Legal
Privacy Policy
Last updated: 1 September 2026
This Privacy Policy explains how Voyara ("Voyara", "we", "us") collects, uses, and protects information when travel agencies ("Agencies", "you") sign up for and use the Voyara platform, and when Agencies' own customers ("Travelers") interact with an Agency's storefront hosted on Voyara. This policy covers Voyara's own conduct as the platform operator — it is separate from, and does not override, the privacy policy each Agency publishes on its own storefront for its Travelers.
1. Information we collect
- Account information: when you create an agency, we collect your name, email address, and a hashed (never plaintext) password.
- Agency configuration: your agency name, chosen subdomain, branding, plan tier, and any third-party API credentials you choose to connect (e.g. your own flight provider key), which are encrypted at rest.
- Usage data: booking volume, feature usage, and basic request logs, used to operate, secure, and improve the platform, and to enforce plan limits.
- Traveler data, on your behalf: when Travelers book through your storefront, the resulting passenger and booking details are stored on your Agency's behalf so your storefront and admin dashboard function — Voyara processes this data as your service provider, not as an independent controller of your Travelers' data.
2. How we use information
We use the information above to provide and operate the platform, authenticate accounts, process bookings through connected flight providers, enforce plan limits, provide customer support, and maintain the security and reliability of the service. We do not sell Agency or Traveler personal data.
3. Third-party services
Voyara integrates with third-party providers to deliver core functionality — including flight search and booking providers (e.g. Duffel), email delivery, and image hosting. These providers process the minimum data necessary to perform their function and are bound by their own data protection obligations.
4. Data retention
We retain account and booking data for as long as an Agency's account is active, and for a reasonable period afterward to comply with legal, accounting, or support obligations. Agencies may request deletion of their account by contacting us.
5. AI support assistant
If you use the AI chat assistant on this website, we collect and store the name and email address you provide to start a conversation, along with the full content of that conversation, so we can respond to follow-up questions and improve the assistant. This data is retained for 90 days, after which it is automatically deleted.
To generate responses, your messages are sent to OpenAI, which processes them solely to produce the assistant's reply — OpenAI acts as our data processor for this purpose and does not receive any other information about you. We do not share your chat data with any other third party.
6. Security
Passwords are hashed, never stored in plaintext. Third-party API credentials you connect to your account are encrypted at rest. We restrict internal access to production data to what's necessary to operate and support the platform.
7. Your rights
Depending on your location, you may have rights to access, correct, or delete your personal information. To exercise these rights, contact us using the details below.
8. Contact
Questions about this policy can be sent to privacy@voyara.app.
This page is a general description of our practices and is provided for informational purposes; it is not legal advice.