Privacy Policy
Last updated: 15 June 2026
1. Who we are
Ezidoo is a software service for travel agencies to create, format, and share itineraries and quotations and to manage related contacts and enquiries. You can reach us at sales@ezidoo.com.
2. Our role
For information about your agency and its users (your account), we act as the data controller. For information your agency enters about its own customers and travellers (such as contact details, passport numbers, and travel preferences), your agency is the controller and we process that information on your agency's behalf. Your agency is responsible for having a lawful basis and any required consent to provide that information.
3. Information we collect
- Account information: your name, work email, agency name, phone, and password (stored only as a one-way hash).
- Customer/traveller information you enter: names, phone, email, and any optional fields you choose to add - which may include passport number, PAN, date of birth, anniversary, frequent-flyer details, travel preferences, and itinerary/quotation content.
- Uploaded content: images and logos you upload.
- Technical data: IP address and standard server logs, used for security and to prevent abuse.
We use only the essential cookies needed to keep you signed in. We do not use advertising or third-party tracking cookies.
4. How we use information
- To provide the service - store and display itineraries and quotations, generate documents, and manage your contacts and enquiries.
- To authenticate users and secure accounts.
- To send transactional emails (for example sign-in confirmation and password reset).
- To maintain security and prevent misuse.
We do not sell personal information, and we do not use it for advertising.
5. AI processing
To format and brand itinerary and quotation text, content you submit may be processed by a third-party AI provider under a business agreement. This is used only to produce your output; the content sent to that provider is not used to train AI models.
6. Where information is stored
Primary data is stored in a database hosted on cloud infrastructure in Mumbai, India. To deliver the service, some sub-processors described below may process limited data outside India.
7. Sub-processors
We rely on a small number of established third-party service providers (sub-processors) to operate the service. Each is engaged under a written agreement that requires it to safeguard your data and to process it only as needed to perform its function. They cover:
- Database, authentication, and file storage - hosted on cloud infrastructure in Mumbai, India.
- Application hosting and content delivery.
- AI formatting of itinerary and quotation text.
- Document rendering - producing PDF files.
- Email delivery - business and transactional email.
- Optional stock imagery - used only when you choose to add it.
The specific providers may change as the service evolves. If your agency needs the identity of a particular sub-processor for its own compliance, contact us at sales@ezidoo.com and we will provide it under a confidentiality undertaking.
8. Security
The measures we currently apply include:
- Encryption in transit: all traffic is served over HTTPS/TLS.
- Encryption at rest: the database and file storage are encrypted at rest by our infrastructure providers.
- Tenant isolation: each agency's data is separated using database row-level security and application-level access scoping, so one agency cannot access another agency's data.
- Password handling: passwords are stored using one-way hashing, and we enforce a minimum length and character complexity.
- Access control: role-based permissions within each agency (owner, admin, manager, agent, finance).
- Private file storage: uploaded images and logos are kept in a private store and served through expiring links.
- Abuse protection: rate limiting on public endpoints.
No method of transmission or storage is completely secure. We work to protect your information but cannot guarantee absolute security.
9. Data retention
We keep account and content data while your account is active. On account closure, or on a verified deletion request, we delete or anonymise personal data within a reasonable period, except where we must retain it to meet a legal obligation.
10. Your rights
Depending on where you are, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. For traveller data that an agency has entered, please contact that agency (the controller); we will assist them. To exercise rights relating to your own account, contact sales@ezidoo.com.
11. Children
The service is intended for travel agencies and is not directed at children. Agencies may enter traveller records that include a minor's details (for example a child on a trip); agencies are responsible for having the right to provide that information.
12. International users
We are based in India and store data primarily in India. If you use the service from another country, you understand that your data may be processed in India and by the sub-processors described above.
13. Changes
We may update this policy. When we do, we will post the revised version here with a new date.
14. Contact
Questions about this policy: sales@ezidoo.com.