Privacy Policy
TourifyHub is software for tour operators. An operator uses it to build an itinerary, price it from supplier rates, send booking requests to suppliers, and send offers to their customers. This page says what personal data that involves, why we hold it, and how long for.
Three different groups of people appear below and it matters which you are. An operator is a company that has an account here and uses the product. A traveller, a supplier or a customer is somebody whose details an operator puts into it. And somebody who has simply asked us for a demo has no account here at all and belongs to no operator — section 5 says separately how long we keep what they told us, because the rest of that section is written around an account and they have none. For an operator's own account we decide how the data is used; for everything an operator puts in, the operator decides and we hold it on their behalf.
1. What we hold, and why
| Data | Why |
|---|---|
| Account details of a person signing in — name, email address, role, organisation | To let them sign in and to show colleagues who did what |
| Itineraries, supplier rates, bookings, invoices, offers | The operator's own working records — this is the product |
| Traveller, customer and supplier details entered by an operator | To produce offers, booking requests and vouchers for the trip they belong to |
| Mailbox contents from a connected mailbox — see section 2 | To send the operator's letters from their own address and to show the replies |
| Technical records — sign-in times, audit entries, error logs | Security, and being able to say what happened when something goes wrong |
| What somebody tells us when they ask for a demo — their name, email address, company, team size and message | To answer the enquiry. This is the only thing on this page belonging to somebody who has no account here |
We do not sell personal data, we do not use it for advertising, and we do not use it to train machine-learning models.
2. A connected mailbox
An operator may connect a Gmail or a Microsoft Outlook mailbox so that offers and booking requests go out from their own address rather than from ours, and so replies come back into the product. This is optional; the product works without it.
What we access
- The mailbox's own address, so the connected account can be named on screen.
- Messages in the mailbox — sender, recipients, subject, date and body. These are read to find the replies to letters the product sent, and to show the operator their correspondence inside the product.
- Sending, so a letter the operator composes in the product leaves from their own mailbox.
We ask for exactly the permissions those three things need and no others. For Gmail that is
gmail.readonly, gmail.send and the address itself. We do not ask
for permission to modify, label, archive or delete anything in a Gmail mailbox.
Who can read it
When a mailbox is connected as the organisation's, everybody in that organisation who holds the "view emails" permission can read what it holds — the product tells you how many people that is before you connect. When it is connected as your own, only you can read it, including our own staff.
Disconnecting and deleting
- Disconnect stops the flow at once: nothing further is fetched and nothing is sent from it. An organisation's archive stays readable by that organisation, because it is that organisation's own correspondence. A personal mailbox's archive stops being readable by anybody.
- Delete connection removes the stored credentials and the stored messages belonging to that mailbox.
- You can also revoke our access directly at myaccount.google.com/permissions or, for Microsoft, at myaccount.microsoft.com. Revoking there stops all further access; it does not by itself delete messages already stored here, so use Delete connection for that.
Google API Services Limited Use
TourifyHub's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, Google user data obtained through these scopes is used only to provide and improve the features described in this section. It is not transferred to anyone else except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition. It is not used for advertising, and it is not sold. It is not used to develop, improve or train generalised artificial-intelligence or machine-learning models. No human reads it except with the operator's explicit consent, where it is necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymised.
3. Artificial intelligence in the product
Some features send text to a third-party model provider — for example reading a supplier's price list, or drafting a paragraph for an offer. What is sent is the document or the text the operator asked us to work on. Mailbox contents are not sent to a model provider, and nothing sent to a provider is used by them to train a model.
4. Where it is held, and who else touches it
Data is held in the European Union with Supabase (PostgreSQL and file storage). We use these processors:
- Supabase — database, authentication and file storage
- Google and Microsoft — only where an operator has connected a mailbox of theirs
- Anthropic and OpenAI — the AI features in section 3
- GoDaddy — hosting for the web front end (static files only; no personal data is stored there)
5. How long we keep it
We keep personal data for as long as the account it belongs to is open. What happens after that depends on what kind of record it is:
- Working records — itineraries, supplier rates, drafts, offers. Deleted within 30 days of an account being closed.
- Financial records — invoices, bookings and payments. Kept for the statutory accounting period we are required to keep them for, and then deleted. We cannot delete these on request before that period ends, because we are obliged to hold them.
- Mailbox messages and OAuth tokens — until the mailbox connection is deleted, or the account is closed, whichever is first. Disconnecting a mailbox removes its credentials at once.
- Short-lived technical records — the sign-in handshake we use when you connect a mailbox, and the copy of an uploaded import file we keep while the import is running. These are deleted on a timer, not on request: the handshake record within 24 hours, and the uploaded copy within 24 hours of the import finishing. What the import created stays; only our copy of the file it was made from goes.
- Demo enquiries — what somebody sends us through the demo form. They have no account here, so “as long as the account it belongs to is open” above does not reach them, and it would be wrong to let it look as though it did. There is no timer on these: we keep a demo enquiry until we delete it, and we delete it on request. Write to the address in section 9 and it goes.
- Audit and sign-in records — the trail of who did what. Kept for the life of the account and removed when the account's data is deleted. We do not expire these on a fixed schedule; they are removed as part of deleting an account, not before. That is deliberate: this trail is what answers a later disagreement about who did what, and we cannot know in advance when somebody will need it.
Apart from the short-lived technical records above, deletion is carried out on request and on account closure — it is an action somebody takes, not a timer. So if you want your data removed, ask us, and the periods above are what we hold ourselves to from that point.
6. Your rights
If you are in the UK or the EEA you may ask for a copy of the personal data we hold about you, ask for it to be corrected or deleted, object to how it is used, or ask us to restrict it. If the data was entered by an operator, ask the operator first — they decide what happens to it and we act on their instructions. Write to us at gokhan@thepangames.com and we will answer within one month. You may also complain to your data-protection authority.
7. Security
Access to an operator's data is enforced in the database itself, row by row, so one operator cannot read another's. Mailbox credentials are stored encrypted and are readable only by the server-side code that sends and fetches mail. Connections are over TLS.
8. Changes
If this policy changes materially we will say so in the product before the change takes effect. The date at the top is when it last changed.
9. Contact
Pan Games Oy, Veijolantie 51, 08150 Lohja, Finland — gokhan@thepangames.com
