Legal
Privacy Policy
This policy explains what personal data Travator collects, why we collect it, where it is stored, and the choices you have. It is written to meet the transparency requirements of the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), as amended by CPRA.
Last updated: 20 July 2026
1. Who we are
Travator is a travel planning product operated by (Pvt) Ltd (“Travator”, “we”, “us”, or “our”).
Registered address: Level 9, Orion Towers, No 752 Dr Danister De Silva Mawatha, Colombo 00900, Sri Lanka.
Privacy contact: hello@travator.com
For the purposes of GDPR, (Pvt) Ltd is the data controller for personal data processed through travator.com and our related services.
2. Scope
This policy applies when you:
- Browse our marketing website (travator.com)
- Use the AI trip planner at /chat
- Sign in with email and one-time passcode (OTP)
- Submit our contact or booking forms
- Communicate with us by email or phone
It does not cover third-party websites or services we link to (for example, Calendly scheduling pages), which have their own privacy policies.
3. Personal data we collect
We collect only what we need to operate Travator. Depending on how you use the product, this may include:
Account and identity
- Email address — used to sign you in and associate your trips with your account
- Name — optional; collected when you provide it (for example, via our contact form)
Trip planning and conversations
- Chat messages and interactions — the text you send, AI replies, and UI actions (destination picks, date changes, booking steps)
- Trip details — destinations, travel dates, guest count, itinerary preferences, hotel and driver selections
- Conversation metadata — titles, planning mode (AI or human agent), and model settings
Contact and support
- Contact form submissions — name, email, message, and optional preferred call time
- Communications — records of emails or calls when you reach out to us
Booking and payment (when enabled)
- Booking records — itinerary holds, quotes, confirmation status, and travel dates
- Payment references — amount, status, and provider reference from Stripe or PayHere. We do not store full card numbers on our servers; payment card data is handled by the payment provider.
- Imported booking emails (planned feature) — flight PNR, confirmation numbers, and email content you choose to forward for import
Technical and security data
- Authentication tokens — a signed JSON Web Token (JWT) issued after OTP verification, valid for up to 30 days, containing your user ID and email
- OTP records — a hashed one-time code and expiry timestamp (we never store plaintext OTPs)
- Server logs — standard request metadata (timestamps, IP address, user agent) for security and debugging
- Cookie consent preference — stored locally in your browser when you respond to our cookie banner
We do not currently run advertising analytics, sell personal data, or use cross-site tracking pixels.
4. How we collect data
- Directly from you — when you type in the planner, submit forms, sign in, or contact us
- Automatically — when our API processes your requests and writes server logs
- From AI and search providers — we send your conversation text to large language model (LLM) providers to generate replies; we send search queries to embedding providers to match hotels and knowledge content
Anonymous users can start planning without an account. When you sign in, we link prior conversations to your account where technically feasible.
5. Why we use your data and legal bases (GDPR)
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide the trip planner and AI assistant | Messages, trip details, interactions | Contract / pre-contract steps (Art. 6(1)(b)) |
| Create and manage your account | Email, name, JWT, OTP hash | Contract (Art. 6(1)(b)) |
| Process bookings and payments | Booking, payment, itinerary data | Contract (Art. 6(1)(b)) |
| Respond to contact requests | Name, email, message | Legitimate interests / steps at your request (Art. 6(1)(b)/(f)) |
| Secure and operate our infrastructure | Logs, tokens, OTP records | Legitimate interests (Art. 6(1)(f)) |
| Remember cookie preferences | Consent choice in local storage | Consent (Art. 6(1)(a)) |
| Comply with law | Relevant records | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, you may object as described in Section 10. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
6. Where data is stored
Personal data is stored in a PostgreSQL database hosted on infrastructure we control or contract with. Database tables include, among others:
users,otp_codes— account and authenticationconversations,messages,interactions— chat and UI actionstrips,itineraries,holds,quotes,bookings,payments— planning and booking lifecyclecontact_requests— contact form submissions
Your browser may store a JWT when you sign in (currently passed via the Authorization header by client applications) and a cookie consent preference in localStorage. We do not set first-party marketing cookies today.
Conversation content is transmitted to LLM providers for processing at inference time. Those providers process data under their own terms and do not receive ongoing access to our database.
7. Third-party processors
We use carefully selected service providers who process data on our behalf. They may only use data as instructed by us:
| Provider | Purpose | Data shared |
|---|---|---|
| Anthropic | AI conversation (Claude) | Conversation history and system context per request |
| OpenAI | AI conversation and embeddings (optional) | Conversation text; search queries for embeddings |
| Voyage AI | Semantic search embeddings (optional) | Hotel and knowledge search text |
| Stripe / PayHere | Payment processing (when enabled) | Payment amount, booking reference; card data stays with provider |
| Google Fonts | Typography delivery | IP address and browser metadata (see Google's policy) |
| Calendly | Call scheduling embed | Information you enter in the Calendly widget |
| Unsplash CDN | Marketing photography | Standard CDN request metadata |
We do not sell or share personal data for cross-context behavioural advertising. Under CCPA/CPRA, we do not “sell” or “share” personal information as those terms are defined in California law.
9. Retention
We keep personal data only as long as needed:
- Account data — while your account is active and for a reasonable period afterward if you delete your account
- Conversations and trips — while you use the service and to support bookings you make through us
- OTP records — until expiry or verification; we aim to purge consumed codes periodically
- Contact requests — typically up to 24 months unless a longer period is needed to handle your inquiry
- Booking and payment records — as required for accounting, tax, and dispute resolution (often 7 years where applicable)
- Server logs — rolling retention, generally limited to operational needs
You may request deletion sooner, subject to legal exceptions (Section 10).
10. Your rights
GDPR (EEA, UK, and similar jurisdictions)
Subject to conditions in law, you have the right to:
- Access — obtain a copy of personal data we hold about you
- Rectification — correct inaccurate data
- Erasure — request deletion (“right to be forgotten”)
- Restriction — limit how we use your data in certain cases
- Portability — receive data you provided in a structured, machine-readable format
- Object — object to processing based on legitimate interests
- Withdraw consent — where processing is based on consent
- Lodge a complaint — with your local supervisory authority
CCPA / CPRA (California residents)
You have the right to:
- Know what personal information we collect, use, and disclose
- Delete personal information, subject to exceptions
- Correct inaccurate personal information
- Opt out of sale or sharing — not applicable today because we do not sell or share data for cross-context advertising
- Non-discrimination — we will not deny service for exercising these rights
To exercise any right, email hello@travator.com with the subject line “Privacy request”. We may need to verify your identity (for example, by confirming control of your account email). We aim to respond within 30 days (GDPR) or 45 days (CCPA), with extensions where permitted.
11. International transfers
Travator is operated from Sri Lanka. Our infrastructure and processors may be located in Sri Lanka, the United States, the European Union, or other countries. Where GDPR applies, we use appropriate safeguards for transfers (such as Standard Contractual Clauses) with processors that receive personal data from the EEA or UK.
12. Security
We protect data using measures appropriate to the risk, including encrypted transport (HTTPS), hashed OTP storage, access controls on production systems, and least-privilege access for staff. No method of transmission or storage is completely secure; please use a strong, unique email account for sign-in.
13. Children
Travator is not directed at children under 16 (or the age required in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
14. Changes
We may update this policy when our product, processors, or legal obligations change. We will post the revised version on this page and update the “Last updated” date. Material changes may also be communicated by email or in-product notice where appropriate.
15. Contact
Questions or requests about this policy or your data:
(Pvt) Ltd — Travator
Level 9, Orion Towers
No 752 Dr Danister De Silva Mawatha
Colombo 00900, Sri Lanka
hello@travator.com