Privacy Policy
How we collect, use, and share personal information in connection with the Sigtrip service.
SigTrip, Inc.(“SigTrip”, “we”, “us”) operates technology that enables users to make direct hotel reservations through AI-powered conversational platforms and automated software agents (“AI Agents”). This Privacy Policy explains how we collect, use, and share personal information in connection with the SigTrip service.
1. Information We Collect
We collect only the information necessary to enable hotel reservations and related functionality.
a. Information Provided by Users
When a user requests or completes a reservation, we may collect:
- First name and last name
- Email address
- Phone number (in international format)
- Reservation details (hotel, dates, room type, number of guests, and special requests)
b. Booking Guarantee
To guarantee a reservation, users are asked to enter credit card details through a secure link generated and operated by the applicable Supply Provider or hotel systems.
SigTrip does not collect, store, or process payment card information.
c. Usage and Technical Information
We may collect limited technical and operational information such as:
- Interaction data related to booking and cancellation requests
- Reservation identifiers and timestamps
This information is used solely to operate, maintain, and improve the SigTrip service.
d. Analytics and Cookies
On our websites we use first-party product analytics to understand how visitors use the site so we can maintain and improve it. This is set and read as a first-party cookie on the sigtrip.com domain and may record pages viewed, links and buttons clicked, approximate location derived from IP address, and device and browser type. We may also capture anonymized session activity (session replay) to diagnose usability and errors; text you type into form fields is masked and is not recorded.
This analytics data is processed in the United States and is used only to operate and improve the SigTrip service. We do not use it for third-party advertising, and we do not sell it. You can limit or block these cookies through your browser settings; doing so does not affect your ability to use the site.
2. How We Use Information
We use personal information only to:
- Enable and transmit hotel reservation and cancellation requests
- Provide booking confirmations and related communications
- Respond to user inquiries related to reservations
- Maintain, operate, and improve the SigTrip service
- Comply with legal and regulatory obligations
SigTrip does not use personal information for advertising or marketing purposes.
SigTrip processes personal information only where necessary to perform a contract requested by the user, to comply with legal obligations, or for legitimate interests related to operating the service, in accordance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and UK GDPR.
3. How Information Is Shared
We share personal information only as necessary to operate the service.
a. Hotels
Reservation information is shared directly with the hotel to enable the booking and stay.
b. Supply Providers
Information may be shared with third-party infrastructure and connectivity providers (“Supply Providers”) that support reservation transmission, booking confirmation, and reservation guarantees.
c. Legal Requirements
We may disclose information if required to do so by law, regulation, or valid legal process.
SigTrip does not sell personal information.
4. Data Security
SigTrip uses reasonable administrative and technical measures designed to protect personal information. Credit card information is handled exclusively by secure third-party systems operated by Supply Providers or hotels.
5. Data Retention
We retain personal information only for as long as necessary to:
- Support reservations and related communications
- Comply with legal, accounting, or reporting obligations
- Prevent and detect fraud and abuse of the service, as described in §5a
5a. Retention after account deletion
When a user deletes their SigTrip account, we delete their account and the data associated with it. We keep one limited record of the deletion itself, separately from the deleted account, so that we can detect and prevent abuse of the service — for example, repeatedly creating and deleting accounts to obtain trials or other introductory offers.
That record contains only:
- An irreversible, secret-keyed fingerprint of the email address, which lets us recognise an address we have seen before but cannot be used to recover the address or to produce a list of people who have deleted accounts
- The domain part of the email address (for example, the part after the “@”)
- The date of deletion, and a small set of non-content usage measures such as how long the account existed, which plans it held, and how many organizations, properties and scans it had
It contains no reservation or scan content, no payment details, and no information about other users. We keep this record for 24 months from the date of deletion, after which it is automatically and permanently erased. We use it only to prevent and detect fraud and abuse, and never to restore, re-link or re-identify a deleted account.
Where the EU or UK GDPR applies, we rely on our legitimate interests in preventing fraud and abuse (Art. 6(1)(f)) and on the exceptions to erasure in Art. 17(3). Where the CCPA/CPRA applies, we rely on the exception permitting retention to detect security incidents and protect against fraudulent or illegal activity. Users may contact us using the details below to ask about this record.
6. International Users
SigTrip is a U.S.-based company. By using the service, users acknowledge that their personal information may be processed in the United States or other jurisdictions where SigTrip or its service providers operate, which may have data protection laws different from those in the user's country of residence.
7. User Rights
Depending on applicable law, including the EU GDPR and UK GDPR, users may have the right to:
- Access, correct, or delete their personal information
- Object to or restrict certain processing
- Request data portability
- Withdraw consent where processing is based on consent
These rights are not absolute. In particular, when a user deletes their account we keep the one limited fraud-prevention record described in §5a above, on a separate legal basis from the account data itself.
Requests may be submitted by contacting SigTrip using the contact details below. Users may also have the right to lodge a complaint with a supervisory authority.
8. Use Within AI Platforms
SigTrip operates within third-party AI-powered conversational platforms. User interactions may also be subject to the privacy policies and data practices of the applicable AI platform provider.
SigTrip does not control and is not responsible for how such AI platform providers process personal information.
9. Third-Party Services
SigTrip relies on third-party services, including hotels and Supply Providers, to enable reservations. This Privacy Policy does not apply to the privacy practices of those third parties, which are governed by their own privacy policies.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be effective when posted.
11. Contact Us
For questions about this Privacy Policy or SigTrip's data practices, contact:
SigTrip, Inc.
Email: privacy@sigtrip.com