Effective date: 7 August 2026
Take Off Go Pty Ltd (“we”, “us”, or “our”) operates the Travalet iOS application, the travalet.app website, and the agency portal at portal.travalet.app (collectively, the “Service”). This Privacy Policy explains what information we collect, how we use it, and your rights.
If you have questions, contact us at privacy@travalet.app.
1. The short version
- Your itinerary data lives on your device and syncs via your iCloud account, not our servers.
- We do not have a Travalet account system, and we never ask for your name, password, or Apple ID.
- To route forwarded bookings to the right device, you register and verify the email addresses you forward from. We store those addresses on our relay alongside your device’s push token. You can remove them at any time in Settings → Travel Addresses.
- When you forward a booking email to trips@travalet.app, we parse it, deliver the structured data to your device, and delete the email. We retain parsed data for up to 30 days for delivery retry purposes only.
- We use a third-party AI model (Anthropic Claude) to parse email content. Anthropic retains submitted content for up to 30 days per their data retention policy.
- Staff at partner travel agencies can forward supplier quotes and confirmations to agents@travalet.app. We keep the original message for 90 days, its attachments for 12 months, and the details we extract from it for as long as that agency’s account is open. Those messages often contain someone else’s personal information, so section 2.5 sets out exactly what we hold and why.
- We do not sell your data. We do not run advertising.
2. Information we collect
2.1 Email parsing
When you forward a booking confirmation to trips@travalet.app, our relay service receives the email, extracts the booking details using an AI model, and delivers the structured data as a push notification to your device. The raw email content is not stored after parsing is complete.
We retain the parsed booking data (not the raw email) for up to 30 days in case delivery to your device needs to be retried. After 30 days, this data is permanently deleted.
2.2 Device registration
To deliver parsed bookings to your device, our relay stores:
- A push notification token provided by Apple’s APNs service.
- A device identifier that you generate within the app.
- The email addresses you have registered and verified in Settings → Travel Addresses, used solely to match forwarded bookings to your device. Each address is verified by sending a one-time code to it. Addresses are stored until you remove them in the app, or until you unregister the device or uninstall the app.
We do not collect your name, password, Apple ID, or any other personally identifying information, and we do not store the contents of your iCloud-synced trips.
2.3 Usage analytics
We may collect anonymised, aggregated usage metrics (such as the number of emails parsed per day) to understand how the Service is used. This data cannot be linked to an individual device or person.
2.4 Website
The travalet.app website uses standard web server logs that may include your IP address, browser type, and the pages you visit. These logs are retained for a maximum of 30 days and are used only for security monitoring and diagnosing technical issues.
2.5 Agent inbox (partner travel agencies)
This section applies to travel agencies that partner with us, and to anyone whose details appear in mail those agencies forward. It does not describe the Travalet app, which never sends, receives or stores any part of this.
Staff at a partner agency can forward supplier quotes and booking confirmations to agents@travalet.app. We parse each message into draft itinerary items and show them in the portal alongside the original text, so the consultant can check every extracted value against the words it came from.
We only keep mail from addresses we recognise. A message is attributed by its sender address, which has to match a registered member of a partner agency. Mail from any other address is not stored at all: it is discarded, the sender gets a single reply explaining why and how to sign up, and we record an audit event that carries neither the address nor the content.
For a message we do accept, we store:
- The original message, along with its plain text and HTML parts, held as files in Cloudflare R2. Access is limited to the agency the message was attributed to.
- Any attachments, such as a supplier rate sheet or a PDF proposal, stored the same way.
- The sender’s name, the sender’s email address and the subject line, encrypted at rest in our database. These are encrypted with keys we hold rather than keys you hold, because the portal has to display them back to the agent who forwarded the message. We can decrypt them, and we do so only to render that agency’s inbox and to operate the Service.
- A SHA-256 hash of the sender’s address, used to find an agency’s messages without decrypting them. A hash is a lookup key, not anonymisation: anyone who already knows an address can test it against the hash.
- What we extract: the structured items (dates, rates, room types, reference numbers), the short quote from the source text that each value came from, and message metadata such as the time it arrived and the identifiers that keep a forwarded thread grouped.
A forwarded message often contains someone else’s personal information
The common case is mail a supplier addressed to the agent’s client, which the agent then forwards to us. That message can carry the client’s name, contact details, travel dates and booking references, and the client has never dealt with Travalet directly. It can equally carry the details of a supplier’s staff, such as a reservations manager’s name, direct line and email signature.
We hold that information because the agency asked us to process it in order to build their client’s itinerary. The agency chooses what to forward and is responsible for having the right to forward it. We act on that agency’s instructions, and our basis for processing is the legitimate interest of the agency and its client in producing an accurate itinerary. We use forwarded mail only to parse it, to show it in that agency’s own portal, and to improve how accurately we parse mail. We do not use it to build a profile of anyone, we do not sell it, and we never expose one agency’s inbox to another.
How long we keep it
- The original message and its body text are deleted 90 days after we receive them. Ninety days is long enough that an improvement to our parser can be replayed against real mail. Past that, holding the original is a liability rather than a benefit.
- Attachments are deleted 12 months after we receive them. A supplier rate sheet stays useful for a season after the covering note has stopped mattering, which is why it outlives the message it arrived with.
- The details we extracted are kept for as long as the agency’s account is open, because they become that agency’s itinerary and library content. That record includes the source quote behind each value, so a consultant can still see where a number came from after the original is gone, and the portal says plainly when an original is no longer retained. The sender’s name and address, the subject line and the message metadata are part of the same record and are kept on the same basis.
Closing an agency’s account deletes its inbox records, including the messages, the attachments and the extracted details.
If you believe a message forwarded to us holds your personal information and you would like it removed, email privacy@travalet.app. We will identify the agency the message was attributed to, act on the request where it is ours to act on, and pass it to that agency where the decision is theirs.
3. How we use your information
We use your information only to:
- Parse booking emails and deliver itinerary data to your device (performing the Service)
- Parse mail forwarded by a partner agency and build the draft itinerary items that agency asked for (performing the Service)
- Retry failed push deliveries (legitimate interest)
- Investigate security incidents (legitimate interest)
- Comply with legal obligations
We do not use your information for advertising, profiling, or sale to third parties.
4. Third-party services
4.1 Anthropic Claude (AI model)
Email content submitted for parsing is sent to Anthropic’s API. This covers both booking emails forwarded by travellers and supplier mail forwarded by partner agencies, including the text of any attachment we parse. It also covers the free-text brief a consultant submits in the portal to draft an itinerary: any notes they type and any enquiry text they paste in from a client, which can be the client’s own words. Anthropic may retain submitted content for up to 30 days for trust and safety purposes, after which it is deleted. Anthropic does not use submitted content to train their models without explicit consent. See Anthropic’s privacy policy for details.
4.2 Apple iCloud
Your itinerary data syncs between your devices via Apple CloudKit. Apple’s privacy policies govern that data. We do not have access to data stored in your iCloud account.
4.3 Cloudflare
Our relay service runs on Cloudflare Workers. Cloudflare may process network traffic data in accordance with their privacy policy.
5. Data retention
| Data type | Retention period |
|---|---|
| Raw email forwarded by a traveller to trips@travalet.app | Deleted after parsing (typically within seconds) |
| Parsed booking data (for delivery retry) | 30 days |
| Device push tokens | Until you unregister the device or uninstall the app |
| Registered sender email addresses | Until you remove the address in the app, or unregister the device |
| Agent inbox: original message and body text | 90 days from receipt |
| Agent inbox: attachments | 12 months from receipt |
| Agent inbox: extracted details, source quotes, sender, subject and message metadata | Kept while the agency’s account is open |
| Website server logs | 30 days |
6. Your rights
Depending on your location, you may have rights to access, correct, delete, or port your personal data. We hold minimal data and never collect your name or Apple ID, so most requests can be handled by removing the relevant records from our relay.
If you’ve registered email addresses with the relay, you can exercise access or erasure against those records by removing the address in Settings → Travel Addresses (which deletes it from our systems), or by emailing privacy@travalet.app from one of those addresses. Otherwise, email us with your device identifier (shown in the app’s Settings screen) and we will delete the associated push token.
If your details appear in mail a travel agency forwarded to our agent inbox, section 2.5 explains what we hold, how long we hold it, and how to ask us to remove it.
7. Children
The Service is not directed at children under 13. We do not knowingly collect personal information from children under 13.
8. Changes to this policy
We will post any changes to this policy on this page and update the effective date. For material changes, we will notify you via an in-app notice.
9. Contact
Take Off Go Pty Ltd
ABN 15 634 608 567
Melbourne, Victoria, Australia
privacy@travalet.app