Who is responsible for your data
Touriyo is operated by Wayfarer E-Commerce Private Limited, CIN U74999UP2017PTC093356, a company registered in India and based in Ghaziabad, India.
For anything about your personal data, write to hola@touriyo.com. A person reads it.
What we collect
- To open an account: your email and your name. We never store your password itself, only a scrambled fingerprint of it that cannot be turned back into the password.
- If you fill in your profile: phone, date of birth, gender, passport or ID number with its expiry date and nationality, and your home city. All of it is optional until a booking needs it.
- The travellers you save so you do not have to type them again.
- Your bookings: what you bought, for whom, when and what you paid.
- Your recent searches, the approximate city your connection comes from, and the technical logs every web server keeps.
- Passport and ID numbers are stored encrypted, and the key is kept apart from the data.
- We do not store card numbers. You type them on the payment page and they go to the payment provider.
What we use it for
- To book and issue what you bought, with the names and documents airlines and hotels require.
- To take payment and send you tickets, vouchers and receipts.
- To help you change or cancel a booking and to answer you.
- To run your account.
- To keep the records that tax and accounting rules require.
- To stop fraud: we look at the connection, the email and details of the card that the payment provider shares with us, such as the issuing bank, the country, the type and the last four digits.
- To send you offers, only if you said yes to that separately. You can say no at any time and it changes nothing about your bookings.
When we ask for photos to confirm a card
Sometimes, to protect a cardholder, we need to confirm that the card used belongs to the person paying. If that happens we ask you for it by email, and it only goes ahead with your express consent.
The photos are stored encrypted and they are deleted 180 days after the trip ends. They are never kept longer than 540 days from the day you sent them.
Who we share it with
We do not sell your data. We share only what each of these needs to do its part:
- The airline, hotel or local operator that provides what you booked, and the booking systems that connect us to them.
- The payment provider that processes your payment.
- Google, only if you choose to sign in with Google: your email, your name and an internal identifier.
- The companies that deliver our emails and messages, so that your tickets reach you.
- Public authorities, when the law obliges us to.
Airlines, hotels and our service providers are in several countries, so your data can be processed outside the country you live in. That is part of booking international travel.
Cookies
A cookie is a small note your browser keeps for a site. We use them for these things:
- To keep you signed in and to remember a booking you started without an account. Without these the site cannot work.
- To remember your choices on the site.
- An optional cookie to measure our own advertising. When we have it switched on and you arrive from one of our ads, it remembers which ad or campaign brought you, for up to 90 days, so we can tell which ads lead to bookings. It holds nothing about you: no name, no email, no searches. Scripts on the page cannot read it and we do not send it to anyone.
- Measurement by Google and Meta. When we have their measurement switched on, those companies set their own cookies to count visits and advertising results, under their own privacy policies.
You can block or delete cookies in your browser settings. If you block the ones that keep you signed in, you will have to sign in each time.
How long we keep it
- Your account, until you ask us to close it.
- Your bookings and receipts, for as long as tax and accounting rules oblige us to keep them, even if you close your account.
- Photos sent to confirm a card: deleted 180 days after the trip, and never kept beyond 540 days.
How we protect it
- The whole site runs over an encrypted connection.
- Passwords are stored scrambled, and we check new passwords against lists of leaked ones.
- Our team signs in to the back office with a second step, and what they do there is logged.
Your choices
You can ask us what we hold about you, ask us to correct it, ask us to delete what we are not obliged to keep, and take back a consent you gave. You can change most of it yourself from your account.
Write to hola@touriyo.com from the email on your account, so we know it is you. We answer every request.
Changes to this policy
When this policy changes, the new text goes on this page with its date at the top.