Data we use
We use account, organization, client, trip, search, proposal, subscription, and minimal event data to operate the advisor workspace.
Search criteria sent to providers is limited to the parameters required for that search. Raw client conversation is not sent to travel providers.
Data we do not request
- Traveler payment cards
- Passport numbers or passport images
- Supplier portal passwords
- Unnecessary provider credentials in client-facing forms
Retention
Raw provider payloads default to a maximum of 24 hours when contract policy allows storage. Normalized offers may remain up to 30 days but become stale according to provider TTL. Search metadata may remain for 12 months.
Uploaded quotes and inbound attachments default to 30 days. Provider contract policy overrides default retention when it is more restrictive.
AI processing
AI features receive redacted client text or selected normalized fields, use structured validation, and do not receive provider credentials. AI responses are requested with storage disabled.
Deletion and access
Organization deletion revokes sessions and public proposals, schedules tenant data and private file removal, and retains only records required for billing, security, or legal obligations.
Privacy questions and data-rights requests can be sent to privacy@voyagefoundry.com.