1. Introduction
At Turizi ("we", "our", or "us"), we operate a cloud-based software-as-a-service (SaaS) platform designed for Destination Management Companies (DMCs), tour operators, and travel agencies. We are deeply committed to protecting the privacy, integrity, and security of the personal and business data entrusted to us by our customers and their team members.
This Privacy Policy describes the types of information we collect, how we process and store it, the measures we take to protect your data, and your rights concerning your personal information when using the Turizi web application and related services (collectively, the "Service").
2. Information We Collect
We collect information in the following ways:
- Account & Registration Information: When you register for an account or are invited to a workspace by an administrator, we collect your name, business email address, company name, phone number, and authentication credentials.
- Operational & Reservation Data: In the course of using the platform, users upload and manage customer itineraries, passenger details, booking schedules, supplier costings, and billing records.
- Google Workspace / Gmail Account Data: When an organization administrator connects a Gmail account through Google OAuth, our application accesses specific email communications to enable team collaboration directly inside reservations.
- Turizi Gmail Linker (Chrome Extension): When using our companion Chrome extension ("Turizi Gmail Linker"), the extension reads the active Gmail conversation metadata (thread ID, subject line, sender address, and snippet) from your active Gmail tab solely to allow you to search and link that specific conversation to a reservation in your Turizi account. The extension does not collect or monitor browsing activity, history, or credentials outside of the active Gmail thread.
3. Google API Data & Limited Use Disclosure
Compliance with the Google API Services User Data Policy & Chrome Web Store Developer Policies
When you connect your Google Account to Turizi or use the Turizi Gmail Linker Chrome extension, our application requests access to authorized Gmail scopes (including reading messages, viewing thread metadata, and sending authorized replies on your behalf).
Google API Services User Data Policy Compliance:
Turizi's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Turizi Gmail Linker Chrome Extension Privacy & Data Practices:
The Turizi Gmail Linker Chrome extension adheres to the Chrome Web Store Single-Purpose and Minimum Permissions guidelines:
- Single-Purpose: The extension operates solely to connect customer email threads directly to Turizi reservations.
- Zero Stored Credentials: The extension never collects, logs, or stores Google passwords, account tokens, or secrets. It relies on your active, authenticated Turizi session cookie.
- Scoped Gmail DOM Access: The content script runs on mail.google.com only to extract thread identifiers, subject lines, and sender addresses for matching. It does not monitor any background browsing activity or data on other websites.
- No Third-Party Transmission: All data is communicated directly and securely to your Turizi instance. Extension data is never sold, transferred, or shared with third parties, advertisers, or data brokers.
4. How We Use Collected Information
We process your information strictly for legitimate business purposes, including:
- Providing, maintaining, and enhancing the Turizi platform and features.
- Enabling collaboration across your team on itineraries, reservations, and supplier bookings.
- Allowing users to link customer email communications to specific reservations and reply seamlessly.
- Processing payments, subscription billings, and account notifications.
- Responding to customer support inquiries and resolving technical issues.
5. Data Sharing and Third Parties
We do not sell or monetize personal information. We only share data with third-party service providers who assist us in operating our platform (such as cloud hosting infrastructure, managed database providers, and email delivery platforms), strictly under binding data processing agreements that mandate confidentiality and security.
We may also disclose information if required by law, subpoena, or government authority, or when necessary to protect the rights, safety, and security of Turizi, our users, or the public.
6. Data Retention, Revocation & Deletion
We retain your information only as long as your workspace account remains active or as needed to provide you with the Service.
- Disconnecting Google Accounts: Workspace administrators may disconnect any connected Gmail account at any time via Settings > Gmail Link. Disconnecting an account immediately revokes access tokens, preventing any further synchronization with Google APIs.
- Google Security Settings: You may also revoke Turizi's permissions at any time directly through your Google Account Permissions Page.
- Account Deletion: You may request complete deletion of your account, organization data, and associated records by contacting us at contacto@turizi.com.
7. Security Standards
We implement robust technical and organizational security controls designed to safeguard your information against unauthorized access, destruction, loss, or alteration. These measures include:
- Enforced Transport Layer Security (TLS 1.3 / HTTPS) encryption for all data in transit.
- Industry-standard AES-256 encryption for persistent data and credentials at rest.
- Strict multi-tenant logical database isolation ensuring no organization can access another tenant's records.
- Automated threat monitoring, audit logs, and continuous vulnerability scanning.
8. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please reach out to our privacy and security team: