SahraSafarPrivacy Policy
SAHRASAFAR GROUP INC — Online Travel Agency
1. INTRODUCTION
SAHRASAFAR GROUP INC ("SahraSafar," "we," "us," or "our") operates the Platform at https://www.sahrasafar.com. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how we protect it, how long we keep it, and your rights.
This policy applies to all Users worldwide — including those in the European Economic Area ("EEA"), United Kingdom ("UK"), Kingdom of Saudi Arabia ("KSA"), United States (including California), India, and all other jurisdictions we serve. It covers both registered account holders and guest Users who complete Bookings without an account.
By using the Platform, you acknowledge this Privacy Policy. It is incorporated by reference into our Terms and Conditions.
2. DATA CONTROLLER
SAHRASAFAR GROUP INC is the data controller (or "data fiduciary" under Indian law).
General contact: support@sahrasafar.com Legal, compliance & data requests: legal@sahrasafar.com Website: https://www.sahrasafar.com
3. WHAT WE COLLECT
3.1 Data You Provide
Account Data: First name, last name, username, email address, phone number, and password (stored in hashed form). If you register via Google or Apple Sign-In, we receive your name, email, and a unique identifier from the provider.
Profile Data (Optional): If you choose to complete your profile, we may collect: gender, date of birth, nationality, emergency contact name and phone number, biography, mailing address (street, city, state, country, postal code), preferred language, timezone, and notification preferences (per-category and per-channel settings for email, SMS, and push notifications). This data is voluntarily provided and can be updated or deleted through your Account settings.
Booking Data (Flights): Traveler names, titles (Mr./Mrs./Ms.), dates of birth, nationality, and contact details (email, phone) for all passengers. For guest Bookings, we collect email and phone number at checkout.
Passport and Identity Data: During the flight checkout process, some airlines require passport or identity information (passport number, expiration date, issuing country). This data passes through SahraSafar's servers for the sole purpose of transmitting it to our flight booking partner and the applicable airline. SahraSafar does NOT store, retain, log, or persist passport or identity data on our servers after transmission. The data is processed transiently in memory and is not written to any database or file system.
Temporary Client-Side Caching: To prevent data loss if a fare expires during checkout (fares expire every ~10 minutes), passenger details you enter are temporarily cached in your browser's sessionStorage. This data exists only on your device, only in your active browser tab, and is automatically and permanently deleted when you close the tab. This data never reaches SahraSafar's servers. You can clear it at any time by closing the browser tab.
Hala AI Data: Conversation messages; contextual memories organized by category (travel style, flight preferences, hotel preferences, activity preferences, dietary restrictions, travel companions, and interested destinations — Hala AI explicitly does not store financial information, health details beyond dietary preferences, personal relationships, employment details, political views, or home addresses); AI-generated travel plans; and any information you voluntarily share in chat. We also track daily message usage counts and tokens consumed per user for tier-based rate limiting (Oasis: 15 messages/day, Caravan: 50/day, Sultan: 100/day). We send your first name, username, email address, conversation messages, and stored memories to OpenAI for processing. Voice conversations are transcribed using ElevenLabs and synthesized using Fish Audio. We advise you not to share sensitive personal data (passport numbers, payment details, ID numbers) in Hala AI conversations. A custom content filter warns Users who attempt to do so.
Communication Data: Messages to our support team, feedback, and reviews.
Payment Reference Data: We store only the last four (4) digits of your card number, the card network (e.g., Visa, Mastercard), and billing address. Full card numbers, CVVs, and PINs are never stored on our systems — Stripe handles all payment data.
3.2 Data We Collect Automatically
Device Data: Device type, operating system, browser type and version, screen resolution, language settings, and device fingerprint. Device fingerprints are generated by a self-hosted fingerprinting solution on our own infrastructure — no fingerprint data is sent to any third-party service.
Network Data: IP address, approximate geographic location (derived from IP address using third-party geolocation services), and ISP information.
Usage Data: Pages viewed, searches performed, Booking activity, session duration, clicks, and interaction timestamps. Aggregated behavioral patterns are used for rule-based bot detection and fraud prevention; these systems operate entirely on our infrastructure and no individual behavioral data is shared externally for this purpose.
Authentication Audit Logs: We log authentication events (logins, logouts, registration, OTP verification, session elevation, and failed attempts) along with IP address, user agent, and device fingerprint for security monitoring and abuse prevention.
API Request Logs: We log API requests with IP address, user agent, device fingerprint, endpoint accessed, response time, geolocation (country, city), bot detection score, and rate-limiting metrics for security and Platform integrity purposes.
Location Data: Approximate location from IP address only. We do NOT collect GPS data unless you explicitly grant device-level permission (optional and revocable).
3.3 Data from Third Parties
Google/Apple Sign-In: Name, email, and account identifier.
Fraud Prevention Services: IP-based fraud risk scores and geolocation data from third-party fraud prevention providers.
Stripe: Transaction confirmation, payment status, and fraud risk indicators.
3.4 What We Do NOT Collect or Store on Our Servers
- Full payment card numbers, CVVs, or PINs;
- Passport numbers, national ID numbers, or government-issued identification — this data passes through our servers transiently during the booking process for the sole purpose of transmission to our flight booking partner and the airline, but is never stored, logged, or persisted in any SahraSafar database or file system;
- Racial or ethnic origin, religious beliefs, political opinions, genetic data, biometric data, health data, or data concerning sexual orientation — unless voluntarily provided for a booking-related purpose (e.g., accessibility needs) with explicit consent.
4. WHY WE PROCESS YOUR DATA
4.1 Providing Services
Processing Bookings; communicating confirmations, updates, and alerts (via email and SMS); displaying search results; processing payments via Stripe; powering Hala AI.
*Legal basis: GDPR Art. 6(1)(b) contractual necessity; Saudi PDPL contractual necessity; CCPA business purpose; India DPDP Act consent/voluntary provision.*
4.2 Fraud Prevention and Security
Device fingerprinting, IP analysis, Stripe fraud checks, velocity monitoring, behavioral analysis; enforcing Terms; maintaining system security.
*Legal basis: GDPR Art. 6(1)(f) legitimate interests; Saudi PDPL legitimate interests; CCPA business purpose; India DPDP Act prevention of offences.*
4.3 Platform Improvement
Usage analytics (server-side, aggregated); improving Hala AI quality; debugging and performance optimization.
*Legal basis: GDPR Art. 6(1)(f) legitimate interests; Saudi PDPL legitimate interests; CCPA business purpose; India DPDP Act consent.*
4.4 Communications
Transactional messages (confirmations, changes, receipts); service announcements; marketing (with explicit consent where required). We record the timestamp and version of your consent for marketing communications and Terms acceptance. You may configure notification preferences by category (offers, loyalty, tools, confirmations, surveys, account, reminders) and by channel (email, SMS, push) through your Account settings.
*Legal basis: GDPR Art. 6(1)(b) transactional, Art. 6(1)(a) marketing; Saudi PDPL prior agreement/consent; CCPA business purpose/consent; India DPDP Act consent.*
4.5 Legal Compliance
Tax, regulatory, and accounting obligations; law enforcement requests; dispute resolution and legal proceedings.
*Legal basis: GDPR Art. 6(1)(c); Saudi PDPL legal obligation; CCPA legal obligation; India DPDP Act compliance with law.*
4.6 Loyalty Program Administration
Tracking points, tier status, and rewards for registered Users with flight Bookings.
*Legal basis: GDPR Art. 6(1)(b) contractual necessity; Saudi PDPL contractual necessity.*
4.7 Affiliate Program Administration
Tracking referrals, commissions, and rewards for enrolled Affiliates and Travel Agents.
*Legal basis: GDPR Art. 6(1)(b) contractual necessity.*
5. WHO WE SHARE DATA WITH
We do NOT sell, rent, or trade your personal data.
5.1 Booking Partners (Direct Services)
Our flight booking and distribution partner (Duffel) and applicable airlines receive traveler data necessary to fulfill flight Bookings (names, contact details, passport data transmitted transiently).
5.2 Payment Processor
Stripe processes payments as an independent controller under PCI-DSS Level 1 certification.
5.3 Categories of Technology Partners
We share data with the following named service providers, each acting as a data processor under contractual obligations:
- AI Provider — OpenAI — processes Hala AI text conversations (receives: name, username, email, messages, memories);
- Voice Transcription Provider — ElevenLabs — processes voice audio for speech-to-text transcription (receives: audio recordings only);
- Voice Synthesis Provider — Fish Audio — processes text for speech synthesis (receives: text content only);
- SMS and Communication Provider — Twilio — delivers SMS notifications and OTP verification codes (receives: phone number, message content);
- Fraud Prevention and Geolocation Provider — MaxMind — provides fraud risk scoring, IP geolocation, device intelligence, and security analysis (receives: IP address, device attributes, session identifiers);
- Authentication Providers — Google, Apple — facilitate sign-in (independent controllers for sign-in data);
- Mapping Provider — Mapbox — powers location, map features, and airport/destination search (receives: search queries, approximate location);
- Hotel Search Provider — LiteAPI — provides hotel search, rates, and availability data (receives: search queries, destination, dates; no personal data shared unless you click through to a partner booking site);
- Activity Search Provider — Viator — provides activities, tours, and experience search results (receives: search queries, destination; no personal data shared unless you click through to the partner booking site);
- Currency Exchange Data — OpenExchangeRates — provides real-time exchange rates for currency display (receives: query parameters only; no personal data shared);
- Authentication Infrastructure — SuperTokens — self-hosted on our infrastructure; manages session tokens and OTP verification. No data is shared with SuperTokens Inc. as the software runs entirely on our servers;
- Self-Hosted Security Tools — device fingerprinting and rule-based bot detection run entirely on our infrastructure; no fingerprint data is shared with external companies.
5.4 Partner Service Providers
When you click through to a Partner Service (such as our hotel booking portal or activity booking partners), any data you enter on the partner's website is collected and processed by that partner under their own privacy policy — not ours. We do not share your SahraSafar account data with Partner Service providers.
5.5 Legal Disclosures
We may disclose data when required by law, regulation, or legal process; to enforce our Terms; to protect rights, property, or safety; or to respond to emergencies.
5.6 Business Transfers
In a merger, acquisition, or asset sale, data may transfer. We will notify you before data becomes subject to a different privacy policy.
6. INTERNATIONAL DATA TRANSFERS
Your data may be processed outside your country of residence. We implement safeguards including: EU-approved Standard Contractual Clauses (SCCs); Saudi SCCs or equivalent safeguards per SDAIA Data Transfer Regulation; contractual protections with all processors; and compliance with India DPDP Act cross-border requirements.
7. DATA RETENTION
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion + 30 days for processing |
| Booking/transaction data | 7 years from travel date (tax/legal/DOT compliance) |
| Guest Booking data | 7 years from travel date |
| Hala AI conversations/memories | Until you delete them, or account deletion |
| Hala AI usage data (daily message counts) | Rolling — overwritten daily; aggregated data up to 12 months |
| Hala AI travel plans | Until you delete them, or account deletion |
| Fraud detection data (fingerprints, IP logs) | Up to 3 years |
| Marketing preferences | Until consent withdrawal or account deletion |
| Authentication audit logs | Up to 12 months |
| API request logs (including bot detection scores) | Archived and cleaned hourly; retained up to 30 days |
| Server/access logs | Up to 12 months |
| Temporary server-side cache (search results, session data) | Up to 24 hours (Redis) |
| Client-side sessionStorage (passport data) | Automatically deleted on tab close — never on our servers |
After retention periods expire, data is securely deleted or irreversibly anonymized. Booking and transaction data is retained for seven (7) years to comply with IRS record-keeping requirements, U.S. Department of Transportation regulations applicable to ticket agents, and potential legal proceedings.
8. DATA SECURITY
We implement: TLS 1.2+ encryption in transit; encryption at rest for sensitive data; bcrypt password hashing; OAuth 2.0 authentication (Google, Apple); self-hosted device fingerprinting (data never leaves our infrastructure); IP-based fraud detection via MaxMind; rule-based bot detection (self-hosted); CSRF protection with signed tokens; Content Security Policy (CSP) headers; HTTP Strict Transport Security (HSTS); role-based access controls; session idle timeout of two (2) hours; regular security assessments; and secure development practices.
No system is 100% secure. We cannot guarantee absolute security. You are responsible for your account credentials and OTP codes.
8.1 Automated Decision-Making
Our fraud prevention systems may automatically decline, hold, or flag transactions based on risk scoring from device fingerprinting, IP analysis, MaxMind risk scores, and behavioral pattern analysis. These automated systems may block Bookings or suspend accounts without human review when fraud indicators exceed defined thresholds. You have the right to contest any automated decision by contacting support@sahrasafar.com, at which point a human review will be conducted. This disclosure is provided pursuant to GDPR Article 22, Saudi PDPL, and similar provisions in applicable law.
9. YOUR RIGHTS
9.1 GDPR (EEA/UK Users)
Access (Art. 15); Rectification (Art. 16); Erasure (Art. 17); Restriction (Art. 18); Portability (Art. 20); Objection (Art. 21); Withdraw consent (Art. 7(3)); Complaint to supervisory authority. Regarding automated decision-making (Art. 22): our fraud prevention systems may make automated decisions that affect your ability to complete a Booking or use the Platform (see Section 8.1). You have the right to obtain human intervention, express your point of view, and contest such decisions by contacting support@sahrasafar.com.
9.2 Saudi PDPL (KSA Users)
Right to be informed; access; correction; deletion/destruction; withdrawal of consent; restriction; breach notification. Enforced by SDAIA. Fines up to SAR 3 million and imprisonment up to 2 years for unauthorized disclosure.
9.3 CCPA/CPRA (California Users)
Right to Know (categories and specific pieces of personal information collected); Delete; Correct; Opt-Out of Sale/Sharing; Limit Use and Disclosure of Sensitive Personal Information. SahraSafar does NOT sell personal information and does NOT share it for cross-context behavioral advertising. We do not use sensitive personal information for purposes other than those permitted under CCPA. Right to Non-Discrimination. No financial incentives offered. California residents may submit requests via legal@sahrasafar.com. We will verify your identity before processing requests and respond within 45 days.
9.4 India DPDP Act (Indian Users)
Access; correction; erasure; grievance redressal; nomination (for exercise of rights in case of death/incapacity); withdrawal of consent. Privacy notices available in English; contact us for specific Indian language requests.
9.5 Emerging Privacy Laws
SahraSafar actively monitors and intends to comply with emerging privacy legislation worldwide, including the EU AI Act (Regulation 2024/1689) as it applies to AI-powered features such as Hala AI, the North Carolina Personal Data Privacy Act (if enacted), and equivalent laws in jurisdictions where we operate. As new laws take effect, we will update this Privacy Policy accordingly.
9.6 U.S. State Privacy Laws
In addition to California (CCPA/CPRA), SahraSafar respects the privacy rights of residents of all U.S. states with comprehensive consumer privacy laws, including but not limited to Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), and other states with enacted privacy legislation. Residents of these states may exercise rights to access, correct, delete, and opt out of the sale of personal data (where applicable) by contacting legal@sahrasafar.com. SahraSafar does NOT sell personal information in any U.S. state.
9.7 How to Exercise Rights
Email legal@sahrasafar.com. We respond within 30 days (or as required by applicable law). Identity verification required. No fee unless the request is manifestly unfounded or excessive.
10. CHILDREN'S PRIVACY
The Platform is for Users 18+. We do not knowingly collect data from children under 18 without parental/guardian involvement in the Booking process. If we discover unauthorized collection from a minor, we will promptly delete it. Contact support@sahrasafar.com to report concerns.
11. DATA BREACH NOTIFICATION
We will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by GDPR, Saudi PDPL, and India DPDP Act. For North Carolina residents, we comply with the North Carolina Identity Theft Protection Act (N.C.G.S. § 75-65), which requires notification to affected individuals without unreasonable delay and to the North Carolina Attorney General if more than 1,000 individuals are affected. We maintain an incident response plan and internal breach register.
12. DO NOT TRACK
The Platform does not currently respond to DNT browser signals. Manage preferences via our cookie consent banner.
13. CHANGES
Material changes will be communicated via email or Platform notice, with an updated "Last Updated" date. Where required by law, we will obtain renewed consent. Continued use after changes constitutes acceptance.
14. CONTACT AND GRIEVANCE OFFICER
SAHRASAFAR GROUP INC Website: https://www.sahrasafar.com
| Purpose | |
|---|---|
| General Support | support@sahrasafar.com |
| Legal, Compliance & Data Requests | legal@sahrasafar.com |
| Security Reports | security@sahrasafar.com |
For data subject requests (access, correction, deletion, portability), email legal@sahrasafar.com.
India DPDP Act — Grievance Officer: Name/Designation: Mohammad Faisal, Grievance Officer. Email: legal@sahrasafar.com. Acknowledgment within 48 hours; resolution within 30 days.
EEA/UK: Complaints to your local Data Protection Authority — https://edpb.europa.eu/about-edpb/about-edpb/members_en
KSA: Complaints to SDAIA — https://sdaia.gov.sa
*By using SahraSafar, you acknowledge this Privacy Policy.*