Privacy Policy and Personal Data Treatment
Last updated: June 7, 2026
1. Identification of the Data Controller
| Field | Details |
|---|---|
| Legal name | Softdev SAS |
| Tax ID (NIT) | 901.684.411-7 |
| Address | Portal de Balcones Mz 2 Ca 6, Calarca, Quindio, Colombia |
| Contact email | privacidad@tripii.co |
| Website | https://tripii.co |
| Contact phone | (+57) 311 222 3780 |
Softdev SAS (hereinafter "Softdev", "we", or "the Platform") is the commercial entity responsible for processing the personal data collected through the Tripii platform (tripii.co) and through the websites of tourism agencies that operate under our technological infrastructure.
1.1. Role of Tourism Agencies
Each tourism agency that uses Tripii acts as a Data Controller with respect to the personal data of its travelers. Softdev SAS acts as a Data Processor by processing such data on behalf of and under the instructions of the agency. This policy applies to the processing that Softdev carries out as a direct controller (platform data, user accounts, technical information) and as a processor (traveler data processed on behalf of the agencies).
2. Applicable Legal Framework
This policy is governed by current Colombian legislation on personal data protection:
- Ley 1581 de 2012 — General Personal Data Protection Regime.
- Decreto 1377 de 2013 (compiled in Decreto 1074 de 2015) — Regulatory Decree of Ley 1581.
- Ley 1266 de 2008 — Financial Habeas Data (where applicable).
- Circular Externa 002 de 2015 of the Superintendencia de Industria y Comercio (SIC).
3. Definitions
- Personal data: Any information linked to or that can be associated with an identified or identifiable natural person.
- Sensitive data: Data that affects the privacy of the data subject or whose misuse may lead to discrimination (e.g., health data, ethnic origin).
- Data subject: A natural person whose personal data is being processed.
- Processing: Any operation performed on personal data (collection, storage, use, circulation, deletion).
- Data Controller: A natural or legal person that decides the purposes and means of data processing.
- Data Processor: A natural or legal person that processes data on behalf of the controller.
- Authorization: Prior, express, and informed consent of the data subject for the processing of their data.
4. Personal Data We Collect
4.1. Traveler Data (Platform Users)
| Category | Specific data | Type |
|---|---|---|
| Identification | Full name, type and number of identity document | General |
| Contact | Email address, phone number | General |
| Access | Password (stored with 12-round bcrypt hash), session tokens | General |
| Demographics | Date of birth, gender | General |
| Booking participants | Emergency contact, EPS (health insurance provider), medical conditions | Sensitive |
| Billing | NIT or cedula, address, tax regime, legal entity name | General |
| Social authentication | Google or Facebook identifier, associated email | General |
4.2. Tourism Agency Data
| Category | Specific data | Type |
|---|---|---|
| Business | Trade name, web domain, corporate email | General |
| Communication | Business WhatsApp number | General |
| Financial | MercadoPago credentials (stored with AES-256-GCM encryption) | Confidential |
4.3. Technical and Usage Data
| Category | Specific data |
|---|---|
| Browsing | Pages visited, time spent (anonymized via Google Analytics) |
| Device | Browser type, operating system, screen resolution |
| Session | Essential authentication cookies (NextAuth) |
4.4. WhatsApp Conversation Data
When you interact with an agency's WhatsApp assistant, we collect:
- WhatsApp phone number
- Content of messages sent and received
- Conversation history (stored per agency)
5. Purposes of Processing
5.1. Purposes for Travelers
We process your personal data for the following purposes:
- Account creation and management: Register your profile, authenticate you, and allow access to the platform.
- Booking processing: Manage the booking of tourism experiences, including participant assignment and coordination with the agency.
- Payment processing: Process experience payments through MercadoPago, issue receipts, and manage refunds.
- Billing: Generate billing documents with the tax information you provide.
- Transactional communication: Send you booking confirmations, reminders, status updates, and notifications related to your purchases.
- WhatsApp assistance: Provide customer service and information about tourism experiences through the AI-powered WhatsApp assistant.
- Security and fraud prevention: Protect your account, detect suspicious activity, and ensure the integrity of transactions.
- Service improvement: Analyze anonymized usage patterns to improve the user experience on the platform.
- Legal compliance: Respond to requests from competent authorities and comply with tax and commercial obligations.
- Emergency contact: In the context of tourism experiences, use the emergency contact and health data you provide for participant safety.
5.2. Purposes for Agencies
- SaaS service provision: Provide the technological infrastructure for operating the agency's marketplace.
- Payment processing: Connect the agency's MercadoPago account to receive traveler payments with a platform commission.
- Subscription billing: Manage the collection of subscription plan fees from the agency.
- Technical support: Handle support requests and resolve technical issues.
- Commercial communications: Inform about new features, updates, and changes to the terms of service.
6. Legal Basis for Processing
The processing of personal data is based on:
- Prior, express, and informed authorization of the data subject (Art. 9, Ley 1581 de 2012): Obtained at the time of registration on the platform or when making a booking.
- Performance of a contract (contractual relationship between the traveler and the agency, and between the agency and Softdev).
- Legal obligation (tax, commercial, and security obligations).
- Legitimate interest (fraud prevention, information security, service improvement).
For the processing of sensitive data (medical conditions, EPS), we request specific and reinforced authorization, informing the data subject that they are not obligated to provide such data and that their refusal does not condition the provision of the main service (except when such data is a safety requirement for the tourism experience).
7. Rights of Data Subjects (ARCO Rights)
In accordance with Article 8 of Ley 1581 de 2012, as a personal data subject you have the following rights:
7.1. Access
Know, update, and consult your personal data held in our databases.
7.2. Rectification
Request the correction of personal data that is inaccurate, incomplete, or outdated.
7.3. Cancellation (Deletion)
Request the deletion of your personal data when:
- You consider that the data is not being processed in accordance with legal principles and duties.
- The data is no longer necessary for the purpose for which it was collected.
- You have revoked the authorization previously granted.
Exceptions: Deletion does not apply when there is a legal or contractual duty to retain the data (e.g., tax records for 5 years).
7.4. Opposition (Revocation of Authorization)
Revoke at any time the authorization granted for the processing of your personal data, provided there is no legal or contractual duty that prevents deletion.
7.5. Right to Be Informed
Request and obtain information about how your personal data has been used.
7.6. Right to Data Portability
Request a copy of your personal data in a structured and commonly used format.
8. Procedure to Exercise Your Rights
8.1. Support Channel
You may exercise your rights through:
- Email: privacidad@tripii.co
- Web form: "My Account" section on tripii.co
8.2. Request Requirements
Your request must include:
- Full name and identity document of the data subject.
- A clear description of the right you wish to exercise.
- Contact information for receiving a response.
- Supporting documents (if applicable).
- If acting through a representative: a power of attorney or document proving the representation.
8.3. Response Deadlines
| Type of request | Maximum deadline |
|---|---|
| Inquiries (access) | 10 business days (extendable by 5 additional business days) |
| Claims (rectification, deletion, revocation) | 15 business days (extendable by 8 additional business days) |
Deadlines are counted from the business day following the receipt of the complete request.
8.4. Unsatisfactory Response
If you consider that your request was not adequately addressed, you may file a complaint with the Superintendencia de Industria y Comercio (SIC) in accordance with the procedure set forth in Article 16 of Ley 1581 de 2012.
9. Data Sharing with Third Parties
We share personal data only with the third parties necessary for the provision of the service, under confidentiality and data protection agreements:
| Third Party | Country | Purpose | Data Shared |
|---|---|---|---|
| Vercel Inc. | United States | Platform hosting and image storage | Technical request data, experience images |
| MercadoPago (MercadoLibre) | Argentina | Payment processing | Name, email, transaction amount, billing data |
| Anthropic (Claude AI) | United States | AI-powered WhatsApp assistant | WhatsApp message content, phone number |
| MailerSend | European Union | Transactional email delivery | Name, email address, email content |
| Meta (WhatsApp Cloud API) | United States | WhatsApp messaging | Phone number, message content |
| Upstash | United States | Technical data caching | No personally identifiable information (PII) |
| Google Analytics | United States | Anonymized usage analytics | Anonymized browsing data (no PII) |
| Google / Facebook | United States | Social authentication (OAuth) | Account identifier, name, email (only if you choose to sign in with these providers) |
9.1. Tourism Agencies
When you make a booking with an agency, we share the data necessary for the provision of the tourism service: name, contact information, participant data, and billing data. The agency is an independent controller for the processing of that data.
10. International Data Transfers
Some of our service providers are located outside Colombia. We perform international data transfers to:
- United States: Vercel, Anthropic, Meta, Google, Upstash.
- Argentina: MercadoPago.
10.1. Safeguards
In accordance with Article 26 of Ley 1581 de 2012 and Decreto 1377 de 2013, these transfers are carried out under the following safeguards:
- Data subject authorization: By accepting this policy, you expressly authorize the international transfer of your data to the countries and providers indicated.
- Contractual clauses: We maintain data processing agreements with each provider that establish equivalent protection obligations.
- Countries with adequate level of protection: Argentina has an adequacy declaration from the SIC. For the United States, we rely on data subject authorization and contractual clauses.
- Minimization: We only transfer the data strictly necessary for each service.
11. Data Retention Periods
| Data type | Retention period | Justification |
|---|---|---|
| User account data | While the account is active + 30 days after deletion request | Service provision |
| Booking and billing data | 5 years from the transaction | Tax obligations (Art. 632, Estatuto Tributario) |
| WhatsApp conversation history | 12 months from the last message | Service quality and dispute resolution |
| Technical and security logs | 6 months | Information security and fraud detection |
| Session cookies | Until logout or 30 days of inactivity | Technical functionality |
| Participant data (health, emergency) | Duration of the experience + 30 days | Participant safety |
Upon expiration of the retention period, data is securely deleted or irreversibly anonymized.
12. Security Measures
We implement appropriate technical and organizational measures to protect your personal data:
12.1. Technical Measures
- Encryption in transit: All communications are conducted over HTTPS/TLS.
- Encryption at rest: Sensitive credentials (MercadoPago tokens) are encrypted with AES-256-GCM.
- Password hashing: Passwords are stored with 12-round bcrypt hash; they are never stored in plain text.
- Secure authentication: JWT tokens with expiration, sessions with secure cookies (HttpOnly, Secure, SameSite).
- Access control: Differentiated roles (Super Admin, Agency Admin, User) with granular permissions.
- Webhook verification: HMAC-SHA256 to verify the authenticity of payment notifications.
- Idempotency: Redis-based mechanisms to prevent duplicate transaction processing.
12.2. Organizational Measures
- Access to personal data is limited to strictly necessary personnel.
- Confidentiality agreements with all team members.
- Periodic review of access permissions.
- Documented procedures for security incident response.
13. Cookies and Tracking Technologies
13.1. Cookies Used
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
next-auth.session-token |
Essential | Keep your session active | Session / 30 days |
next-auth.csrf-token |
Essential | Protection against CSRF attacks | Session |
next-auth.callback-url |
Essential | Redirect after authentication | Session |
13.2. Cookie Policy
We use only essential cookies necessary for the technical operation of the platform (authentication and security). We do not use advertising or profiling cookies.
13.3. Google Analytics
We use Google Analytics with IP anonymization enabled to obtain aggregated usage statistics. We do not collect personally identifiable information through this tool. You can disable Google Analytics by installing the Google Analytics Opt-out Browser Add-on in your browser.
14. Data of Minors
14.1. General Policy
The Tripii platform is not intended for children under 14 years of age. We do not intentionally collect personal data from children under 14 without the prior, express, and informed authorization of their legal representative (parent or guardian).
14.2. Minors Between 14 and 18 Years of Age
Minors between 14 and 18 years of age may register on the platform with authorization from their legal representative. The processing of their data respects their best interest in accordance with Article 7 of Ley 1581 de 2012.
14.3. Minor Participants in Bookings
When an adult registers minor participants in a booking, the adult declares that they have legal representation or authorization to share the minor's data. Sensitive data of minors (medical conditions, EPS) receives reinforced protection.
14.4. Deletion of Minors' Data
If we identify that we have collected data from a child under 14 without authorization, we will proceed to delete it immediately. If you are a parent or guardian and believe that your child under 14 has provided us with data without your consent, please contact us at privacidad@tripii.co.
15. Security Incident Notification
15.1. Notification Commitment
In the event of a security incident that compromises the confidentiality, integrity, or availability of personal data:
- Notification to the SIC: We will inform the Superintendencia de Industria y Comercio within 15 business days following the moment we become aware of the incident.
- Notification to affected data subjects: We will inform the data subjects whose data may have been compromised, indicating:
- Nature of the incident.
- Personal data potentially affected.
- Measures taken to mitigate the impact.
- Recommendations for the data subject to protect their interests.
- Contact information for further details.
15.2. Reporting Channel
If you suspect unauthorized access to your data or any security vulnerability, report it immediately to: seguridad@tripii.co
16. Modifications to This Policy
We reserve the right to modify this policy at any time. When we make substantial changes:
- We will publish the updated version on tripii.co with the new effective date.
- We will notify registered users by email at least 10 business days in advance of the changes taking effect.
- If the changes require new authorization (e.g., new processing purposes), we will request your express consent.
Continued use of the platform after the changes take effect constitutes acceptance of the updated policy, provided that no additional express authorization is required.
17. Supervisory Authority
The competent authority for personal data protection in Colombia is:
Superintendencia de Industria y Comercio (SIC) Delegatura para la Proteccion de Datos Personales
- Address: Carrera 13 No. 27-00, Bogota D.C., Colombia
- Phone: (+57) 601 587 0000
- Website: https://www.sic.gov.co
- Database registry: https://rnbd.sic.gov.co
You may file complaints with the SIC when you believe your habeas data right has been violated, once you have exhausted the inquiry or claim process with us.
18. Authorization Mechanisms
18.1. Platform Registration
When creating an account on Tripii (directly or through Google/Facebook), you are presented with this policy and your express acceptance is required via a checkbox ("I have read and accept the Privacy Policy").
18.2. Booking Process
When completing a booking, specific authorization is requested for:
- The processing of billing data.
- The processing of participant data (including sensitive health data if provided).
- The transfer of data to the corresponding tourism agency.
18.3. WhatsApp
When starting a conversation with an agency's WhatsApp assistant, you are informed that the message content will be processed by artificial intelligence and stored. Continuing the conversation constitutes authorization for such processing.
18.4. Authorization for Sensitive Data
The processing of sensitive data (medical conditions, EPS, emergency contact) is carried out only with express and reinforced authorization. The data subject is informed that:
- They are not obligated to provide this data.
- Their refusal does not prevent general use of the platform.
- This data may be required by the agency for safety during the tourism experience.
19. Contact Information for Data Protection
For any inquiry, request, or claim related to the processing of your personal data:
| Channel | Details |
|---|---|
| privacidad@tripii.co | |
| Email subject | "Personal Data Request - [Your name]" |
| Physical address | Softdev SAS — Cra 54c #143a-96, Plazuela de Moretto casa 6 |
| Business hours | Monday to Friday, 8:00 a.m. to 6:00 p.m. (Colombia time, GMT-5) |
20. Effective Date
This Privacy Policy and Personal Data Treatment enters into effect on June 7, 2026, and will remain in effect as long as Softdev SAS operates the Tripii platform, unless modified in accordance with Section 16.
21. Acceptance
By using the Tripii platform, you declare that:
- You have read and understood this Privacy Policy in its entirety.
- You grant prior, express, and informed authorization for the processing of your personal data in accordance with the purposes described herein.
- You authorize the international transfer of your data to the countries and providers indicated in Section 10.
- You are aware of your rights as a data subject and the mechanisms to exercise them.
Document prepared in compliance with Ley 1581 de 2012 and its regulatory decrees.
Softdev SAS — Cra 54c #143a-96, Plazuela de Moretto casa 6