Privacy Policy
Last updated 17 July 2026
This Privacy Policy explains how LittleTrips collects, holds, uses and discloses personal information in connection with our website and travel agency management application (together, the "Service"). It is intended to be read with the applicable order form, account agreement or data processing agreement.
LittleTrips' legal entity name, ABN/ACN and registered address are currently pending. They will be added to this Policy and the Terms of Service when finalised. References to "LittleTrips", "we", "us" and "our" mean the operator of the Service.
1. Scope and Roles
This Policy covers two different relationships, and it's important to understand which one applies to you:
- Website visitors and waitlist enquiries: if you simply browse this website or contact us to join the waitlist, this Policy explains what we collect about you directly.
- Application users (travel agencies and their staff): if your business uses the LittleTrips application, this Policy explains how we handle your account information, and how we process (on your behalf) the client and traveller information you choose to store in the Service.
Where an agency stores information about its own clients or travellers in LittleTrips (for example, passport numbers, visa details, medical notes, or travel insurance records), your agency determines the purposes and means of handling that information. LittleTrips acts as its service provider and processes that data only on the agency's documented instructions, subject to law. If you are a traveller whose information has been entered into LittleTrips by a travel agency, please direct any privacy questions to that agency in the first instance.
2. Information We Collect and How We Collect It
Depending on how you interact with us, we may collect:
- Contact details you provide to us, such as your name, agency name and email address when joining the waitlist, requesting access or contacting support.
- Account information, such as your name, email address, and role, when your agency sets you up as a user of the application.
- Agency and client data that you or your agency enter into the application, which may include client contact details, passport and visa information, travel preferences, medical notes, emergency contacts, travel insurance details, trip bookings, and payment records relating to your clients' travel.
- Usage and technical information, such as log data, browser type, device information, IP address and security events generated when you use the website or application.
We collect information directly from you, from your agency or its authorised users, and automatically through the use of the Service. We hold information in our application database, backups and the service-provider systems described below.
3. How We Use Information
We use personal information to:
- Provide, operate, and maintain the Service;
- Respond to enquiries and provide customer support;
- Send transactional communications, such as itinerary and quote documents you ask us to send on your behalf;
- Maintain the security and integrity of the Service; and
- Improve and develop the Service using aggregated or de-identified information; and
- Meet legal, accounting and regulatory obligations.
We do not sell personal information, and we do not use client or traveller data stored by agencies in the Service for our own marketing purposes.
4. Service Providers and Overseas Processing
We do not share personal information with third parties except as described here. We use a small number of trusted service providers to help us operate the Service, including:
- A transactional email provider, to deliver itinerary, quote, account-related and waitlist emails;
- A cloud storage provider, to store documents and files uploaded to the Service (such as scanned passport copies);
- Cloud hosting infrastructure, to run the application and database.
These providers process information only as needed to provide their services to us. Information may be processed outside Australia. Our current object storage is in Singapore. Our email, hosting and support providers may process information in the United States and other countries in which they or their subprocessors operate. We will take reasonable steps to ensure overseas recipients handle personal information consistently with applicable privacy law. A current list of material service providers is available on request. We may also disclose information where required by law, to protect rights or safety, or in connection with a business transfer.
5. Data Storage and Security
We take reasonable technical and organisational steps to protect personal information against unauthorised access, loss, misuse, or disclosure, including encrypted connections, access controls, tenant-level data isolation, backups, and processes for managing security incidents. We regularly review these measures, but no method of storage or transmission is completely secure.
6. Data Retention
We retain personal information for the life of an active account and then for the period set out in the applicable agreement or required by law. We maintain backups for a limited period (currently up to 14 days). Account closure, export and deletion requests are handled under the applicable agreement; information may remain in backups until their normal expiry. Export and deletion timeframes may also be set out in the applicable agreement.
7. Access, Correction and Complaints
You may request access to, or correction of, personal information we hold about you by emailing hello@littletrips.com.au. We may need to verify your identity and will respond within a reasonable time. For agency client or traveller data, we will generally refer the request to the relevant agency and assist it as required.
To make a privacy complaint, contact us at the address above with the details of your concern. We will acknowledge the complaint, investigate it and provide a written response. If you are not satisfied, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.
8. Direct Marketing, Cookies and Tracking
We may send waitlist and product information where permitted by law. You can unsubscribe from marketing communications at any time; service and transactional messages are not marketing. This website does not currently use analytics or advertising cookies. We use only technologies necessary to operate and secure the Service. If this changes, we will update this Policy.
9. Data Breaches
We assess and respond to suspected data breaches. Where required by applicable law, we will notify affected individuals, the relevant agency and the regulator. Agencies remain responsible for their own legal notification obligations in relation to their client data.
10. Children's Privacy
The Service is intended for use by travel professionals and their agencies, not by children. We do not knowingly collect personal information directly from children. Where an agency records information about a traveller who is a minor (for example, as part of a family booking), that information is provided and controlled by the agency in accordance with Section 1 above.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to the Service or our practices. We will post the updated Policy on this page with a revised "last updated" date, and where changes are material, we will take reasonable steps to notify you.
12. Contact Us
If you have any questions about this Privacy Policy or how we handle personal information, please contact us at hello@littletrips.com.au.