Tifa Travels & Tours respects your privacy and is committed to protecting your Personal Data. This Privacy Policy describes the Personal Data we collect, the reasons we collect it, how we use, share and protect it, and the rights and choices available to you.
Please read it carefully. If you do not agree with it, please do not use the Services.
1. Definitions and interpretation
In this Privacy Policy, “Tifa Travels”, “we”, “us” and “our” mean Tifa Travels & Tours, of 31 Oba Akran Ave, Ikeja, Lagos 100282, Nigeria.
“You” and “your” mean any person who visits or uses our website, creates an account, makes or manages a booking, or otherwise communicates with us, including a person on whose behalf a booking is made.
“Personal Data” means any information relating to an identified or identifiable individual, and includes anything described as personal data, personal information or similar under applicable data protection law.
“Services” means our website, accounts, flight search and booking, ticketing, payment facilitation, agent and partner tools, customer support, newsletters, and any other travel-related service we provide.
“Applicable Law” includes the Nigeria Data Protection Act 2023, regulations and directions issued by the Nigeria Data Protection Commission, and, where it applies to you, the data protection laws of the country in which you are located.
Headings are for convenience only and do not affect interpretation. The words “including” and “includes” are not limiting.
2. Scope and acceptance
This Privacy Policy explains how we collect, use, disclose, store and otherwise process Personal Data in connection with the Services. It forms part of our Terms of Service and should be read together with our Cookie Policy and Refund Policy.
By using the Services, creating an account or making a booking, you acknowledge that you have read and understood this Privacy Policy. Where Applicable Law requires your consent for a particular use of your Personal Data, we will ask for it separately and you may withdraw it at any time.
This Privacy Policy does not apply to third-party websites, airlines, payment providers or other services that we link to or work with. Those parties are responsible for their own privacy practices and we encourage you to review their policies.
3. Who is responsible for your data
Tifa Travels & Tours is the data controller of the Personal Data processed through the Services, except where we act as a processor on behalf of a business customer, in which case that customer’s privacy terms also apply.
Where you make a booking, airlines, global distribution systems and other travel suppliers receive your Personal Data and process it for their own purposes as independent controllers. We are not responsible for their processing.
You can contact us about privacy matters using the details in the section headed “Contact us” below.
4. Personal Data we collect
Information you give us. This includes:
- identity and contact details, such as your name, email address, telephone number, and postal address;
- account credentials, such as your email and a password, which we store only in hashed form;
- traveller details for each passenger, such as names as shown on travel documents, date of birth, gender, nationality, and frequent-flyer numbers;
- travel document details, such as passport number, issuing country, and issue and expiry dates, where an airline, authority or destination requires them;
- special-service requests, such as meal, mobility or medical-assistance needs, which may reveal information about health or religion. We process these only to arrange the service you request;
- booking, itinerary, ticketing and fare information, and your travel history with us;
- messages, enquiries, feedback and survey responses you send us, including call and chat records; and
- newsletter and marketing preferences.
Payment information. Payments are handled by third-party payment processors. We receive confirmation of the transaction, its status, amount, reference, and limited details such as the type of payment method. We do not receive or store your full card number, CVV or PIN.
Information collected automatically. When you use the Services we collect technical data, including your IP address, approximate location derived from it, browser type and version, device identifiers, operating system, language, referring pages, pages and features used, search queries, date and time of access, and error and diagnostic logs. We collect much of this using cookies and similar technologies described in our Cookie Policy.
Information from other sources. We may receive Personal Data from airlines and booking systems (for example ticket numbers and booking status), from payment processors, from the person who made a booking on your behalf, from agents or partners acting for you, and from fraud-prevention and identity-verification providers.
If you give us Personal Data about another person, such as a fellow traveller, you confirm that you are authorised to do so and that you have informed them of this Privacy Policy.
You are not obliged to give us Personal Data, but we cannot make or manage a booking if the information that an airline, authority or Applicable Law requires is missing.
5. How and why we use Personal Data
We use Personal Data for the following purposes, relying on the lawful bases shown:
- To provide the Services, including searching fares, making, ticketing, changing, cancelling and refunding bookings, and sending confirmations, e-tickets and itinerary updates (performance of a contract);
- To process payments, detect and prevent fraud, and recover amounts owed (performance of a contract; legitimate interests; legal obligation);
- To manage your account, authenticate you, and keep it secure, including through two-factor authentication where offered (performance of a contract; legitimate interests);
- To provide customer support and handle complaints and claims (performance of a contract; legitimate interests);
- To send service communications, such as schedule changes, payment reminders and security alerts (performance of a contract; legitimate interests);
- To send marketing, such as newsletters and offers, where you have subscribed or where permitted by law (consent; legitimate interests). You may opt out at any time;
- To operate, analyse and improve the Services, including testing, troubleshooting, measuring performance, and developing new features (legitimate interests; consent where required for non-essential cookies);
- To secure our systems and keep audit records of administrative actions (legitimate interests; legal obligation);
- To comply with law, including tax, accounting, anti-money-laundering, sanctions, aviation-security and immigration requirements, and to respond to lawful requests from authorities (legal obligation); and
- To establish, exercise or defend legal claims (legitimate interests; legal obligation).
We will not use your Personal Data for a purpose that is incompatible with those above without telling you and, where required, obtaining your consent.
We may use automated tools, such as search ranking, fraud screening and rate limiting, to operate the Services. We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing, other than the automatic refusal of transactions that our fraud controls identify as high risk, which you may ask us to review.
6. Sensitive Personal Data
Some information you give us, such as a request for wheelchair assistance or a special meal, may amount to sensitive Personal Data. We process it only where you have asked us to arrange the related service, where you have given your consent, or where Applicable Law otherwise permits.
To fulfil your request we must pass this information to the relevant airline or supplier. If you do not want it shared, please do not include it in your booking.
7. Disclosure of Personal Data
We do not sell your Personal Data. We disclose it only as described in this section, and only to the extent necessary for the purpose concerned.
Airlines, travel suppliers and booking systems. To make and manage your booking we must transmit traveller, contact and travel-document data to the operating and marketing airlines, to global distribution systems and flight-content aggregators, and to other suppliers such as hotels, transfer providers and insurers.
Payment processors and financial institutions that authorise, process, settle and reconcile payments and refunds, and that carry out fraud and risk checks.
Service providers that act on our instructions, such as providers of cloud hosting, databases, email and SMS delivery, analytics, error monitoring, customer-support tools and security services. They are bound by contract to protect Personal Data and use it only to provide services to us.
Agents and partners. Where you book through an authorised travel agent or business partner, that party can see the bookings it makes and the related traveller details, and is responsible for its own handling of that data.
Authorities. We may disclose Personal Data to immigration, customs, border-control, aviation-security, tax, law-enforcement and regulatory bodies, in Nigeria and elsewhere, where required by law, by an airline’s or destination’s entry requirements, or in response to a valid legal process.
Professional advisers, auditors and insurers that need access to advise us or to assess our compliance, under duties of confidentiality.
Corporate transactions. If we are involved in a merger, acquisition, financing, reorganisation or sale of assets, Personal Data may be disclosed to the other parties and their advisers and transferred to the successor, which will be bound by this Privacy Policy or notify you of changes.
We may also disclose Personal Data where you ask us to, or with your consent, and in aggregated or de-identified form that cannot reasonably identify you.
8. International transfers
Travel is international by nature. Airlines, booking systems and our service providers may be located in, or access Personal Data from, countries other than Nigeria, including countries whose data protection laws differ from those of your country.
Where we transfer Personal Data outside Nigeria, we do so in accordance with Applicable Law. We rely on the transfer being necessary to perform your booking, on your consent, on adequacy decisions, or on appropriate safeguards such as contractual protections, as the case may be.
Data that we must give an airline or authority in order to carry you is transferred to that party and is then subject to its own legal framework, over which we have no control.
10. Retention
We keep Personal Data only for as long as it is needed for the purposes for which it was collected, including to provide the Services, to satisfy legal, tax, accounting and reporting requirements, to resolve disputes and to enforce our agreements.
Booking, payment and refund records are retained for the periods required by Nigerian tax, accounting and company law and by the rules of the airline and payment industries. Account data is kept while your account is active and for a reasonable period afterwards. Marketing preferences are kept until you opt out.
When Personal Data is no longer needed, we delete or irreversibly anonymise it, except where we must keep it for a legal reason or to establish, exercise or defend a legal claim.
11. Security
We maintain technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and access. These include encryption of data in transit, hashing of passwords, role-based access controls, optional two-factor authentication for staff and agents, rate limiting, and logging of administrative activity.
No method of transmission or storage is completely secure and we cannot guarantee absolute security. You are responsible for choosing a strong, unique password, for keeping your credentials confidential, and for notifying us immediately of any suspected unauthorised access to your account.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Nigeria Data Protection Commission and, where required, affected individuals, within the periods set by Applicable Law.
12. Your rights
Subject to Applicable Law and its exceptions, you have the right to:
- be informed about how we use your Personal Data, as we do in this Privacy Policy;
- request access to the Personal Data we hold about you and a copy of it;
- request correction of inaccurate or incomplete Personal Data;
- request deletion of Personal Data that we no longer need or are not entitled to keep;
- restrict, or object to, our processing of your Personal Data, including for direct marketing;
- receive Personal Data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal; and
- not be subject to a decision based solely on automated processing that significantly affects you, in the circumstances set out in Applicable Law.
To exercise any of these rights, contact us using the details below. We may need to verify your identity before acting, and we will respond within the time required by Applicable Law. We may decline a request, in whole or in part, where law permits or requires, for example where it would reveal another person’s Personal Data or where we must keep records for legal reasons.
Deleting or restricting data we need to make or manage a booking may mean we can no longer provide some or all of the Services.
You also have the right to lodge a complaint with the Nigeria Data Protection Commission or, where it applies, with the supervisory authority in your country. We would appreciate the chance to address your concerns first.
13. Marketing communications
If you subscribe to our newsletter or are otherwise entitled to receive marketing, we may email you offers, travel news and promotions. You can unsubscribe at any time using the link in any message or by contacting us.
Opting out of marketing does not stop service messages that we must send about your account or bookings.
14. Children
The Services are not directed at children, and you must be at least 18 to create an account or make a booking. We collect the Personal Data of a child, such as a minor passenger’s name, date of birth and passport details, only when a parent or legal guardian provides it to book travel for the child, and we use it only for that purpose.
If you believe a child has given us Personal Data without the consent of a parent or guardian, contact us and we will take appropriate steps to delete it.
15. Third-party links and services
The Services may contain links to, or embed content from, third-party websites and services, including social media platforms. Once you leave our site or interact with embedded content, the third party’s own privacy policy applies. We do not control and are not responsible for those practices.
16. Bookings made for other people and group bookings
Many bookings are made by one person for several travellers, such as family members, colleagues, friends or members of a group. Where you make a booking for someone else, you will need to give us that person’s Personal Data, including the details that an airline or authority requires for each traveller.
By doing so, you confirm that you are entitled to provide that information, that you have told each traveller how their information will be used, and that you have obtained any consent that the law requires. Where you are acting for a company, club, church, school or other organisation, you also confirm that you have the authority of the organisation and of each traveller to do so.
We will usually send booking confirmations, e-tickets, schedule changes and payment communications to the person who made the booking, and, where a separate email address has been provided for a traveller, to that traveller as well. The person who made the booking is responsible for passing on relevant information to the other travellers.
Where a traveller contacts us to ask about a booking made by someone else, we may need to verify their identity and may be unable to share booking information or make changes without the authority of the person who made the booking, in order to protect everyone’s privacy and security.
17. Travel agents, corporate customers and business partners
We work with authorised travel agents, corporate customers and business partners who may use our systems to search for and book travel for their own customers. Where this happens, the agent or partner decides why and how the personal data of its customers is collected and used, and is responsible for informing its customers and meeting its own legal obligations.
Where you make a booking through an agent or partner, that agent or partner can see the booking and the traveller information that it entered, and its own privacy policy will also apply to the way it handles your data. We encourage you to read it.
Where we receive Personal Data from an agent or partner, we use it to make and service the booking and for the other purposes set out in this Privacy Policy, and we protect it in the same way as the data we collect directly.
Business customers and partners who access our platform, including through an application programming interface, are required to use it only for lawful purposes, to keep their credentials secure, and to handle the Personal Data they obtain in accordance with applicable law.
18. Our legitimate interests
Where we rely on our legitimate interests as the lawful basis for processing, we have considered whether those interests are overridden by your rights and freedoms, and we use your data in ways that you would reasonably expect and that have a minimal impact on your privacy.
Our legitimate interests include operating, administering and securing our business and our website; preventing and detecting fraud, abuse and other crime; protecting our customers, staff and property; understanding how our services are used so that we can improve them; promoting our services to existing customers and people who have shown interest in them; keeping accurate business records; and establishing, exercising or defending legal claims.
You have the right to object to processing based on our legitimate interests, as described in the section on your rights. If you object, we will stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing is needed for legal claims.
19. Accuracy of your information
We take reasonable steps to keep Personal Data accurate and up to date, but we rely on you to give us correct information. Please check that every detail you provide, especially names, dates of birth, passport numbers and contact details, is accurate and matches your travel documents.
Inaccurate information can lead to denied boarding, delays, additional fees charged by airlines, or booking problems that we may be unable to correct. We are not responsible for the consequences of incorrect information that you have supplied.
If your details change, please update your account or contact us so that we can correct our records. Where we hold information in a booking that has already been ticketed, an airline may charge a fee for corrections, and some corrections may not be possible.
20. Communications and records of our interactions
When you contact us by email, telephone, messaging, social media or any other channel, we may keep a record of the communication and of any action taken, so that we can respond to you properly, train our staff, resolve disputes, and maintain evidence of the advice and services we have provided.
If we record or monitor telephone calls, we will tell you at the start of the call. We do not use call records for any purpose other than those described in this Privacy Policy.
Please do not send us information that we have not asked for, such as payment card numbers, passwords or sensitive information, through email or open messaging. If you do, we may delete it, and we cannot guarantee its security in transit.
21. Analytics, monitoring and service improvement
We analyse how our website and services are used, including which pages and search features are most popular, where users encounter difficulties, and how quickly pages load, so that we can improve their reliability, design and usefulness.
Where possible, we use aggregated, de-identified or anonymised information for this purpose. Aggregated and anonymised information is not Personal Data, and we may use and share it for any lawful business purpose, for example to report on travel trends or to improve our services.
We also keep system logs and records of administrative activity, so that we can investigate security incidents, resolve technical faults and demonstrate that our systems are being used properly.
22. Additional information about how we protect your data
We limit access to Personal Data to staff, agents and service providers who need it to do their jobs, and who are subject to duties of confidentiality. Access rights are based on role and are reviewed when roles change.
We use secure connections to transmit information between your browser and our servers, and we apply protections to our infrastructure, including authentication controls, request limits and monitoring designed to detect abuse.
Our staff and authorised agents may be required to use a second authentication factor when signing in to administrative tools. If you are a customer, we recommend that you use a strong password that you do not use for other services, that you do not share it with anyone, and that you sign out when using a shared device.
We review our security measures from time to time and update them as threats and technology change. However, you should be aware that you are responsible for the security of your own devices, email accounts and internet connection.
If you receive a message that claims to come from us and asks for your password, payment card details or other sensitive information, or asks you to pay into an unfamiliar account, please do not respond, and contact us using the details on this website to check whether it is genuine. We will never ask you for your password.
23. Personal data breaches
We maintain procedures to identify, investigate and respond to suspected personal data breaches. Where a breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the Nigeria Data Protection Commission within the period required by law, and, where the risk is high, we will also notify the individuals affected without undue delay.
Any notice will describe, as far as we know, the nature of the breach, the categories of data and individuals concerned, the likely consequences, and the measures we have taken or propose to take, together with our contact details for further information.
24. Visitors from outside Nigeria
Our services are operated from Nigeria, and the Personal Data that we collect is processed in Nigeria and, where necessary to provide your travel, in other countries, as explained in the section on international transfers.
If you are located in another country, such as a member state of the European Economic Area, the United Kingdom or another jurisdiction with its own data protection laws, you may have additional rights under those laws. Where that is the case, we will respect those rights to the extent that they apply to our processing of your Personal Data.
By using our services and giving us your Personal Data, you understand that your information will be transferred to, stored and processed in Nigeria and the other countries described in this Privacy Policy.
25. Requests from authorities and legal proceedings
We may receive requests for Personal Data from courts, law-enforcement agencies, regulators, tax authorities and other public bodies. We will comply with requests that we believe, in good faith, to be valid and legally binding.
Where permitted by law, we will take reasonable steps to check the validity and scope of a request, to disclose only what is necessary, and, where appropriate, to tell you about it.
We may also use or disclose Personal Data where we reasonably believe it is necessary to protect the rights, property or safety of Tifa Travels & Tours, our customers, our staff or others, to investigate or prevent fraud or other unlawful activity, or to establish, exercise or defend legal claims.
26. Complaints and how we handle privacy enquiries
If you have a complaint about the way we have handled your Personal Data, please contact us in the first instance so that we can investigate and, where possible, resolve it. Please give us enough information to identify you and understand your concern.
We will acknowledge your complaint, investigate it, and respond to you in writing within the period required by Applicable Law. If you are not satisfied with our response, you may refer the matter to the Nigeria Data Protection Commission or, where it applies, to the supervisory authority in your country.
27. Language, interpretation and validity
This Privacy Policy is written in English. If it is translated into another language, the English version prevails to the extent permitted by law.
If any part of this Privacy Policy is found to be invalid or unenforceable, the remaining parts will continue in full force and effect.
This Privacy Policy is not a contract and does not create any rights or obligations beyond those that already exist under Applicable Law, but it sets out our commitments to you as to how we handle your Personal Data.
28. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Services or Applicable Law. The “Last updated” date at the top shows when it was last revised.
Where changes are material, we will take reasonable steps to notify you, such as by email or a notice on the site. Your continued use of the Services after an update takes effect means you accept the updated policy, to the extent permitted by Applicable Law.
29. Contact us
For questions about this Privacy Policy, or to exercise your rights, contact us at:
Tifa Travels & Tours
31 Oba Akran Ave, Ikeja, Lagos 100282, Nigeria
Email: support@tifatravels.com
Telephone: +234 201 629 0064
31 Oba Akran Ave, Ikeja, Lagos 100282, Nigeria
Email: support@tifatravels.com
Telephone: +234 201 629 0064
