Legal

Privacy Policy

Last updated September 10, 2026

This policy explains what Aida Dev LLC, operating as TravelVault ("we", "us"), collects through travelvaulthq.com and the TravelVault platform, why, who else handles it, and what you can ask us to do with it. TravelVault is a business-to-business service; the people whose information we hold are mostly agency owners, their agents, and, for bookings, their clients.

1. What we collect and why

The access request form

When you apply, we ask for: your name, agency name, work email, phone number, state, which type of business you are (agency with agents, solo agency, or other), the booking tool you currently use, an IATA/CLIA/ARC number if you have one (optional), and an estimated range of monthly hotel bookings. We also record which page the form was submitted from.

We use this to verify that you are a US travel business, decide on your application, and contact you about it. Your stated business type and volume help us set up the right account type. We don't use the form to build marketing lists and we don't sell it.

Your account and your agents

Once approved, we hold the account details needed to run the platform: login credentials, your agency's branding (logo, domain, confirmation-email details), the agent accounts you create and the permissions you give them, and a record of bookings, payments, and commission attribution.

Your clients' booking details

To make a hotel booking, the platform needs traveler names, stay dates, and sometimes contact details. These are passed to our supply partner and to the hotel so the booking can be fulfilled. We don't use your clients' details for marketing, and we don't share your client list with other agencies on the platform.

Website analytics

We use Google Analytics 4 to understand how the website is used (pages viewed, approximate location by region, device type, and whether the access request form was submitted). This uses cookies and similar identifiers set by Google. We don't add other tracking or advertising scripts to the site.

Email

If you email us or reply to one of our emails, we keep the correspondence so we can answer you and have a record of what was agreed.

2. Who processes it for us

  • Form delivery. The access request form is delivered to our team by email through a third-party form-delivery service, and a copy of each submission is added to a spreadsheet (Google Sheets) that we use to track applications.
  • Email and documents. Our mailboxes and internal documents are hosted by our business email and document provider.
  • Analytics. Google Analytics 4, as described above.
  • Supply partners. Booking details are shared with the supply partner that processes the booking and with the hotel. They use those details to fulfill the booking under their own terms.
  • Hosting. The website and platform are hosted by infrastructure providers who store data on our behalf.

These providers process information only to provide their service to us. We don't sell personal information and we don't share it with third parties for their own marketing.

3. How long we keep it

  • Access requests that are declined or never completed: up to 12 months, then deleted.
  • Account and booking records: for as long as you have an account, then as long as needed for accounting, tax, and dispute purposes (generally 7 years for financial records).
  • Analytics data: retained according to our Google Analytics data-retention setting, then aggregated or deleted by Google.
  • Email correspondence: for as long as it is relevant to your relationship with us.

4. Your choices

You can ask us to show you the information we hold about you or your agency, correct it, or delete it, subject to records we're required to keep. You can also ask us to stop contacting you. Email contact@travelvaulthq.com; we respond within one business day and complete straightforward requests within 30 days. To limit analytics, you can block cookies in your browser or use Google's opt-out browser add-on.

Residents of states with consumer-privacy laws (for example California) may have additional rights, including the right to know, delete, and not be discriminated against for exercising those rights. We don't sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of on that front. Requests can be made by email; we may need to verify your identity before acting.

5. Security

Access to account data is limited to people who need it to run the platform and support you. Connections to the website and platform are encrypted (HTTPS). No system is perfectly secure; if we learn of a breach affecting your information we will tell you without unreasonable delay.

6. Children

The website and platform are for businesses and are not directed at children under 16. We don't knowingly collect information from them.

7. Changes

If we change this policy in a material way, we'll post the new version here with a new date and, for account holders, tell you by email or through the platform.

Contact

Aida Dev LLC (operating as TravelVault)
Delaware, United States
contact@travelvaulthq.com