UAT environment - not the published legal text

Octopus Privacy Policy

Octopus Travel Tech LTD | Version 1.0 | Effective 01/10/2026

This Privacy Policy explains how Octopus Travel Tech LTD collects, uses, shares, stores and protects personal data when people visit or use the Octopus website or mobile application, create an Account, purchase Membership, search for or book Travel Services, travel as a Guest under another person’s Booking, receive marketing, or contact support.

Octopus is responsible for personal data that it determines how and why to process. Travel Suppliers, payment providers and certain other third parties may separately determine how they process personal data for their own services. Their privacy notices will also apply where they act as independent controllers.

Please read this Policy together with the Octopus Terms of Use and Booking Terms, the applicable Booking Terms and any privacy information provided by a Supplier or payment provider.

1. Who we are

1.1 Octopus Travel Tech LTD ("Octopus", "we", "us" or "our") is a company incorporated in the Abu Dhabi Global Market with registered office at. Unit 1405, Floor 14, Addax Port Office Tower, Al Rayfa Street, Al Reem Island, Abu Dhabi, United Arab Emirates

1.2 Octopus is the controller of personal data where it determines the purposes and means of processing. This includes personal data used to operate the Platform, administer Accounts and Membership, facilitate Bookings, provide support, protect the Platform and conduct Octopus marketing.

1.3 Octopus is not the controller of every use of personal data connected with a Travel Service. A Supplier, payment provider, app store, identity provider or other third party may act as an independent controller where it determines its own purposes and means of processing.

1.4 Octopus has not appointed a formal Data Protection Officer. Privacy questions and requests should be sent to our Privacy Contact at compliance@octopus.travel .

2. Scope of this Policy

2.1 This Policy applies to Members and Account holders, Guests travelling under another Member’s Booking, people who contact Octopus support, and visitors who use the Platform without creating an Account.

2.2 It covers the Octopus website, mobile application, Membership, customer support, marketing and the facilitation of accommodation.

2.3 This Policy does not govern a third-party website or service that Octopus does not control. You should review the privacy notice of each Supplier and third party with whom you interact.

3. What personal data means

3.1 “Personal data” means information relating to an identified or identifiable living person. It includes information that directly identifies a person and information that can identify a person when combined with other data, such as an online identifier, device identifier, location or booking reference.

3.2 “Processing” includes collecting, recording, organising, storing, accessing, using, disclosing, transferring, restricting, deleting and otherwise handling personal data.

4. Personal data we collect

4.1 Depending on how a person uses the Platform and the requirements of a particular Travel Service, Octopus may collect the following categories of personal data:

CategoryExamplesHow we obtain it
Identity dataName, title, gender, date of birth, nationality.You, a Member booking for you, a Supplier, support correspondence or an identity-verification provider.
Contact dataEmail address, telephone number, residential or billing address and emergency-contact information.You, a Member booking for you, communications and customer-support channels social sign-in or a Supplier.
Account and authentication dataAccount identifier, sign-in tokens, session information, verification status and information received from supported social sign-in providers.You, authentication providers, Apple, Google or another sign-in provider.
Membership and profile dataMembership plan and status, language, currency, saved searches, preferences, interests, wish lists and personalised settings.You and your use of the Platform.
Travel and Booking dataDestinations, dates, itineraries, accommodation, flight and transfer details, Guest names and ages, room occupancy, baggage information, loyalty or frequent-flyer numbers, special requests, Booking history, confirmation status, amendments, cancellations, refunds, no-shows and check-in issues.You, the booking Member, Suppliers, wholesalers, aggregators, airlines, hotels and transfer providers.
Payment and transaction dataPayment token or reference, card type, transaction identifier, payment status, payment amount refund and chargeback history.You, payment providers, banks, card networks and Suppliers.
Technical and device dataDevice identifies and browser, operating system, app version, push-notification token, network and diagnostic information.Your device, browser, application, analytics and security providers.
Usage and analytics dataSearches, browsing activity, clicks, feature use, marketing engagement, analytics events, and A/B test participation.Your use of the Platform and analytics technologies.
Communications and support dataEmails, chat, in-app messages, call recordings, support requests, complaint details and documents, photographs or other evidence submitted to support.You, a Member, Guests, Suppliers and support providers.
Marketing dataMarketing consent, channel preferences, unsubscribe status, campaign interaction and inferred interests used to personalise offers.You and your interaction with our communications.
Security and compliance dataFraud and risk indicators, identity and payment checks, sanctions-screening results, Account restrictions, suspected misconduct and records needed for complaints, disputes or legal claims.You, Suppliers, payment or fraud-prevention providers, public sources and authorities.
Business dataBusiness name, job title, employer, corporate contact details and business-travel information.You or the relevant business.

4.2 Octopus does not necessarily collect every item listed above from every person. The data collected depends on the Platform features used, the relevant Travel Service, the Supplier’s requirements and applicable law. Octopus collects and stores Member telephone numbers from launch to provide customer support through WhatsApp deep links and to administer related support communications.

5. Data relating to Guests and other people

5.1 A Member may provide personal data about accompanying Guests and other people, including children. Octopus receives that data through the Member and may use and disclose it as necessary to facilitate and administer the Booking.

5.2 Where a Member submits personal data relating to another person, including an accompanying Guest, the Member shall be responsible for ensuring that this Policy and any relevant Supplier privacy information have been shared with and acknowledged by that person before their personal data is submitted to Octopus. The Member shall also be responsible for ensuring that the personal data submitted is accurate and that the Member has the authority required under applicable law to submit it for the purposes of the relevant Booking.

5.3 A Guest may contact Octopus at compliance@octopus.travel to exercise applicable rights regarding personal data held by Octopus. Octopus may need to verify the Guest’s identity and Booking relationship.

6. Children

6.1 Accounts and Membership are intended only for people aged 18 or over. Octopus does not knowingly permit a child to create an Account or purchase Membership.

6.2 Octopus may process a child traveller’s name, age, date of birth, nationality, passport or other Booking data when an adult submits it for a Travel Service. The adult submitting the data confirms that they are the child’s parent or guardian or otherwise have lawful authority to provide it and make the Booking.

6.3 If you believe a child has provided personal data directly without appropriate authority, contact compliance@octopus.travel.

7. Special category and sensitive data

7.1 A Booking or support request may contain medical, disability, mobility, dietary, religious or other sensitive information, particularly where a person asks for accessibility assistance or another special arrangement.

7.2 Please provide only information reasonably necessary for the request. Where required by law, Octopus will process such data with explicit consent or another permitted legal condition, and may share it with the relevant Supplier solely to arrange or provide the requested Travel Service or assistance.

8. How and why we use personal data

8.1 Octopus uses personal data only where it has a lawful basis. The principal purposes and bases are set out below:

PurposeData usedLawful basis
Create, authenticate and administer Accounts and MembershipIdentity, contact, Account, Membership and payment dataPerformance of a contract and steps requested before entering into a contract.
Search for, arrange and administer Travel ServicesIdentity, contact, Travel and Booking, profile, payment and Guest dataPerformance of a contract and steps requested before entering into a contract.
Process payments, refunds and chargebacksIdentity, contact, payment, transaction and Booking dataPerformance of a contract; legal obligations; legitimate interests in collecting payment and preventing loss.
Communicate confirmations, schedule changes, security notices, renewal reminders and service messagesContact, Account, Membership, Travel and Booking dataPerformance of a contract; legal obligations; legitimate interests in operating and supporting the service.
Provide customer support and resolve complaintsIdentity, contact, Booking, communications and support dataPerformance of a contract; legitimate interests in customer service, dispute resolution and service improvement; legal claims.
Protect the Platform, verify identity, prevent fraud and enforce TermsIdentity, Account, payment, technical, security and compliance dataLegitimate interests in security, fraud prevention and protecting Users and the business; legal obligations; legal claims.
Personalise searches, recommendations and offersProfile, Booking, usage, technical and marketing dataLegitimate interests in improving relevance and User experience; consent where required for the relevant tracking technology.
Conduct analytics, A/B testing, and crash diagnosticsTechnical, device, usage and analytics dataConsent for optional analytics and session recording; legitimate interests for strictly necessary diagnostics where permitted.
Send direct marketingContact, profile, Booking, marketing and usage dataConsent, which may be withdrawn at any time; another lawful basis only where applicable law permits.
Comply with law and respond to authoritiesIdentity, contact, Booking, payment, communications and compliance dataLegal obligations; public interest where applicable; legal claims.
Establish, exercise or defend legal claimsAny data reasonably relevant to the matterLegitimate interests and legal claims.
Plan or complete a corporate transactionRelevant Account, Booking, commercial and compliance dataLegitimate interests in corporate development, subject to confidentiality and applicable law.

8.2 Where Octopus relies on legitimate interests, it considers whether the processing is necessary and balanced against the rights and reasonable expectations of the people affected.

8.3 Octopus may use personal data for another purpose compatible with the original purpose. If a new purpose is not compatible, Octopus will provide additional information and rely on an appropriate lawful basis before processing, unless the law permits or requires otherwise.

9. Payments

9.1 Payments are processed through one or more third-party payment service providers. Those providers may collect full card or bank details directly and may act as independent controllers for payment processing, fraud prevention, regulatory compliance and their own legal obligations.

9.2 Octopus may receive and retain payment references, tokens, limited card information, billing details, transaction status, refunds and chargeback information. Octopus does not intend to store full payment-card numbers or security codes on its own systems.

9.3 The payment provider’s privacy notice describes its separate processing. Octopus may disclose Booking and identity information to the provider to process or reconcile payment, investigate fraud and handle refunds or chargebacks.

10. Automated processing and profiling

10.1 Octopus and its providers may use automated tools to detect fraud, assess payment or security risk, identify suspicious activity, screen transactions and personalise search results or offers.

10.2 A risk indicator may cause a transaction or Account to be delayed, restricted, rejected or referred for manual review. Where a decision is based solely on automated processing and produces legal or similarly significant effects, Octopus will provide the safeguards required by applicable law, which may include the right to obtain human review, express a point of view and challenge the decision.

10.3 Contact compliance@octopus.travel if you wish to ask about a significant automated decision affecting you.

11. Marketing and communications

11.1 Essential communications include Booking confirmations, itinerary and schedule updates, security messages, support responses, Membership and renewal notices, changes to legal terms, customer-support communications and other information necessary to provide or administer the service. Octopus provides customer support through WhatsApp using WhatsApp deep links and collects and stores the Member’s telephone number for this purpose. These communications are processed as necessary to perform the relevant contract or take steps requested by the Member in connection with that contract. Essential communications are not marketing communications and may continue while you maintain an Account, Membership or Booking.

11.2 Subject to applicable law and your choices, Octopus may send promotions, personalised offers, destination information and product news by email, push notification, SMS, WhatsApp, telephone or in-app message.

11.3 Octopus will obtain consent for direct marketing where required. You may withdraw consent or opt out through Account settings, the unsubscribe mechanism in a message, your device settings, the in-app privacy form or compliance@octopus.travel.

11.4 Opting out of marketing does not stop essential service communications. Octopus may retain a minimal suppression record to ensure that it respects an opt-out.

11.5 Octopus does not permit Suppliers to use Booking data received from Octopus for their own unrelated marketing unless the traveller has separately agreed or another lawful basis applies.

12. Cookies and similar technologies

12.1 The website and application may use cookies, software-development kits, pixels, local storage, device identifiers and similar technologies to operate the Platform, remember preferences, authenticate Users, secure transactions, diagnose failures, measure performance, analyse use, record sessions, personalise content and support marketing.

12.2 These technologies may fall into the following categories:

CategoryPurposeBasis and control
Strictly necessaryAuthentication, security, fraud prevention, network management, shopping or Booking functions and recording privacy choices.Required for the Platform to function; consent is not requested where law permits.
FunctionalRemembering language, currency, region and other preferences.Consent where required.
Analytics and performanceMeasuring use, conducting A/B tests, diagnosing crashes and improving the Platform.Consent for optional analytics; legitimate interests only where permitted for necessary diagnostics.
Advertising and personalisationMeasuring campaigns, personalising offers and supporting retargeting or cross-platform advertising.Consent where required.

12.3 On the Octopus website, Octopus will request consent before placing or accessing any optional cookies or similar technologies, including Google Analytics. Optional technologies will remain disabled unless and until the website visitor provides consent. The website consent banner will provide options to accept or reject optional technologies with equal ease, and visitors may subsequently withdraw consent or change their choices through https://octopus.travel/cookie-settings. Google Analytics will not be activated before the consent banner and preference controls are operational.

12.4 Blocking strictly necessary technologies may prevent Account access, payment or Booking functions. Device and browser controls may also allow you to restrict cookies, and push notifications.

12.5 Current technologies and providers include, without limitation, PostHog; Firebase Crashlytics; Firebase Remote Config; Firebase Cloud Messaging; Auth0; Meta/WhatsApp; Freshdesk; Microsoft Azure SignalR; on-device storage; Google Analytics; Cloudflare; and self-hosted fonts.

13. Who we share personal data with

13.1 Octopus shares personal data only where reasonably necessary for the purposes described in this Policy. Recipient categories include:

13.2 Current providers may include, without limitation, Auth0, Microsoft Azure, PostHog, Freshdesk, Airtable Google/Firebase, Cloudflare, GTBeds, wbe.travel, Meta, WhatsApp, Apple, Google Play, payment service providers and public price-comparison providers. Providers and Suppliers may change as the Platform develops.

13.3 Where a recipient processes data only on Octopus’s documented instructions, Octopus requires appropriate contractual privacy, confidentiality and security obligations. Some recipients, including many Suppliers, payment providers, app stores and public authorities, act as independent controllers for their own processing.

13.4 Where customer support is provided through WhatsApp, Octopus may disclose or otherwise make available the Member’s telephone number, message content, attachments, device information and communications metadata to WhatsApp, Meta and their relevant service providers. WhatsApp and Meta may process such personal data for their own purposes in accordance with their applicable terms and privacy policies.

14. Travel Suppliers

14.1 Octopus may send personal data directly to a hotel, airline, transfer operator or other Supplier, or indirectly through a wholesaler, aggregator, reservation system or supply partner. The route depends on the Booking and inventory source.

14.2 The data shared may include identity, contact, Guest, itinerary, special-request, payment-status and other information necessary to request, confirm, amend, perform, support or refund the Booking.

14.3 Once a Supplier receives personal data and determines how it will use that data to provide the Travel Service, comply with law or manage its operations, it may act as an independent controller. Its own privacy notice applies to that processing.

14.4 Suppliers may process data in the country where the Travel Service takes place or from other locations used by their corporate group or service providers. Octopus does not control every independent processing activity of a Supplier but will take reasonable steps in its contractual arrangements to protect Booking data shared by Octopus.

15. International transfers

15.1 Octopus’s core customer database is hosted in the Microsoft Azure UAE region. Personal data may nevertheless be remotely accessed or otherwise processed by authorised Octopus personnel located in Egypt, the United Arab Emirates, Belgium and the United Kingdom and, where reasonably necessary for urgent development or technical support, Germany, France, the Netherlands and Luxembourg. Personal data may also be processed in the European Economic Area, the United Kingdom, the United States and other jurisdictions in which Octopus’s Suppliers and service providers, including PostHog, Google/Firebase, Meta and WhatsApp, and their respective subprocessors operate.

15.2 Remote access to personal data from outside ADGM constitutes an international transfer where applicable. Octopus restricts such access to authorised personnel who require it for their functions and subjects those personnel to confidentiality, data-protection and information-security obligations. Octopus shall apply the transfer mechanism required under clauses 15.3 and 15.4 and appropriate technical and organisational measures having regard to the nature of the access and the risks involved.

15.3 Where personal data is transferred to a jurisdiction designated by the ADGM Commissioner of Data Protection as providing an adequate level of protection, Octopus may rely on that designation. In the case of a recipient in the United States, Octopus may rely on adequacy only where the specific recipient actively participates in the EU-US Data Privacy Framework and the relevant processing falls within the scope of its certification.

15.4 Where no adequacy designation applies, Octopus uses an appropriate safeguard permitted under the ADGM Data Protection Regulations 2021, such as the ADGM Standard Contractual Clauses, together with supplementary technical and organisational measures where appropriate. In limited circumstances, Octopus may rely on a statutory derogation where the conditions are satisfied. This may apply, without limitation, to remote access from Egypt or the UAE outside ADGM and to transfers to any Supplier, service provider or subprocessor that is not covered by a current adequacy designation.

15.5 A service provider’s primary hosting location may differ from the locations used by its affiliates, subprocessors, backups, failover systems or disaster-recovery arrangements. Octopus requires its service providers to provide appropriate information and contractual safeguards concerning such processing and will update this Policy where a material change affects the information provided to Users.

15.6 Contact compliance@octopus.travel for further information about the transfer mechanism relevant to your personal data, subject to lawful confidentiality and security restrictions.

16. How long we retain personal data

16.1 Octopus retains personal data only for as long as reasonably necessary for the purposes described in this Policy, including service delivery, legal and regulatory compliance, accounting, fraud prevention, dispute resolution and legal claims.

Data categoryIndicative retention period
Account, Membership and profile dataFor the life of the Account, then ordinarily 90 days after closure.
Booking and payment recordsOrdinarily seven years after the relevant transaction or longer where required for tax, accounting, regulatory or claims purposes.
Search historyOrdinarily 12 months.
Analytics eventsUp to 12 months.
Marketing profileUntil opt-out or withdrawal, after which active marketing data is removed within 30 days and a minimal suppression record may be retained.
Support tickets and complaint recordsOrdinarily 24 months after closure, or longer for an unresolved dispute or legal claim.
Crash and diagnostic dataOrdinarily 90 days.
Consent and privacy-choice recordsFor the life of the Account plus six years, or another period reasonably necessary to demonstrate compliance.
Identity, fraud and compliance recordsFor as long as reasonably necessary to prevent fraud, comply with law or establish, exercise or defend claims.
BackupsUp to 30 days under Octopus’s applicable backup cycle.
Technical and device dataDevice identifiers, with analytics events available for up to 1 year; push notification tokens for the life of the app install.
Airtable beta-tester dataFor the life of the Account plus as long as reasonably necessary .

16.2 A period may be extended where records are subject to a legal hold, complaint, chargeback, fraud or sanctions investigation, tax audit, regulatory enquiry or actual or anticipated legal claim. Data may be deleted or anonymised earlier where it is no longer required.

17. Security

17.1 Octopus uses appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure, access or misuse. Measures may include encryption in transit and at rest where appropriate, access controls, authentication, logging, secure hosting, staff training, confidentiality obligations, vulnerability management, backups and incident-response procedures.

17.2 Access is limited according to role and business need. No internet transmission or storage system is completely secure, and Octopus cannot guarantee absolute security.

17.3 If a personal data breach creates a legally reportable risk, Octopus will notify the ADGM Office of Data Protection and affected people as required by applicable law.

18. Your rights

18.1 Subject to the conditions and exceptions in applicable law, you may have the right to:

18.2 Rights are not absolute. Octopus may retain or continue processing data where permitted or required by law, including to perform a contract, comply with a legal obligation, protect another person’s rights or establish, exercise or defend legal claims.

18.3 Submit a request to compliance@octopus.travel. Octopus may request information reasonably necessary to verify identity, authority and the data concerned.

18.4 Octopus will ordinarily respond within two months after receiving a valid request. Where permitted due to complexity or the number of requests, Octopus may extend that period and will explain the extension.

18.5 Requests are generally free of charge. Where permitted by law, Octopus may charge a reasonable fee or refuse to act on a request that is manifestly unfounded or excessive and will explain the decision.

19. Your choices and required information

19.1 You may browse limited parts of the Platform without creating an Account, but Octopus requires certain personal data to provide Membership, confirm identity, process payment, facilitate a Booking or respond to support requests.

19.2 If required data is not provided, Octopus or the relevant Supplier may be unable to create an Account, process payment, confirm or perform a Booking, provide a requested feature or comply with law.

19.3 You may manage marketing, cookies, location and push-notification choices through the controls described in this Policy. Octopus may also offer Account deletion or data-download functions through the Platform.

20. Third-party links and services

20.1 The Platform may link to or interoperate with Supplier websites, maps, app stores, payment services and other third-party services. Octopus is not responsible for an independent third party’s privacy practices merely because it is linked or integrated.

20.2 Review the third party’s privacy notice before providing data directly to it. This clause does not reduce Octopus’s responsibility for a processor acting on Octopus’s instructions.

21. Changes to this Policy

21.1 Octopus may update this Policy to reflect changes in law, technology, providers, Travel Services or processing practices. The current version and effective date appear at the top.

21.2 Octopus will provide reasonable advance notice of a material change by email and in-app notification, unless an earlier change is necessary to comply with law or address an urgent privacy or security issue.

21.3 A change takes effect on the date stated in the revised Policy. Continued use is not treated as consent to processing that requires consent; Octopus will request consent separately where required.

22. Contact and complaints

22.1 For questions, rights requests or complaints, contact:

Privacy email: compliance@octopus.travel
Telephone: +971559734254
Postal address: Unit 1405, Floor 14, Addax Port Office Tower, Al Rayfa Street, Al Reem Island, Abu Dhabi, United Arab Emirates

22.2 Octopus would appreciate the opportunity to address a concern first. You may also complain to the ADGM Office of Data Protection through the contact details and complaint channels published on the ADGM website, or to another competent authority where applicable.