Legal

Privacy Policy

How we collect, use, and protect your personal data

01

Introduction

This Privacy Policy explains how TrvlEz [LEGAL ENTITY NAME], a company registered in England and Wales under company number [COMPANY NUMBER], with its registered office at [REGISTERED ADDRESS] ("TrvlEz", "we", "us", or "our"), collects, uses, stores, shares, and protects personal data when you use the TrvlEz mobile application, website, and related services (together, the "Platform").

This Policy applies to travellers who create a TrvlEz identity, hotels and other accommodation providers who use TrvlEz to verify guests ("Partners"), and individuals who participate in the TrvlEz Findr referral programme ("Findr").

TrvlEz is the data controller for the personal data described in this Policy, except where stated otherwise. If you have any questions about this Policy or how we handle your data, contact our Data Protection Officer using the details in Section 16.

We process special category personal data, including biometric data derived from facial images and government identity documents. Section 5 of this Policy explains this in detail and describes the additional protections that apply.

02

Information We Collect

2.1 Information you provide directly

  • Full legal name, date of birth, nationality, and gender as it appears on your identity document
  • Contact details, including email address, phone number, and postal address
  • Government-issued identity document information, including passport number, issuing country, document expiry date, and the data encoded on the document's biometric chip
  • A live photograph or short video of your face, captured for the purpose of comparing it against your identity document ("Selfie")
  • Payment and billing information, where you make or receive payments through the Platform
  • Information you provide when contacting customer support, including the content of your communications
  • For Findr: bank account details for the purpose of receiving commission payments, and any notes or information you submit when referring a hotel

2.2 Information generated through the verification process Biometric data. A facial geometry scan generated by comparing your Selfie to the photograph on your identity document, used solely to confirm that the two images depict the same person. See Section 5. NFC chip data. The data stored on your passport's embedded chip, read using near-field communication (NFC) technology, which we use to confirm the authenticity of the document and cross-check it against the printed information. A unique verification status and an internal identifier for your verified profile.

2.3 Information collected automatically Device information, including device type, operating system, unique device identifiers, and mobile network information IP address and approximate location derived from it App usage data, including pages viewed, features used, crash reports, and timestamps Cookies and similar tracking technologies, as described in our Cookie Policy (Section 14)

2.4 Information from third parties Information from hotel partners regarding your booking and stay, where you check in using TrvlEz Information from payment processors regarding the success or failure of a transaction Information from fraud prevention and sanctions screening services, where required by law

03

Legal Basis for Processing (UK and EU GDPR)

Where UK GDPR or EU GDPR applies to you, we rely on the following legal bases:

  • Creating and verifying your identity: Performance of a contract with you, and your explicit consent for biometric processing
  • Facial biometric comparison: Your explicit, separately given consent (Article 9(2)(a) UK/EU GDPR)
  • Facilitating hotel check-in: Performance of a contract with you
  • Fraud prevention and platform security: Our legitimate interests, balanced against your rights
  • Marketing communications: Your consent, which you may withdraw at any time
  • Compliance with legal obligations, including anti-money laundering and tax law: Legal obligation
  • Findr commission payments and referral tracking: Performance of a contract with you

Where we rely on your consent for biometric processing, you may withdraw that consent at any time as described in Section 5.4. Withdrawing consent will not affect the lawfulness of processing carried out before withdrawal, but it will mean you can no longer use the verification features of the Platform.

04

How We Use Your Information

We use the information described in Section 2 to:

  • Verify your identity and create a trusted digital identity profile
  • Confirm the authenticity of identity documents and detect forged, altered, or expired documents
  • Facilitate check-in at participating hotels by sharing your verification status with the relevant Partner
  • Detect, investigate, and prevent fraud, impersonation, and misuse of the Platform
  • Process payments, including hotel bookings, travel credit, and Findr commission payouts
  • Provide customer support and respond to enquiries
  • Comply with legal and regulatory obligations, including know-your-customer (KYC) and anti-money laundering (AML) requirements where applicable
  • Improve the security, reliability, and performance of the Platform
  • Send service-related communications, and, where you have consented, marketing communications

We do not use your biometric data to train artificial intelligence or machine learning models without separately asking for and obtaining your explicit consent to do so. We do not use your data to make any decision about you that has a legal or similarly significant effect on you without human review being available on request.

05

Biometric Data: Special Protections

Because biometric data is treated as a special, higher-risk category of personal data under UK GDPR, EU GDPR, and biometric privacy laws in certain other jurisdictions (including parts of the United States), we apply the following additional protections.

5.1 What counts as biometric data For the purposes of this Policy, "Biometric Data" means:

  • The Selfie image or video you provide
  • The photograph and any facial image stored on your identity document
  • Any facial geometry scan, facial template, or similar mathematical representation generated by comparing the two
  • Any data read from the NFC chip embedded in your passport that is used to verify the document's authenticity

5.2 Standalone consent Before we collect or process any Biometric Data, you will be shown a dedicated consent screen, separate from your general acceptance of these Terms and this Policy. We will not proceed with biometric verification unless you actively confirm your consent on that screen. You may decline, in which case alternative verification methods may be offered where available, or you may be unable to complete verification.

5.3 How Biometric Data is used Biometric Data is used exclusively to: compare your Selfie against your identity document to confirm they depict the same individual; confirm the authenticity of your identity document via NFC chip verification; and detect signs of document tampering, forgery, or impersonation. We do not use Biometric Data for any other purpose, including marketing, profiling, or advertising. We do not sell, lease, trade, license, or otherwise profit from your Biometric Data.

5.4 Retention and deletion of Biometric Data The facial geometry scan generated for comparison purposes is deleted automatically within 72 hours of a successful or unsuccessful verification attempt, once the comparison has been completed. Your Selfie image and the image of your identity document are retained for as long as your TrvlEz account remains active, and for 12 months after account closure or your last platform activity, whichever is later, unless a longer period is required to comply with a legal obligation, resolve a dispute, or investigate suspected fraud. NFC chip verification data confirming document authenticity is retained for the same period as the document image above. The raw chip data itself is not retained beyond the verification session; only the verification result (pass or fail) is stored. You may request earlier deletion of your Biometric Data at any time, as described in Section 5.5, save where we are required to retain it by law or where retention is necessary to defend against a legal claim.

5.5 Withdrawing consent and requesting deletion You may withdraw your consent to biometric processing, and request deletion of your Biometric Data, at any time by using the "Delete my identity data" function within the app, or contacting privacy@trvlez.io. We will process your request within 30 days. Please note that withdrawing consent or deleting your Biometric Data will mean you can no longer use TrvlEz's verification-based check-in features, and any previously verified status will be revoked.

5.6 No automated biometric decision-making without review Where a facial comparison results in a failed match, you will always be offered the option of manual review by a human member of our verification team before any final decision is made about your account or access to the Platform.

06

Sharing of Information

We do not sell your personal data. We share personal data only in the following circumstances:

6.1 With hotel Partners When you check in at a participating hotel using TrvlEz, we share your name, nationality, date of birth, passport number, a profile photograph (not your raw Biometric Data), your verification status, and your booking reference with that hotel, solely for the purpose of completing check-in and meeting the hotel's legal guest registration obligations. We do not share your Biometric Data itself with hotel Partners.

6.2 With service providers We engage third-party service providers to help us operate the Platform, including cloud infrastructure and storage providers (currently Amazon Web Services), payment processors, customer support and communication tools, and fraud prevention and sanctions screening providers. These providers are contractually required to use personal data only as instructed by us, to apply security measures at least as strong as our own, and to delete or return data when their engagement with us ends.

6.3 For legal and safety reasons We may disclose personal data where required by law, in response to a valid request from a law enforcement or regulatory authority, to protect the safety of any person, to investigate fraud or security incidents, or to establish, exercise, or defend our legal rights.

6.4 Business transfers If TrvlEz is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction. We will notify you of any such transfer and any choices you may have.

6.5 With your consent We may share personal data with other third parties where you have given specific consent for us to do so.

07

International Data Transfers

Your personal data, including Biometric Data, is primarily stored and processed within the United Kingdom and the European Economic Area. Where we or our service providers transfer personal data outside the UK or EEA, we ensure appropriate safeguards are in place, which may include:

  • Adequacy regulations recognising that the destination country provides an adequate level of data protection
  • Standard Contractual Clauses approved by the UK Information Commissioner's Office or the European Commission
  • Other legally recognised transfer mechanisms

You may request further information about the safeguards we use for a specific transfer by contacting us using the details in Section 16.

08

Data Security

We implement technical and organisational measures designed to protect personal data, including:

  • Encryption of data in transit and at rest using AES-256 or equivalent industry-standard encryption
  • Access controls limiting which employees and systems can access personal data, based on the principle of least privilege
  • Network security monitoring and regular security testing
  • Contractual security requirements imposed on all service providers who process personal data on our behalf
  • Secure deletion procedures for data that has reached the end of its retention period

No system can be guaranteed perfectly secure. If we become aware of a data breach affecting your personal data that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay, in accordance with applicable law.

09

Data Retention

Other than Biometric Data, which is governed by Section 5.4, we retain personal data as follows:

  • Account and profile information: For as long as your account is active, plus 12 months after closure
  • Booking and check-in records: 6 years from the date of the transaction, to comply with tax and accounting obligations
  • Findr referral and commission records: 6 years from the date of the relevant payment, to comply with tax and accounting obligations
  • Customer support communications: 3 years from the date of the last communication
  • Marketing consent records: Until you withdraw consent, plus a record of the withdrawal for 3 years
  • Device and usage data: 24 months

Where data is needed to comply with a legal obligation, resolve an ongoing dispute, or defend a legal claim, we may retain it for longer than the periods above, limited to what is necessary for that specific purpose.

10

Your Rights

Depending on your jurisdiction, you have some or all of the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate or incomplete data.
  • Erasure: Request deletion of your personal data, subject to the exceptions described in this Policy.
  • Restriction: Request that we limit how we use your data while a dispute is resolved.
  • Portability: Request a copy of your data in a structured, machine-readable format.
  • Objection: Object to processing based on our legitimate interests, including for marketing purposes.
  • Withdraw consent: Withdraw consent for any processing based on consent, including biometric processing, at any time.
  • Complain: Lodge a complaint with your local data protection authority. In the United Kingdom, this is the Information Commissioner's Office (ico.org.uk).

To exercise any of these rights, contact us using the details in Section 16. We will respond within one month, extendable by a further two months for complex requests, in which case we will explain the delay.

11

Children

The Platform is not directed at, and must not be used by, individuals under the age of 18. We do not knowingly collect personal data, including biometric data, from anyone under 18. If we become aware that we have inadvertently collected data from a person under 18, we will delete it promptly. If you believe a child has provided us with personal data, please contact us using the details in Section 16.

12

Automated Decision-Making

We use automated systems to assist with document authenticity checks and facial comparison. Where an automated check results in a failed verification, you are always entitled to request human review before any final decision is made regarding your account. We do not make any decision that produces legal effects or similarly significantly affects you based solely on automated processing without the opportunity for human review.

13

Marketing Communications

Where you have given consent, we may send you marketing communications about TrvlEz features, partner hotels, and the Findr programme. You may withdraw consent at any time by using the unsubscribe link in any marketing email or through your account settings. Withdrawing marketing consent will not affect service-related communications necessary for the operation of your account.

14

Cookies and Similar Technologies

We use cookies and similar tracking technologies on our website and within the app to:

  • Keep you signed in
  • Remember your preferences
  • Understand how the Platform is used, so we can improve it
  • Measure the effectiveness of marketing campaigns, where you have consented

You can control cookie preferences through your browser settings or, where available, through the cookie consent tool presented when you first visit our website. Disabling certain cookies may affect the functionality of the Platform.

15

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. If we make material changes, including any change affecting how we process Biometric Data, we will notify you by email or through a prominent notice within the app before the change takes effect, and we will seek fresh consent where required by law.

16

Contact Us

Data Protection Officer / Privacy Team

privacy@trvlez.io

Postal address: [REGISTERED ADDRESS]

Information Commissioner's Office (UK supervisory authority) Website: ico.org.uk Telephone: 0303 123 1113

This document was last reviewed on [DATE]. TrvlEz is registered with the Information Commissioner's Office under registration number [ICO REGISTRATION NUMBER].