who enquire through our widgets, and suppliers. Written to describe what the platform actually does today.
1. Who we are, and the roles we play
The TravelBookingWidgets platform is operated by [COMPANY LEGAL NAME], registered in England & Wales (company no. [company number]), registered office at [registered office address] ("TravelBookingWidgets", "we", "us"). You can reach our privacy team at privacy@travelbookingwidgets.com.
We are a business-to-business software provider. Tour operators subscribe to our platform to manage enquiries, quotes, itineraries, documents, communications and payment initiation. We are not a tour operator, travel agent or package organiser: we do not sell, offer or confirm travel services to travellers. Trips are sold, confirmed and paid directly by the tour operator you book with.
We act in two data-protection roles:
- As a controller for our own business data — our operator accounts and billing, website leads and newsletter subscribers, support conversations, supplier outreach contacts, and our website analytics.
- As a processor for the data our operator customers store about their travellers and bookings (the operator is the controller of that data). We process it only on the operator's documented instructions.
We apply this notice alongside the UK General Data Protection Regulation and Data Protection Act 2018, and — because operators, travellers and suppliers are located in Kenya — the Kenya Data Protection Act 2019. Our UK data protection fee registration number is [ICO registration number]; our Kenya ODPC registration status is [ODPC registration status/number].
2. Whose data this notice covers
- Operators (subscribing tour operators) and their staff who use the platform.
- Visitors to our public website — including people who submit a booking request through an embedded widget, use our chat, or join our newsletter.
- Travellers and guests: if you are a traveller, the operator you are booking with is the controller of your data. We process it on their behalf, and this notice explains how. For anything specific to your trip or booking, contact your operator.
- Suppliers (hotels, camps, activity providers) and their contacts who provide rates or use the supplier portal.
- Operator billing contacts.
3. What we collect
- Account data: your name, work email, workspace/company name, role and seat, multi-factor authentication settings, and IP addresses and session/security logs.
- Traveller and booking data (processed on behalf of operators): travellers' names, contact details, trip details, quotes, itineraries, generated documents such as invoices and payment requests, and payment metadata.
- Website submissions: booking requests sent through embedded widgets (name, email, phone number, trip notes) — these are routed to the operator the widget belongs to so the operator can reply; chat messages and attachments sent through our website chat; newsletter subscriptions; and page-referral information (for example UTM parameters).
- Communications: where an operator connects a mailbox to the platform, we sync that mailbox's emails and attachments (including supplier rate documents) so the operator can manage correspondence in one place. We also send approved support replies over WhatsApp via the WhatsApp Business Cloud API (recipient phone number and reply text).
- Supplier data: supplier business names, contact names and emails, rate correspondence and rate documents, and supplier-portal accounts.
- Payment metadata only: amount, currency, provider tracking references, payment status and redirect URLs. We never receive card numbers or payment credentials — card checkout takes place on the payment provider's own hosted page (Pesapal), mobile-money approvals take place on the guest's own phone (M-Pesa), and funds settle directly to the operator's own merchant accounts.
- Analytics: pseudonymous, cookie-based analytics (Google Analytics 4) on our public marketing website only, loaded after you opt in via the cookie banner. We do not run analytics inside the operator app, and not inside widgets embedded on operators' own sites. See the Cookie Policy.
- Uploads: documents and rate sheets uploaded by operators or suppliers are stored in managed cloud storage buckets.
We do not currently use AI/LLM features or third-party session-recording on this product, and we do not sell personal data or share it for third-party advertising. If that changes, we will update this notice (and our consent mechanisms) first.
4. Why we use data, and on what basis
| Purpose | Our role | Basis (UK GDPR) |
|---|---|---|
| Providing and securing the service to operators | Controller | Contract; legitimate interests (security) |
| Storing and processing travellers' bookings, documents and communications | Processor | The operator's documented instructions — the operator determines the lawful basis (typically its contract with the traveller) |
| Responding to website enquiries, chat and demo requests | Controller | Legitimate interests / contract |
| Newsletter and marketing emails to individuals | Controller | Consent (you can withdraw at any time). For corporate subscribers we rely on the electronic-marketing rules that permit business opt-out marketing, and every marketing email has an unsubscribe link |
| Analytics on our public marketing site | Controller | Consent — off until you opt in via the cookie banner (see the Cookie Policy) |
| Supplier outreach and the supplier portal | Controller | Legitimate interests / contract with the supplier |
| Billing operators for their subscriptions | Controller | Contract; legal obligation (tax and accounting) |
| Fraud, abuse and security prevention | Controller | Legitimate interests; legal obligation |
Where we rely on consent for marketing, we keep a record of the consent source and timestamp, and honour opt-outs (including one-click unsubscribe in campaign emails).
5. Who we share data with
We share personal data only with the service providers (subprocessors) needed to run the platform — hosting, database and authentication, email, messaging, payments and analytics. The current list, with each provider's purpose and location, is published at /legal/subprocessors.
For guest payments: we initiate payment requests on behalf of the operator using the operator's own credentials with its payment providers (Pesapal, and M-Pesa via Safaricom Daraja). Funds settle directly to the operator's accounts; we never hold or settle traveller funds.
A booking request submitted through a widget is shared with the operator that widget belongs to — that is the purpose of the enquiry. We also share data with professional advisers where needed, and with authorities where the law requires or permits it.
6. International transfers
We and our subprocessors process data in, and from, countries other than the UK and Kenya. Examples: our hosting provider (Vercel, a US company), our database and authentication provider (Supabase), Google Analytics (US), Meta (US) and Microsoft. Kenyan data subjects' data may also be processed outside Kenya, for example payment data with Pesapal in Kenya and communications data with Meta and Microsoft abroad. Hosting regions are being recorded in our subprocessor documentation [regions to be confirmed and published].
Where UK GDPR applies to a transfer, we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with transfer risk assessments. For data subjects located in Kenya, we apply safeguards consistent with the Kenya Data Protection Act 2019 and ODPC guidance on cross-border transfers.
7. How long we keep data
The general principle is to keep personal data only as long as needed for the purpose it was collected, plus any legal minimum. As the product works today:
- Account and subscription data: for the life of the subscription, plus accounting-record periods [retention period to be confirmed].
- Traveller and booking data: while the operator's subscription is active. After a subscription ends, data is retained for a limited wind-down window [period to be confirmed] so the operator can export what it needs, after which we delete or de-identify it.
- We do not currently operate an automated deletion or "30-day soft delete" process. Deletion is performed manually on request or at wind-down; we have described this as it is, not as we plan it to be.
- Marketing consent records: kept with their source and timestamp until consent is withdrawn, plus a short period afterwards to evidence the opt-out.
- Analytics: per the analytics provider retention settings [period to be confirmed].
- Payment metadata: as long as needed for accounting and dispute handling [period to be confirmed].
8. Your rights
Subject to applicable law, you have the right to: access a copy of your data; correct inaccurate data; have your data erased; restrict or object to processing; data portability; and withdraw consent where processing is based on consent. Data subjects in Kenya have substantially similar rights under the Kenya Data Protection Act 2019.
If you are a traveller or guest: your request should go to the operator you are booking with — it is the controller of your data. We support operators in fulfilling requests and will handle directly any request addressed to us. Today, exports and deletions are handled manually by our team (there is no self-service tool yet); we aim to respond within one month.
You can complain to the UK Information Commissioner's Office (ico.org.uk) or, for data subjects in Kenya, the Office of the Data Protection Commissioner (odpc.go.ke). Please contact us first and we will try to resolve the issue directly.
9. How we protect data
- Encryption in transit and at rest.
- Two-step verification for operator accounts, with optional multi-factor authentication.
- Tenant isolation enforced at the database level (row-level security), so operators only see their own data.
- Mailbox connection credentials stored encrypted.
- Attachment scanning, rate limiting and monitoring.
No system is perfectly secure. If you have a security concern, contact security@travelbookingwidgets.com.
10. Changes and how to contact us
We will post any changes to this notice on this page and update the date above. If changes materially affect how we process your personal data, we will provide a more prominent notice.
Questions, requests or complaints: privacy@travelbookingwidgets.com [confirm mailbox is live before publication]. You can also write to [COMPANY LEGAL NAME], [registered office address].