Privacy Policy
Last updated: August 22, 2026
Ratiba (“Ratiba”, “we”, “us”) is an itinerary and proposal platform for tour operators, operated by Brighton Benedict Mboya. This policy explains what information we collect through ratiba.io and our application (together, the “Service”), how we use it, and the choices you have.
Information we collect
Account information. When you sign up, we collect your name, email address, and organization details, either directly or via Google OAuth sign-in.
Client and itinerary data you enter. As an operator using Ratiba, you enter data about your own clients and trips — names, emails, phone numbers, country of residence, itinerary details, and pricing. Where our client-portal feature is enabled, travelers you invite may also submit passport and health information for booking purposes; these fields are encrypted at rest using AES-256-GCM encryption.
Billing information. Subscription payments are processed by our payment processor, Polar; we do not store your card details ourselves.
Usage data. We collect standard technical data (IP address, browser type, pages visited) to operate and secure the Service.
How we use information
We use the information we collect to provide and improve the Service, process payments, generate itinerary pricing and translations, communicate with you about your account, and comply with legal obligations. We do not sell your personal information or your clients' personal information to third parties.
Third-party service providers
We rely on the following providers to operate Ratiba, each of which processes data only as necessary to provide their service to us:
- Google (OAuth sign-in, Places, Translation, and Maps APIs)
- Polar (subscription billing)
- Resend (transactional email delivery)
- Cloudflare (image and file storage)
- Supabase (database hosting)
- Vercel (application hosting)
- Groq (AI-generated day-by-day itinerary copy)
If you choose to connect Ratiba to ChatGPT, Claude, or another AI assistant via our Model Context Protocol (MCP) connector, that assistant can read and write proposal, client, and accommodation data in your Ratiba account on your behalf, subject to the access you grant it. We don't control what that assistant provider does with data during your session — review their own privacy policy before connecting.
Data security
We use industry-standard safeguards to protect your data, including encryption in transit (HTTPS) and at rest for sensitive fields such as passport and health information. No system is perfectly secure, and we cannot guarantee absolute security.
Data retention
We retain account and itinerary data for as long as your account is active, and for a reasonable period afterward to comply with legal, accounting, or reporting requirements. You can request deletion of your account and associated data at any time.
Your rights
Depending on where you're located, you may have the right to access, correct, export, or delete your personal information. To exercise any of these rights, contact us at sales@ratiba.io.
Children's privacy
Ratiba is a business-to-business tool for tour operators and is not directed at children. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. We'll update the “Last updated” date above when we do, and material changes will be communicated to account holders.
Contact
Questions about this policy? Email us at sales@ratiba.io.