Privacy Policy
Last updated: Mar 6, 2026
1. Introduction
This Privacy Policy explains how Southern Cross Traveltech PTY LTD ("SCTT", "we", "us", or "our") collects, uses, discloses, stores, and protects personal information in connection with our business-to-business travel technology platform, websites, APIs, integrations, support services, and related services (collectively, the "Service").
SCTT provides technology services to travel businesses, travel agencies, tour operators, destination management companies, corporate travel teams, suppliers, and other business customers ("Customers"). The Service is intended for business use and is not designed for direct consumer use unless expressly stated otherwise.
By accessing or using the Service, you acknowledge that your personal information may be handled as described in this Privacy Policy.
2. Our Role in Processing Personal Information
Our role depends on the context in which personal information is processed.
2.1 Information We Control
We act as the controller or organization responsible for personal information that we collect for our own business purposes, such as:
- Business contact and account administration information;
- Customer relationship and sales information;
- Billing and payment administration information;
- Website, product, security, and usage analytics;
- Support and communications records;
- Compliance, fraud prevention, and legal records.
2.2 Customer Data
When a Customer uploads, submits, connects, or otherwise processes business or travel-related data through the Service, the Customer generally determines why and how that information is used. In those cases, we process the information on the Customer's behalf to provide the Service.
"Customer Data" may include information about:
- Travelers, passengers, guests, or end customers;
- Customer employees, contractors, agents, and authorized users;
- Suppliers, partners, and business contacts;
- Bookings, reservations, itineraries, orders, pricing, inventory, availability, and operational workflows.
Customers are responsible for ensuring that they have the legal right, permission, notice, consent, or other lawful basis required to provide Customer Data to us and to allow us to process it as part of the Service.
3. Information We Collect
The information we collect depends on how you interact with the Service.
3.1 Business and Account Information
We may collect:
- Name;
- Work email address;
- Phone number;
- Job title or role;
- Company name and business address;
- Account username, user ID, and authentication details;
- Subscription, plan, billing, and account administration information;
- Communications you send to us, including support requests and feedback.
3.2 Travel and Operational Data
Customers may submit or synchronize information such as:
- Traveler or passenger names and contact details;
- Booking, reservation, itinerary, or order information;
- Travel dates, destinations, preferences, and service requirements;
- Supplier, agent, partner, or corporate account information;
- Pricing, inventory, availability, and product information;
- Passport, visa, nationality, date of birth, loyalty program, or travel document information where required for travel processing;
- Dietary, accessibility, medical, or other special-service information where voluntarily provided and necessary for a requested travel service.
Customers should provide only the personal information reasonably necessary for the intended travel or business purpose.
3.3 Payment and Billing Information
We may collect billing contact details, invoice information, transaction history, and payment status.
If payments are processed through a third-party payment provider, we do not directly collect or store full payment card numbers or card security codes. Payment information is handled by the applicable payment provider under its own privacy policy and security standards.
3.4 Technical and Usage Information
We may automatically collect:
- IP address;
- Device, browser, and operating system information;
- Log-in time, access logs, and session identifiers;
- Pages viewed, features used, and actions taken within the Service;
- API requests, error logs, diagnostics, and performance data;
- Cookie or similar tracking identifiers where applicable.
3.5 Integration Data
If a Customer connects the Service to a third-party system, such as a booking platform, supplier system, accounting tool, CRM, payment provider, or travel inventory provider, we may receive and process information made available through that integration according to the Customer's configuration.
4. How We Use Personal Information
We use personal information to:
- Provide, operate, maintain, and support the Service;
- Create and manage business accounts and authorized users;
- Process subscriptions, invoices, payments, and account changes;
- Configure and maintain API connections and third-party integrations;
- Process travel, booking, inventory, supplier, reporting, and operational workflows;
- Communicate with Customers about accounts, service updates, support, security, and administrative matters;
- Respond to inquiries and provide customer support;
- Monitor, secure, troubleshoot, and improve the Service;
- Prevent fraud, abuse, unauthorized access, and security incidents;
- Conduct product analytics and improve features and performance;
- Comply with legal, regulatory, tax, accounting, and contractual obligations;
- Establish, exercise, or defend legal claims.
Where permitted by law, we may also use business contact information to send service-related or marketing communications. You may opt out of marketing communications at any time by using the unsubscribe mechanism or contacting us.
5. Traveler and End-Customer Information
The Service may process personal information about travelers, passengers, guests, or other end customers on behalf of our business Customers.
Customers are responsible for:
- Providing appropriate privacy notices to travelers and end customers;
- Obtaining consent or establishing another lawful basis where required;
- Ensuring that traveler information is accurate and up to date;
- Limiting the information submitted to what is reasonably necessary;
- Handling traveler requests, booking communications, cancellations, refunds, and travel service obligations unless otherwise agreed in writing.
If you are a traveler or end customer and have questions about your personal information, you should first contact the travel business or organization that provided your information to the Service. Where appropriate, we may assist the Customer in responding to your request.
6. How We Share Personal Information
We do not sell personal information.
We may share personal information with the following categories of recipients where reasonably necessary:
6.1 Service Providers
Third-party vendors that help us operate the Service, such as providers of:
- Cloud hosting and infrastructure;
- Authentication and identity management;
- Data storage and database services;
- Payment processing and invoicing;
- Customer support and communication tools;
- Security monitoring, logging, and fraud prevention;
- Product analytics and performance monitoring;
- Email delivery and business productivity tools.
These providers are permitted to process personal information only as necessary to provide services to us and are expected to protect it appropriately.
6.2 Customer-Requested Integrations
We may disclose information to third-party systems, travel suppliers, booking channels, payment providers, or business tools when a Customer requests, configures, or authorizes an integration or transfer.
6.3 Business Transfers
We may disclose personal information in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar business transaction, subject to appropriate confidentiality and legal protections.
6.4 Legal and Safety
We may disclose personal information where we believe in good faith that disclosure is necessary to:
- Comply with applicable law, regulation, court order, subpoena, or government request;
- Protect the rights, property, safety, or security of SCTT, Customers, users, travelers, or others;
- Detect, prevent, or investigate fraud, abuse, security incidents, or illegal activity;
- Enforce our agreements or respond to legal claims.
6.5 Aggregated or De-Identified Information
We may use or disclose aggregated or de-identified information that cannot reasonably be used to identify a person, Customer, or traveler.
7. International Data Transfers
Depending on the location of our Customers, users, suppliers, and service providers, personal information may be processed, stored, or transferred outside the country or region where it was collected.
Where required by applicable law, we will take reasonable steps to ensure that cross-border transfers are protected by appropriate safeguards, contractual protections, or other lawful transfer mechanisms.
8. Data Retention
We retain personal information for as long as reasonably necessary to:
- Provide and support the Service;
- Maintain active Customer accounts;
- Perform contractual obligations;
- Maintain security, audit, backup, and business records;
- Comply with legal, tax, accounting, and regulatory requirements;
- Resolve disputes and enforce agreements.
Customer Data is generally retained for the duration of the applicable Customer relationship or agreement, unless the Customer deletes it earlier, requests deletion where applicable, or retention is required by law.
When personal information is no longer reasonably required, we will delete it, de-identify it, or securely archive it in accordance with our retention practices.
9. Data Security
We use commercially reasonable administrative, technical, and organizational measures designed to protect personal information from unauthorized access, loss, misuse, alteration, or disclosure.
These measures may include:
- Encrypted connections;
- Access controls and authentication;
- Role-based permissions;
- Security logging and monitoring;
- Backup and recovery processes;
- Staff confidentiality and security practices;
- Vendor risk management.
No method of transmission or storage is completely secure. Customers and users are responsible for maintaining the confidentiality of their login credentials and for promptly notifying us of suspected unauthorized account access.
10. Cookies and Similar Technologies
We may use cookies, local storage, pixels, software development kits, and similar technologies to:
- Keep users signed in;
- Remember preferences and settings;
- Maintain security;
- Analyze website and Service usage;
- Diagnose errors and improve performance.
Where required by law, we will provide notice or obtain consent before using non-essential cookies or similar technologies. You can usually control cookies through your browser settings, but disabling certain cookies may affect the functionality of the Service.
11. Your Privacy Rights
Depending on where you live and the applicable law, you may have rights regarding your personal information, including the right to:
- Request access to your personal information;
- Request correction of inaccurate or incomplete information;
- Request deletion of your personal information;
- Object to or restrict certain processing;
- Request portability of certain information;
- Withdraw consent where processing is based on consent;
- Opt out of marketing communications;
- Lodge a complaint with a data protection authority or privacy regulator.
To exercise your rights, contact us at info@sctt.net.
If we process your personal information on behalf of a Customer, we may direct your request to the relevant Customer because the Customer controls that information.
We may need to verify your identity or authority before responding to a request. Certain rights may be limited by applicable law, contractual obligations, security requirements, or legitimate business needs.
12. Australian Privacy Rights
Where the Australian Privacy Act 1988 (Cth) applies, we will handle personal information in accordance with applicable requirements, including the Australian Privacy Principles where relevant.
You may contact us to request access to or correction of your personal information, or to make a privacy complaint. We will investigate and respond within a reasonable period.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner or another applicable privacy regulator.
13. Children's Privacy
The Service is intended for business users and is not directed to children. We do not knowingly collect personal information directly from children for our own purposes.
However, Customers may submit travel-related information about minors where necessary to arrange travel services, such as a child passenger's name, age, or travel document details. In those cases, the Customer is responsible for ensuring that it has the required authority, notice, consent, or lawful basis to provide that information.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by posting the updated policy, updating the "Last updated" date, or notifying Customers through the Service or by email where appropriate.
Your continued use of the Service after the updated Privacy Policy takes effect constitutes acknowledgment of the revised policy, except where additional consent is required by law.
15. Contact Us
If you have questions, requests, or complaints about this Privacy Policy or our privacy practices, please contact us at:
Southern Cross Traveltech PTY LTD
Email: info@sctt.net