Privacy Policy

Last updated: 25 July 2026

Quick summary

  • This policy covers the AsiaTravelPlan website, services, and native iOS staff app.
  • We collect only what we need to plan trips, manage bookings, and provide authorized staff access.
  • We use cookies and sessions to keep you logged in and support secure API access.
  • The iOS app stores its authentication session securely in the device Keychain and may cache staff profile photos.
  • If an eligible staff member grants notification permission, we register the app installation for Apple push notifications.
  • We only share necessary booking-related information with trusted travel partners.
  • We do not sell personal data or use the iOS app for advertising or cross-app tracking.

This privacy policy covers the AsiaTravelPlan website and services (asiatravelplan.com) and the native Asia Travel Plan iOS app used by authorized staff.

About this service

AsiaTravelPlan runs a static web frontend with an API-backed backend for travel enquiries, bookings, and internal operations.

  • Frontend: HTML, CSS, and JavaScript.
  • Backend: A Node.js HTTP API with PostgreSQL, filesystem-backed media and generated documents, and Keycloak authentication for staff.
  • iOS app: A staff-only SwiftUI app for viewing permitted booking information, assigning bookings, and receiving role-appropriate booking or assignment notifications when permission is granted in iOS.

What data we collect

We only collect information needed to provide booking and trip-planning services.

Personal data you provide

  • Name, email, phone number, and message details from enquiry and support forms.
  • Booking request details, travel dates, preferences, and itinerary-related notes.
  • Account and authentication details during login flow.

Data used by the iOS staff app

The iOS app makes existing operational data available only to signed-in staff whose assigned roles permit access. Depending on those permissions, this may include:

  • Staff account identifiers and permissions, such as username, display name, email address, account subject identifier, and assigned roles.
  • Booking identifiers, booking titles, customer or traveler names and contact details, travel dates, duration, preferences, budget ranges, notes, submission timing, and assignment information.
  • Operational actions performed through the app, such as assigning or reassigning a booking to a staff member.
  • Staff usernames, display names, booking counts, and profile photos used in assignment controls.

Push-notification data

The app automatically requests notification permission only for eligible staff. If permission is granted, the app and backend process a randomly generated installation identifier, the Apple Push Notification service (APNs) device token, notification status, app version, bundle identifier, and APNs environment. A notification may include a booking identifier so the app can open the relevant booking after the user taps it. Notification text is intentionally generic and does not contain customer names or contact details.

Automatically collected data

  • Technical request data, such as IP address and browser information, needed for booking intake, security, abuse prevention, and troubleshooting.
  • Technical app and device-registration data needed to operate the iOS app, secure its API access, deliver optional notifications, diagnose failures, and enforce supported app versions.

Stored by the browser

  • localStorage values used for convenience features, such as language, selected filters, and a tour-customization draft.
  • Authentication cookies when you sign in.

Stored on an iOS device

  • Authentication tokens and the signed-in staff profile are stored in the iOS Keychain using device-only protection. Logging out clears the stored authentication session.
  • A random installation identifier, APNs device token, notification-registration state, and related retry information may be stored in app preferences.
  • Staff profile photos may be stored in the app's cache to improve loading performance.
  • Booking responses are normally held in memory and requested using no-store networking. The app does not intentionally create a durable offline booking database.

Cookies and session data

By continuing to use AsiaTravelPlan, you agree to the use of cookies described below.

  • Session cookies are used for login state and secure API access.
  • Browser preference values store non-sensitive UI settings, such as language and tour filtering state.

No analytics-cookie integration is part of the current application. This policy will be reviewed before adding one.

You can block or clear cookies in your browser settings, but this may limit site functionality, including login and saved session state.

iOS permissions and tracking

  • The app automatically asks eligible staff for notification permission; iOS lets staff deny or later disable notifications.
  • Notification permission can be changed at any time in iOS Settings.
  • The current app does not request access to location, contacts, camera, microphone, photo library, health data, or advertising identifiers.
  • The current app does not include advertising or cross-app tracking functionality.

Third-party services

We may share relevant booking-related data with trusted partners needed to process your travel request, such as transportation or accommodation providers, and only to the extent needed to deliver the service. Configured infrastructure, email-notification, authentication, and translation providers may process the limited data needed to perform their service.

The iOS app uses Apple platform services, including APNs when notification permission is granted, and Keycloak for staff authentication. Apple processes the device and notification data needed to deliver push notifications under Apple's applicable terms and privacy policy.

Data sharing and retention

  • We do not sell personal data.
  • Access is protected by role- and session-based controls.
  • Data sent between the iOS app, authentication service, and backend is transmitted over encrypted network connections in production.
  • Booking and customer data is retained only as long as needed for operations, legal obligations, and service quality.
  • Authentication sessions remain on the device until logout, expiry, or invalidation. The app clears its stored session on logout. Notification registrations are deactivated on logout when possible and retained only as needed to provide notifications.
  • On-device cache data may be removed automatically by iOS or when the app is removed.

Your rights

You can ask us for access, correction, deletion, and withdrawal of consent for your personal data, subject to legal requirements.

Staff can disable notifications in iOS Settings and can log out of the app to clear the stored authentication session and deactivate the current notification registration.

Contact

If you have questions about this policy, the iOS app, or your data, contact AsiaTravelPlan at info@asiatravelplan.com or through the contact details published on the website.