Legal
Privacy Policy
This policy explains what information Travel Outlook Billing collects, how we use and protect it, how long we keep it, and how to reach us. Travel Outlook Billing is a private, invitation-only application used by Travel Outlook and its authorized staff to prepare and issue client invoices. It is not open to public sign-up.
Last updated: July 29, 2026
Who we are
Travel Outlook Billing (“the Service”) is operated by Travel Outlook (“we”, “us”). The Service is used by our staff to import operational reports, calculate client invoices, and manage the related billing records. Access is granted by invitation only; there is no public registration.
Information we collect
- Account information you give us: your name, display name, email address, and — if you choose to add them — phone number, mailing address, profile links, a short bio, and a profile image.
- Authentication and security information: your password, stored only as a salted cryptographic hash; a history of previous password hashes so that a password cannot be reused; your two-factor authentication secret and recovery codes, stored encrypted, if you enable two-factor authentication; and, where an organization enables sign-in through Google or GitHub, the account identifier that provider returns to us.
- Security and activity logs: records of sign-in attempts (including the email address used, the IP address, browser user-agent string, approximate location derived from the IP address, and whether the attempt succeeded), active session records (IP address and device description), and security events such as password changes and two-factor enrollment.
- Change history: an audit log recording which user changed which record, when, and what the values were before and after the change.
- Access tokens you create: if you connect an AI assistant or another external client to the Service, we store the token you generate, the name you give it, and when it was created, last used, and revoked.
- Operational data imported for billing: the Service imports reports supplied by Travel Outlook and its vendors in order to calculate invoices. These reports include call-detail records (call date and time, the calling and called telephone numbers, campaign and call-type identifiers, agent group, and call handling times), reservation and revenue reports from central reservation systems (reservation and booking counts, revenue amounts, and arrival and booking dates), and payroll and labor exports (agent hours, reimbursements, and expense amounts). Where these reports identify individuals — for example the telephone number of a caller, or the hours worked by an agent — we process that information solely to calculate and support the resulting invoices.
- Files you upload: documents and images you upload, together with their file name, type, and size.
- Technical information: standard web-server information such as IP address and browser type, and, where analytics are enabled for a deployment, information collected through Google Tag Manager.
How we use information
We use it to operate and secure the Service: to authenticate you and keep your account secure, to detect and investigate suspicious activity and abuse, to calculate and issue invoices and support the resulting billing records, to send transactional messages such as invitations, email verification, password resets, and billing notifications, to maintain an audit trail of changes for accountability, and to meet our legal, tax, and accounting obligations. We do not sell your information. We do not share it with advertisers, and we do not use it for advertising or for any purpose unrelated to operating this Service.
QuickBooks Online
The Service can connect to QuickBooks Online to support invoicing.
- The connection is made by an administrator through Intuit’s OAuth 2.0 authorization flow. We never ask for, receive, or store your QuickBooks username or password.
- We request the QuickBooks accounting scope only (
com.intuit.quickbooks.accounting). We do not request the QuickBooks Payments scope, and we do not process payment card data through QuickBooks. - When a QuickBooks company is connected, we store that company’s realm identifier, the company name returned by Intuit, and the OAuth access and refresh tokens. The tokens are encrypted at rest and are not written to application logs.
- We use the connection to read accounting data needed for billing — customer records, invoices, accounts-receivable balances and aging — and to create draft invoices in QuickBooks. Data retrieved from QuickBooks is stored in our database only to the extent needed to prepare, reconcile, and support invoices.
- We do not sell QuickBooks data, we do not use it for advertising or analytics, and we do not share it with any third party other than the infrastructure providers listed below that host the Service on our behalf.
- An administrator can disconnect a QuickBooks company at any time from within the Service. On disconnection we revoke the tokens with Intuit and delete them from our systems, and no further QuickBooks data is retrieved.
How we store and protect information
The Service runs on managed cloud infrastructure and stores data in a PostgreSQL database. All traffic to the Service is encrypted in transit using HTTPS. Passwords are stored only as salted hashes, and two-factor secrets, recovery codes, and QuickBooks tokens are encrypted at rest. Session tokens are issued as HttpOnly cookies so they cannot be read by scripts in your browser. Access to data inside the Service is restricted by role-based permissions, administrative data-browsing tools are restricted to super-administrators, and changes to records are recorded in an audit log. Accounts support optional two-factor authentication, and repeated failed sign-in attempts lock an account. No system can be guaranteed to be perfectly secure, and we do not claim to hold any security certification or third-party compliance attestation.
Service providers we share information with
We share information only with providers that operate parts of the Service for us, and only to the extent they need it:
- Intuit (QuickBooks Online) — accounting and invoicing, where a QuickBooks company has been connected.
- Our cloud hosting and database provider — hosting the application and its database.
- Our email provider (SMTP) — sending transactional email.
- Twilio — sending SMS messages, where SMS is enabled.
- Stripe — subscription billing, where subscription billing is used. Payment card details are entered with and handled by Stripe; we never receive or store full card numbers.
- Our file-storage provider — storing uploaded files. Depending on how a deployment is configured this may be Amazon S3, Google Cloud Storage, Cloudinary, ImageKit, or storage on our own server.
- Google (Tag Manager) — website analytics, where analytics are enabled for a deployment.
We may also disclose information if we are legally required to do so, or where it is necessary to protect our rights or the safety of others.
How long we keep information
We keep information for as long as it is needed to provide and secure the Service, and for as long as we are required to keep it in order to meet our legal, accounting, tax, and audit-record obligations. When information is no longer needed for either purpose, we delete or anonymize it.
- Account and profile information — kept while your account is active, and deleted or anonymized after the account is closed, except where we are required to keep it.
- Billing records, invoices, and the operational reports imported to produce them — kept for the period we are required to retain accounting, tax, and audit records.
- Audit-log entries — retained alongside the billing records they relate to.
- Security and sign-in logs, and session records — kept for as long as they are useful for investigating suspicious activity and abuse.
- QuickBooks access and refresh tokens — revoked with Intuit and deleted from our systems when a company is disconnected. Accounting data retrieved from QuickBooks is deleted once it is no longer needed, unless it forms part of a billing record subject to the record-retention obligations described above.
- Uploaded files — until deleted by a user or until account closure.
Your choices and rights
You can view and update your profile information, manage your active sessions and API tokens, and enable or disable two-factor authentication from within the Service. To request a copy of your information, to correct it, or to ask us to delete it, contact us at the address below; we will respond promptly, and in any event within the period required by applicable law. Some information — in particular billing records and security logs — may need to be retained as described above even after such a request.
Children
The Service is a business tool and is not directed to, or intended for use by, anyone under 18. We do not knowingly collect information from children.
International users
The Service is operated from the United States, and information is stored and processed there.
Changes to this policy
If we change this policy we will update the “Last updated” date at the top of this page. Material changes will also be communicated to account holders.
Contact us
Questions about this policy, or requests concerning your information, can be sent to privacy@traveloutlook.com.