Privacy Policy
Last updated: September 30, 2026
Ratiba (“Ratiba”, “we”, “us”) is an itinerary and proposal platform for tour operators, operated by Brighton Benedict Mboya. This policy explains what information we collect through ratiba.io and our application (together, the “Service”), how we use it, and the choices you have.
Information we collect
Account information. When you sign up, we collect your name, email address, and organization details, either directly or via Google OAuth sign-in.
Client and itinerary data you enter. As an operator using Ratiba, you enter data about your own clients and trips — names, emails, phone numbers, country of residence, itinerary details, and pricing. Where our client-portal feature is enabled, travelers you invite may also submit passport and health information for booking purposes; these fields are encrypted at rest using AES-256-GCM encryption.
Connected mailboxes. If you connect a Gmail account or another mailbox (over IMAP/SMTP) to Ratiba, we store the email conversations you choose to import — sender and recipient addresses, subject, message body, date, and the names, types, and sizes of attachments — along with the credentials needed to keep that mailbox in sync. See Gmail and connected mailboxes below for exactly how this data is handled.
Billing information. Subscription payments are processed by our payment processor, Polar; we do not store your card details ourselves.
Usage data. We collect standard technical data (IP address, browser type, pages visited) to operate and secure the Service.
How we use information
We use the information we collect to provide and improve the Service, process payments, generate itinerary pricing and translations, communicate with you about your account, and comply with legal obligations. We do not sell your personal information or your clients' personal information to third parties.
Gmail and connected mailboxes
Connecting a mailbox is optional. When you connect a Gmail account, Ratiba asks Google for two permissions:
- Read your email (
gmail.readonly) — to import conversations with your clients and show them on that client's record in Ratiba, next to their itineraries, proposals, and invoices, and to pick up new replies on those conversations. - Send email as you (
gmail.send) — so that replies and proposals you send from Ratiba go out from your own address and stay in the same Gmail thread.
What we read and store. You choose which conversations are imported. By default, Ratiba only imports conversations with email addresses that match a client in your Ratiba account, and background sync follows the same rule: new replies on imported conversations, and new conversations with your clients, are added; everything else in your mailbox is left alone. For each imported message we store the sender and recipients, subject, body, date, and attachment names, types, and sizes. Attachment files themselves are not copied to our servers: when you open one, Ratiba fetches it from Gmail at that moment and passes it to your browser. We only read your mailbox — we never delete, archive, label, or mark messages as read.
What we send. Ratiba sends email from your account only when you press send in Ratiba. It never sends messages automatically, in bulk, or without your action.
Who can see it. Imported conversations are visible only to members of your own Ratiba organization. We do not use Gmail data for advertising, do not sell it, do not use it to train artificial intelligence or machine learning models, and do not send it to AI providers. Ratiba staff do not read it, except with your explicit permission for a specific support request, where needed for security purposes such as investigating abuse, or to comply with the law.
Security. The Google access token that keeps your mailbox connected, and the password for any IMAP/SMTP mailbox, are encrypted at rest with AES-256-GCM and never sent to your browser.
Disconnecting and deletion. You can disconnect a mailbox at any time from Emails → Mailboxes. Disconnecting revokes Ratiba's access with Google and permanently deletes that mailbox's stored credentials and every conversation, message, and attachment record imported from it. You can also revoke access at any time from your Google Account's third-party access page.
Ratiba's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Mailboxes connected over IMAP/SMTP (for example cPanel, Zoho, or your own mail server) are handled the same way: we read only the Inbox and Sent folders, never change or delete messages on your server, and a copy of each reply you send from Ratiba is saved to your Sent folder so it appears in your usual mail app.
Third-party service providers
We rely on the following providers to operate Ratiba, each of which processes data only as necessary to provide their service to us:
- Google (OAuth sign-in, Gmail, Places, Translation, and Maps APIs)
- Polar (subscription billing)
- Resend (transactional email delivery)
- Cloudflare (image and file storage)
- Supabase (database hosting)
- Vercel (application hosting)
- Groq (AI-generated day-by-day itinerary copy)
If you choose to connect Ratiba to ChatGPT, Claude, or another AI assistant via our Model Context Protocol (MCP) connector, that assistant can read and write proposal, client, and accommodation data in your Ratiba account on your behalf, subject to the access you grant it. We don't control what that assistant provider does with data during your session — review their own privacy policy before connecting.
Data security
We use industry-standard safeguards to protect your data, including encryption in transit (HTTPS) and at rest for sensitive fields such as passport and health information, mailbox access tokens, and mailbox passwords. No system is perfectly secure, and we cannot guarantee absolute security.
Data retention
We retain account and itinerary data for as long as your account is active, and for a reasonable period afterward to comply with legal, accounting, or reporting requirements. You can request deletion of your account and associated data at any time. Data imported from a connected mailbox is deleted as soon as you disconnect that mailbox, as described above.
Your rights
Depending on where you're located, you may have the right to access, correct, export, or delete your personal information. To exercise any of these rights, contact us at sales@ratiba.io.
Children's privacy
Ratiba is a business-to-business tool for tour operators and is not directed at children. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. We'll update the “Last updated” date above when we do, and material changes will be communicated to account holders.
Contact
Questions about this policy? Email us at sales@ratiba.io.