Skip to content

Privacy policy

Version 1.0 ·

Parvaz is an app for travel agencies: tickets, receipts and bookkeeping. This page explains what we do with the information in it.

1.Who we are

Parvaz is provided by [to be added] ([to be added]). In this policy, "we" means that business.

Questions about privacy: [to be added]. See also Contact at the end of this page.

2.Two kinds of information, two roles

1. Your agency's records. Passengers, passport details, tickets, bookings, receipts and bookkeeping that your agency enters. Your agency decides what to store and why, so the agency is responsible for it (in legal words, the agency is the controller). We store and process it only on the agency's behalf and on its instructions (we are the processor).

2. Staff accounts. The account you use to sign in: username, name, PIN, sessions and the security log. For this we are responsible (the controller).

If you are a passenger or a customer of an agency and want to see, correct or delete your information, please ask that agency first. We will help the agency do it.

3.What we keep about staff

Accounts are made by Parvaz or by your agency's manager. There is no sign-up, and we do not ask for your email address (only Google or Apple may give us one, if you link them — see below).

  • Account: username, name, role in each team (Manager, Agent or Viewer), when the account was made and when you last signed in.
  • PIN or password: stored only as a one-way scrambled code (a bcrypt hash). Nobody — not even us — can read your PIN from it.
  • Passkeys (fingerprint or face unlock), if you add one: only the public key and the name of the device. Your fingerprint or face never leaves your phone.
  • Google or Apple sign-in, if you link one ("Continue with Google" or "Continue with Apple"): the account id Google or Apple gives us and the email address they share (Apple may give a private relay address). It only opens the account you already have — it never creates one. You can unlink it in Settings, and it is removed when your PIN is reset or your account is deleted.
  • Signed-in devices: for each session, the IP address, the browser or device type and when it was last used.
  • Security log: sign-ins (with IP address), wrong-PIN lockouts, and changes to accounts and teams (who did what, and when).
  • Notifications and push: your list of in-app notifications and — if you allow notifications — the push address of your browser, or the device token of the Parvaz app on your phone (removed when you sign out or uninstall the app).
  • Team discussions: the messages you write in your team's discussions.
  • AI use: how many AI requests your team made and how much credit they used, per person per month.

4.What agencies store in Parvaz

Depending on what an agency uses, its records can include:

  • Passengers and customers: names, title, gender, date of birth, nationality, passport number and expiry, phone, address and notes.
  • Tickets and bookings: flights, booking references (PNR), ticket numbers, fares, baggage and the printed receipt.
  • Bookkeeping: sales, purchases, payments, expenses, parties (customers and suppliers), accounts and balances.
  • History: who created or changed each record and when, with earlier versions.

We use these records only to provide Parvaz to the agency: to save, sync, show, print and share them as the agency's staff ask. We never use them for advertising, never sell them and never look at them without a reason (for example when the agency asks for help, or to keep the service safe).

5.Why we use it

  • To run the service your agency has agreed with us: sign-in, saving and syncing records, printing tickets, team discussions and notifications.
  • To keep accounts safe: locking an account after many wrong PINs, showing who did what, and finding misuse.
  • To help you when you or your agency contact us.
  • To follow the law when we must.

Legal grounds (for people in the EU and UK): for staff accounts, our legitimate interest in providing the service your agency signed up for and in keeping it secure; our contract with the agency; and legal duties. For agency records, the agency decides the grounds, and we act on its instructions.

We do not use your information to make automatic decisions about you. The AI only suggests what to type into a form; a person always checks and saves it.

6.AI features (DeepSeek)

Parvaz can read a ticket, a passport or a receipt for you. This happens only when someone in your agency presses an AI button and only if Parvaz has turned AI on for that agency.

Then the photos, PDFs or text that person chose are sent to DeepSeek, an AI company with servers in the People's Republic of China. DeepSeek reads them and sends back the details it found. Your staff then check them before saving.

We do not keep the photos or files after the AI has read them. Only the details your staff save become part of your agency's records. DeepSeek handles the data under its own terms; its privacy policy says it stores data in China, and we cannot promise how long DeepSeek keeps it.

The assistant. When someone asks the Parvaz assistant something, their question and the agency records that matter for it (for example matching tickets, people or payments, or totals worked out on their own device) are sent to DeepSeek so it can write the answer. To find those records, Parvaz computes search data ("embeddings") from short summaries of your agency's records on Parvaz's own server; no other company receives your records for this. The assistant never changes anything by itself: it suggests, and a person checks and confirms. A manager can switch the assistant off for the agency. We keep assistant conversations for 30 days.

China does not have an EU "adequacy decision". If your agency's customers are in the EU or UK, your agency should decide whether to use AI for their documents. A manager can choose not to use AI, and Parvaz can turn AI off for an agency at any time — just ask us.

7.Who else receives information

We do not sell or rent information, and we do not share it for advertising. These service providers help us run Parvaz:

OVHcloud
What forOur servers and backups
WhereGermany (EU)
What they receiveEverything stored in Parvaz, kept on our servers
DeepSeek
What forAI reading of documents
WhereChina
What they receiveOnly the files and text someone sends with an AI button, and questions to the assistant with the records needed to answer them
Google, Apple, Mozilla (push services)
What forDelivering web notifications
WhereTheir own servers worldwide
What they receiveYour device's push address and an encrypted message they cannot read
Google Firebase Cloud Messaging
What forNotifications in the Android and iPhone apps (on iPhones together with Apple's push service)
WhereGoogle servers worldwide
What they receiveA device token for each app install, and each notification's short title and text (for example "Mariam: message preview"). Nothing else about you; no Firebase analytics.
Google and Apple (sign-in)
What for"Continue with Google" or "Continue with Apple" — only if you use it
WhereTheir own servers
What they receiveThey see that you sign in to Parvaz; we receive your account id and email address from them

Airline logos are downloaded by our server from pics.avs.io using only the airline's two-letter code. Your device talks only to our server, and no personal information is sent.

Customer links: your agency can send a customer a link to one ticket, or switch on a page where customers find their tickets with their passport number and booking reference. Anyone with a link can see that ticket's printed details; passport numbers are hidden except for the last 3 characters. Links can be switched off at any time and can expire.

We may also give information when the law forces us to (for example a valid court order), and only as much as required.

8.Countries where data is handled

Parvaz's servers and backups are in Germany, in the European Union. People use Parvaz from many countries, including Afghanistan, the UK, the UAE, Pakistan, Iran and Turkey, so information also travels to and from their devices.

Data leaves the EU only in the cases in the table above: AI reading in China (only when someone presses an AI button), notification delivery by Google and Apple, and signing in with Google or Apple if you use it.

9.How long we keep it

Your staff account
Until it is deleted. Deleting it anonymises it at once (see below).
Signed-in sessions
Until you sign out, or are signed out by a PIN reset, a block or the account deletion.
Linked Google or Apple sign-in
Until you unlink it, your PIN is reset or your account is deleted.
Phone push token
Until you sign out or uninstall the app.
Security log
24 months, then deleted.
In-app notifications
12 months, then deleted.
Server error logs
30 days, then deleted.
Backups
Made every day; each one is kept 14 days.
Account deletion requests (from the web form)
12 months after we handle them, as proof that we did.
Files sent to AI
Not kept by us after they are read.
Assistant conversations
30 days after the last message.
Agency records
As long as the agency uses Parvaz. When an agency leaves, we delete all of its records; they are gone from backups within 14 days.

When a staff account is deleted we remove the name, username, PIN, sessions, passkeys, linked Google or Apple sign-ins, push addresses and phone tokens, and the notification list. What stays belongs to the agency: the records you made or changed (their history keeps the name you had at the time) and the messages you wrote in team discussions, now shown as "Deleted user". Details: Delete your account.

Get started form. If you ask for a demo on our website, we keep the name, phone or WhatsApp number, agency, city and message you send, only so we can contact you and set up your account. We do not store your IP address. We delete a request 12 months after we close it.

10.How we protect it

  • Everything travels over encrypted connections (HTTPS).
  • PINs and passwords are stored only as one-way bcrypt hashes. After 5 wrong tries the sign-in pauses for 15 minutes; after 30 wrong tries in a day the account is locked until Parvaz unlocks it.
  • Each person sees only the teams they belong to, and roles limit what they can change. Managers and Parvaz can see who did what.
  • Passkeys keep only a public key on our side.
  • Backups stay on our own servers in Germany.

No system is perfectly safe. If we learn of a breach that affects you, we will tell your agency and, where the law requires, you and the authorities.

11.On your device: cookies and local storage

We use only the cookies that are needed for Parvaz to work. No analytics, no advertising and no third-party cookies, so there is no cookie banner.

  • parvaz_session — keeps you signed in.
  • XSRF-TOKEN — a security check that stops other websites from acting in your name.

So you can keep working without internet, Parvaz saves a copy of your team's records and your settings (language, theme) on your device. Signing out removes your team's records from that device. Our website pages load no outside scripts, fonts or trackers.

12.Your choices and rights

  • Get a copy: Settings → Account → Download my data gives you a file with your account, devices, team memberships, the discussion messages you wrote, your notifications and the security log about you.
  • Correct: your manager can change your name; ask us for anything else.
  • Delete: Settings → Account → Delete my account, or the form on Delete your account.
  • Object or limit: you can switch off notifications or unlink a Google or Apple sign-in at any time, and you can ask us to stop or limit some uses.
  • Complain: you can complain to a data-protection authority — in the EU, the one in your country; in the UK, the ICO. We would like to hear from you first, so we can try to fix it.

We give these rights to everyone, wherever they live. Some laws (for example in Turkey or the UAE) give extra rights; we follow them too. We answer within one month. For an agency's records (for example a passenger's details), we pass the request to the agency and help it answer.

13.Children

Parvaz is a work tool for agency staff and is not meant for anyone under 16. Agencies may store children's details as passengers; the agency is responsible for that, and parents or guardians should contact the agency.

14.Changes to this policy

When we change this policy, we update the version and date at the top. If a change is important, we tell agency managers in the app before it takes effect.

15.Contact

Write to us about anything on this page. We usually answer within a few days.

Provider[to be added]
[to be added]

Email[to be added]

Our contact details will be added here soon. Until then, ask your agency's manager.