Intraverse provides the technology and services that help businesses sell and manage travel. This Privacy Policy explains how Intraverse Africa Technology Limited (“Intraverse”, “we”, “us” or “our”) handles personal information when you visit our website, use our products, contact us or have your travel arrangements processed through our platform.
It also explains your choices and how to contact us about your information.
1. Who we are and how to contact us
Intraverse Africa Technology Limited is a company registered in Nigeria.
Business address: 14B Wole Ariyo Street, Lekki Phase 1, Lagos, Nigeria.
Email: hello@intraverse.africa
Website: intraverse.africa
For privacy enquiries or requests concerning your information, email us with the subject line “Privacy request”. Please describe your request and the service or business involved. Do not include passwords, complete payment-card details or passport copies in your initial message. If we need additional information to identify the relevant records, we will explain what is needed.
2. Services covered by this policy
This policy covers personal information handled through our website, Seller Platform, Intraverse Mobile, White-label Website, Travel Widget, Travel Links, Travel API and related support, onboarding and travel operations services.
It applies to website visitors, account holders, business representatives, authorised team members, people who contact us and travellers whose details are supplied through our services.
A travel agency, employer or other business may use Intraverse to serve its customers. That business may have its own privacy notice explaining its use of personal information. Airlines, hotels, payment providers and other suppliers also have their own privacy practices. This policy describes Intraverse’s activities; it does not replace those organisations’ notices.
3. Our role in handling information
When we decide why and how personal information is used—for example, to manage our business accounts, answer enquiries or protect our services—we act as a data controller.
When a business uses Intraverse to store or process traveller information on its instructions, we may act as its data processor. The relevant agreement and instructions govern that processing. Our role depends on the particular activity; we do not act only as a processor for every booking or service.
If your request concerns information managed by your travel agency, employer or another business, you may contact that business directly. You may also contact us, and we will help identify the appropriate organisation or assist it with your request where applicable.
4. Information we collect
The information involved depends on the service you use and the travel arrangements requested.
| Category | Examples and circumstances |
|---|---|
| Account and business information | Your name, work email, telephone number, business name, role, account preferences and information supplied during business verification. Verification documents may contain information about business owners or representatives. |
| Traveller and booking information | Traveller names, contact details, dates of birth, nationality, travel-document details where required, itineraries, booking references, loyalty programme details, travel preferences and booking changes or service requests. |
| Payment and transaction information | Billing details, payment references, payment status, wallet transactions, invoices, refunds and settlement information. Depending on the payment method, a payment provider may collect additional information directly under its own notice. |
| Communications | Enquiries, support conversations, correspondence, feedback and documents you choose to send through our supported channels. |
| Technical and service-use information | IP address, browser and device information, access times, pages or features used, application errors, security logs and records of activity within an account or API integration. |
| Preferences and permissions | Language and display settings, communication preferences and permission choices relevant to the features you use. |
Some travel requests may reveal sensitive information, such as health information supplied for special assistance. Please provide only what is necessary. Such information requires an applicable legal basis and any additional safeguards or consent required for sensitive data.
Mobile permissions and travel documents
Intraverse requests device access in the context of the feature you choose to use. Access is limited to that purpose, and optional permissions are not a condition of using unrelated booking or account features. Some actions use your device’s file picker, save dialogue or sharing menu without requiring broad device permissions.
Permissions and device actions depend on the features available in your version of the app. Where supported, they are used as follows:
| Permission or device action | Travel-related purpose and information involved | Your choice |
|---|---|---|
| Notifications | Deliver booking confirmations, ticketing updates, supplier schedule changes, payment updates and account-security alerts where those notifications are supported. Push delivery can involve a device notification token and delivery provider. | Optional. You can change notification permissions in device settings. Turning them off does not cancel your bookings. |
| Camera | Photograph a passport or other document you choose to submit for traveller details, business verification or an applicable service request. A document photo is not the same as collecting a facial biometric template. | Access is requested when you choose to capture a document, where required by the operating system. Upload an existing file or enter details manually where the feature offers those alternatives. |
| Selected photos and files | Upload a document, payment receipt or supporting attachment that you select for an enquiry, booking or verification task. | Use the system picker to select the specific item. This does not require access to unrelated photos or the entire file system. |
| Saving travel documents | Save a ticket, itinerary, hotel voucher, invoice or receipt you choose to download. | You choose the save action and destination using supported device controls. Broad access to all device storage is not required for this purpose. |
| Sharing documents | Send a selected itinerary, quote, ticket or receipt through an app you choose in the device’s sharing menu. | Sharing is initiated by you and does not require importing your address book. The receiving app and recipient then handle the shared information under their own arrangements. |
Documents you select for upload may be transmitted to Intraverse and, where required, the travel business, verification provider or supplier handling the request. They are not necessarily confined to your device. They are handled under the purposes, sharing and retention sections of this policy. Only upload another person’s documents when you have the appropriate authority.
Downloads and copies you share can remain on your device or with recipients after deletion from Intraverse. You control those copies, subject to the relevant device or recipient’s arrangements.
Optional convenience features
Where the relevant feature is available and you choose to use it:
- Nearby search: location access is used to support the search you request while using that feature. We request only the level of location accuracy needed for the search and explain the purpose when asking for access. This does not authorise background tracking. You may instead enter a destination. An agent’s location is not assumed to be the customer’s location.
- Calendar export: the itinerary you select is passed to your chosen calendar through the supported event-creation or export controls. This does not require reading unrelated calendar entries.
- Biometric sign-in: authentication through your device’s biometric service provides an authentication result rather than your fingerprint or facial biometric template. Any separate identity-verification process has its own explanation and requirements.
Core travel-booking functions do not require access to your microphone, SMS inbox, call history, complete contact list, background location or advertising identifier. Any separate live feature requiring additional access must explain its purpose and request the appropriate permission when used.
You can change permissions through your device settings. A denied permission may prevent the related feature from working, but should not block unrelated functions. Revoking permission prevents future access subject to the operating system’s controls; it does not automatically delete information already uploaded. Use the privacy-request process if you also want to request deletion.
Technical information generated by the app may include device and operating-system information, app version, error reports, access logs and notification tokens. These may be processed by providers supporting app operation, security, diagnostics and message delivery. Their use is limited to the relevant service purpose and the sharing and retention provisions below. Permission prompts do not cover every form of technical data processing; you can contact us for more information about providers involved in your service.
5. Where information comes from
We receive information directly from you when you register, complete a form, make a request or use our services.
We may also receive information from your travel agency, employer, authorised account administrator or another person arranging travel on your behalf; from businesses integrating our API or other products; and from travel suppliers, payment providers or verification providers involved in the requested service.
Technical information may be generated when your browser, device or integration communicates with our systems.
If you provide another person’s information, you must have appropriate authority and a lawful basis to do so, give them the relevant privacy information and obtain any consent that is required. Permission to arrange travel does not automatically authorise unrelated marketing.
6. Why we use information
We use relevant information to:
- Create and administer business accounts and authorised user access.
- Respond to enquiries, demonstrate products and support onboarding.
- Search for travel options, arrange bookings, process ticketing and deliver requested services.
- Manage payments, wallet activity, invoicing, settlement and reconciliation.
- Handle booking changes, cancellations, refunds and other service requests.
- Send account, payment, booking and service notifications.
- Investigate errors, secure accounts, prevent misuse and maintain reliable services.
- Understand and improve our services using information appropriate to that purpose.
- Meet applicable obligations, maintain necessary records and handle disputes.
- Send optional marketing communications where you have given the required consent.
We do not treat use of our website or acceptance of this policy as blanket consent to every processing activity.
7. Our legal bases
We identify a legal basis for each activity. Depending on the circumstances, this may be performance of a contract with you or steps you request before entering one; a legal obligation; your consent; or a legitimate interest that is not overridden by your rights. Our legitimate interests may include securing our services, administering business relationships and resolving support issues.
A business contract does not automatically provide a contractual legal basis for every individual traveller’s data. Where we act on a business customer’s instructions, that customer must establish the appropriate basis for its processing, and we have our own obligations for the activities we control.
Where consent is the basis, you can withdraw it. Withdrawal does not undo processing already lawfully carried out, and other information may still need to be retained for a separate lawful purpose.
If required account or booking information is not provided, we may be unable to supply the requested service. We will distinguish required information from optional choices where we collect it.
8. Who receives information
We disclose information relevant to the purpose to the following categories of recipients, where applicable:
- Your travel business or organisation: the agency, employer, account administrators or authorised users involved in your booking or account. Access depends on their role and the service arrangement.
- Travel suppliers and distribution partners: airlines, hotels, tour operators, booking systems, consolidators and other providers needed to fulfil or service travel arrangements.
- Payment and verification providers: organisations involved in payments, settlement, identity or business verification and fraud prevention.
- Service providers: providers supporting hosting, system operation, communications, customer support, storage and security. They receive information needed for their assigned services under appropriate arrangements.
- Professional advisers and authorities: where necessary for legal advice, disputes, applicable obligations or lawful requests.
- Parties to a business transaction: where a merger, financing, acquisition or transfer requires a limited disclosure, subject to appropriate protections and any required notice.
Some recipients act on our instructions; others, including certain travel suppliers and payment providers, determine their own processing purposes and obligations.
We do not sell personal information or disclose it for third parties’ independent advertising. We share relevant information with travel suppliers, payment providers and service providers as explained above to deliver and support our services.
9. International processing
Travel arrangements can require information to reach suppliers in other countries. Our technology and service providers may also process information outside your country of residence, where privacy laws may differ.
The destinations depend on your travel arrangements and the providers involved. They may include countries where airlines, accommodation providers, booking systems, payment providers or technology services operate. Transfers for travel fulfilment may differ from those used for hosting, backups or support.
We require a lawful basis for international transfers and protections appropriate to applicable data-protection requirements. Depending on the circumstances, these may involve recognised adequacy protections, appropriate contractual safeguards or another permitted transfer ground. Where a particular transfer requires your informed consent, we will request it separately rather than infer it from this policy. You may contact us for information about the protections relevant to your data.
10. Cookies, local storage and analytics
Our digital services use cookies or similar storage where needed to operate features such as sessions, security and preferences. You can manage browser storage through your browser settings, although disabling necessary storage may affect functionality.
At the effective date of this policy, the new Intraverse marketing website is configured for essential functionality and user-selected preferences, with advertising trackers disabled and no connected analytics provider. This statement applies to the marketing website and should not be taken as a description of every app, product or external service.
Session storage supports the current interaction; persistent preference storage can remember choices between visits until it expires, is replaced or you clear it. Storage used for authentication and security follows the relevant session and security requirements. You can contact us for details of the technologies and providers associated with a particular service.
Where optional analytics or advertising technologies require consent, they will be subject to a separate choice. You may change that choice through the relevant controls once available.
The use of a third-party service, embedded content or an external link may involve that provider’s own technologies and privacy notice. Any new analytics integration must be reflected in the applicable disclosures and choices before activation.
11. How long we keep information
We retain information for the relevant service and recordkeeping purposes, with access limited where records are retained only for a specific obligation, dispute or security need. Closing an account does not necessarily remove records held by airlines, hotels, payment providers or other independent organisations.
Our retention schedule distinguishes account information, operational records and information that must be kept for a specific obligation:
| Information | Retention period and trigger |
|---|---|
| Active account information | While the account is active and the information remains necessary to provide the service. |
| Closed-account profile and preferences | Delete within 30 days of a verified deletion request, except the specific records retained under the categories below. |
| Invoices, wallet ledger, payments and accounting records | Six years from the date the record was created, or longer where a specific applicable requirement or documented legal hold requires it. This period does not apply automatically to every traveller document or profile. |
| Booking and servicing information | Through travel completion and any outstanding changes, refunds or other servicing. After that, retain only the minimum transaction evidence required for accounting or a documented claim; delete other operational information within 30 days after its purpose ends. |
| Passport images and sensitive assistance documents | Delete within 30 days after the purpose is complete, unless a specific obligation or active case requires continued retention. |
| Business-verification documents | Retain while necessary for initial verification and justified ongoing checks. Delete raw documents within 30 days after that need ends, unless a specific obligation or active case requires longer retention. Keep only the minimum verification evidence needed for the continuing relationship or a documented obligation. |
| Unconverted enquiries | Six months after the last substantive interaction. A separate marketing subscription is managed under its own preferences and consent. |
| Routine support conversations | Six months after resolution. Necessary evidence for an active dispute is separated into a restricted case record with its own documented retention basis. |
| Routine application, access and diagnostic logs | 90 days. Incident-specific evidence may be retained separately where justified for an investigation or legal obligation. |
| Marketing preferences and consent records | While the subscription is active, retain the preferences and consent evidence needed to administer it. After withdrawal, retain only minimal evidence needed to honour the opt-out and any consent evidence required for a documented legal purpose. Review this continued need at least annually. |
| Backups | A rolling maximum of 90 days. Information deleted from active systems expires through this cycle; if a backup is restored, deletion instructions are reapplied before the information is returned to ordinary use. |
When retention is no longer justified, information is deleted or made anonymous. A shorter applicable legal deadline or valid erasure requirement takes priority over an ordinary retention period. Any longer retention for a legal hold or unresolved claim is limited to the relevant records and purpose and is reviewed when that need ends.
12. Security
We take technical and organisational measures appropriate to the information and risks involved. Access and handling arrangements are intended to protect information against unauthorised use, disclosure, alteration or loss. No internet service or storage system can be guaranteed completely secure.
Keep your login details confidential and contact us promptly if you suspect misuse of your account. Where a personal-data incident triggers notification obligations, we will provide the required notifications.
13. Your rights and choices
Depending on applicable law and the circumstances, you may request access to your information, correction, deletion, restriction of processing or a portable copy. You may also object to certain processing, withdraw consent and challenge qualifying automated decisions.
Email us using the contact details above. We may need proportionate information to verify your identity or authority. We will explain any lawful limits on a request and respond within the applicable time limit. You can complain to the Nigeria Data Protection Commission at ndpc.gov.ng, or another competent authority where applicable, without first having to resolve the matter with us.
We aim to acknowledge privacy requests within two business days and resolve them within 30 days, unless a shorter legal deadline applies. Where a lawful extension is necessary, we will explain the reason and expected response date within the required timeframe. Verification requests will be proportionate; they do not automatically restart or suspend a legal deadline.
14. Account closure and deletion requests
To request closure of your Intraverse account and deletion of associated personal information, contact hello@intraverse.africa with the subject “Account deletion request”. Include the account email address and business name, where relevant.
We will explain what can be deleted, what must be retained, why it is retained and the relevant period. A deletion request is not a booking cancellation request. Contact the business or support team managing your travel if you also want to cancel or change a booking.
If your information belongs to records managed by another business using Intraverse, we may need to coordinate the request with that business.
Deleting an individual user account does not automatically delete an agency’s shared booking, wallet or accounting records. We will distinguish your user profile from business records that the organisation or Intraverse must lawfully retain and explain any limits on deletion.
15. Communications
You may opt out of marketing through an available unsubscribe option or by contacting us. We may still send messages needed to administer your account, provide a service you requested or meet an obligation.
Where a mobile feature uses notifications, its device-level permissions can be managed in your device settings. Disabling notifications does not cancel bookings or remove account information.
16. Children’s information
Our business account services are intended for adults acting for themselves or a business. Travel bookings may nevertheless involve children, and their details may be supplied by a parent, guardian or authorised travel arranger.
Children’s information must be limited to the requested travel purpose and handled with the authorisation, consent and safeguards required by applicable law. Contact us if you believe a child has submitted information without appropriate authority.
17. Automated processing
Booking, payment and operational workflows may use automated processing. Routine automation is not necessarily a decision made solely by automated means that has legal or similarly significant effects on a person.
You may ask for human review of a contested automated decision affecting account access or payment eligibility, explain your circumstances and challenge the outcome. Contact us using the privacy-request details above. If an independent supplier made the decision, we will explain our role and help identify the appropriate contact where possible.
Where a decision is based solely on automated processing and has legal or similarly significant effects, we will provide the information required by applicable law about its purpose, the information used, the main factors involved and its likely consequences. We will also explain the available options to express your views, obtain human intervention or challenge the decision.
18. Changes to this policy
We will update this page when our relevant practices change and show the revised date. Where a change requires additional notice or consent, we will provide that notice or obtain that consent. Continuing to use a service does not replace consent where consent is legally required.