Skip to main content

Privacy policy

Travel agencies trust Tripaxa with their daily work and with the details of the people they serve. This policy explains, in plain terms, what we collect, why, where it is kept and what you can ask of us. It applies to the tripaxa.pro website, the Tripaxa workspace, the agency storefronts at agencies.tripaxa.pro and our support channels.

Last updated
Developed by
CCIMI
  • Everything you record in your Tripaxa workspace is hosted on servers in Algeria and is not transferred abroad.
  • We never sell personal data and never use it for advertising.
  • Your agency’s customers and travelers belong to your agency. We process their data only to run the service for you.
  • You can ask to see, correct or object to the use of your data, and you can complain to the ANPDP.
  • When a subscription ends, the workspace stays readable for 90 days, then its data is deleted.

1. Who we are

Tripaxa is a management platform for travel, Umrah and Hajj agencies, developed by CCIMI. In this policy, “Tripaxa”, “we” and “us” refer to the team that operates the platform.

This policy follows Law No. 18-07 of 10 June 2018 on the protection of natural persons in the processing of personal data, as amended and supplemented.

2. Two roles, clearly separated

We decide how data is used when it concerns our own relationship with you: your user account, a demo request, a support message or your agency’s subscription. For that data, we are the controller.

Your agency also records data about its own customers and travelers. That data belongs to the agency, which remains the controller. We act as its processor: we store and process it only to provide the service, following the agency’s instructions and the commitments set out in our terms of service.

A booking request you send to an agency from its storefront also goes to that agency. If you are a traveler and want to exercise your rights over a booking, a booking request or a file, contact your agency first. We will help it answer you.

3. The data we collect

We only collect what the service needs:

  • Demo requests: your name, email address, phone number, agency name, optional message and the time slot you chose.
  • Booking requests on an agency storefront: your name and phone number, an optional email address and message, the trip you chose, and the name and age group of each traveler. No passport details are asked for there. The request goes to the agency you chose.
  • User accounts: email address, display name, preferred time zone, and your password, which we store only in hashed form and can never read.
  • Agency workspace: the agency and branch names you enter, the users you invite and their permissions.
  • Subscription: the plan, billing periods and the payments we record. Payments are made offline, so we never receive card numbers.
  • Support: the messages and feedback you send us, and our replies.
  • Activity log: which user performed which action in the workspace, with their name and email address, so your agency can trace every change.
  • Technical data: server logs record requests and their outcome, including the IP address. The IP address is also used briefly to block repeated sign-in attempts.

4. Why we use it

We use this data to create and secure your account, run the service your agency has subscribed to, bill and support you, arrange the demos you request, and meet our legal obligations.

We do not use it for advertising, we do not build marketing profiles, and we do not make automated decisions about you.

5. Your data stays in Algeria

Everything recorded in the Tripaxa workspace is hosted on servers located in Algeria: user accounts, customers, travelers, bookings, trips, visas, finance and subscription records, and the booking requests sent through agency storefronts. We do not transfer this data outside Algeria.

Two limited services on the edge of the platform run outside Algeria, and neither receives workspace data. The public website tripaxa.pro uses Umami to count visits; it sets no cookies and does not identify you. And messages you send to our email addresses pass through our email provider.

If we ever need to change this, we will update this policy beforehand and obtain any authorization the law requires.

6. Who can access it

Within Tripaxa, only the people who need data to operate, support or bill the service can access it, and they are bound by confidentiality.

Outside Tripaxa, data is handled only by the service providers listed above: our hosting provider in Algeria, our website audience measurement and our email provider. We disclose data to public authorities only when the law requires it.

We never sell or rent personal data.

7. Cookies and browser storage

The public website sets no cookies. While you fill in the demo form, your entries are kept in your browser tab so you do not lose them; they disappear when you close the tab.

The workspace uses only the cookies it needs to work:

  • tripaxa_sid: keeps you signed in. It cannot be read by scripts and expires after 12 hours at most.
  • i18n_locale: remembers your language for one year.
  • Interface preferences, such as the collapsed menu or your chosen theme, kept for one year.

8. How long we keep it

We keep data only as long as it serves a purpose:

  • Workspace data: for as long as the subscription runs. When it ends, the workspace remains readable for 90 days so your agency can retrieve what it needs; then we delete its data.
  • Demo requests: up to 12 months after the demo, unless your agency becomes a customer.
  • Storefront booking requests: a request that is declined, withdrawn or left unanswered is deleted after 180 days. An accepted request stays with the agency’s booking.
  • Subscription and payment records: for the period required by accounting and tax law.
  • Server logs: rotated automatically and kept only for a short period.

9. How we protect it

Connections are encrypted with HTTPS. Passwords are hashed with a modern algorithm. Session cookies are protected from scripts. Each user sees only what their role and branches allow, and the activity log keeps track of every change.

If an incident affects personal data, we take immediate steps to contain it, inform the agencies concerned without delay and notify the authorities as the law requires.

10. Your rights

Under Law No. 18-07, you have the right to be informed, to access your data, to have it corrected, updated or deleted when it is inaccurate or no longer needed, and to object to its use for legitimate reasons.

To exercise these rights, write to the addresses at the end of this page. We may ask you to confirm your identity. We answer free of charge and as quickly as possible.

You can also lodge a complaint with the National Authority for the Protection of Personal Data (ANPDP).

11. Changes to this policy

We may update this policy as the service evolves. The date at the top shows the latest version. If a change significantly affects how we use your data, we will tell workspace owners before it takes effect.