The short version
JetNova AI (“we”) makes software that travel agencies use to serve their customers: the B2C bot an agency releases to the public, and Buraq B2B, which agencies use between themselves. When you talk to an agency's bot or work in an agency's portal, that agency is responsible for your data and we process it on the agency's instructions. When you visit this website, create an agency account, or write to us, we are responsible.
This website sets no advertising cookies. It loads nothing from third parties unless you ask: a demo video plays from YouTube only when you press play, and Google Analytics counts visits, by default outside Europe and only with your permission in the EEA, UK and Switzerland; you can turn it off with Analytics settings (see cookies). If you use the “Ask JetNova” assistant, what you write is sent to our API and to the assistant’s model provider to compose an answer, and the conversation is kept so a person can follow up; the AI disclosure says what it may and may not do. The products keep only what they need to do the job you asked for, and the assistant never decides on its own to move money, issue a ticket or contact someone else.
Who is responsible
For agency staff accounts, billing and this website: JetNova AI, Office address to be confirmed, Karachi, Pakistan. Write to privacy@jetnova-ai.com.
For travellers, guests and open clients using an agency's B2C bot, and for sub-agent staff using an agency's Buraq B2B: the agency whose brand you see is the controller. We are its processor under the data processing addendum. Requests about your data go to that agency first; if you cannot reach it, write to us and we will pass the request on and help.
What we collect
Information you give
- Contact details: name, email address, phone or WhatsApp number, and a postal address if you provide one.
- Account credentials. Passwords are stored only as one-way hashes; sign-in with Google, Microsoft or LinkedIn gives us your name and email address from that provider and nothing else.
- Conversations with the assistant: text, voice recordings you make, and files you attach (photos, PDFs, scans, text).
- Travel details: passenger names as on passport, dates of birth, passport numbers and expiry, nationality, travel preferences, itineraries and trip companions you add.
- Payment details you enter in a booking, which are passed to the payment provider your agency uses. Full card numbers are not stored by us.
- Documents you submit for review, such as a visa application or a booking from elsewhere, and the record locator, itinerary, passenger names and ticket numbers of a booking an agent imports into Buraq B2B from an airline or GDS system.
- Conversations with the “Ask JetNova” assistant on this website, and the details you leave to be contacted (name, agency, city, WhatsApp number or email, what you sell).
- Feedback, support messages and anything else you choose to send.
Information collected automatically
- Device and browser type, language, IP address, and approximate location derived from it, for security and to render the right agency brand for your hostname.
- Usage inside the products: which screens and tools you open, searches you run, bookings you make and their status.
- Delivery records for email and WhatsApp messages: sent, delivered, bounced, complained.
- On this website, with Google Analytics: pages viewed, how you arrived, and device, browser and approximate location, to count visits and see which pages help. In the European Economic Area, the United Kingdom and Switzerland this runs only with your consent; elsewhere it relies on our legitimate interest in understanding how the site is used, and you can object at any time with Analytics settings at the foot of every page. Google signals and advertising features are off; Google does not store your full IP address for this. See cookies and storage.
- Where you allow it, your device location for tools that need it (Qibla direction, nearby halal food and mosques, planes overhead, local essentials). Location is used at that moment and is not tracked in the background.
What stays in your browser
Session tokens, your theme and text-size preferences, which one-time tips you have dismissed, saved items and drafts are kept in your browser's local storage so the product works between visits. The cookies and storage page lists each item.
How we use it
- To answer you: search fares and rates (including flexible-date searches of up to three days either side of your dates), quote, hold and book through the content your agency has connected, and explain rules and options.
- To run your account: sign you in, keep your trips, bookmarks and preferences, send you one-time codes (by WhatsApp and email, for two-factor sign-in, password resets and, in Buraq B2B, before a ticket is issued, voided, refunded or wallet credit transferred), receipts, e-tickets and reminders. Codes are stored only as one-way hashes and expire within minutes.
- To let the agency serve you: agency staff can read conversations, review drafted replies, take over a chat and see booking timelines. In Buraq B2B, the tenant and the agencies above a sub-agency can see that sub-agency's bookings, wallet and logins, act on a booking on its behalf, and decide its refund requests, as its contract allows; an e-ticket is emailed to a passenger only when an agent asks for it, from the agency's own sender.
- To keep the service safe: detect abuse, enforce rate limits, verify webhooks and senders, audit changes.
- To bill the agency: usage of the assistant is counted against the agency's plan as credits; individual messages are not sold or shared for advertising.
- To improve the product, using aggregate usage; we do not train AI models on your conversations.
The assistant and your data
The assistant is a large language model reached through a routing provider, with tools that call the travel systems your agency connected. The text you write, the relevant parts of your conversation history, and the results of those tool calls are sent to the model to compose an answer. Voice is transcribed by a speech-to-text provider and read back by a text-to-speech provider when you use voice features. These providers are listed on the sub-processors page and process data only to return a result. A flight search entered in the B2C bot's search form is different: the route, dates, travellers and cabin go only to the travel systems, the reply is assembled from their results without a model, and the search is saved in your conversation like a typed message, so it becomes part of the history the assistant can see if you carry on chatting. The AI disclosure explains what the assistant may and may not do.
Who else sees it
- Your agency, which is the controller for its customers and sub-agents.
- Travel suppliers: the airlines, global distribution systems, hotels and other providers needed to fulfil a booking receive passenger and contact details as required by the booking. Their privacy policies govern what they do with them.
- Payment providers chosen by your agency, which receive what is needed to take a payment.
- Service providers that host, deliver messages, route AI requests, transcribe speech, geocode places and serve weather and exchange rates, as listed on the sub-processors page, each bound to process only on our instructions.
- Authorities, when the law requires it, under the government requests policy.
- A successor, if the business is transferred, under the same commitments.
We do not sell personal data and do not share it for advertising.
WhatsApp and email
When you message an agency's number, WhatsApp delivers your message to us through the official WhatsApp Business Platform, which is operated by Meta and subject to Meta's terms and privacy policy. When you email an agency's desk, the message, its headers and attachments are stored privately for that agency, replies are sent through the agency's verified domain or a platform address, and delivery events are recorded. Email is never used to complete a ticket, a payment or a cancellation.
Guests
An agency may let you chat without an account. A guest session is identified by a token in your browser, lasts up to 24 hours, and is not linked to a name. If you later sign in, you can bring the conversation with you. Guest use does not consume the agency's credits and cannot be used for voice, attachments or saved trips.
How long we keep it
- Account data: while the account exists and for a short period afterwards to complete deletion.
- Conversations, trips and bookmarks: while your account exists, or until you delete them; agencies may set shorter retention for their customers.
- Bookings, tickets, invoices and ledger entries: for as long as the agency's accounting and travel-industry record-keeping obligations require.
- Audit logs: for security and dispute resolution, then deleted or anonymised.
- Email and WhatsApp delivery records: with the thread they belong to. One-time codes: until they expire or are used, then only the fact that a challenge was made, for the audit log.
- Guest sessions: expire within 24 hours; signed-in sessions expire after 12 hours of inactivity.
- Website analytics: event-level data is kept in Google Analytics for two months, then only aggregate reports remain; the analytics cookies last up to two years unless you clear them or turn analytics off.
- Conversations with the website assistant and call-back requests: kept for sales follow-up and deleted or anonymised once the enquiry is closed, or on request to the privacy address.
How we protect it
Traffic is encrypted in transit. Content credentials that agencies connect are encrypted at rest and are never displayed back in full. Passwords are stored as salted one-way hashes. Sessions expire. Webhooks from messaging providers are verified by signature and rejected when they fail. Access to production data is limited to people who need it to run the service, and every administrative change is recorded. The security page describes our practices and how to report a problem.
Your rights
Depending on where you live you may have the right to access, correct, delete or receive a copy of your personal data, to restrict or object to processing, and to withdraw consent where processing relies on it. Inside the B2C bot you can update your profile, download your data, and delete your account from the account and security drawer. For anything else, write to your agency, or to privacy@jetnova-ai.com. We answer within one month. You may also complain to your data-protection authority.
International transfers
We operate from Pakistan and use service providers in the United States and the European Union. Where data leaves the country it was collected in, we rely on the providers' standard contractual clauses and equivalent safeguards, and we keep the list of providers and their locations on the sub-processors page.
Children
The products are for adults arranging travel. Passenger details for children and infants are entered by the adult booking for them. We do not knowingly open accounts for anyone under 18; if you believe a child has an account, tell us and we will close it.
Which laws
This policy is written to meet Pakistan's data-protection and electronic-transactions rules and, where they apply to a traveller or an agency, the GDPR, the UK GDPR and comparable laws. Where a law gives you more than this policy does, the law wins.
Changes
When this policy changes we update the date at the top and, for changes that matter, tell agencies by email and travellers inside the product. Earlier versions are available on request.
Contact
JetNova AI, Office address to be confirmed, Karachi, Pakistan. Privacy requests: privacy@jetnova-ai.com. Security reports: security@jetnova-ai.com.