Privacy Policy
The current legal text for Travel Smart public web, member, and mobile experiences.
Last updated: 24 June 2026
Travel Smart respects personal data privacy. This Privacy Policy explains how we collect, use, retain, disclose, and protect personal data when providing the Travel Smart website, mobile app, member features, APIs, push notifications, content, merchants, events, promotions, and related services.
This policy is prepared with reference to Hong Kong's Personal Data (Privacy) Ordinance (Cap. 486) and its Data Protection Principles. It is a general statement and does not replace any Personal Information Collection Statement provided to you when specific personal data is collected.
1. Data We May Collect
We collect personal data by lawful and fair means, and only where needed or reasonably required for purposes connected with Travel Smart. Categories may include:
- Account data: name, email address, password hash, preferred locale, email verification status, account status, login and last login timestamps.
- Social login data: social platform, platform user identifier, social account email, name, and avatar URL.
- Member activity data: bookmarks, itineraries, itinerary dates, stops, share invitation emails, notifications, content reports, suggested locations, suggested links, report details, and related page URLs.
- Device and technical data: push notification tokens, platform, device identifiers, preferred locale, IP address, user agent, referrer, short-link click records, system logs, and security logs.
- Communications and marketing data: enquiries, service emails, verification emails, password reset emails, notifications, event or campaign recipient details, and your marketing communication choices.
- Merchant, event, and content management data: if you act for a merchant, partner, supplier, or content provider, we may collect contact name, title, email, phone, website, social links, media, and cooperation records.
If you provide another person's personal data, such as an itinerary share invitation email or personal data in a content suggestion, you confirm that you are authorized to provide it and have notified the relevant person where required.
2. Whether Data Is Obligatory
Unless stated otherwise when collected, providing personal data is generally voluntary. However, if you do not provide data needed for registration, login, verification, notifications, itinerary sharing, content reports, merchant contact, or security, we may be unable to provide the relevant features, respond to requests, or maintain account security.
3. Purposes of Use
We may use personal data to:
- Create, verify, manage, and protect member accounts.
- Provide articles, travel spots, itineraries, bookmarks, sharing, notifications, search, content reports, merchants, events, promotions, and other service features.
- Process login, social login, email verification, password reset, push notifications, and service messages.
- Moderate member submissions, handle reports, suggested edits, customer service, technical support, and disputes.
- Maintain system security and prevent fraud, abuse, unauthorized access, policy breaches, or service disruption.
- Analyze, test, improve, personalize, and develop the service, including language preferences, content recommendations, feature performance, and usage trends.
- Manage merchants, events, promotions, advertising, content partnerships, email campaigns, and operational records.
- Send marketing communications or conduct direct marketing where we have the required consent or where permitted by applicable law.
- Comply with legal, regulatory, accounting, audit, security, enforcement, or other compliance requirements.
4. Cookies and Similar Technologies
We may use cookies, sessions, local storage, or similar technologies to maintain login status, remember language preferences, protect security, improve user experience, and analyze service performance. You can manage cookies through your browser or device settings, but disabling some technologies may affect login, locale switching, member features, or normal site operation.
5. Direct Marketing
If we intend to use your personal data for direct marketing, we will provide the required information and obtain your consent where required by applicable law. You may ask us at any time to stop using your personal data for direct marketing, and we will not charge you for handling that request.
We will not provide your personal data to third parties for their direct marketing unless we have obtained your required written consent or are otherwise permitted by applicable law.
6. Disclosure and Transfer
We do not sell personal data. Where necessary and subject to appropriate safeguards, we may disclose or transfer personal data to:
- Service providers who support hosting, cloud storage, email, push notifications, search, analytics, security, customer service, payment, communications, development, audit, or operations.
- Social login providers, push notification platforms, external links, merchants, event organizers, or other third-party services you choose to use.
- People you invite to share itineraries with, collaborate with through features, or who can view information because you publish or share content.
- Merchants, partners, or advertisers, but only to handle activities, promotions, enquiries, cooperation, consented marketing, or necessary operational matters.
- Legal, regulatory, enforcement, court, professional adviser, insurer, auditor, or rights and safety protection recipients where required.
- Successors or potential successors in a reorganization, merger, sale, transfer, or business succession involving Travel Smart.
7. Cross-Border Processing
Your personal data may be stored, processed, or transferred outside Hong Kong, especially where we use cloud, email, push notification, analytics, search, development, or support service providers. We will take reasonably practicable steps to require recipients to protect personal data consistently with this policy and applicable law.
8. Retention
We retain personal data only for as long as needed to fulfil the collection purposes, provide the service, handle enquiries or disputes, maintain security and audit records, comply with law, or protect legitimate interests. When data is no longer required, we will delete, anonymize, or archive it by reasonably practicable means.
9. Security
We take reasonably practicable technical and organizational measures to protect personal data against unauthorized or accidental access, processing, erasure, loss, or use. Internet transmission and electronic storage are not absolutely secure, so you should also protect your password, devices, email account, and login tokens.
10. Access and Correction
You may request access to and correction of personal data we hold about you under Hong Kong's Personal Data (Privacy) Ordinance. You may also update some data in your member account. We may need to verify your identity and may charge a reasonable fee where permitted by law.
11. Children and Minors
The service is not specifically directed to children. If you are under the legal age of majority in your location, you should use the service with the consent and supervision of a parent or guardian.
12. Updates
We may update this Privacy Policy from time to time. The updated version will be posted on this page and will be effective according to the date shown above. For material changes, we may notify you through the website, app, email, or other reasonable means.
13. Contact
To request access or correction, withdraw direct marketing consent, or make a privacy enquiry or complaint, please contact us through the contact channels shown on the Travel Smart website or app, or email travelsmart@alpha-labs.app. Before production launch, the actual responsible contact details should be inserted for Hong Kong privacy compliance and operational handling.