Last Updated: January 1, 2026 • Version 2.8
GDPR & PCI-DSS Aligned
Your privacy is our priority. We never sell, rent, or monetize your personal travel data. Information collected is used exclusively to fulfill your travel bookings and provide customer support.
1. Information We Collect
To process flight tickets, hotel reservations, visa documentation, and agent transactions, we collect the following categories of information:
- Identity & Passport Data: Full name, date of birth, gender, nationality, passport number, expiry date, and issuing authority.
- Contact Details: Email address, mobile/WhatsApp telephone numbers, and physical mailing address.
- Booking & Travel Preferences: Flight itineraries, dietary meal requests, seat selections, and hotel room preferences.
- Payment & Financial Information: Bank deposit slips, transaction reference numbers, and encrypted payment tokens (credit card details are processed directly via PCI-DSS compliant gateways and never stored on our servers).
2. How We Use Your Information
Your information is processed strictly for legitimate travel operation purposes, including:
- Issuing electronic airline tickets (GDS / PNR creation) and hotel check-in vouchers.
- Submitting Saudi Umrah e-Visa and international visa applications to authorized governmental portals.
- Sending flight schedule update notifications, gate changes, and invoice receipts.
- Maintaining B2B agency ledger balances and financial audit trails.
3. Data Protection & Encryption Standards
Tripeo employs rigorous technical and organizational security controls to protect your data:
- 256-Bit SSL/TLS Encryption: All data transmitted between your browser and our servers is secured using modern TLS 1.3 cryptographic protocols.
- Encrypted Database Storage: Sensitive credentials and session tokens are hashed using industry-standard
bcrypt and AES-256 encryption.
- Restricted Internal Access: Only authorized operations personnel with role-based access controls (RBAC) are granted access to passenger manifest data.
4. Disclosure to Third-Party Service Providers
We share necessary passenger information solely with vetted travel suppliers required to execute your booking:
- Airlines, Global Distribution Systems (Sabre, Amadeus), and consolidators.
- Hotels and on-ground transfer operators in destination cities.
- Consulates, embassies, and the Saudi Ministry of Hajj & Umrah for visa clearance.
5. Your Privacy Rights & Data Control
In accordance with global data protection regulations (including GDPR), you retain full rights to:
- Request a full copy of the personal data held about you.
- Request corrections to any inaccurate or incomplete personal records.
- Request the deletion or anonymization of your data (subject to statutory financial and airline record retention rules).
Data Privacy Inquiries
To exercise your data privacy rights or speak with our Data Protection Officer, contact us below.
Contact Data Privacy Team