1.Who we are, and our two roles
touratoz is made and run by NextApp Lab ("we", "us"). We hold two kinds of data, in two different roles.
- Account data: the details of the agency and of the people who sign in (name, e-mail address, phone number, password), and its billing and support records. We decide why and how this is used: for it we are the controller.
- Agency data: the records an agency enters about its own customers, passengers, suppliers and staff. The agency decides why and how this is used. We only store and process it on the agency's instructions, as its processor.
2.The data we collect
What you give us:
- At registration: the agency's name and country, and the owner's name, e-mail address, phone number and password.
- The agency's profile: its address, tax and licence numbers, logo, the bank details printed on its invoices, and its settings.
- The records you enter: customers and passengers (names, contact details, and passport, visa and birth details where you record them), tickets, hotel bookings, invoices, payments, suppliers, staff, attendance and uploaded files.
- Payments to us: the plan bought, the amount, the method and the transaction reference. We do not collect or store card numbers or wallet PINs.
- What you write to us: support requests, e-mails and calls.
What is recorded automatically:
- Sign-in and activity records: who did what and when, the IP address, and the device and browser used.
- Technical logs needed to run and secure the service.
- Cookies that the service cannot work without (see "Cookies").
We do not buy personal data from anyone, and the website carries no advertising or tracking tools.
3.How we use it
We use personal data to:
- create and run your account, and provide the service you asked for;
- sign you in safely, and keep the activity record your agency's administrators see;
- send service messages: verification codes, invitations, receipts, notices about your plan, security alerts and changes to our policies;
- take payments, issue receipts and keep the accounts the law requires;
- answer support requests;
- protect the service: find and stop misuse, fraud and attacks;
- manage each agency's account: authorised staff may view a summary of how the agency uses the service — sign-ins and activity, the number and value of its sales, collections and amounts owed, the features it uses and its use of its plan's limits — as totals only, never a customer's or passenger's details; we keep a record of who viewed it;
- understand, in totals, how the service is used, so that we can improve it;
- meet our legal duties.
We do not sell personal data, and we do not use your agency's records for advertising.
4.Our legal grounds
We process personal data on these grounds: to carry out our contract with your agency; with your consent, given when you tick the box at sign-up (you may withdraw it — see "Your rights"); to meet a legal duty; and for our legitimate interest in keeping the service secure and working, managing accounts and improving the service, where that does not override your rights.
5.Data an agency enters about its customers
An agency that records its customers' and passengers' details in touratoz is responsible for that data: for telling those people how it is used, for having a lawful reason to hold it, and for answering their requests.
We process that data only to provide the service to the agency. We keep it apart from every other agency's data and do not use it for purposes of our own. Our staff open an agency's records only when that is needed to fix a fault or answer a support request, or when the law requires it. The account summaries described under “How we use it” are totals and never show a customer's or passenger's details.
If you are a customer of an agency and want to see, correct or delete your details, please contact that agency. If you write to us instead, we pass your request on to it.
7.Where data is kept
Our servers and our service providers may be in a country other than yours. When personal data leaves your country, we take the steps the applicable law asks for — such as contractual safeguards with the receiver — so that it stays protected to the same standard.
8.How we protect it
We protect data with technical and organisational measures, including:
- encryption in transit: every connection to the service uses HTTPS;
- passwords kept only as one-way encrypted hashes and checked against lists of leaked passwords; they are never stored or shown in a readable form;
- sign-in sessions held in secure cookies that page scripts cannot read, which expire and are cancelled at sign-out;
- each agency's data kept apart from every other agency's;
- access by role and permission inside your agency, and a record of sign-ins and changes;
- two-step sign-in for our own operators, and access to the systems limited to the staff who need it;
- regular backups, and defences against common attacks.
No system is perfectly secure. You have a part too: keep your password secret, give each person their own account and only the permissions they need, and remove the people who leave.
9.How long we keep it
- Account and agency data: for as long as the agency's account is open.
- After a plan ends or the account is closed: kept for at least 30 days so that you can download it; after that it may be deleted permanently.
- Backups: overwritten after about 30 days.
- Data you delete yourself: no longer available in the service. We are not obliged to restore it, and may be unable to.
- Billing records, and records the law makes us keep (for example tax and accounting records): for the period the law sets.
- Security and activity logs: for as long as needed to keep the service safe and look into incidents.
10.Your rights
Depending on the law that applies to you — including Saudi Arabia's PDPL, Bangladesh's personal data protection law and, where it applies, the GDPR — you have the right to:
- know what data we hold about you, and receive a copy;
- have wrong or incomplete data corrected;
- have your data deleted when there is no longer a reason to keep it;
- receive your data in a usable format (the dashboard's backup download gives an agency its records);
- withdraw a consent you gave, or object to a use of your data;
- complain to the data protection authority of your country.
Most details can be corrected in the dashboard, under your profile and your agency's settings. For anything else, write to us at the address at the end of this page. We answer within 30 days, and may first ask you to show who you are.
If you withdraw a consent, or ask us to delete data the service needs, we may no longer be able to provide the service to you.
12.Children
touratoz is a tool for businesses. It is not meant for anyone under 18, and we do not knowingly open an account for them. An agency may record a child passenger's details as part of a booking; the agency is responsible for that data.
13.If data is breached
If we learn of a breach of security that puts your personal data at risk, we tell the affected agencies without undue delay — and within 72 hours where the law requires it — and we notify the competent authority as the law requires. We say what happened, which data was involved, and what we are doing about it.
14.Changes to this policy
We may update this policy. The date at the top shows the latest version. We announce a material change at least 15 days before it takes effect, in the dashboard or by e-mail.
This policy is published in several languages; if they differ, the English version prevails.
Questions about this policy?
Get in touch with NextApp Lab, the company that makes touratoz.
- Emailhello@nextapplab.com
- Phone+880 1712 345 678
- Head officeNextApp Lab, Gulshan Avenue, Dhaka-1212