Skip to content

Legal

Privacy Policy

This policy explains the information handled through Voyara and the choices and rights available to people whose data is involved.

1. What Voyara does

Voyara provides software for travel companies to manage enquiries, travellers, supplier information, quotations, itineraries, tasks, payment records and related operations. Contact us at arjunshah.kenya@gmail.com.

2. Our role and the travel company’s role

Voyara may act as controller for user accounts, support, security and its direct customer relationships. A travel company generally decides why its travellers’ information is collected and used; Voyara processes that information to provide the service to that company. Travel companies are responsible for an appropriate legal basis for information they place into Voyara, including authorization or consent required by law for minors.

3. Information we process

This may include account, company and staff information; traveller identity and contact information; enquiries, trips, dates and preferences; quotations, pricing and supplier information; documents, rate sheets and uploads; itineraries; payment records entered into Voyara; notes, messages and audit information; browser, device and security data; and information submitted to AI functionality.

4. Why we process it

We use information to operate Voyara, authenticate users, maintain company workspaces, support travel workflows, process supplier documents, provide AI assistance and content generation, support customers, prevent misuse, diagnose errors, maintain reliability and comply with law. Voyara does not sell personal information.

5. AI-assisted processing

When an AI feature is used, relevant submitted information may be sent to an AI service provider to generate a result. AI results are intended to assist operators and require human review; they are not intended to make independently significant final decisions about travellers. Do not submit more sensitive information than the task requires.

6. Service providers and international transfers

We rely on providers for categories of service such as hosting, databases, authentication, private file storage, AI processing, email and, where configured, monitoring or analytics. Voyara and its providers may process information in other countries. Appropriate safeguards should be used where law requires them.

7. Security

Controls in the product include authenticated access, private document storage, organization-scoped permissions, server-side secrets and tenant-isolation checks. We work to maintain these controls, but no online service can guarantee absolute security.

8. Retention

Information is retained for reasonable periods needed to provide the service, meet customer instructions and address legitimate legal, security and operational needs. Travel companies control much of the information they enter. A deletion request may be subject to verification and applicable retention obligations.

9. Your rights

Where applicable, you may have rights to be informed, access, correction, objection, deletion, withdrawal of consent where relevant, and complaint to a competent authority. If a travel company supplied your information, that company may be the appropriate controller for your request and we may assist it.

Send requests to arjunshah.kenya@gmail.com. We may verify your identity or authority before disclosing or changing data. See our data rights page.

10. Connected agency mailboxes

Where enabled and authorized by an agency administrator, Voyara uses read-only Google or Microsoft access to import recent inbox messages when the administrator requests an import. We store the mailbox address, sender, subject, plain-text message or preview, received time and provider message identifiers in the agency workspace. OAuth tokens are encrypted and kept server-side. Imported messages are shared with the agency’s authorized active team, not other agencies. Connect only a mailbox you are authorized to share with that team.

The connector does not send email, retrieve attachments, load remote images, automatically create enquiries or send mailbox content to AI providers. Disconnecting removes Voyara’s stored access credentials and stops further imports; imported records remain part of the agency’s saved work. You may also revoke consent in your Google or Microsoft account. Request deletion of imported records through your agency administrator or our support address.

Google user data is used only to provide this correspondence workflow, not advertising, sale of data or training general-purpose AI models. Voyara’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Service providers process this information only as needed to operate the service.

11. Changes

We may update this policy as the service changes. The last-updated date above will change when we do.