AtlasTrail

Privacy policy

How traveller and booking data should be protected

A travel platform handles sensitive traveller information. This policy describes privacy expectations for customers, staff, documents, and operational records.

Back to policy center

Data collected

The platform may collect names, email, phone, nationality, date of birth, passport details, identity documents, travel preferences, payment references, support messages, and notification preferences.

Restricted access

Sensitive traveller data and private documents should be accessible only to authorized staff who need it for booking fulfilment, support, finance, or compliance.

Payment data

The database must never store full card numbers, CVV values, gateway secrets, raw authentication tokens, or publicly accessible traveller document URLs.

Data collected

The platform may collect names, email, phone, nationality, date of birth, passport details, identity documents, travel preferences, payment references, support messages, and notification preferences.

Restricted access

Sensitive traveller data and private documents should be accessible only to authorized staff who need it for booking fulfilment, support, finance, or compliance.

Payment data

The database must never store full card numbers, CVV values, gateway secrets, raw authentication tokens, or publicly accessible traveller document URLs.

Audit history

Staff changes, status transitions, payment reconciliation, document requests, and refund actions should be recorded in audit logs.