1. Who We Are
NXVOY Trips ("NxVoy", "we", "us", or "our") is operated by the following entities (together, the "Company"):
- NxVoy Labs Private Limited, registered in India under company number U52291KA2025PTC212665, with its principal place of business (head office) at No. 552E, Vinayak Layout, Nagarbhavi, Bangalore North, Bangalore-560072, Karnataka ("NxVoy India"); and
- NxVoy Labs Ltd, registered in England and Wales under company number 16209402, with its principal place of business at 86-90 Paul Street, London, EC2A 4NE ("NxVoy UK").
Together, NxVoy India and NxVoy UK are referred to as the "Company" or "Company Entities".
We operate the website nxvoytrips.ai and associated mobile applications (collectively, the "Platform"). NxVoy is an AI-powered travel planning and booking platform that enables users to discover destinations, plan trips with an AI travel assistant, and book flights, hotels, activities, and visa services.
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, NxVoy Labs Ltd (UK) is the data controller responsible for your personal data. NxVoy Labs Private Limited (India) is the head office and operates the Platform's engineering, product, and operational functions.
If you have any questions about this Privacy Policy or how we handle your data, please contact us:
- Email: privacy@nxvoy.ai
- General support: support@nxvoy.ai
- Directors: Madhan Mahadevan and Deepak Anniyappa
- Postal address: 86-90 Paul Street, London, EC2A 4NE, United Kingdom
2. Scope of This Policy
This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have. It applies to all users of the Platform, including visitors who browse without creating an account, registered users, and anyone whose data is provided to us as part of a booking (for example, fellow travellers added to an itinerary).
By using the Platform you acknowledge that you have read and understood this Privacy Policy. Where we rely on consent as a legal basis, we will ask for your explicit agreement separately.
3. Personal Data We Collect
We collect and process different categories of personal data depending on how you interact with the Platform.
3.1 Identity Data
- Title, first name, middle name, last name
- Gender
- Date of birth
- Nationality
- Profile picture (if you choose to upload one)
3.2 Contact Data
- Email address
- Phone number and alternate phone number
- Postal address (street address, city, state/county, postal code, country)
3.3 Account Data
- Email address and password (stored as a one-way bcrypt hash — we never store your password in plain text)
- Email and phone verification status
- Third-party authentication identifiers (Google account ID, Apple authentication ID) if you sign in via Google or Apple SSO
3.4 Traveller and Passenger Data
When you make bookings for yourself or others, we collect:
- Passport details (number, issuing country, expiry date) — encrypted at rest
- Date of birth — encrypted at rest
- Nationality — encrypted at rest
- Emergency contact details (name, phone, relationship)
- Health information and dietary requirements (only if you choose to provide them)
- Travel insurance policy details
- Frequent flyer programme membership numbers
3.5 Payment Data
- Card type, cardholder name, card number (encrypted with AES-256-GCM), expiry date
- Billing address
- Stripe customer and payment intent identifiers
Full card numbers are processed by our PCI-compliant payment processor (Stripe). When stored on our servers for your convenience, card numbers are encrypted using AES-256-GCM encryption and are never stored in plain text.
3.6 Travel Preferences
- Preferred currency and language
- Seat preference (window, aisle, etc.)
- Meal preference
- Cabin class preference
- Travel style preferences
3.7 Booking and Transaction Data
- Flight, hotel, activity, and visa booking details
- Itineraries (both AI-generated and user-edited)
- Booking references, order IDs, and payment transaction records
- Cancellation and refund history
3.8 Device, Technical, and Usage Data
- Device identifier (a UUID stored in a cookie with a 30-day rolling expiry)
- Device platform, browser name, browser version, operating system
- IP address
- User agent string
- Pages visited, features used, clicks, scroll depth, and session duration
- Search queries and filter selections
- Referring URL
3.9 Communication Data
- Messages exchanged with our AI travel assistant ("Shasa")
- Feedback and reviews you submit
- Customer support correspondence
3.10 Consent Records
- Cookie consent preferences and timestamps
- Marketing opt-in/opt-out records
- Notification preferences (booking updates, travel alerts, marketing communications, AI learning)
4. How We Collect Your Data
4.1 Directly From You
We collect data you provide when you create an account, fill in your profile, add passengers, make a booking, complete a payment, use the AI assistant, submit feedback, or contact support.
4.2 Automatically
When you use the Platform we automatically collect technical and usage data through cookies, server logs, and analytics tools. This includes your IP address, device fingerprint, browser details, and interaction data.
4.3 From Third Parties
- Authentication providers — Google and Apple provide basic profile information (name, email, profile picture) when you sign in via SSO.
- Payment processors — Stripe provides payment confirmation and transaction status data.
- Fraud detection services — Riskified and Google reCAPTCHA provide risk scores and fraud signals.
- Geolocation services — We use your IP address to determine your approximate location and local currency via a geolocation API. This is used to display prices in your local currency.
5. Legal Bases for Processing (UK GDPR)
Under the UK GDPR, we must have a lawful basis for each type of processing. The table below sets out the legal bases we rely on.
| Purpose | Data Categories | Legal Basis |
|---|---|---|
| Account creation and management | Identity, Contact, Account | Contract — necessary to provide our services to you |
| Processing bookings (flights, hotels, activities, visas) | Identity, Contact, Traveller, Booking, Payment | Contract — necessary to fulfil your booking |
| Payment processing and fraud prevention | Payment, Device, Identity | Contract and Legitimate Interest — to process payments and protect against fraud |
| AI trip planning and chat assistant | Communication, Travel Preferences, Booking | Contract — core feature of the service you requested |
| Currency detection and localisation | IP address, Device | Legitimate Interest — to display prices in your local currency |
| Device fingerprinting and session management | Device, Technical | Legitimate Interest — to secure your account and enforce session limits (3 devices) |
| Analytics and Platform improvement | Usage, Device, Technical | Legitimate Interest — to understand how our Platform is used and improve it |
| Marketing emails and promotional communications | Contact, Travel Preferences | Consent — you can opt out at any time |
| Storing health information or dietary requirements | Traveller (special category) | Explicit Consent — only collected when you voluntarily provide it |
| Compliance with legal obligations (tax, anti-money laundering) | Identity, Payment, Booking | Legal Obligation — required by law |
| Fraud detection (reCAPTCHA, Riskified) | Device, IP, behavioural signals | Legitimate Interest — to protect users and the Platform from fraudulent activity |
| Cookie consent record-keeping | Consent Records | Legal Obligation — to demonstrate compliance with PECR and UK GDPR |
6. Cookies and Similar Technologies
We use cookies and similar technologies to operate the Platform, remember your preferences, and understand how you use our services. Below is a summary of the cookie categories we use.
6.1 Strictly Necessary Cookies
These cookies are essential for the Platform to function. They include session cookies, authentication tokens, CSRF protection tokens, and cookie consent preference cookies. You cannot opt out of these cookies as the Platform will not work without them.
6.2 Functional Cookies
These cookies remember your choices (such as language, currency, and travel preferences) to provide a more personalised experience. They also include the device fingerprint cookie (a UUID with a 30-day rolling expiry) used for multi-device session management.
6.3 Analytics Cookies
We use PostHog (hosted in the EU at eu.i.posthog.com) to collect anonymised usage data, such as pages visited, features used, and session duration. This helps us understand how the Platform is used and where we can improve. PostHog data is not shared with third parties.
6.4 Security Cookies
Google reCAPTCHA v3 sets cookies to help distinguish human users from bots and prevent automated abuse of the Platform. Riskified may set cookies during the payment flow to detect and prevent fraudulent transactions.
6.5 Managing Cookies
You can manage your cookie preferences at any time through our cookie preferences centre (accessible via the "Cookie Preferences" link in the footer) or through your browser settings. Disabling certain cookies may affect the functionality of the Platform.
For full details on individual cookies, their purposes, and durations, please see our Cookie Policy.
7. Who We Share Your Data With
We share your personal data only when necessary to provide our services, comply with the law, or protect our legitimate interests. We never sell your personal data.
7.1 Travel Suppliers
To fulfil your bookings, we share relevant traveller data (names, dates of birth, passport details, contact information) with the following suppliers:
- TravelFusion — for flight bookings. TravelFusion processes data as a data controller in its own right.
- HotelBeds (HBX Group) — for hotel bookings. HotelBeds processes data as a data controller in its own right.
- Viator (a Tripadvisor company) — for activity and experience bookings. Viator processes data as a data controller in its own right.
- SimpleVisa — for visa application services. SimpleVisa processes data as a data controller in its own right.
7.2 Payment Processors
- Stripe — processes your payment card details to authorise and capture payments. Stripe is PCI DSS Level 1 certified. See Stripe's Privacy Policy.
- Cardinal Commerce / Braintree — provides 3D Secure (3DS) authentication for payment verification.
7.3 Fraud Prevention
- Google reCAPTCHA v3 — analyses behavioural signals to distinguish human users from bots. See Google's Privacy Policy.
- Riskified — analyses transaction data to detect and prevent fraudulent payments, particularly for activity bookings.
7.4 Analytics
- PostHog — product analytics, hosted in the EU. We do not share identifiable personal data with PostHog; analytics data is pseudonymised.
7.5 Infrastructure and Hosting
- Google Cloud Platform (GCP) — cloud hosting, storage (Google Cloud Storage for profile images), and computing infrastructure.
- Mapbox — provides map tiles and geocoding. IP addresses may be transmitted to Mapbox when loading maps.
- Cloudflare — content delivery network (CDN) for static assets and media.
7.6 Communication Providers
- SendGrid — email delivery for verification emails, password resets, and booking confirmations. Your email address is shared with SendGrid for delivery purposes.
- Twilio — SMS and WhatsApp delivery for OTP verification codes. Your phone number is shared with Twilio for delivery purposes.
7.7 AI Service Providers
Our AI trip planning features use large language models and supporting services from:
- Google (Gemini models) — for trip planning and the Shasa AI chat assistant.
- xAI (Grok) — used as an emergency fallback model only.
- Groq — for speech-to-text processing when you use voice input features. Audio recordings are sent to Groq for transcription.
- Perplexity — for AI-powered web search to retrieve travel-related content and information.
Conversation data sent to these models may include your travel preferences, destination queries, and itinerary details. We do not send your passport details, payment information, or passwords to AI model providers. See Section 15 (AI Features) for more detail.
7.8 Legal and Regulatory
We may share your data with law enforcement, regulators, or courts when required by law, to protect our legal rights, or to prevent fraud or other illegal activity.
8. International Data Transfers
Some of the third parties described above are located outside the United Kingdom. When we transfer your personal data outside the UK, we ensure that appropriate safeguards are in place, including:
- UK adequacy decisions — transfers to countries that the UK Government has determined provide an adequate level of data protection (including EEA countries).
- International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses — for transfers to countries without an adequacy decision (e.g. the United States), we enter into the IDTA or EU SCCs with the UK Addendum as applicable.
Key transfers include:
- Google Cloud Platform — data is primarily stored in EU/UK regions, but certain processing may occur in the US. Google operates under approved transfer mechanisms.
- Stripe — headquartered in the US, with data centres in the EU and US. Stripe participates in the EU-US Data Privacy Framework.
- PostHog — EU-hosted instance (
eu.i.posthog.com); data remains in the EU. - AI model providers — Google (Gemini) and xAI (Grok) may process data in the US. We rely on appropriate transfer mechanisms.
You can request a copy of the safeguards we use by contacting privacy@nxvoy.ai.
9. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.
| Data Category | Retention Period | Reason |
|---|---|---|
| Account data | Duration of your account + 30 days after deletion request | Soft delete with 30-day recovery window |
| Booking and transaction records | 7 years from booking date | Legal and tax compliance (HMRC requirements) |
| Payment card data | Until you remove the card, or account deletion + 30 days | To facilitate future bookings at your request |
| Passport and traveller data | Until you remove the passenger, or account deletion + 30 days | To facilitate future bookings at your request |
| AI chat conversations | Duration of your account | To provide conversation history and improve trip suggestions |
| Device and session data | 30 days (rolling) | Security, session management, and fraud prevention |
| Analytics data (PostHog) | 12 months | Product improvement; pseudonymised |
| Cookie consent records | 2 years | Regulatory compliance (PECR) |
| Marketing consent records | Duration of consent + 3 years | To demonstrate consent was obtained |
| Support correspondence | 3 years from resolution | Customer service quality and dispute resolution |
When data reaches the end of its retention period, it is securely deleted or anonymised. We use a soft-delete model for account data: when you request account deletion, your data is marked as deleted and becomes inaccessible, then permanently purged after 30 days.
10. Your Rights
10.1 Rights Under UK GDPR and EU GDPR
If you are in the United Kingdom or the European Economic Area, you have the following rights:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — request deletion of your data where there is no compelling reason for continued processing.
- Right to restrict processing — request that we limit how we use your data in certain circumstances.
- Right to data portability — receive your data in a structured, commonly used, machine-readable format (JSON or CSV).
- Right to object — object to processing based on legitimate interests, including profiling and direct marketing.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Rights related to automated decision-making — you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Our AI features make recommendations but do not make binding decisions about you.
To exercise any of these rights, contact us at privacy@nxvoy.ai. We will respond within one month. In complex cases, we may extend this by up to two additional months, and we will inform you if we need to do so.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
10.2 Rights for California Residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with additional rights regarding your personal information.
Categories of Personal Information Collected
In the preceding 12 months, we have collected the following categories of personal information as defined by the CCPA:
- Identifiers — name, email address, phone number, IP address, device identifiers, account ID, passport number.
- Personal information under Cal. Civ. Code 1798.80(e) — name, address, telephone number, passport number, financial information (payment card details).
- Protected classification characteristics — date of birth, gender, nationality.
- Commercial information — booking history, transaction records, travel preferences.
- Internet or electronic network activity — browsing history on our Platform, search queries, interactions with our AI assistant.
- Geolocation data — approximate location derived from IP address (city/country level).
- Inferences — travel preferences and interests derived from your activity on the Platform.
- Sensitive personal information — passport number, precise geolocation (if provided), health information (only if you voluntarily provide it).
Your California Privacy Rights
- Right to Know — you may request that we disclose what personal information we have collected, the categories of sources, the business purpose for collection, the categories of third parties with whom we share it, and the specific pieces of personal information we hold about you.
- Right to Delete — you may request deletion of your personal information, subject to certain exceptions (e.g., completing a transaction, legal obligations).
- Right to Correct — you may request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing — we do not sell your personal information. We do not share your personal information for cross-context behavioural advertising as defined by the CCPA.
- Right to Limit Use of Sensitive Personal Information — you may request that we limit the use of your sensitive personal information to purposes necessary for providing our services.
- Right to Non-Discrimination — we will not discriminate against you for exercising any of your CCPA rights.
Exercising Your California Rights
To submit a request, email privacy@nxvoy.ai with the subject line "California Privacy Request". We will verify your identity before processing your request. You may also designate an authorised agent to make a request on your behalf.
We will respond to verifiable requests within 45 days. If we need additional time (up to 45 more days), we will notify you in writing.
Financial Incentives
We do not offer financial incentives or price differences in exchange for the collection, retention, or sale of personal information.
Do Not Sell or Share My Personal Information
We do not sell or share (as defined by the CCPA) your personal information. We have not sold or shared personal information in the preceding 12 months.
11. Marketing Communications
We will only send you marketing communications (such as promotional offers, travel inspiration, and new feature announcements) if you have given your consent. You can manage your marketing preferences at any time through:
- Your account notification settings on the Platform
- The "unsubscribe" link in any marketing email
- Contacting us at support@nxvoy.ai
Opting out of marketing will not affect transactional communications, such as booking confirmations, payment receipts, itinerary updates, and service announcements.
12. Children's Privacy
The Platform is not directed at children under 16 years of age. We do not knowingly collect personal data from children under 16 without parental consent. If we become aware that we have collected personal data from a child under 16 without appropriate consent, we will take steps to delete that data promptly.
We do collect limited data about child travellers (name, date of birth, passport details) when an adult user adds them as passengers to a booking. This data is collected with the consent and under the authority of the responsible adult making the booking.
13. How We Protect Your Data
We take the security of your personal data seriously and implement a range of technical and organisational measures to protect it:
- Encryption at rest — sensitive personal data including passport numbers, dates of birth, nationalities, and payment card numbers are encrypted using AES-256-GCM encryption.
- Encryption in transit — all data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher. HSTS (HTTP Strict Transport Security) is enforced in production.
- Password security — passwords are hashed using bcrypt with appropriate salt rounds. We never store or log passwords in plain text.
- CSRF protection — double-submit cookie pattern to prevent cross-site request forgery.
- Rate limiting — per-IP rate limiting on all API endpoints to prevent brute-force attacks.
- Content Security Policy (CSP) — strict CSP headers to mitigate cross-site scripting (XSS) and other injection attacks.
- Input sanitisation — all user inputs are sanitised to prevent injection attacks.
- Session management — multi-device session management with a maximum of 3 active devices per account.
- PCI compliance — payment card processing is handled by PCI DSS Level 1 certified processors (Stripe). For Viator activity payments in production, payment details are captured via an isolated iframe, meaning card data never touches our servers (PCI SAQ-A).
- Access controls — internal access to personal data is restricted on a need-to-know basis.
- Infrastructure security — our services run on Google Kubernetes Engine (GKE) with network policies, pod security, and automated patching.
While we implement robust security measures, no method of electronic transmission or storage is 100% secure. If you believe your account has been compromised, please contact us immediately at support@nxvoy.ai.
14. Automated Decision-Making and Profiling
We use limited automated processing in the following areas:
- Fraud detection — Riskified and Google reCAPTCHA analyse behavioural signals to generate fraud risk scores. A high-risk score may result in additional verification steps or a blocked transaction.
- Currency detection — your IP address is automatically used to determine your approximate location and local currency.
- AI trip recommendations — our AI assistant generates personalised trip suggestions based on your stated preferences and conversation context.
None of these processes make legally binding decisions about you without human involvement. AI trip recommendations are suggestions only — you have full control over your itinerary and booking decisions. If a fraud check blocks a legitimate transaction, you can contact support for manual review.
15. AI Features and Your Data
NxVoy uses artificial intelligence to power several core features:
- Shasa AI Assistant — a conversational travel assistant that helps you discover destinations, plan trips, and answer travel questions.
- Itinerary generation — AI-generated day-by-day trip plans based on your preferences, budget, and travel dates.
- Smart search — AI-enhanced search for flights, hotels, and activities.
15.1 What Data Is Used by AI
When you interact with our AI features, the following data may be processed:
- Your chat messages and travel queries
- Travel preferences (destinations, dates, budget, interests, travel style)
- Itinerary context (previously selected destinations, hotels, activities)
15.2 What Data Is NOT Sent to AI Models
We do not send the following to third-party AI model providers:
- Passport numbers or identity documents
- Payment card details
- Passwords or authentication tokens
- Health information
15.3 AI Model Providers
We use AI models from Google (Gemini) and xAI (Grok) via API. Conversations are sent to these providers for processing and are subject to their respective data processing terms. We select providers that commit to not using customer API inputs for training their models.
If you use voice input, your audio is processed by Groq for speech-to-text transcription. The resulting text is then sent to the AI assistant. Audio data is processed in transit and is not stored by NxVoy after transcription.
15.4 AI Learning Preferences
You can control whether your interaction data is used to improve our AI recommendations through the AI Learning toggle in your notification preferences. Disabling this will not affect the core AI features but may result in less personalised suggestions.
16. Third-Party Links and Services
The Platform may contain links to third-party websites, including supplier booking confirmation pages, airline websites, hotel websites, review platforms, and map services. We are not responsible for the privacy practices of these third-party sites. We encourage you to read their privacy policies before providing any personal data.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:
- We will update the "Last updated" date at the top of this page.
- For significant changes, we will notify you via email (if you have an account) or through a prominent notice on the Platform.
- Where required by law, we will obtain your consent to material changes before they take effect.
We encourage you to review this Privacy Policy periodically. Your continued use of the Platform after changes are published constitutes acceptance of the updated policy, except where consent is required.
18. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us using the details below:
- Privacy enquiries: privacy@nxvoy.ai
- General support: support@nxvoy.ai
- Head office: NxVoy Labs Private Limited, No. 552E, Vinayak Layout, Nagarbhavi, Bangalore-560072, Karnataka, India
- UK office: NxVoy Labs Ltd, 86-90 Paul Street, London, EC2A 4NE, United Kingdom
- Directors: Madhan Mahadevan and Deepak Anniyappa
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. In the UK, this is the Information Commissioner's Office (ICO).