Authentication & access
- Accounts are protected by email/password and Google sign-in.
- Sessions use industry-standard JWT tokens managed by our backend provider.
- Role-based access controls separate trekkers, guides, and administrators.
Trust Center
This page is maintained by Travo to answer common security and privacy questions about our platform. It describes the controls currently enabled in our app — it is not an independent certification or audit.
We collect the information needed to fulfil your bookings — name, contact details, trek preferences, and messages with guides. Full details are listed in our Privacy Policy.
We rely on a small set of trusted providers to operate the platform, including our managed backend (database, auth, storage), hosting/CDN, and analytics. We do not sell your personal data.
You can request access, correction, or deletion of your account data at any time. Booking records may be retained for accounting and legal obligations. See our Privacy Policy and Terms.
If you believe you've found a vulnerability or have a security concern, please email security@travo.tours. We aim to acknowledge reports within 3 business days.
Shared responsibility: Travo maintains the application-level controls described above. Underlying platform security (hosting, database engine, encryption primitives) is provided by our infrastructure partners. Customers are responsible for safeguarding their own account credentials.