Legal

Privacy Policy

What personal data we hold, why we hold it, how long we keep it, and the rights you have over it.

Last updated

Who we are

TIME TRAVEL operates a business-to-business travel platform for travel agencies, tour operators and corporate travel teams in Saudi Arabia. Our registered address is PM4R+W33, Musa Ibn Nusair St, Al Olaya, Riyadh 12241, Saudi Arabia.

For anything in this policy, or to exercise any of the rights described below, contact us at privacy@timetravel.com.

Our role: controller and processor

For data about the agencies who use our platform and their staff — account details, KYC documents, wallet and billing records — we act as the data controller.

For data about travellers, we act as a processor on behalf of the agency that entered it. The agency is the controller of its travellers’ data and is responsible for having a lawful basis to collect it and for telling those travellers how it will be used. We process it only to deliver the bookings that agency asks us to make.

Personal data we collect

We collect only what is needed to operate an agency account and issue airline tickets. Specifically:

  • Account data — name, email address, password (stored only as an argon2id hash, never in readable form), assigned role, and the organisation you belong to.
  • Agency verification (KYC) data — business licence, authorised signatory passport, and tax or registration certificates uploaded during onboarding.
  • Traveller data — first, middle and last name, gender, date of birth, passport number, passport expiry date, nationality, passport issuing country, and the contact email and phone number given for the booking.
  • Booking and financial data — bookings, tickets, invoices, wallet balance, top-up requests, uploaded payment receipts, and the immutable ledger of wallet transactions.
  • Technical and security data — IP address, browser user-agent string, session records, and an audit log of significant actions taken in the platform.

Why we process it, and on what basis

  • To perform our contract with your agency — creating accounts, searching and booking flights, issuing tickets, and settling payment through the agency wallet.
  • To meet legal obligations — airlines and border authorities require accurate passenger and travel-document data, and tax law requires us to retain financial records.
  • For our legitimate interests in operating the platform securely — authentication, fraud prevention, rate limiting, audit logging, and diagnosing faults.
  • With consent, where you have given it — for example, subscribing to our agent newsletter. You can withdraw consent at any time.

Who we share it with

We do not sell personal data, and we do not share it for advertising.

We share it only where delivering the service requires it:

  • Airlines and travel suppliers — passenger and travel-document details necessary to issue and honour a ticket.
  • Infrastructure providers who host the platform and its database, and our email delivery provider.
  • Government authorities, regulators or law enforcement where we are legally required to do so.

International transfers

Some of our infrastructure providers process data outside Saudi Arabia. Where personal data is transferred abroad, we take steps to ensure it remains protected to a standard consistent with Saudi data protection law, including contractual safeguards with those providers.

How long we keep it

  • Booking, ticket and financial records — retained for the period required by Saudi tax and commercial law.
  • Agency KYC documents — retained for the life of the agency relationship and for the period required afterwards by anti-money-laundering and commercial record-keeping rules.
  • Audit logs — retained to provide a security and compliance trail, then archived or deleted under our retention schedule.
  • Account data — deleted or anonymised after an account is closed, except where we must keep it to meet a legal obligation.

How we protect it

Passwords are hashed with argon2id and are never recoverable in readable form. Sessions use signed, httpOnly cookies that JavaScript cannot read, with refresh-token rotation and automatic revocation if a token is replayed. Access within the platform is restricted by role, and significant actions are written to an audit log. Uploaded documents are validated and stored privately, not on the public web.

More detail is on our security page. No system is perfectly secure, but we treat traveller documents and agency financial data as the most sensitive data we hold and design accordingly.

Your rights

Subject to Saudi data protection law, you have the right to ask us to:

  • Confirm what personal data we hold about you and give you a copy of it.
  • Correct data that is inaccurate or incomplete.
  • Delete data where we no longer have a lawful reason to keep it.
  • Restrict or object to certain processing.
  • Withdraw consent where processing relies on it.

How to exercise your rights

Email privacy@timetravel.com and tell us what you need. We will verify your identity before acting, and will respond within the period required by law.

If you are a traveller whose data was entered by an agency, contact that agency first — they control the data and can correct or remove it directly. If you cannot reach them, contact us and we will help.

If you are not satisfied with our response, you may complain to the competent Saudi data protection authority.

Changes to this policy

We will update this page when our practices change, and revise the date at the top. Where a change materially affects how we handle your data, we will tell account holders directly rather than relying on this page alone.