Your Privacy is Important to TravelSwitch

Learn how TravelSwitch FZ LLC collects, uses, protects, and manages your personal information.

TravelSwitch Privacy Policy

Effective Date: August 15, 2026

Introduction and Organizational Info

We, at TravelSwitch FZ LLC ("TravelSwitch", "we", "us", or "our"), are dedicated to serving our customers and contacts responsibly and securely. Part of our commitment involves the responsible management of personal information collected through our website, products, services, platforms, applications, APIs, and related interactions.

Our primary goals in processing personal information include:

  • Enhancing the user experience on our platforms by understanding customer needs and preferences.
  • Providing timely support and responding to inquiries or service requests.
  • Improving our products and services to meet the evolving demands of our users.
  • Providing travel technology, travel booking, and related services.
  • Conducting necessary business operations, such as billing, account management, and contractual administration.
  • Maintaining the security, reliability, and performance of our services.
  • Complying with applicable legal, regulatory, and contractual requirements.

It is our policy to process personal information with the utmost respect for privacy and security. We adhere to applicable regulations and guidelines to ensure that the data we handle is protected against unauthorized access, disclosure, alteration, loss, and destruction. Our practices are designed to safeguard the confidentiality and integrity of personal information while enabling us to deliver the services entrusted to us.

TravelSwitch has a designated Data Protection & Privacy Officer. Should you have any questions or require further information about how we manage personal information, please contact us at:

dpo@travelswitch.com

Your privacy is our priority. We are committed to processing personal information transparently and responsibly. This commitment extends to our collaboration with third-party service providers and subprocessors that may process personal information on our behalf. All such activities are managed in accordance with applicable privacy and data protection requirements.

Scope and Application

Our Privacy Policy is designed to protect the personal information of our stakeholders, including website visitors, registered users, customers, business contacts, partners, and individuals whose personal information may be processed through our products and services.

Whether you are browsing our website , using our services as a registered user, interacting with us as a customer or business partner, or communicating with TravelSwitch, we aim to ensure that personal information is processed with appropriate standards of privacy and security.

This Privacy Policy outlines our practices and your rights relating to personal information.

Where a customer or other organization has separately provided a privacy notice, data processing agreement, contractual terms, or other specific instructions, those documents may also apply to the relevant processing activities.

Controller and Processor Roles

Depending on the nature of the processing activity, TravelSwitch may act as either a data controller or a data processor.

  • Where TravelSwitch determines the purposes and means of processing personal information, TravelSwitch acts as the controller for that processing.
  • Where TravelSwitch processes personal information on behalf of a customer or other organization, TravelSwitch acts as a processor or service provider and processes such personal information in accordance with the documented instructions of the applicable controller and the applicable contractual requirements.
  • Where TravelSwitch acts as a processor, the customer's privacy notice, instructions, contractual terms, and applicable data protection requirements may also govern the processing.
  • Individuals seeking information about processing carried out on behalf of a TravelSwitch customer may, where applicable, be directed to the relevant customer or controller.

Data Collection and Processing

Our commitment to transparency and data protection extends to how we collect and use personal information. We gather personal information through various interactions, including when you utilize our services or products such as Software as a Service (SaaS), use our travel technology platforms, communicate with us, or directly provide information to us.

The following list details the types of personal information we may process:

  • First and last name
  • Email address and/or phone number
  • Address, city, country, or other location information
  • IP address
  • Browser information and language
  • Operating system and version
  • Account and authentication information
  • Information provided through customer support or business communications
  • Information relating to travel transactions and services, where applicable
  • Billing and account administration information
  • Technical, usage, and service interaction information

Please note that we seek to process only information that is reasonably necessary for delivering our services, complying with legal obligations, fulfilling contractual requirements, maintaining security, or carrying out other legitimate and disclosed purposes.

Purposes of Processing

At TravelSwitch FZ LLC, we believe in using personal information responsibly and ethically. The personal information we process may be used for purposes including:

  • Authentication and security
  • Providing and operating our products and services
  • Travel booking and related transaction processing, where applicable
  • Customizing and adapting user experience
  • Content delivery
  • Communication and customer support
  • Billing and account management
  • Analytics and performance tracking
  • Product and service improvement
  • Fraud prevention and security monitoring
  • Marketing and advertising, where permitted by applicable law
  • Compliance with legal and regulatory obligations
  • Responding to lawful requests from governmental, regulatory, law enforcement, or judicial authorities

Your privacy is our priority. We process personal information transparently and in accordance with applicable privacy laws. We are committed to using personal information only for appropriate purposes and in accordance with applicable legal, contractual, and customer requirements.

Legal Basis for Processing

Depending on the nature of the processing and the applicable law, TravelSwitch may process personal information based on one or more lawful bases, including:

  • Performance of a contract or taking steps at the request of an individual before entering into a contract.
  • Compliance with a legal or regulatory obligation.
  • Legitimate interests, where permitted by applicable law and where such interests are not overridden by applicable rights and freedoms.
  • Consent, where consent is required or relied upon.
  • Other lawful grounds recognized under applicable data protection laws.

Where processing is based on consent, individuals may withdraw consent where permitted by applicable law. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Data Minimization

TravelSwitch follows data minimization principles and seeks to collect and process personal information that is relevant and reasonably necessary for the applicable purpose.

We do not intentionally collect personal information that is unnecessary for the purpose for which it is being processed.

Access to personal information is also restricted based on role, authorization, business need, and the principle of least privilege.

Data Storage and Protection

Data Storage

Personal information may be stored and processed using secure cloud infrastructure and technology environments.

For applicable TravelSwitch deployments, personal information may be stored in secure servers located in Saudi Arabia.

The applicable hosting environment and data residency may vary depending on the service, customer requirements, contractual arrangements, deployment architecture, and applicable legal or regulatory requirements.

Where a customer requires specific data residency or hosting arrangements, such requirements may be addressed through the applicable contractual and technical arrangements.

TravelSwitch partners with reputable technology and hosting providers that are selected based on their security, reliability, privacy, and data protection practices.

Data Protection Measures

TravelSwitch implements appropriate technical and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration, loss, destruction, or other unauthorized processing.

Depending on the applicable system and processing environment, these measures may include:

  • Encryption: Data is protected using encryption technologies for data in transit and at rest.
  • Access control: Access to personal information is strictly limited to authorized personnel and systems with a legitimate business or operational need.
  • Authentication and authorization: Appropriate authentication and authorization controls are implemented to restrict unauthorized access.
  • Security monitoring: Systems and environments are monitored for unusual or potentially unauthorized activities.
  • Security assessments: Security assessments, vulnerability management activities, penetration testing, and other assurance activities may be performed based on the applicable environment and risk.
  • Secure development: Appropriate secure software development and code review practices are applied to relevant systems.
  • Incident management: TravelSwitch maintains procedures for identifying, assessing, containing, investigating, and responding to security and privacy incidents.
  • Backup and recovery: Appropriate backup, recovery, and business continuity controls are maintained for applicable systems.

Data Processing Agreements

When TravelSwitch shares or provides access to personal information to third-party service providers or subprocessors acting on behalf of a customer, appropriate contractual arrangements are maintained where required.

Such arrangements may include obligations relating to confidentiality, security, data protection, processing instructions, incident management, data subject rights, international transfers, retention, deletion, and return of personal information.

Third parties processing personal information on behalf of TravelSwitch or its customers are expected to maintain appropriate technical and organizational measures to protect the information.

Subprocessors and Third-Party Service Providers

TravelSwitch may engage third-party service providers and subprocessors to support the operation, security, maintenance, and delivery of its products and services.

These may include:

  • Cloud infrastructure providers.
  • Security and monitoring providers.
  • Technology and software providers.
  • Travel technology and travel content providers.
  • Travel suppliers and distribution partners where applicable.
  • Payment service providers where applicable.
  • Other service providers necessary to provide contracted services.

TravelSwitch assesses relevant subprocessors based on the services provided, processing activities, categories of information involved, processing locations, security controls, privacy practices, and applicable contractual and legal requirements.

Where appropriate, subprocessors are required to comply with contractual obligations relating to:

  • Confidentiality.
  • Data protection.
  • Information security.
  • Processing limitations.
  • Access controls.
  • Incident notification.
  • Data deletion or return.
  • International data transfers.
  • Applicable further-subprocessing requirements.

Where contractual requirements require advance notification or approval of material changes to subprocessors, TravelSwitch follows the applicable contractual process.

Transparency and Control

We believe in transparency and providing individuals and customers with appropriate control over their personal information.

You will be informed of material changes to our privacy practices where required by applicable law or contractual requirements.

Where consent is required for a particular processing activity or change, TravelSwitch will obtain consent in accordance with applicable law.

Your trust is important to us, and we strive to ensure that personal information is disclosed only for appropriate purposes and in accordance with applicable legal, contractual, and privacy requirements.
For any queries or concerns about how we share and disclose personal information, please contact:

connect@travelswitch.com

User Rights and Choices

At TravelSwitch FZ LLC, we recognize and respect your rights regarding your personal information, in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. We are committed to ensuring you can exercise your rights effectively.

The rights available to you may depend on the applicable data protection law and the circumstances of the processing. Where the GDPR applies, you may have the following rights:

Your Rights

  • Right of access (Art. 15 GDPR): You have the right to request access to the personal information we hold about you and to obtain information about how we process it.
  • Right to rectification (Art. 16 GDPR): If you believe that any personal information we hold about you is incorrect or incomplete, you have the right to request its correction or completion.
  • Right to erasure ("right to be forgotten") (Art. 17 GDPR): You have the right to request the deletion of your personal information when it is no longer necessary for the purposes for which it was collected, among other circumstances.
  • Right to restriction of processing (Art. 18 GDPR): You have the right to request that we restrict the processing of your personal information under certain conditions.
  • Right to data portability (Art. 20 GDPR): You have the right to receive your personal information in a structured, commonly used, and machine-readable format and to transmit those data to another controller.
  • Right to object (Art. 21 GDPR): You have the right to object to the processing of your personal information, under certain conditions, including processing for direct marketing.
  • Right to withdraw consent (Art. 7(3) GDPR): Where the processing of your personal information is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
  • Right to lodge a complaint (Art. 77 GDPR): You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal information violates applicable data protection laws.

Exercising Your Rights

To exercise any of these rights, please contact us at:

dpo@travelswitch.com

We will respond to your request in accordance with applicable data protection laws and within the timeframes stipulated by those laws.

Please note that, in some cases, we may need to verify your identity as part of the process to ensure the security of your personal information.

Where TravelSwitch processes personal information on behalf of a customer or other Controller, we may refer the request to the applicable Controller in accordance with the applicable contractual and legal requirements.

TravelSwitch will provide reasonable technical and organizational assistance to customers in responding to applicable data subject rights requests where required by the applicable agreement.

We are committed to facilitating the exercise of applicable rights and to ensuring appropriate control over personal information.

Cookies and Tracking Technologies

At TravelSwitch FZ LLC, we value your privacy and are committed to being transparent about our use of cookies and other tracking technologies on our website

These technologies play a crucial role in ensuring smooth operation of digital platforms, enhancing user experience, and providing insights to help us improve.

Understanding Cookies and Tracking Technologies

Cookies are small data files placed on your device that enable us to remember your preferences and collect information about website usage.

Tracking technologies such as web beacons and pixel tags, may help us understand how you interact with our site and which pages you visit.

How We Use These Technologies

  • Essential cookies: Necessary for the website's functionality, such as authentication and security.
  • Performance and analytics cookies: These collect information about how visitors use our website and help us improve our services.
  • Functional cookies: These enable the website to provide enhanced functionality and personalization, such as remembering preferences.
  • Advertising and targeting cookies: Where applicable, these may be used to deliver advertisements more relevant to you and to measure the effectiveness of advertising campaigns.

Your Choices and Consent

Where required by applicable law, our website will present a cookie consent mechanism through which you may:

  • Accept all cookies.
  • Reject non-essential cookies.
  • Customize your preferences by selecting the categories of cookies you wish to allow.

Changes to Our Cookie Use

We may update our use of cookies and tracking technologies to improve our services or comply with legal requirements.

Where required, we will provide appropriate notice and obtain consent for changes that require consent under applicable law.

For more detailed information about the cookies we use, their purposes, and how you can manage your preferences, please visit our detailed Cookie Policy:

https://travelswitch.com/en/policy#cookies

Should you have any questions or concerns about our use of cookies and tracking technologies, please contact connect@travelswitch.com.

International Data Transfers

At TravelSwitch FZ LLC, we may process or transfer personal information to locations outside of your country of residence, including countries that may have different data protection laws from those in your jurisdiction.

Where personal information is transferred to or accessed from another country, TravelSwitch considers applicable legal, regulatory, contractual, and security requirements.

Depending on the circumstances, TravelSwitch may consider:

  • The countries involved in the transfer.
  • The nature and purpose of the processing.
  • The categories of personal information involved.
  • Applicable adequacy decisions.
  • Applicable contractual safeguards.
  • Technical and organizational safeguards.
  • Encryption and access controls.
  • Applicable transfer mechanisms.
  • Transfer Impact Assessments where applicable.

For customer deployments involving Saudi Arabia, applicable requirements governing transfers of personal information outside the Kingdom will be considered.

International transfers are managed in accordance with applicable privacy and data protection requirements.

Government and Public Authority Requests

Where TravelSwitch receives a legally valid request for personal information from a governmental, regulatory, law enforcement, or judicial authority, the request will be reviewed and handled in accordance with applicable law.

Where legally permitted, TravelSwitch will notify the affected customer or Controller before disclosure.

Where notification is legally prohibited, TravelSwitch will comply with the applicable legal restriction.

TravelSwitch will seek to limit any disclosure to the information legally required and will appropriately record and escalate relevant requests.

Data Retention and Secure Disposal

TravelSwitch retains personal information only for as long as reasonably necessary to fulfill the applicable processing purpose or as required by contractual, legal, regulatory, security, or legitimate business requirements.

Retention periods may vary depending on the nature of the information, the purpose of processing, applicable contractual requirements, and applicable legal or regulatory obligations.

Where TravelSwitch processes personal information on behalf of a customer, retention and deletion are managed in accordance with the customer's documented instructions and applicable contractual requirements.

At the end of the applicable retention period, personal information may be:

  • Securely deleted.
  • Returned to the applicable Controller.
  • Anonymized where appropriate.
  • Retained where continued retention is required by applicable law or contractual requirements.

Where personal information is contained in backups, deletion is managed in accordance with applicable backup retention and secure disposal procedures.

Data Breach Notification Procedures

At TravelSwitch FZ LLC, we understand the importance of protecting personal information and maintain procedures for promptly identifying, assessing, containing, investigating, and mitigating the impact of security and personal data breaches.

Our data breach response procedures are designed to comply with applicable data protection laws and contractual requirements.

Detection and Assessment

  • Internal monitoring: We employ security measures and monitoring systems to detect and respond to potential security and data breaches.
  • Assessment of breach impact: Upon discovery of a potential data breach, we conduct an assessment to determine the nature and scope of the incident, including the types of personal information involved and the potential impact on affected individuals and customers.
  • Containment and mitigation: Appropriate measures are taken to contain the incident and reduce potential harm.

Notification Obligations

Where TravelSwitch acts as a processor and becomes aware of a confirmed personal data breach affecting personal information processed on behalf of a customer, TravelSwitch will notify the affected customer without undue delay and, where contractually agreed, within 24 hours of becoming aware of the confirmed breach.

TravelSwitch will provide relevant information reasonably available to support the customer's assessment, regulatory notification, data subject notification, and remediation obligations.

Where TravelSwitch acts as a controller, TravelSwitch will comply with applicable legal requirements relating to regulatory authorities and affected individuals.

Where required by applicable law, regulatory authorities or affected individuals may be notified within the applicable statutory timeframes.

Communication Channels

Where appropriate and legally permitted, notifications may be made through:

  • Email.
  • Customer or contractual communication channels.
  • Website or other appropriate communication channels.

Support and Assistance

In the event of a data breach, TravelSwitch is committed to providing affected customers and individuals with appropriate support and assistance, including relevant information about the incident and guidance on steps that may be taken to mitigate potential risks.

If you have questions or concerns about a data breach or believe you may have been affected, please contact dpo@travelswitch.com or connect@travelswitch.com.

Privacy Compliance and Assurance

TravelSwitch maintains a privacy and information security compliance framework supported by documented policies, procedures, assessments, and assurance activities.

Depending on the applicable service, customer requirements, and contractual arrangements, compliance and assurance evidence may include:

  • Privacy and data protection policies.
  • Data retention and secure disposal documentation.
  • Data subject rights procedures.
  • Subprocessor management documentation.
  • International data transfer documentation.
  • Data breach response documentation.
  • Security assessments.
  • Penetration testing evidence.
  • GDPR compliance documentation.
  • PCI DSS compliance documentation where applicable.
  • Customer-specific privacy and security assessments.
  • Other relevant assurance records.

Appropriate compliance evidence may be provided to customers subject to applicable confidentiality, security, contractual, and information-sharing requirements.

Privacy Reviews and Assessments

TravelSwitch reviews its privacy and data protection practices periodically and when significant changes occur.

Reviews and assessments may be triggered by:

  • Changes to applicable privacy laws or regulations.
  • Significant changes to TravelSwitch's processing activities.
  • Significant changes to products, services, or technology architecture.
  • Changes to customer requirements.
  • Significant privacy or security incidents.
  • Changes to relevant third-party or subprocessor arrangements.
  • Findings from internal or external assessments.

The purpose of these reviews is to maintain the effectiveness and relevance of TravelSwitch's privacy and data protection practices.

Policy Updates and Changes

At TravelSwitch FZ LLC, we are committed to keeping you informed about how we handle personal information and any changes to our privacy practices.

We may update this Privacy Policy from time to time to reflect changes in:

  • Legal or regulatory requirements.
  • Industry standards and practices.
  • TravelSwitch products and services.
  • Processing activities.
  • Technology and security controls.
  • Customer or contractual requirements.

Notification of Changes

In the event of significant changes to this Privacy Policy that may materially affect your rights or the way we handle personal information, we will provide appropriate notice through suitable channels, such as:

  • Email.
  • Website notifications.
  • Other appropriate communication channels.

We will also indicate the effective date of the updated Privacy Policy at the top of the document.

We encourage you to review this Privacy Policy periodically to stay informed about how we collect, use, and protect personal information.

Reviewing and Approving Changes

Changes to this Privacy Policy are reviewed through TravelSwitch's applicable privacy and document control processes.

Material changes are assessed based on applicable legal, regulatory, contractual, operational, security, and privacy requirements and are reviewed and approved by the appropriate responsible personnel before becoming effective.

Where notification to customers or Controllers is required under an applicable agreement, TravelSwitch will provide the required notification through the applicable contractual communication channel.

Consent for Material Changes

For material changes to our privacy practices that require consent under applicable data protection laws, including where applicable under the GDPR, TravelSwitch will seek the required consent before implementing the relevant processing activity.

Contact Us

If you have any questions or concerns about this Privacy Policy, your personal information, your privacy rights, or any updates to our privacy practices, please contact us.

TravelSwitch FZ LLC

Data Protection & Privacy Officer

Email: dpo@travelswitch.com

For general privacy, business, or service-related enquiries:

Email: connect@travelswitch.com

Phone: +91 9967782449

TravelSwitch will review and respond to privacy-related enquiries and requests in accordance with applicable data protection laws and applicable contractual requirements.