Skip to main content
Piyam Travel Customer Portal

Privacy

Customer Portal Privacy Policy

How Piyam Travel handles personal information in the customer portal. Last updated 1 September 2026.

1. Who is responsible for your information

Piyam Travel Ltd is the controller of personal information used to provide the Piyam Customer Portal and the travel services linked to it. The customer portal is separated from Piyam's staff systems and is designed to expose only the customer-safe information needed for each feature.

2. Information we collect

  • Account identifiers, name, verified email and sign-in provider.
  • Age band and evidence that eligibility was checked, rather than a date of birth kept solely for the age gate.
  • Customer code, loyalty balance and earning history.
  • Appointment contact details and customer-safe application or trip information that you look up, save or link.
  • Consent records, notification choices, invitations and account privacy requests.
  • Security and technical data such as session, device, IP, request and abuse-prevention information.

3. Social sign-in and email sign-in

If you choose Google, Microsoft or Apple, that provider sends us an account identifier and available profile information, normally your verified email and name. Their own privacy terms govern their service. Piyam Travel does not receive your provider password. Passwordless email sign-in uses a time-limited link sent to the address you provide.

4. Why we use your information

We use information to create and secure your account, respond to requested travel services, track applications, manage appointments, provide released trip documents, maintain loyalty records, deliver transactional notifications, prevent fraud and meet legal obligations.

Our main UK GDPR bases are contract or steps requested before a contract for customer services, legitimate interests for proportionate security and service improvement, legal obligation where applicable, and consent for optional marketing or optional analytics. You can withdraw consent without affecting earlier lawful processing.

5. How portal and staff records work together

Piyam's staff system remains the authoritative source for applications, appointments, packages, released invoices and documents, and loyalty transactions. The customer portal keeps only the account, permissions and limited customer-safe projections needed to deliver the service. Documents are streamed from private storage and are not copied into the customer account database or cached for offline use.

6. Who we share information with

We use carefully selected processors for cloud hosting, authentication, email, web push, monitoring and abuse prevention. These currently include Supabase and Vercel, plus the sign-in provider you select. Travel suppliers, public authorities or professional advisers may receive information where necessary for your service or required by law. We do not sell personal information.

7. International transfers

Some providers may process information outside the United Kingdom. Where UK data-protection law requires it, we use an adequacy decision, approved contractual safeguards or another lawful transfer mechanism, together with proportionate technical and organisational controls.

8. How long we keep information

We keep customer-portal information only for as long as needed for the purposes described above, security, dispute handling and legal or regulatory duties. Account closure removes customer-side information where permitted, but operational travel, financial and compliance records may remain under separate retention schedules. Short-lived guest sessions and verification challenges expire automatically.

9. Customers aged 16 or 17

Accounts are available from age 16. We use high-privacy defaults for 16- and 17-year-olds: marketing profiling is disabled, financial documents cannot be shared with them through family invitations, and notices are written to be clear and age appropriate. Under-16 dependants are managed by an adult or lead traveller.

10. Security and automated decisions

We use access controls, encryption, short-lived grants, audit events, rate limits and monitoring to protect the portal. No internet service can be guaranteed completely secure, so please report unexpected access promptly. The portal does not make solely automated decisions that produce legal or similarly significant effects about you.

11. Your rights

Depending on the circumstances, UK data-protection law may give you rights to access, correct, erase or restrict information, object to processing, receive portable data, withdraw consent and complain to the Information Commissioner's Office. You can export account data and make correction, link-removal or closure requests from the Account area. We may need to verify your identity before acting on a request.

12. Contact and updates

For privacy questions or rights requests, use the Account area or email privacy@piyamtravel.com. You can also contact your Piyam Travel branch.

We will update this policy when our practices, processors or legal obligations materially change. Please also review the portal Terms of Use.