Privacy Policy
Navio provides software that travel advisors and agencies use to run their business — managing clients, building itineraries, and collecting payment details. This policy explains what personal information we handle, why, and the choices you have.
1. Scope & our role
This policy applies to the Navio website and application (the “Service”). It covers two different relationships:
- When you are a Navio account holder (a travel advisor or agency), we act as the controller of your account information and handle it as described here.
- When an advisor uses Navio to store their own clients’ information (traveler details, and card data in the encrypted vault), the advisor or agency is the controller of that data and Navio acts as their processor — we process it only to provide the Service and on the advisor’s instructions. If you are a traveler, please direct requests about your data to the advisor you worked with.
2. Information we collect
Information you give us (account holders)
- Account and profile details — name, email, password (stored hashed), agency name, brand assets, and settings.
- Support messages and anything you choose to send us.
Information advisors enter about their clients
- Traveler contact details, trip preferences, itineraries, notes, and documents the advisor adds.
- Payment card details, when a client submits them through a pay link. Card data is encrypted in the client’s browser before it reaches us; we store only ciphertext and cannot read it. The card security code (CVC), when collected, is stored encrypted separately and automatically deleted within 30 days.
Information collected automatically
- Basic technical data needed to run and secure the Service — IP address, device/browser type, and log/audit records of key actions (such as sign-ins and card reveals).
3. How we use your information
- To provide, maintain, and secure the Service.
- To authenticate you, including sending sign-in codes and verification emails.
- To send transactional messages (verification, password reset, invoices, reminders) and, where you opt in, product updates.
- To provide support and respond to your requests.
- To detect, prevent, and investigate fraud, abuse, and security incidents.
- To comply with legal obligations.
We do not sell your personal information, and we do not use it for third-party advertising.
4. How we share your information
We share personal information only as needed to run the Service:
- Infrastructure providers that host and deliver the Service (for example, our cloud and email-delivery providers), acting as our processors under contract.
- Within your agency — data is visible to members of the agency workspace it belongs to, according to the roles and visibility settings the agency configures.
- Legal & safety — when required by law, to enforce our terms, or to protect the rights and safety of users.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this policy.
5. Security & retention
- All traffic is encrypted in transit (HTTPS).
- The card vault is end-to-end encrypted: cards are encrypted to the advisor’s key in the browser, the private key is protected by the advisor’s passphrase, and Navio cannot decrypt stored cards. Vault access requires two-factor authentication and is audit-logged.
- Card security codes (CVC) are retained only for a bounded window and deleted within 30 days.
- We retain account and client data for as long as your account is active, and then for a reasonable period as needed for legal, accounting, or security purposes, after which it is deleted or anonymized.
No system is perfectly secure, but we work to protect your information using industry-standard measures.
6. Your rights & choices
Depending on where you live, you may have rights to access, correct, delete, or export your personal information, and to object to or restrict certain processing. Account holders can update much of their information directly in settings. To make a request, contact us using the details below. If you are a traveler whose data an advisor stored in Navio, please contact that advisor, who controls the data; we will assist them as their processor.
You can opt out of non-essential product emails at any time via the unsubscribe link. Transactional messages (such as sign-in codes) are required to use the Service.
7. Cookies
Navio uses only strictly-necessary cookies to keep you signed in and to secure your session. We do not use advertising or third-party tracking cookies, so no cookie-consent banner is required. Because these cookies are essential to the Service, disabling them will prevent you from signing in.
8. Children
Navio is a business tool and is not directed to children. We do not knowingly collect personal information directly from children. Advisors may store traveler details (which can include minors traveling with a family) on behalf of their clients; that information is controlled by the advisor.
9. International data transfers
We may process and store information in countries other than where you live. Where we transfer personal information across borders, we take steps to ensure it remains protected consistent with this policy and applicable law.
10. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the version and effective date above and, for account holders, ask you to review and agree the next time you sign in.
11. Contact us
Questions or requests about privacy? Reach us at hello@gonavio.app, or through the in-app support chat.