Agent Privacy Policy
How Travel Dash processes personal data about independent travel agents
1. General
1.1 What is this Privacy Policy and who is your data controller? In this privacy policy (the “Privacy Policy”), Tripdash, company code 306210193 (“Platform”, “we”, “us”, or “our”), explains how we handle the personal data (“Personal Data”) of independent travel agents and agencies (“Agent”, “you”) who register for, access, or use our websites and applications (the “Platform”) to offer or provide Travel Services to Travellers.
Platform is the controller in respect of the personal data processing activities relating to the operation of the Platform and to connecting Agent with Travellers through the Platform, and in respect of Agent’s own account, Verification, and business data. Platform is also the controller when sending Agent product updates, offers, or newsletters.
Agent is a joint controller with Platform under Article 26 GDPR - of personal data relating to Travellers that Agent collects or receives in order to provide Travel Services, including Sensitive Booking Data such as passport and payment details. By design, Platform does not collect or store Sensitive Booking Data: Agent collects it directly from Travellers through the secure channel(s) Platform designates for that purpose, and Agent is responsible for that processing under the Agent Terms and Conditions and any Data Processing Addendum between Agent and Platform. If Agent fails to meet its data protection obligations toward Travellers, Platform may suspend or terminate Agent’s account in accordance with the Agent Terms and Conditions.
1.2 Capitalised terms used in this Privacy Policy have the meaning given in the Agent Terms and Conditions, unless this Privacy Policy expressly provides otherwise.
1.3 What is personal data? Personal Data means any information relating to an identified or identifiable natural person - for example, your name or email address, or, where Agent is an individual or sole trader, information about Agent personally. When processing Personal Data, Platform is guided by and complies with the General Data Protection Regulation 2016/679 (“GDPR”), the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and other applicable data protection law.
1.4 Questions or inquiries. If you have questions about this Privacy Policy or wish to exercise any right described in it, contact us using the details in Section 20, or contact our Data Protection Officer at team@tripdash.net
2. What information will you find below in this Privacy Policy?
In this Privacy Policy you will find information about:
- (a) the data processing principles we follow (Section 3);
- (b) the Personal Data we collect about you, why, on what legal basis, and for how long (Section 4);
- (c) how Traveller personal data is handled in connection with your use of the Platform, and the boundary between Platform’s role and yours (Section 5);
- (d) Personal Data retention periods generally (Section 6);
- (e) to whom we provide your Personal Data (Section 7);
- (f) marketing communications and cookies (Sections 8-9);
- (g) AI tools (Section 10);
- (h) security of your Personal Data (Section 11);
- (i) your rights (Section 12); and
- (j) other privacy matters (Sections 13-20).
3. What data processing principles do we follow?
We adhere to the general data processing principles established in applicable data protection law, including:
- (a) Lawfulness, fairness and transparency — we process Personal Data in a lawful, fair, and transparent manner;
- (b) Purpose limitation — we process Personal Data for specified, explicit, and legitimate purposes and do not further process it in a manner incompatible with those purposes;
- (c) Data minimisation — we process Personal Data that is adequate, relevant, and limited to what is necessary;
- (d) Accuracy — we process accurate and, where necessary, up-to-date Personal Data;
- (e) Storage limitation — we keep Personal Data in identifiable form for no longer than necessary for the purposes for which it is processed; and
- (f) Integrity and confidentiality — we process Personal Data using appropriate technical and organisational security measures.
4. Personal data we collect about you, purposes, legal grounds and retention
We process the following categories of Personal Data about you, the Agent, for the purposes below.
4.1 Registration, Verification and account management. To create and maintain your Agent Account, we may process your name, email address, phone number, residential or business address, date of birth or equivalent identifier, business registration and tax details, and evidence of any professional licence, registration, bond, or insurance referred to in the Agent Terms and Conditions (such as seller-of-travel registration). We obtain this data directly from you and, where relevant, from public business or professional registers. The legal basis is performance of the Agent Terms and Conditions (Art. 6(1)(b) GDPR) and, for regulatory checks, our legal obligations and legitimate interest in preventing fraud and verifying eligibility (Art. 6(1)(c) and (f) GDPR). We retain this data for as long as your Agent Account is active and for 3 years afterward, unless a longer period is required by law.
4.2 Identity Verification. To confirm your identity, we use [Identity Verification Provider, e.g., Onfido / Stripe Identity / Persona / Veriff] (the “Identity Verification Provider”) to match a government-issued identity document you provide against a live selfie or other biometric check. This involves processing: (a) an image or scan of your identity document; (b) a live selfie or short video; and (c) biometric data derived from matching (a) and (b), such as a facial map or similar biometric template. Because this involves biometric data used to uniquely identify you, the legal basis for this specific processing is your explicit consent (Art. 9(2)(a) GDPR), which we obtain separately before Identity Verification takes place; you may withdraw that consent at any time, though doing so will prevent you from completing Verification and accessing the Platform as an Agent. Where the match is performed by automated means, you have the right to request human review of a failed or inconclusive result, as described in Section 12.2(i). We retain the biometric template used for matching for no longer than [30] days after Identity Verification is complete, after which it is deleted; we retain the identity document image and the verification outcome (pass or fail, and supporting record) for 5 years for compliance and audit purposes, or longer if required by law. Your identity document image and biometric data are shared with the Identity Verification Provider, which processes them as our process strictly to perform the verification.
4.3 Your Agent profile and matching you with Travellers. To connect you with Travellers and display your profile, we process your name, agency name, areas of specialisation, destination expertise, language skills, service area or location, and your ratings and reviews. This data is used to match Traveller requests to suitable Agents and is shown to Travellers who view or contact you through the Platform. The legal basis is performance of the Agent Terms and Conditions (Art. 6(1)(b) GDPR). We retain this data for as long as your Agent Account is active and, for ratings and review history, for 3 years after account closure for accountability and dispute-resolution purposes.
4.4 Subscription Fees, Commission and payment. To bill your Subscription Fee and, where applicable, deduct Commission, we process your billing details, transaction history, and payout details (such as bank account or connected-account information held with our Payment Service Provider). We do not collect or store full payment card numbers; these are held by our PSP as a separate controller. The legal basis is performance of the Agent Terms and Conditions (Art. 6(1)(b) GDPR) and compliance with accounting and tax law (Art. 6(1)(c) GDPR). We retain transaction and invoicing data for 3 years after the last related invoice, or for 10 years where required for accounting purposes.
4.5 Ratings, feedback, complaints and dispute resolution. When a Traveller rates or comments on services you provided, or a complaint or dispute is raised, we process the content of the rating or complaint, related booking metadata, and your responses, in order to resolve the matter, maintain service quality, and meet our obligations under the Agent Terms and Conditions. The legal basis is performance of the Agent Terms and Conditions and our legitimate interest in maintaining a trustworthy marketplace (Art. 6(1)(b) and (f) GDPR). We retain this data until the matter is resolved and for 3 years afterward, or until the expiry of the applicable limitation period, whichever is later.
4.6 Customer support. When you contact our support team, we process your contact details, the content of your communication, and related metadata to respond to your query. The legal basis is performance of the Agent Terms and Conditions and our legitimate interest in providing effective support (Art. 6(1)(b) and (f) GDPR). We retain support communications for 3 years after the query is resolved.
4.7 Platform administration, security and analytics. To operate, secure, and improve the Platform, we process device and usage data, which may include IP address, browser type, operating system, log-in times, pages visited, and similar technical information, obtained using cookies and similar technologies (see Section 9). The legal basis is our legitimate interest in the secure and effective operation of the Platform (Art. 6(1)(f) GDPR) or your consent where required by law. We retain this data for no longer than 2 years, unless a longer period is needed for security investigations.
4.8 Legal claims, insurance and risk management. Where necessary to establish, exercise, or defend legal claims, or to obtain or maintain insurance, we process the Personal Data reasonably necessary for that purpose. The legal basis is our legitimate interest in protecting our legal position (Art. 6(1)(f) GDPR) and, where applicable, legal obligation (Art. 6(1)(c) GDPR). We retain this data for as long as necessary for the relevant claim, proceeding, or insurance requirement.
4.9 Compliance with legal obligations. We process the Personal Data necessary to comply with legal obligations to which we are subject, including responding to lawful requests from courts and public authorities. The legal basis is legal obligation (Art. 6(1)(c) GDPR). We retain this data for as long as required by the applicable law.
4.10 Should the purpose or legal basis of a processing activity described in this Section materially change, we will inform you.
5. Traveller personal data processed in connection with your use of the Platform
5.1 This Section explains the boundary between Platform’s role and your role as Agent in respect of personal data belonging to Travellers — the individuals who engage you through the Platform.
5.2 Platform, as controller, processes limited Traveller data that passes through Platform’s own systems in the ordinary course of connecting you with Travellers: a Traveller’s name and contact details, itinerary or trip-planning information shared with the AI itinerary assistant, messages exchanged with you through the Platform’s chat, ratings and reviews, and booking metadata (such as destination, dates, and status). This data is processed to operate the Platform, match Travellers with Agents, enable communication, and resolve disputes, on the legal bases described in Section 4.
5.3 Platform does not, by design, collect or store Sensitive Booking Data - passport numbers, other government-issued identifiers, or full payment card or bank details relating to a Traveller. The Agent Terms and Conditions require you to collect Sensitive Booking Data solely through the secure intake channel(s) Platform designates for that purpose, and not through the Platform’s general chat or itinerary-planning functionality. Where you collect Sensitive Booking Data through that designated channel, it is transmitted to you (or, where applicable, to the relevant supplier) and is not retained in Platform’s general systems.
5.4 In respect of Sensitive Booking Data and any other Traveller personal data you collect or receive to provide Travel Services, you act as an independent controller or, where you and Platform have agreed in writing, a joint controller under Article 26 GDPR. This means you are responsible for having your own lawful basis, providing Travellers with appropriate privacy notice, implementing appropriate security, retaining the data no longer than necessary, and responding to Traveller rights requests concerning that data, all as further described in the Agent Terms and Conditions and any Data Processing Addendum between you and Platform.
5.5 If a Traveller submits a rights request to Platform concerning data that you, the Agent, control (for example, Sensitive Booking Data you collected directly), Platform will direct the Traveller to contact you, and you agree to respond as required by applicable law.
5.6 Nothing in this Section reduces your obligations under the Agent Terms and Conditions, including your obligation to comply with applicable data protection law in your own right.
6. How long do we store your personal data?
6.1 Your Personal Data processed for a specific purpose is not kept longer than necessary for that purpose. Specific retention periods are set out in Section 4.
6.2 After the applicable retention period ends, or upon your valid request, we delete or destroy your Personal Data using secure deletion or anonymisation methods.
6.3 We may aggregate, anonymise, or de-identify your Personal Data so that it can no longer reasonably be used to identify you. Such data is no longer personal, and we may use it without restriction, including for statistics, research, and improving the Platform.
6.4 Notwithstanding the retention periods in Section 4, we may retain Personal Data for longer where necessary to comply with a legal obligation (for example, accounting or tax law) or to establish, exercise, or defend legal claims.
7. To whom do we provide your personal data?
7.1 Travellers. As described in Section 4.2, Travellers who view your profile or engage you through the Platform see your name, agency name, areas of specialisation, language skills, service area, and ratings.
7.2 Payment Service Provider. We share your billing and payout details with our PSP insofar as necessary to process your Subscription Fee, remit Commission, and settle Traveller payments to you in accordance with Section 8.6 of the Agent Terms and Conditions. The PSP acts as a separate controller (or, where applicable, our processor) for the data it holds directly.
7.3 Verification and compliance providers. We share identity documents, biometric data collected for Identity Verification (Section 4.2), business-registration, licensing, and insurance information with our Identity Verification Provider and other third-party know-your-business, anti-fraud, and compliance service providers insofar as reasonably necessary to complete Verification and ongoing compliance monitoring under the Agent Terms and Conditions.
7.4 Professional advisers. We may disclose your Personal Data to our insurers, auditors, attorneys, and other professional advisers insofar as reasonably necessary for obtaining insurance, managing risk, obtaining professional advice, or establishing, exercising, or defending legal claims.
7.5 AI service providers. We may share limited data with third-party providers powering AI-assisted features described in Section 10, insofar as reasonably necessary to provide those features. These providers are bound by data protection obligations and appropriate security measures.
7.6 Other service providers. We may disclose your Personal Data to other providers insofar as reasonably necessary to deliver specific services, including hosting and IT providers, customer support tooling, and analytics providers. We enter into data processing agreements with these providers and require appropriate technical and organisational security measures.
7.7 Legal and regulatory disclosure. We may disclose your Personal Data where necessary to comply with a legal obligation, including lawful requests from courts, regulators, or law enforcement.
7.8 Business transfers. Where Platform assigns this Agreement or is subject to a merger, acquisition, or sale of assets as contemplated by the Agent Terms and Conditions, your Personal Data may be transferred to the relevant party, subject to appropriate protections.
7.9 International transfers. Recipients described in this Section may be located outside the European Economic Area or United Kingdom, including in the United States. Where we transfer your Personal Data to such recipients, we use appropriate safeguards required by applicable law, including Standard Contractual Clauses approved by the European Commission or the UK’s International Data Transfer Addendum, or we rely on another lawful transfer mechanism under Articles 45-49 GDPR. You may contact us for more information about the safeguards used for a specific transfer.
8. Marketing communications
8.1 We may contact you via email or phone to inform on what we are up to (we may send newsletters, the latest information about our products and services, special offers, marketing campaigns). Also, we may inform you about our similar products and services that might interest you via email. You have a right to object to such your Personal data processing at any time.
8.1.1. We may share your contact information with our group companies for direct marketing purposes.
8.2 When contacting you by phone (if you agreed to receive marketing communications via phone), SMS/text messages or phone calls from us will be received through your wireless provider to the mobile number you provided. SMS/text messages may be sent using an automatic telephone dialing system or other technology. Message frequency varies. Message and data rates may apply.
8.3 We may use your Personal data used to create your account and related to your use of our services to personalize marketing messages and advertisements presented to you. The legal basis for this processing is our legitimate interest to present you with marketing messages that we consider relevant to you (Art. 6(1)(f) of the GDPR).
8.4 You may opt out of receiving marketing communications at any time. You may do so by choosing the relevant link in our marketing messages or contacting us via means provided on our website, or you can contact us via email. If you are receiving both email and phone marketing communications and you wish to opt out of receiving them, you will need to opt out separately by following the relevant link in any of our marketing messages or contacting us via means provided in our Website or this Policy.
8.5 Upon you having fulfilled any of the provided actions, we will update your profile to ensure that you will not receive our marketing communication in the future.
8.6 In case you opt out of receiving marketing communications, we will immediately stop sending marketing communications to you. Nevertheless, please be informed that as our business activities consist of a network of closely related services, in certain cases, it may take a few days until all the systems are updated, thus you may continue to receive marketing communication while we are still processing your request.
8.7 In any case, the opt-out of the marketing communications will not stop you from receiving communication directly related to the provision of services.
Other marketing operations and cookies
8.8 We may use marketing tools of social media platform operators (e.g. Google LLC, Meta Platforms Inc.) or other third parties and, therefore, share your Personal data relevant for marketing operations to such social media platform operators or other third parties for marketing purposes.
8.9 For EU residents: Please note that social media platform operators may be established not in the EU and EEA, thus your Personal data may be transferred outside the EU and EEA. In this case, your Personal data will be protected by concluding Standard Contractual Clauses approved by the European Commission. More information about Standard Contractual Clause could be found here: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en.
9. Cookies and similar technologies
9.1 Please refer to our Cookies Policy.
10. AI tools
10.1 We use AI-assisted tools to support the Platform, which may include: matching Traveller requests to suitable Agents based on specialisation, language, and location; assisting you in drafting itineraries or responses to Traveller enquiries; and triaging support requests or disputes.
10.2 These tools may process your profile information, booking metadata, and the content of your communications on the Platform. They do not process Sensitive Booking Data, which, as described in Section 5.3, does not pass through Platform’s general systems.
10.3 Data processed by AI tools may be shared with third-party AI service providers who power that functionality. We require these providers to maintain appropriate confidentiality and security and to process data only as instructed.
10.4 Any transfer of Personal Data to an AI service provider located outside the EEA is subject to the safeguards described in Section 7.9.
11. Security of your personal data
11.1 We use appropriate technical and organisational measures to protect your Personal Data. Organisational measures include restricting access to personnel with a legitimate need, confidentiality obligations, training, and internal policies. Technical measures include encryption in transit and at rest where appropriate, access controls and authentication, and monitoring for unauthorised access.
11.2 Your Personal Data is stored on the servers of Platform or of contractors bound by data processing agreements and confidentiality obligations.
11.3 Personal Data is processed automatically wherever possible, without access by personnel. Where personnel access is necessary, it is limited to those whose role requires it, and they are bound by confidentiality obligations.
11.4 Despite the measures we take, we cannot guarantee the absolute security of your Personal Data.
11.5 If we become aware of a personal data breach affecting your Personal Data, we will notify you and the competent supervisory authority as required by applicable law.
12. Your rights
12.1 This Section summarises your principal rights under data protection law regarding Personal Data for which Platform is the controller (see Section 5 for the position regarding Traveller data you control). Some rights are complex; consult the GDPR and guidance from your supervisory authority for a full explanation.
12.2 Your principal rights are:
- (a) The right to be informed about how we process your Personal Data;
- (b) The right of access — to confirm whether we process your Personal Data and to obtain a copy of it, along with certain additional information;
- (c) The right to rectification of inaccurate or incomplete Personal Data;
- (d) The right to erasure in certain circumstances, such as where the data is no longer necessary for the purpose for which it was collected, subject to exceptions including our legal obligations and the exercise or defence of legal claims;
- (e) The right to restrict processing in certain circumstances, such as while you contest the accuracy of the data;
- (f) The right to object to processing based on our legitimate interest, including for direct marketing;
- (g) The right to data portability, where the legal basis is your consent or performance of a contract;
- (h) The right to withdraw consent at any time, where consent is the legal basis for processing, without affecting the lawfulness of processing before withdrawal;
- (i) The right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you, subject to exceptions described in Section 10.3; and
- (j) The right to lodge a complaint with a supervisory authority, as described in Section 16.
12.3 To exercise a right described in this Section, contact us using the details in Section 20. We may need to verify your identity before acting on your request. We will respond within one month, extendable by two months for complex or multiple requests, in which case we will inform you of the extension.
12.4 If your request concerns Traveller personal data that you, the Agent, control (see Section 5.4), we will direct the requester to you.
13. Third-party websites
13.1 The Platform may contain links to third-party websites. Such websites have their own privacy policies, and we are not responsible for their content or practices. We recommend reviewing the privacy policy of any third-party website before providing it with Personal Data.
14. Business users and minors
14.1 The Agent-facing Platform is intended for business use and is not directed at children. Under the Agent Terms and Conditions, Agent confirms it has full legal capacity to contract, and Agent is responsible for ensuring that any individual who accesses the Agent Account on its behalf is an adult with authority to do so.
15. US privacy addendum (CCPA / CPRA and other state laws)
15.1 If you are a California resident, in addition to the rights described in Section 12, you have the following rights under the CCPA/CPRA and, where applicable, other US state privacy laws:
- (a) we do not sell your Personal Data and do not share it for cross-context behavioural advertising; if this changes, we will notify you and provide a right to opt out;
- (b) we will retain, use, or disclose the Personal Data we process about you only for the purposes described in this Privacy Policy, and will notify you if this changes;
- (c) government identifiers (such as passport or identity document numbers) and financial account details you provide for Verification are treated as “sensitive personal information” under the CPRA; we use such information only as reasonably necessary to provide the Service and you have the right to limit its use for other purposes;
- (d) you have the right not to be discriminated against for exercising any right described in this Privacy Policy.
16. Right to complain
16.1 If you consider that our processing of your personal information infringes data protection laws, you have a legal right to lodge a complaint with a supervisory authority responsible for data protection. You may do so in the EU member state of your habitual residence, your place of work or the place of the alleged infringement. Our data processing is supervised by the State Data Protection Inspectorate of the Republic of Lithuania, registered office at L. Sapiegos St. 17, LT-10312 Vilnius, email address ada@ada.lt, www.vdai.lrv.lt.
17. Data scraping
17.1 Automated collection of data from the Platform (“data scraping”), including by software, bots, or scripts, is strictly prohibited without our explicit written consent.
18. Updating your data
18.1 Please let us know if the Personal Data we hold about you needs to be corrected or updated.
19. Changes to this Privacy Policy
19.1 We may change this Privacy Policy from time to time. Changes take effect on publication to the Platform. Where a change is material, we will inform you by email or another appropriate means.
19.2 We will avoid changes that impose materially greater obligations on you or reduce your rights under this Privacy Policy without advance notice.
20. Contacts
20.1 For any inquiry or to exercise a right described in this Privacy Policy, contact us at team@tripdash.net or UAB Spine Revolution, Aludarių g. 3.