Skip to content

Platform

How TravelSpy works Traveller intelligence AI traveller profiles Data sources Journey orchestration Integrations Live demo

Solutions

Tour operators Airlines Online travel agencies Hotels & resorts Cruise lines Travel advisors Pricing

Resources

Insights library Case studies Documentation & API Trust & security

Company

About us Careers Contact Book a demo Log in
Trust & security

Behavioural intelligence, not surveillance

We named the company TravelSpy because it is memorable, not because it describes how we behave. Everything below is what we commit to contractually, and what we will happily walk your DPO through line by line.

Consent first

No profile is created and no score is computed until a consent decision is recorded. Consent state travels with the record into every downstream system and is enforced at the point of export.

Data minimisation

We collect what the models demonstrably need and nothing else. Feeds that fail to improve model performance are removed rather than kept "just in case".

Right to erasure

A single API call or portal action deletes a traveller profile and propagates the deletion to every connected destination, with a completion receipt.

Encryption

TLS 1.2+ in transit, AES-256 at rest, envelope encryption for identifiers, and customer-managed keys available on Atlas.

Access control

Role-based access, SSO and SCIM, mandatory MFA for staff, least-privilege service accounts and a full audit log of every profile view.

Data residency

EU, UK and US regions with in-region processing and storage. Cross-region transfer is off by default and requires an explicit configuration change.

Model governance

An AI system you can defend in a review

Prediction is only useful if you can explain it. Every model in TravelSpy is versioned, monitored and accountable to a human.

  • Every score carries a confidence value and the evidence that produced it.
  • Bias testing against protected attributes before any model is promoted.
  • Drift monitoring with automatic rollback to the last known-good version.
  • Full audit trail of training runs, datasets and deployments.
  • Human override on any automated decision, with overrides fed back as training signal.
  • No fully automated decisions with legal or similarly significant effects on individuals.

Compliance posture

Where we are, and where we are honest about still being in progress.

FrameworkStatusNotes
UK GDPR & EU GDPRCompliantDPA and SCCs available on request. DPIA template provided to every customer.
ePrivacy / PECRCompliantCMP integration required before any storage on device.
CCPA / CPRACompliantDo-not-sell and limit-use signals honoured automatically.
SOC 2 Type IIAudit in progressReport expected within the current financial year; bridge letter available.
ISO 27001CertifiedCertificate and statement of applicability available under NDA.
EU AI ActMappedTravelSpy models are classified as limited risk; transparency obligations implemented.

Reporting a vulnerability

If you believe you have found a security issue, email security@travelspy.io with enough detail to reproduce it. We acknowledge within one working day, and we will not pursue action against good-faith research that respects traveller data.

Bring your DPO to the demo

Genuinely. The privacy conversation is much easier to have at the start, and we would rather have it with you than around you.