Privacy policy
Version 1.0 ·
Parvaz is an app for travel agencies: tickets, receipts and bookkeeping. This page explains what we do with the information in it.
1.Who we are
Parvaz is provided by [to be added] ([to be added]). In this policy, "we" means that business.
Questions about privacy: [to be added]. See also Contact at the end of this page.
2.Two kinds of information, two roles
1. Your agency's records. Passengers, passport details, tickets, bookings, receipts and bookkeeping that your agency enters. Your agency decides what to store and why, so the agency is responsible for it (in legal words, the agency is the controller). We store and process it only on the agency's behalf and on its instructions (we are the processor).
2. Staff accounts. The account you use to sign in: username, name, PIN, sessions and the security log. For this we are responsible (the controller).
If you are a passenger or a customer of an agency and want to see, correct or delete your information, please ask that agency first. We will help the agency do it.
3.What we keep about staff
Accounts are made by Parvaz or by your agency's manager. There is no sign-up, and we do not ask for your email address (only Google or Apple may give us one, if you link them — see below).
- Account: username, name, role in each team (Manager, Agent or Viewer), when the account was made and when you last signed in.
- PIN or password: stored only as a one-way scrambled code (a bcrypt hash). Nobody — not even us — can read your PIN from it.
- Passkeys (fingerprint or face unlock), if you add one: only the public key and the name of the device. Your fingerprint or face never leaves your phone.
- Google or Apple sign-in, if you link one ("Continue with Google" or "Continue with Apple"): the account id Google or Apple gives us and the email address they share (Apple may give a private relay address). It only opens the account you already have — it never creates one. You can unlink it in Settings, and it is removed when your PIN is reset or your account is deleted.
- Signed-in devices: for each session, the IP address, the browser or device type and when it was last used.
- Security log: sign-ins (with IP address), wrong-PIN lockouts, and changes to accounts and teams (who did what, and when).
- Notifications and push: your list of in-app notifications and — if you allow notifications — the push address of your browser, or the device token of the Parvaz app on your phone (removed when you sign out or uninstall the app).
- Team discussions: the messages you write in your team's discussions.
- AI use: how many AI requests your team made and how much credit they used, per person per month.
4.What agencies store in Parvaz
Depending on what an agency uses, its records can include:
- Passengers and customers: names, title, gender, date of birth, nationality, passport number and expiry, phone, address and notes.
- Tickets and bookings: flights, booking references (PNR), ticket numbers, fares, baggage and the printed receipt.
- Bookkeeping: sales, purchases, payments, expenses, parties (customers and suppliers), accounts and balances.
- History: who created or changed each record and when, with earlier versions.
We use these records only to provide Parvaz to the agency: to save, sync, show, print and share them as the agency's staff ask. We never use them for advertising, never sell them and never look at them without a reason (for example when the agency asks for help, or to keep the service safe).
5.Why we use it
- To run the service your agency has agreed with us: sign-in, saving and syncing records, printing tickets, team discussions and notifications.
- To keep accounts safe: locking an account after many wrong PINs, showing who did what, and finding misuse.
- To help you when you or your agency contact us.
- To follow the law when we must.
Legal grounds (for people in the EU and UK): for staff accounts, our legitimate interest in providing the service your agency signed up for and in keeping it secure; our contract with the agency; and legal duties. For agency records, the agency decides the grounds, and we act on its instructions.
We do not use your information to make automatic decisions about you. The AI only suggests what to type into a form; a person always checks and saves it.
6.AI features (DeepSeek)
Parvaz can read a ticket, a passport or a receipt for you. This happens only when someone in your agency presses an AI button and only if Parvaz has turned AI on for that agency.
Then the photos, PDFs or text that person chose are sent to DeepSeek, an AI company with servers in the People's Republic of China. DeepSeek reads them and sends back the details it found. Your staff then check them before saving.
We do not keep the photos or files after the AI has read them. Only the details your staff save become part of your agency's records. DeepSeek handles the data under its own terms; its privacy policy says it stores data in China, and we cannot promise how long DeepSeek keeps it.
The assistant. When someone asks the Parvaz assistant something, their question and the agency records that matter for it (for example matching tickets, people or payments, or totals worked out on their own device) are sent to DeepSeek so it can write the answer. To find those records, Parvaz computes search data ("embeddings") from short summaries of your agency's records on Parvaz's own server; no other company receives your records for this. The assistant never changes anything by itself: it suggests, and a person checks and confirms. A manager can switch the assistant off for the agency. We keep assistant conversations for 30 days.
China does not have an EU "adequacy decision". If your agency's customers are in the EU or UK, your agency should decide whether to use AI for their documents. A manager can choose not to use AI, and Parvaz can turn AI off for an agency at any time — just ask us.
8.Countries where data is handled
Parvaz's servers and backups are in Germany, in the European Union. People use Parvaz from many countries, including Afghanistan, the UK, the UAE, Pakistan, Iran and Turkey, so information also travels to and from their devices.
Data leaves the EU only in the cases in the table above: AI reading in China (only when someone presses an AI button), notification delivery by Google and Apple, and signing in with Google or Apple if you use it.
9.How long we keep it
| What | How long |
|---|---|
| Your staff account | Until it is deleted. Deleting it anonymises it at once (see below). |
| Signed-in sessions | Until you sign out, or are signed out by a PIN reset, a block or the account deletion. |
| Linked Google or Apple sign-in | Until you unlink it, your PIN is reset or your account is deleted. |
| Phone push token | Until you sign out or uninstall the app. |
| Security log | 24 months, then deleted. |
| In-app notifications | 12 months, then deleted. |
| Server error logs | 30 days, then deleted. |
| Backups | Made every day; each one is kept 14 days. |
| Account deletion requests (from the web form) | 12 months after we handle them, as proof that we did. |
| Files sent to AI | Not kept by us after they are read. |
| Assistant conversations | 30 days after the last message. |
| Agency records | As long as the agency uses Parvaz. When an agency leaves, we delete all of its records; they are gone from backups within 14 days. |
- Your staff account
- Until it is deleted. Deleting it anonymises it at once (see below).
- Signed-in sessions
- Until you sign out, or are signed out by a PIN reset, a block or the account deletion.
- Linked Google or Apple sign-in
- Until you unlink it, your PIN is reset or your account is deleted.
- Phone push token
- Until you sign out or uninstall the app.
- Security log
- 24 months, then deleted.
- In-app notifications
- 12 months, then deleted.
- Server error logs
- 30 days, then deleted.
- Backups
- Made every day; each one is kept 14 days.
- Account deletion requests (from the web form)
- 12 months after we handle them, as proof that we did.
- Files sent to AI
- Not kept by us after they are read.
- Assistant conversations
- 30 days after the last message.
- Agency records
- As long as the agency uses Parvaz. When an agency leaves, we delete all of its records; they are gone from backups within 14 days.
When a staff account is deleted we remove the name, username, PIN, sessions, passkeys, linked Google or Apple sign-ins, push addresses and phone tokens, and the notification list. What stays belongs to the agency: the records you made or changed (their history keeps the name you had at the time) and the messages you wrote in team discussions, now shown as "Deleted user". Details: Delete your account.
Get started form. If you ask for a demo on our website, we keep the name, phone or WhatsApp number, agency, city and message you send, only so we can contact you and set up your account. We do not store your IP address. We delete a request 12 months after we close it.
10.How we protect it
- Everything travels over encrypted connections (HTTPS).
- PINs and passwords are stored only as one-way bcrypt hashes. After 5 wrong tries the sign-in pauses for 15 minutes; after 30 wrong tries in a day the account is locked until Parvaz unlocks it.
- Each person sees only the teams they belong to, and roles limit what they can change. Managers and Parvaz can see who did what.
- Passkeys keep only a public key on our side.
- Backups stay on our own servers in Germany.
No system is perfectly safe. If we learn of a breach that affects you, we will tell your agency and, where the law requires, you and the authorities.
11.On your device: cookies and local storage
We use only the cookies that are needed for Parvaz to work. No analytics, no advertising and no third-party cookies, so there is no cookie banner.
- parvaz_session — keeps you signed in.
- XSRF-TOKEN — a security check that stops other websites from acting in your name.
So you can keep working without internet, Parvaz saves a copy of your team's records and your settings (language, theme) on your device. Signing out removes your team's records from that device. Our website pages load no outside scripts, fonts or trackers.
12.Your choices and rights
- Get a copy: Settings → Account → Download my data gives you a file with your account, devices, team memberships, the discussion messages you wrote, your notifications and the security log about you.
- Correct: your manager can change your name; ask us for anything else.
- Delete: Settings → Account → Delete my account, or the form on Delete your account.
- Object or limit: you can switch off notifications or unlink a Google or Apple sign-in at any time, and you can ask us to stop or limit some uses.
- Complain: you can complain to a data-protection authority — in the EU, the one in your country; in the UK, the ICO. We would like to hear from you first, so we can try to fix it.
We give these rights to everyone, wherever they live. Some laws (for example in Turkey or the UAE) give extra rights; we follow them too. We answer within one month. For an agency's records (for example a passenger's details), we pass the request to the agency and help it answer.
13.Children
Parvaz is a work tool for agency staff and is not meant for anyone under 16. Agencies may store children's details as passengers; the agency is responsible for that, and parents or guardians should contact the agency.
14.Changes to this policy
When we change this policy, we update the version and date at the top. If a change is important, we tell agency managers in the app before it takes effect.
15.Contact
Write to us about anything on this page. We usually answer within a few days.
Provider[to be added]
[to be added]
Email[to be added]
Our contact details will be added here soon. Until then, ask your agency's manager.