Collab Travel CRM Trust Center

Privacy Policy

Last updated: February 25, 2026

Collab Travel CRM is committed to protecting the traveler and supplier information that powers your business. This Privacy Policy explains the personal data we collect, why we collect it, and how we keep it secure.

1. Data controller

Collab Travel CRM ("we", "us", "our") is the data controller responsible for your personal data. If you have questions about how your data is handled, contact us at hello@collabtravelcrm.com.

2. Information we collect

Collab Travel CRM collects information that you provide directly, including account details, traveler and supplier records, support requests, and feedback submitted through the platform.

We also automatically collect technical data such as log files, device identifiers, browser type, operating system, IP address, and usage analytics that help us understand how the platform performs.

3. Legal basis for processing (GDPR)

Under the General Data Protection Regulation (GDPR), we process personal data on the following legal bases:

• Contract performance — to deliver the Collab Travel CRM service you signed up for.

• Legitimate interests — to improve our product, prevent fraud, and ensure platform security, where those interests are not overridden by your rights.

• Consent — for analytics cookies, advertising cookies, and marketing communications. You may withdraw consent at any time via your cookie preferences or by contacting us.

• Legal obligation — to comply with applicable laws, regulations, and legal processes.

4. How we use information

We use collected information to deliver and maintain the Collab Travel CRM service, personalize your experience, provide customer support, and develop new functionality.

Data also helps us improve security, monitor suspicious activity, conduct aggregated analytics, and send product updates or educational resources relevant to travel advisors and supplier teams.

5. When we share information

We do not sell your personal information. We may share limited data with trusted service providers (sub-processors) who assist with hosting (Supabase/AWS), analytics (Google Analytics, Segment, Amplitude), communications (Customer.io), and payments (Stripe). Those providers process data only to support the services we offer and are bound by data processing agreements.

**Third-Party Travel Providers**: To facilitate bookings and travel services, Personally Identifiable Information (PII) is securely transmitted to third-party travel providers, including Global Distribution Systems (GDS) (e.g., Sabre, Amadeus), airlines, and hotels, via our API gateway and related backend services. This data sharing is strict and limited only to what is necessary to fulfill your requested travel arrangements.

We may disclose information if required by law, to protect the rights and safety of Collab Travel CRM or our users, or in connection with a business transaction such as a merger, acquisition, or asset sale.

6. Customer content

Traveler, deal, and supplier information that you upload to Collab Travel CRM remains your content. We process that content solely as directed by you and in accordance with applicable data protection laws.

You are responsible for ensuring that your use of the platform complies with contractual obligations to travelers, suppliers, and partners, as well as with relevant privacy regulations.

7. Cookies and tracking technologies

We use cookies, pixels, and similar technologies to remember your preferences, keep you signed in, measure campaign effectiveness, and better understand how Collab Travel CRM is used.

For users in the European Economic Area (EEA), non-essential cookies (analytics, advertising) are disabled by default and only activated after you provide explicit consent, in compliance with the GDPR and ePrivacy Directive.

You can manage your cookie preferences at any time using the "Cookie Preferences" link in the site footer, or through your browser settings. Disabling essential cookies may limit core functionality of the platform.

iOS app: the Collab Travel CRM iOS application does not track users across apps or websites owned by other companies, and does not share device identifiers with data brokers. Third-party analytics and advertising cookies are disabled inside the iOS app, and no App Tracking Transparency prompt is shown because no cross-app tracking takes place.

8. Data retention

We retain account information for as long as your workspace remains active. We may also retain data as needed to comply with legal obligations, resolve disputes, enforce agreements, or maintain business records.

When data is no longer required, we take reasonable steps to delete or anonymize it in line with our retention policies.

9. Security

Collab Travel CRM applies administrative, technical, and physical safeguards to protect information, including AES-256 encryption at rest, TLS 1.3 encryption in transit, role-based access controls, and regular security monitoring.

No system is completely immune from risk. If we discover a security incident that affects your data, we will notify you in accordance with applicable laws (including GDPR Article 33/34 requirements) and contractual commitments.

10. International data transfers

Collab Travel CRM is based in the United States, and we may process information using infrastructure located in other countries. When we transfer data from the EEA, UK, or Switzerland to countries without an adequacy decision, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission.

By using the platform, you acknowledge that your information may be processed outside of your country of residence under these protections.

11. Your rights

Under the GDPR and other applicable data protection laws, you have the right to:

• Access — request a copy of the personal data we hold about you.

• Rectification — request correction of inaccurate or incomplete data.

• Erasure ('right to be forgotten') — request deletion of your personal data where there is no compelling reason for continued processing.

• Restriction — request that we limit how we process your data in certain circumstances.

• Data portability — receive your data in a structured, machine-readable format and transmit it to another controller.

• Object — object to processing based on legitimate interests, including profiling.

• Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.

Submit privacy requests to hello@collabtravelcrm.com. We will respond within 30 days (or one month under GDPR). We may need to verify your identity before fulfilling your request.

12. Right to lodge a complaint

If you are in the EEA and believe your data protection rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority (DPA). A list of EEA DPAs is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

13. Children

Collab Travel CRM is not directed to individuals under the age of 16 (or the applicable age in your jurisdiction), and we do not knowingly collect personal information from children. If we learn that a child has provided us with personal data, we will delete it promptly.

14. Policy updates

We may update this Privacy Policy to reflect product changes, legal obligations, or evolving best practices. When material updates occur, we will post the revised policy on this page and update the "Last updated" date.

If the changes materially affect your rights, we will provide additional notice through Collab Travel CRM or via email at least 30 days before the changes take effect.

15. Contact us

For any questions about this Privacy Policy, your personal data, or to exercise your rights, contact us at hello@collabtravelcrm.com.

Collab Travel CRM — United States.

16. AI Training Disclosure

We utilize artificial intelligence to enhance your experience, including conversational AI agents and smart task suggestions.

Chat logs and interactions with our AI agents may be used to train and improve our AI models. However, all data is strictly anonymized to remove Personally Identifiable Information (PII) before any training occurs.

You have the right to opt-out of having your data used for AI model training at any time using the Privacy Control Dashboard below or in your account settings.

Privacy Controls

Manage your data processing and AI training preferences using the dashboard below.