Trust Center

Security, privacy & transparency

This page is maintained by Travo to answer common security and privacy questions about our platform. It describes the controls currently enabled in our app — it is not an independent certification or audit.

Authentication & access

  • Accounts are protected by email/password and Google sign-in.
  • Sessions use industry-standard JWT tokens managed by our backend provider.
  • Role-based access controls separate trekkers, guides, and administrators.

Data protection

  • Data is stored in a managed Postgres database with row-level security policies that scope records to their owners.
  • Traffic between your browser and our servers is encrypted in transit via HTTPS/TLS.
  • Administrative actions on sensitive records (bookings, messages) are restricted by policy.

What we collect & why

We collect the information needed to fulfil your bookings — name, contact details, trek preferences, and messages with guides. Full details are listed in our Privacy Policy.

Subprocessors & hosting

We rely on a small set of trusted providers to operate the platform, including our managed backend (database, auth, storage), hosting/CDN, and analytics. We do not sell your personal data.

Retention & your rights

You can request access, correction, or deletion of your account data at any time. Booking records may be retained for accounting and legal obligations. See our Privacy Policy and Terms.

Reporting a security issue

If you believe you've found a vulnerability or have a security concern, please email security@travo.tours. We aim to acknowledge reports within 3 business days.

Shared responsibility: Travo maintains the application-level controls described above. Underlying platform security (hosting, database engine, encryption primitives) is provided by our infrastructure partners. Customers are responsible for safeguarding their own account credentials.