Privacy Policy

Last updated: August 22, 2026

Ratiba (“Ratiba”, “we”, “us”) is an itinerary and proposal platform for tour operators, operated by Brighton Benedict Mboya. This policy explains what information we collect through ratiba.io and our application (together, the “Service”), how we use it, and the choices you have.

Information we collect

Account information. When you sign up, we collect your name, email address, and organization details, either directly or via Google OAuth sign-in.

Client and itinerary data you enter. As an operator using Ratiba, you enter data about your own clients and trips — names, emails, phone numbers, country of residence, itinerary details, and pricing. Where our client-portal feature is enabled, travelers you invite may also submit passport and health information for booking purposes; these fields are encrypted at rest using AES-256-GCM encryption.

Billing information. Subscription payments are processed by our payment processor, Polar; we do not store your card details ourselves.

Usage data. We collect standard technical data (IP address, browser type, pages visited) to operate and secure the Service.

How we use information

We use the information we collect to provide and improve the Service, process payments, generate itinerary pricing and translations, communicate with you about your account, and comply with legal obligations. We do not sell your personal information or your clients' personal information to third parties.

Third-party service providers

We rely on the following providers to operate Ratiba, each of which processes data only as necessary to provide their service to us:

  • Google (OAuth sign-in, Places, Translation, and Maps APIs)
  • Polar (subscription billing)
  • Resend (transactional email delivery)
  • Cloudflare (image and file storage)
  • Supabase (database hosting)
  • Vercel (application hosting)
  • Groq (AI-generated day-by-day itinerary copy)

If you choose to connect Ratiba to ChatGPT, Claude, or another AI assistant via our Model Context Protocol (MCP) connector, that assistant can read and write proposal, client, and accommodation data in your Ratiba account on your behalf, subject to the access you grant it. We don't control what that assistant provider does with data during your session — review their own privacy policy before connecting.

Data security

We use industry-standard safeguards to protect your data, including encryption in transit (HTTPS) and at rest for sensitive fields such as passport and health information. No system is perfectly secure, and we cannot guarantee absolute security.

Data retention

We retain account and itinerary data for as long as your account is active, and for a reasonable period afterward to comply with legal, accounting, or reporting requirements. You can request deletion of your account and associated data at any time.

Your rights

Depending on where you're located, you may have the right to access, correct, export, or delete your personal information. To exercise any of these rights, contact us at sales@ratiba.io.

Children's privacy

Ratiba is a business-to-business tool for tour operators and is not directed at children. We do not knowingly collect personal information from children.

Changes to this policy

We may update this policy from time to time. We'll update the “Last updated” date above when we do, and material changes will be communicated to account holders.

Contact

Questions about this policy? Email us at sales@ratiba.io.