Privacy Policy
This Privacy Policy explains how Jungle CRM (“we”, “us”, or “the Platform”) collects, uses, stores, and protects information when you access or use our travel customer relationship management software. The Platform is intended for authorized staff of travel companies and their partners who manage leads, quotations, bookings, payments, and related operations.
1. Scope
This policy applies to users who sign in to Jungle CRM with a company-issued account, and to limited public features such as password reset, quotation preview links, and payment receipt pages that may be shared with customers or agents. If you are a traveler or customer whose data is stored in the Platform, your travel company (not Jungle CRM alone) is typically the data controller for that information.
2. Information we collect
Account and authentication data
- Name, email address, role, and profile details for authorized users
- Login credentials (passwords are stored in hashed form)
- Session cookies and security tokens used to keep you signed in
- Password reset and first-login setup activity
CRM and business data you enter
Depending on how your organization uses the Platform, this may include lead and customer contact details, travel preferences, itineraries, quotations, invoices, vouchers, tasks, notes, supplier records, payment records, and operational documents.
Guest and traveler information
- Names, contact details, and travel dates
- Identity documents such as passport or ID numbers when recorded
- Uploaded files (for example passport copies, visas, PAN, or other guest documents)
- Visa, insurance, hotel, safari, transfer, and related booking details
Communications and integrations
- Emails sent through or logged in the Platform
- Data imported from or synced with connected services (such as Zoho CRM or Facebook lead integrations)
- Webhook and import logs related to third-party integrations
- Call or telephony metadata if your organization enables PBX or auto-call features
Technical and usage data
- IP address, browser type, device information, and request logs
- Timestamps of sign-in, data changes, and system events needed for security and auditing
- Error and performance data required to operate and secure the service
3. How we use information
We use collected information to:
- Provide, operate, and maintain the CRM and its features
- Authenticate users and enforce role-based access controls
- Manage leads, quotations, invoices, payments, documents, and post-sale operations
- Send transactional emails (such as password reset or supplier communications configured by your team)
- Sync or import data from integrations your administrators enable
- Generate reports, dashboards, and exports authorized by your organization
- Protect against fraud, abuse, and unauthorized access
- Comply with legal obligations and respond to lawful requests
4. Legal bases (where applicable)
Where data protection laws require a legal basis, we rely on: performance of a contract with your organization; legitimate interests in operating a secure business platform; compliance with legal obligations; and, where required, consent (for example for certain marketing integrations configured by your administrator).
5. Cookies and similar technologies
We use essential cookies to maintain authenticated sessions and support core security features. These cookies are necessary for the Platform to function and are not used for third-party advertising. You can control non-essential cookies through your browser settings, but disabling session cookies will prevent you from staying signed in.
6. Sharing and disclosures
We may share information:
- Within your organization — according to roles and permissions assigned by administrators (for example Admin, Sales, Operations, or Accountant access levels)
- With service providers — such as cloud hosting, database providers, email (SMTP) services, and infrastructure needed to run the Platform
- With integrations you enable — such as Zoho CRM, Facebook lead tools, payment or telephony providers, and other third parties configured by your organization
- With customers or agents via share links — when your team generates quotation previews, payment receipts, or similar public links protected by tokens or identifiers
- For legal reasons — when required by law, regulation, court order, or to protect rights, safety, and security
We do not sell personal information.
7. Data retention
We retain information for as long as your organization uses the Platform and as needed to provide services, resolve disputes, enforce agreements, and meet legal or accounting requirements. Retention periods for leads, financial records, and uploaded documents may be determined by your company's policies and applicable travel or tax regulations.
8. Security
We implement administrative, technical, and organizational measures designed to protect information, including access controls, password hashing, encrypted connections in production, rate limiting, and role-based permissions. No method of transmission or storage is completely secure; please use strong passwords and report suspected unauthorized access to your administrator immediately.
9. International transfers
Your data may be processed in countries where our infrastructure or service providers operate. Where required, appropriate safeguards will be used for cross-border transfers.
10. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or export personal information, or to object to certain processing. Authorized users should contact their organization's Jungle CRM administrator. Travelers and customers should contact the travel company that collected their data. We will assist controllers in responding to valid requests where applicable.
For Facebook / Instagram connection data stored by Jungle CRM, see our User Data Deletion instructions (also used for Meta App Dashboard compliance).
11. Children
The Platform is a business tool and is not directed at children under 16. Guest records for family travel may include minor travelers as part of a booking managed by an adult customer or authorized agent.
12. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will reflect the latest version. Continued use of the Platform after changes become effective constitutes acceptance of the revised policy.
13. Contact
For privacy questions about your organization's use of Jungle CRM, contact your company administrator or the data protection contact designated by your travel company. For Platform-related inquiries, reach out through the support channel provided by your organization's Jungle CRM license holder.