Ēzidash is a software platform designed for travel advisors, agencies, and travel professionals globally. By accessing or using Ēzidash, you acknowledge and agree to this Privacy Policy.
1. Scope
This Privacy Policy applies to:
- the Ēzidash platform
- websites operated by us
- customer support
- onboarding
- training services
- billing and subscriptions
- communications with us
It applies globally, subject to applicable laws.
2. Your Role and Our Role
Where you use Ēzidash to collect, store, or process information about your own clients:
- You are the Data Controller
- Ēzidash is the Data Processor
You are responsible for obtaining all required client consents, disclosures, and permissions.
We process personal information only as necessary to provide our services.
3. Information We Collect
A. Account Information
We may collect:
- name
- business name
- agency name
- email address
- phone number
- billing address
- subscription details
- login credentials
B. Client Information Entered by Users
Users may enter:
- client names
- birthdays
- anniversaries
- passport information
- travel preferences
- dietary restrictions
- accessibility needs
- loyalty program numbers
- emergency contacts
- travel documents
- payment-related information
- invoices
- itineraries
- proposals
- notes
- communications
This information is controlled by the user.
C. Payment Information
Subscription payments are processed through Stripe, Inc.
We do not directly store raw payment card details.
Where temporary payment data is stored for operational purposes, it is encrypted and tokenized using Enigma Vault, which states it is PCI Level 1 and SOC 2 Type II compliant. Enigma Vault uses AES-256 encryption and tokenization architecture to reduce exposure of sensitive payment data.
Payment-related records stored through our systems may be retained for up to 7 days before deletion or secure purging.
Access to protected payment data requires PIN-based authentication.
D. Technical Information
We may collect:
- IP address
- browser type
- operating system
- device identifiers
- usage logs
- access timestamps
- crash reports
- security logs
- API usage
- feature interaction data
4. How We Use Information
We use personal information to:
- provide and operate Ēzidash
- process subscriptions and billing
- provide customer support
- improve product performance
- troubleshoot issues
- monitor platform security
- prevent fraud
- comply with legal obligations
- generate reports
- send service notifications
- communicate product updates
5. Legal Bases for Processing (GDPR/UK)
Where applicable, we process personal information based on:
- performance of a contract
- legitimate business interests
- legal obligations
- consent (where required)
6. Data Storage and Security
Ēzidash uses enterprise cloud infrastructure including Microsoft and Amazon Web Services.
Data is protected using industry-standard security measures including:
- AES-256 encryption at rest
- TLS encryption in transit
- access controls
- role-based permissions
- secure backups
- audit logging
- PIN-restricted access to sensitive vault data
- tokenization of payment data
- secure key management
- multi-layer cloud security architecture
Microsoft documents Azure storage encryption using AES-256 and FIPS 140-2 aligned encryption methods for data at rest and TLS/IPsec protections for data in transit.
However, no system can guarantee absolute security.
7. International Transfers
Because Ēzidash serves users globally, personal information may be processed or stored in Canada, the United States, or other jurisdictions where our service providers operate.
By using Ēzidash, you acknowledge that data may be transferred internationally.
Where required, we implement safeguards such as contractual protections and security controls.
8. Data Retention
We retain personal information only as long as necessary for:
- service delivery
- legal compliance
- dispute resolution
- enforcement of agreements
- backup and recovery
Retention periods vary depending on the data type.
Users are responsible for deleting outdated client data where required.
9. Your Rights
Depending on your jurisdiction, you may have rights including:
- access
- correction
- deletion
- restriction
- portability
- objection
- withdrawal of consent
- complaint to a regulator
Requests may be submitted to us at support@ezidash.com.
Where data belongs to your clients, requests may need to be directed to the applicable travel advisor or agency.
10. California Privacy Rights
California residents may have rights under CCPA/CPRA, including:
- right to know
- right to delete
- right to correct
- right to opt-out of sale/sharing
11. Australian Privacy Rights
Australian users may request access or correction of personal information under the Privacy Act 1988.
12. Cookies and Analytics
We may use cookies, analytics tools, and similar technologies to:
- remember preferences
- maintain sessions
- improve performance
- analyze usage
- enhance user experience
Users may adjust browser settings to manage cookies.
13. Third-Party Providers
We may share data with:
- payment processors
- hosting providers
- email providers
- customer support systems
- analytics tools
- security vendors
- backup services
Examples may include:
- Stripe, Inc.
- Microsoft
- Amazon Web Services
- Enigma Vault
Each provider may have its own privacy practices.
14. Sensitive Data Warning
Users should avoid storing unnecessary sensitive information unless required for legitimate travel-related business purposes.
Users are solely responsible for ensuring lawful collection of:
- passport data
- health-related requests
- dietary restrictions
- accessibility details
- emergency contact information
15. Children's Privacy
Ēzidash is not directed to children.
Users may store information relating to minor travelers as part of legitimate travel bookings, but users remain responsible for obtaining all necessary parental or legal authority.
16. Data Breaches
In the event of a security incident affecting personal information, we will take reasonable steps to investigate, contain, and notify affected parties where required by law.
17. Changes to This Policy
We may update this Privacy Policy at any time.
Material changes may require renewed acknowledgement.
Continued use of Ēzidash after changes means acceptance of the updated policy.
18. Contact
Privacy questions or requests: