Tripwise
Privacy Policy
Last updated: September 26, 2026 · Version 1.1
This Privacy Policy explains how personal data is processed in Tripwise, a back-office management platform for travel agencies. It is drafted in accordance with Argentina's Personal Data Protection Act (Ley 25.326) and its supplementary regulations. By using Tripwise you accept the practices described in this document.
1. Data controller
The controller of the personal data of user accounts is:
- Entity — [RAZÓN SOCIAL / TITULAR]
- Tax ID (CUIT) — [CUIT]
- Address — [DOMICILIO LEGAL]
- Privacy contact — [EMAIL DE PRIVACIDAD]
Hereinafter, “Tripwise”, “we” or “the controller”.
2. Two roles: controller and processor
Tripwise acts in two distinct capacities depending on the type of data:
- As controller — for the data of user accounts (the agency's employees or owners who register and use the platform) and the agency's own data. The purposes, legal bases and rights described in this Policy fully apply to that data.
- As processor — for the data of passengers and clients that each agency loads to manage its bookings, and for the invoices it receives from its suppliers. In that case the agency is the controller of that data, and Tripwise processes it on the agency's behalf and per its instructions, under the Data Processing Agreement included in the Terms and Conditions.
3. What data we collect
User account data (agency employees/owners):
- First and last name, identity document, email address and phone number.
- Password, stored encrypted (hashed) by the authentication service; Tripwise never accesses the plaintext password.
- Profile photo, if the user chooses to upload one.
- Device push-notification token and platform (web/Android/iOS), to deliver alerts.
- Technical and error-diagnostics data (user identifier, email, role, error traces and navigation events) used for service stability and security.
Agency (company) data:
- Legal name, Tax ID (CUIT), tax address, VAT condition, gross-income registration number and activity start date.
- Branches and their associated information.
Passenger and client data (loaded by the agency, processed by Tripwise as processor):
- First and last name, date of birth, email address, phone number, address and country.
- Client tax data where applicable: Tax ID (CUIT) and VAT condition.
- Document type and number (for example, national ID or passport) and its expiration date.
- Attachments uploaded by the agency (for example, images or scans of documents, visas or certificates).
- Booking data: flights, accommodations, transfers, insurance, destinations and travel dates.
- Payment and billing data: amounts, currency, exchange rate, issued invoices and the tax data required for electronic invoicing.
Supplier invoices and documents (loaded by the agency, processed by Tripwise as processor):
- Invoices and other vouchers the agency receives from its suppliers, as PDFs or photos, with the data printed on them: the issuer's legal name, Tax ID (CUIT) and VAT condition, amounts, and passenger names or booking references.
- Booking confirmations from tour operators, as PDFs or images, that the agency imports to create a booking.
Tripwise does not collect or store full credit or debit card details: the subscription charge is processed through an external payment provider (see Processors and third parties).
4. Why we use the data (purposes)
- To provide and operate the platform: managing bookings, passengers, operators, finances and commissions.
- To read, with artificial intelligence, the documents the agency imports (booking confirmations and supplier invoices) and suggest their data, which the agency reviews before confirming them.
- To issue electronic tax invoices through the tax authority, and to verify with it the invoices the agency receives from its suppliers.
- To handle the sign-up, charging and administration of the service subscription and of AI-import packs.
- To provide support, send operational notices and answer enquiries.
- To ensure security, prevent fraud and abuse, and diagnose and fix errors.
- To comply with legal, tax and accounting obligations.
5. Legal basis and consent
The processing of user account data is based on the informed consent given at registration (Section 5 of Ley 25.326) and on the need to perform the service's contractual relationship.
Certain processing is carried out without additional consent where a law allows or requires it, such as issuing invoices and retaining tax and accounting information.
For passenger data, the legal basis and obtaining the consent of the data subjects is the responsibility of the agency, in its capacity as controller.
6. Processors and third parties we share data with
To provide the service we rely on providers that process data on Tripwise's behalf, or to whom the law requires us to transfer certain information. We do not sell personal data. The main ones are:
- Supabase — infrastructure provider that hosts the database, authentication and file storage. The platform's data resides on its infrastructure.
- Mercado Pago — processes the service subscription charge and the purchase of AI-import packs. It receives the data needed for the charge (payer and subscription or purchase identifiers, amounts and currency).
- ARCA / AFIP — Argentina's tax authority. Transferring data to issue electronic invoices (CUIT, amounts and invoice data) is required by law. In addition, to verify an invoice the agency received from a supplier, its data is sent (the issuer's CUIT, type, point of sale, number, date, total amount, authorization code and, depending on the invoice, the agency's CUIT), using the agency's own certificate.
- Resend — transactional email provider (invitations, invoices and notices). It receives the recipient's email address and the message content.
- Sentry — error-monitoring service. It receives user identifiers and technical traces to diagnose failures.
- Firebase Cloud Messaging (Google) — push-notification service. It receives the device token to deliver alerts.
- Gemini API (Google) — artificial-intelligence service that reads the documents the agency imports (booking confirmations from tour operators and supplier invoices, as PDFs or images) to suggest their data. It receives the file and the reading instructions, and returns the data it found. Google does not use these documents or its responses to train or improve its products: it processes them as a processor under its data processing terms, and keeps them for up to 55 days solely to detect abuse of its service and to meet legal obligations. Large files are uploaded to it temporarily and deleted as soon as the reading ends (within 48 hours at the latest).
We may also share data when required by a competent authority within the law, or to defend rights in administrative or judicial proceedings.
7. International transfers
Some of the providers listed above may store or process data outside Argentina. In those cases we seek to ensure adequate protection safeguards, in line with Section 12 of Ley 25.326. By accepting this Policy you consent to such transfers to the extent necessary to provide the service.
In particular, Google may temporarily store the documents it reads with artificial intelligence in any of the countries where it has facilities.
8. Data retention
We keep data while the account remains active and for as long as necessary to fulfil the purposes described.
Tax information and invoices are retained for the periods required by tax and accounting regulations, even after the account is closed.
Supplier invoices that the agency imports and then discards, or that the platform rejects (for example, because the file is not an invoice), are deleted together with their file after 30 days.
For security and audit purposes we keep historical change logs for certain tables. Once the legal periods elapse, data is deleted or anonymized.
9. Information security
We apply reasonable technical and organizational measures to protect data, including:
- Isolation of each agency's information through database-level access rules (multi-tenant).
- Encryption of communications in transit.
- Password storage using hashing functions.
- Safeguarding of sensitive credentials (for example, invoicing certificates) in an encrypted secrets store.
- Access control by roles and per-user permissions.
No system is completely infallible; we work continuously to maintain and improve these measures.
10. Your rights
You may exercise the rights of access, rectification, updating and deletion of your personal data (Sections 14 to 16 of Ley 25.326) by writing to [EMAIL DE PRIVACIDAD]. The right of access may be exercised free of charge at intervals of no less than six months, unless a legitimate interest applies, and will be answered within the legal timeframes.
Argentina's Agency for Access to Public Information (AAIP), the supervisory authority for Ley 25.326, is empowered to handle complaints and claims regarding non-compliance with personal data protection rules.
11. Passenger and client data
Where Tripwise acts as a processor, passengers and clients should direct the exercise of their rights to the agency that loaded their data, which is the controller. If we receive a request from a passenger, we will forward it to the relevant agency or assist according to its instructions.
12. Minors
The service is aimed at travel agencies and their professional users; it is not intended to be used by minors as account holders. Any loading of minors' passenger data is done under the agency's responsibility, which must hold the appropriate authorization.
13. Changes to this Policy
We may update this Policy to reflect changes in the service or in applicable regulations. We will publish the current version on this page, indicating the last-updated date. Material changes may be notified through the platform.
14. Contact
For questions about this Policy or the processing of your personal data, write to us at [EMAIL DE PRIVACIDAD].