Axus Platform Privacy Policy
Effective: September 11, 2026 · Last updated: September 11, 2026
The short version
- The Axus Platform is a set of tools for travel advisors and their travelers — the Axus Travel App itinerary platform, the custom iOS and Android apps we build for travel agencies, and services such as AxusBuilder. This policy covers all of them.
- If you are a traveler using an app with your agency's name on it, we built and run it. The app is operated by Axus on your travel agency's behalf, and this policy explains what it collects — including notifications, a copy of your trip stored on your device for offline use, and approximate location if you allow it, which never leaves your device.
- Most of what we hold, we hold for an advisor. Your trip information is on the Platform because your travel advisor or agency put it there. We use it to run the service for them — not for our own marketing.
- Three features use AI — building an itinerary from a booking, enhancing booking descriptions, and translating content. All three use the same provider, section 6 names it, and none of it is used to train AI models.
- We do not sell personal information, we do not share it with advertisers, and we do not use your location for advertising. Any marketing we send is our own, and advisors can unsubscribe.
- You can get your information, correct it, or have it deleted. Section 13 explains how, and what we can and can't do.
This summary is for orientation only — the sections below are the actual policy.
1. Who we are and what this policy covers
The Axus Platform is operated by Axus Travel App, a division of Northstar Travel Media, LLC ("Axus," "we," "us"), a Northstar Travel Group company.
This policy explains how we handle personal information across the Axus Platform — the Axus Travel App itinerary platform and the member services built to work with it. Those currently include:
- Axus Travel App — the itinerary platform where advisors build, manage and share trips with their travelers (axustravelapp.com).
- Our mobile apps for iOS and Android — travel apps we custom-build and operate for travel agencies, so their travelers can view and use their trips on a phone or tablet. Several such apps exist; they are built on one common Axus platform, and each is usually branded with the agency's own name. Section 7 covers them in detail.
- AxusBuilder — an AI service that converts a booking document, a GDS/PNR record, a cruise confirmation or a plain-language description into a structured Axus itinerary (axus-builder.ai).
- Our public websites, sign-in pages, support channels and billing flows for the above.
As new services join the Platform, they are covered by this policy unless we say otherwise at the point you use them.
What this policy does not cover. It does not cover the separate websites, events and media products of other Northstar Travel Group businesses, which have their own privacy notices. It also does not cover a travel agency's own handling of its clients' information, or a third-party service you connect to the Platform — for example a supplier or booking tool authorized through an API. Once information passes to a party you have chosen, their own privacy policy governs it.
This policy replaces any earlier Northstar privacy notice as it applied to the Axus Platform.
2. Advisors and travelers — different roles
Almost everything in this policy follows from a distinction worth making up front, because these groups have different relationships with us.
| Who | Their relationship with us | Our role |
|---|---|---|
| Travel advisors and agencies | Our direct customers. You hold the account, sign in, subscribe or buy credits, commission an app, and decide what goes into the Platform. | We decide how your account information is handled, and this policy tells you how. |
| Travelers whose trips are on the Platform | Your clients. We hold their information because an advisor put it there. | We handle it on the advisor's behalf and under their instructions — to provide the Platform's services to them, and for nothing else. The advisor, or their agency, decides what is collected and why. |
| Travelers using one of our mobile apps | You installed an app, most likely carrying your travel agency's name, to see your trip. You interact with software we built and operate. | We still act on your agency's behalf for your trip information. But the app itself also needs information to work — your device, your notification token, your location if you permit it — and we handle that as described in section 7. |
A point worth being direct about. If you are a traveler, the app on your phone may carry your travel agency's name and branding, and you may never have heard of Axus. The app is built and operated by us for your agency. Your agency decides what trip information exists and who can see it; we run the software that shows it to you.
If you are a traveler and want to know why your information is on the Platform, or want it changed or removed, the fastest route is to ask your travel advisor. You can also contact us directly and we will work with them — see Your choices and rights.
3. Information we collect
3.1 Account and organization information
- Your name, business email address, phone number, employer or agency, and the account identifiers we assign.
- Your sign-in credentials, and the roles and permissions that apply to your account.
- Subscription, plan, credit balance and usage information, and the history of purchases — amounts, dates, and the payment processor's transaction reference.
- Your settings and preferences, and records of your communications with our support team.
3.2 Trip content — including traveler information
This is the largest and most sensitive category, and the reason most of this policy exists. When a trip is built on the Platform, we receive and store the content put into it, which typically includes:
- Traveler names and contact details.
- Trip details — flights, accommodation, tours, transfers, cruises, dates, confirmation numbers and notes.
- Documents and source material uploaded or pasted — booking confirmations, PDFs, images, GDS/PNR records and cruise documents.
- Anything else that appears in those documents. Depending on the source, that can include dates of birth, travel-document or passport numbers, frequent-traveler numbers, and traveler preferences.
We do not choose what is in this category — the advisor does. We receive whatever the trip and its source documents contain. See section 14 for what that means for advisors and agencies.
3.3 Traveler app information
If you use one of our mobile apps as a traveler, we collect the information needed to run it — device and app details, your push-notification token, your location if you grant permission, and diagnostics. Because that category needs proper explanation rather than a bullet, section 7 is devoted to it.
3.4 Payment information
Card payments on the Platform — Axus Travel App subscriptions and AxusBuilder credit purchases alike — are handled by Braintree, a PayPal service. Card details are entered into payment fields hosted by Braintree and go to them, not to us.
No cardholder data is stored anywhere on the Axus Platform. We never receive or store your card number, expiry date, security code, cardholder name or billing address — not in our databases and not in our logs. What we keep is what was purchased, the price, the total, Braintree's transaction reference, and the status.
Nothing is sold inside the mobile apps. There are no in-app purchases, so travelers never make a payment through an app.
3.5 Technical and usage information
- Device and connection information, including IP address, browser and operating system type, and device identifiers.
- Server and security records of requests to the Platform — what was requested and when.
- Sign-in events and failed sign-in attempts, which we use to detect and block password guessing.
- How the Platform is used — features opened, actions taken, and for metered services how much was consumed and whether it succeeded.
- Information collected through cookies, app storage and similar technologies, described in section 8.
3.6 Information from other sources
We may receive information about you from your agency or employer when they set up or administer your account, from your travel advisor when they add you to a trip, from a Platform partner or integration you connect, and from our service providers — for example a payment processor confirming a transaction or an app store confirming an install.
4. How we use information
- Provide the Platform — build, store and share itineraries; run the features you use; deliver trip content to the travelers it is shared with; and operate the mobile apps, including offline access and notifications.
- Run your account — authenticate you, keep you signed in, administer permissions, and maintain your history.
- Bill accurately — manage subscriptions, meter usage, process payments, and reconcile accounts.
- Support you — answer your questions and investigate a specific problem you report. This is the main reason we retain trip content and source documents after a trip is built.
- Keep the Platform secure and reliable — detect and prevent abuse, fraud and unauthorized access; diagnose faults and app crashes; and monitor performance.
- Improve the Platform — using usage patterns, aggregate statistics and failure rates. We review the content of a particular trip only where it is needed to diagnose a problem with it or to investigate a security issue.
- Communicate with you — service, security and billing messages, which are part of the service and cannot be opted out of while you hold an account; trip notifications in the apps, which you control; and marketing about Axus products to advisors, which you can opt out of at any time.
- Meet legal, tax and accounting obligations, and enforce our terms.
What we do not do: we do not sell personal information; we do not share it with third-party advertisers or use it for targeted or cross-context behavioral advertising; we do not market to your travelers using information an advisor puts on the Platform; we do not use your location for advertising; and we do not use trip content to train AI models — ours or anyone else's.
The marketing we do send is our own. We email advisors about Axus products and features, and you can unsubscribe at any time. We do not pass advisor contact details to advertisers or industry partners, and we do not upload them to advertising platforms to build audiences.
5. Our legal bases for processing
Where the laws of the EEA, the UK, Switzerland or a similar jurisdiction apply, we rely on the following legal bases:
- Performance of a contract — to provide the Platform to the advisor or agency that holds the account, and to bill for it.
- Legitimate interests — to secure the Platform, prevent abuse and fraud, keep it working, and improve it, balanced against the rights of the people concerned.
- Consent — for marketing communications where consent is required, and for device permissions in the apps such as location and notifications, which are always requested from you and can be withdrawn at any time.
- Legal obligation — where we must retain or disclose information by law.
For traveler information, the advisor or agency determines the purpose and legal basis; we act as their processor and handle it on their instructions.
6. AI features on the Platform
Several Platform services use artificial intelligence. Because that is the kind of thing a privacy policy should be specific about rather than reassuring about, this section says exactly what happens.
6.1 One provider, and what that means
Every AI feature described below uses the same model and the same provider: Anthropic's Claude, accessed through Amazon Bedrock, a service of Amazon Web Services (AWS). We do not send Platform content to any other AI provider.
What that means in practice, and it applies to all of these features:
- The AI provider does not keep it. Under AWS's terms for Amazon Bedrock, the content of a request and its response are not stored after the request is served.
- It is not used for training. The content is not used to train or improve any AI model, whether AWS's or the model provider's.
- Anthropic does not receive it. Because Claude is accessed through Amazon Bedrock, the request is served within AWS and the model's developer does not receive the content.
- A person is not reading it. The processing is automated. Our staff access content only where it is needed to investigate a support issue or a security incident.
- No automated decisions about people. These features work on travel information. They do not evaluate, score, profile or make decisions about any traveler or advisor.
6.2 AxusBuilder — building an itinerary from a booking
AxusBuilder converts what an advisor submits — pasted text, a GDS/PNR record, a cruise confirmation, an uploaded PDF or image, or a plain-language description — into a structured Axus itinerary. The model reads the booking and returns structured itinerary data.
This feature sends the whole submitted booking, so whatever personal information is in it goes too — traveler names, contact details, and anything else the source document happens to contain (see section 3.2). It is the only AI feature on the Platform that handles traveler identities.
AI can make mistakes, which is why every generated itinerary is presented to the advisor for review before it is added to an Axus account. The advisor remains responsible for checking an itinerary before sharing it with a traveler.
6.3 Booking enhancement
The Platform can use generative AI to enrich a booking's description — writing or improving the descriptive text about a hotel, an activity or a destination so that the itinerary reads well.
Only descriptive content is sent for this: the text about the place or the activity. Traveler names and personal details are not included.
6.4 Language translation
Itinerary content can be translated into a traveler's preferred language, using the same model.
Only the content being translated is sent — again the descriptive text, not traveler personal details.
6.5 Web look-ups by AxusBuilder
For some import types, AxusBuilder can look information up on the web to fill in details such as a venue or a location. Those look-ups go to Tavily, a commercial search provider, and may retrieve the contents of a page in the results.
Which imports can do this is restricted in the software itself, not left to the AI's discretion:
| Import type | Web look-ups |
|---|---|
| GDS/PNR | Never. These records carry the most sensitive traveler data, including travel-document details, so the capability is switched off entirely for them. |
| Cruise | Never. |
| Itinerary | No searching. If an advisor pastes a web address as the input, we retrieve that page — the one they chose — and nothing else. |
| Describe | Searching is permitted, within a fixed limit per import. The search text is composed from the description the advisor wrote, so if a traveler's name is included in a description, it can appear in a search query sent to our search provider. Advisors who are concerned about this for a particular trip should describe it without naming the traveler. |
6.6 Other AI features
Where another Platform service or app uses AI, we will describe it here and identify the provider before or when the feature becomes available to you. We will not begin using trip content for a materially different AI purpose without updating this policy and telling advisors first.
7. Our mobile apps
We build and operate custom mobile apps for iOS and Android on behalf of travel agencies. Several such apps exist, built on one common Axus platform, and each is usually published under the agency's own name and branding. They are distributed through the Apple App Store and Google Play, which collect their own information about downloads and purchases under their own privacy policies.
This policy applies to those apps, unless a particular app tells you at install or sign-in that a different policy governs it.
7.1 What the apps collect
- Your trip information — the itinerary and trip details your travel advisor has shared with you, as described in section 3.2.
- Device and app information — device model, operating system version, app version, language and region settings, and device or installation identifiers.
- Access information — how you were invited to the app, when you signed in, and which trips are available to you.
- Notification token — an identifier issued by Apple or Google that lets us deliver notifications to your device. See section 7.2.
- Location — only if you grant permission, only approximate, and it stays on your device. See section 7.3.
- Diagnostics — crash and error information, so we can find and fix faults. The apps contain no third-party analytics software; crash reports reach us through Apple's and Google's own developer tools, and only where you have agreed to share them.
What the apps do not ask for. They do not request access to your camera, your photo library, your contacts, your calendar, your microphone or your health data.
And what they do not contain. The apps carry no third-party analytics, advertising or attribution software. There is no advertising identifier, no ad network and no tracking SDK — so there is nothing in them that follows you between apps or across websites.
7.2 Notifications
With your permission, an app can send you notifications — for example a reminder that a trip is coming up, a change to a booking, or a message from your travel advisor. To deliver them we use Apple's Push Notification service and Google's Firebase Cloud Messaging, which receive the notification token for your device and the content needed to deliver the message.
Notification content can include trip details — a flight time, a hotel name — and depending on your device settings those may be visible on your lock screen without unlocking your phone. You can change that in your device's notification settings.
You can turn notifications off at any time in your device settings, or in the app where it offers the choice. Uninstalling the app stops them.
7.3 Location
An app may ask for your location to power features such as maps, nearby recommendations, and showing where you are in relation to your itinerary. Location is only ever used with your permission, which your device asks for before the app can access it.
Your location stays on your device. The apps use it on the phone itself — to draw a map, or to work out what is near you. It is not sent to our servers, we do not store it, and we never receive a record of where you have been.
- Approximate location is all we ask for. The apps request approximate location — roughly neighborhood or city level — not your exact position.
- Only while you are using the app. No app requests background or "always" location, so none of them can look up where you are once the app is closed.
- You can refuse or withdraw permission at any time in your device settings. The app keeps working without location — you lose only the features that need it.
- We do not use your location for advertising, and we do not sell it.
7.4 Offline access to your trip
So that your itinerary works without a signal — on a plane, or abroad without data — the apps store a copy of your trip on your device. That copy contains the trip information described in section 3.2, which can include other travelers' names and details where they are part of the same trip.
Signing out deletes that copy, and so does removing the trip from your account or deleting the app. While it is on your device, it is protected by the device's own encryption, which iOS and Android apply to app data when a passcode is set — so protecting your device with a passcode or biometric lock is the most effective thing you can do to protect it.
7.5 Permissions and your controls
| Permission or feature | What it is for | How to turn it off |
|---|---|---|
| Notifications | Trip reminders, booking changes, messages from your advisor | Device notification settings, or in the app where offered |
| Location | Maps, nearby suggestions, and where you are in relation to your trip | Device location settings — the app continues to work without it |
| Offline copy of your trip | So your itinerary works with no signal | Sign out of the app, or delete the app from your device |
| The app itself | — | Deleting the app removes the offline copy and stops notifications. It does not delete your trip from your agency's account — for that, see section 13 |
8. Cookies, app storage and similar technologies
On our websites, we and our service providers use cookies and similar technologies, which can include local storage and pixel tags in email, to operate the Platform, remember your preferences, keep you signed in, secure your session, and understand how our sites are used.
We group them as follows:
- Strictly necessary — sign-in, session security and load balancing. The Platform cannot work without these, so they are not optional.
- Preferences — remembering choices such as language or display settings.
- Analytics — understanding how our websites are used so we can improve them. We use Google Analytics for this, without its advertising features enabled, so the data is not used to target advertising at you and is not shared with advertisers.
We do not use advertising, remarketing or social-media tracking cookies, and there are no advertising pixels on our websites.
You can control cookies through your browser settings — blocking or deleting them at any time, and most browsers can refuse third-party cookies specifically. Blocking strictly necessary cookies will stop you from signing in.
8.1 In the mobile apps
Apps do not use browser cookies in the same way. Instead they store information on your device — your sign-in state, your preferences, and the offline copy of your trip described in section 7.4. They contain no third-party analytics or tracking software, so there is no in-app tracking to switch off; your controls are your device's app settings and permissions, described in section 7.5, rather than browser settings.
8.2 AxusBuilder specifically
AxusBuilder uses one cookie, and it is strictly necessary: a sign-in cookie named
axusbuilder.session that tells the service you are logged in. It cannot be read by
scripts in your browser, it is sent only over HTTPS, and it expires after about eight hours of
inactivity. Signing out clears it. AxusBuilder sets no advertising, analytics or tracking
cookies, and its pages load no third-party tracking scripts.
9. Who we share information with
We share personal information with service providers who help us run the Platform, and only as much as they need. They are bound by contract to protect it and to use it only to provide their service to us.
| Category of provider | What they do for us | What they receive |
|---|---|---|
| Cloud hosting and storage including Amazon Web Services |
Run the Platform's servers, databases and file storage | Account information, trip content including traveler information, and usage records |
| AI processing Amazon Web Services (Amazon Bedrock) |
Structures submitted bookings into itineraries, enhances booking descriptions, and translates itinerary content | The content submitted for an import, and the descriptive text sent for enhancement or translation — see sections 6.1 to 6.4 |
| Web search Tavily |
Web look-ups for the AxusBuilder import types listed in section 6.5 | Search text and the addresses of pages retrieved |
| App distribution Apple, Google |
Distribute our apps through the App Store and Google Play, and provide the crash reports in their developer consoles | Install, update and purchase information they collect under their own policies, and crash diagnostics where you have agreed to share them |
| Push notification delivery Apple, Google |
Deliver notifications to your device — see section 7.2 | Your device's notification token and the notification content |
| Maps Apple Maps on iOS, Google Maps on Android |
Display maps and places in the apps and on the Platform, using whichever map service is native to your device | The place or area being displayed. Your own location is not sent to us — it is used on your device, where the map software on your phone may use it to centre the map. See section 7.3 |
| Payment processing including Braintree (PayPal) |
Process card payments for subscriptions and credits | Your card and billing details, which you provide directly to them, plus your account email and the amount |
| Email delivery Amazon Web Services (Amazon SES) |
Send service, security, billing and marketing messages, and deliver itineraries that are shared with you | Recipient name and email address, and the content of the message or itinerary being sent |
| Website analytics Google (Google Analytics) |
Measure how our websites and the web platform are used, so we can improve them. Our mobile apps contain no third-party analytics software — see section 7.1 | Device, connection and usage information from our websites — see section 8 |
| Content delivery network Amazon Web Services (CloudFront) |
Serve our websites and app content quickly and reliably, and absorb malicious traffic | Your IP address and the requests your browser or app makes, in order to route and serve them |
| Customer support Zendesk |
Help-desk and ticketing for support requests | Account and contact information, and whatever you include in a support request |
At your direction. When an advisor shares an itinerary with a traveler or a colleague, or connects a third-party tool to their account, information goes where they send it. We also pass an itinerary into an Axus account when a service such as AxusBuilder is asked to do so.
With your travel agency. If you are a traveler using one of our apps, the agency that commissioned it is our customer and can see the trip information it holds about you, along with information about how their app is used.
Within Northstar Travel Group. Other companies in our corporate group may handle this information on our behalf for the purposes described in this policy, under the same protections.
Legal and corporate reasons. We may disclose information to comply with law, a subpoena or other legal process; to enforce our terms; or to protect the rights, safety or property of Axus, Northstar, our users or others. If we are involved in a merger, acquisition or sale of assets, information may be transferred as part of that transaction, and we will say so before it becomes subject to a different privacy policy.
10. Where information is processed
The Platform is operated from the United States, and information is stored and processed there. For AxusBuilder's AI processing we can be precise: it takes place within AWS in the United States, and because we use a cross-region service configuration an individual request may be served by any of several US regions rather than one fixed region. Uploaded files are stored in a US region.
If you use one of our apps while traveling, your information still returns to the United States for processing, wherever in the world you happen to be.
Our service providers may process limited information in other countries in the course of their own operations.
If you are outside the United States and use the Platform or one of our apps, the information you provide is transferred to the United States and processed there. Data-protection laws in the United States differ from those in some other countries, including the countries of the EEA and the United Kingdom.
11. How long we keep information
We keep personal information for as long as we need it for the purposes in this policy, and then delete it or remove its connection to an identifiable person.
| Information | How long |
|---|---|
| Account and organization information | For as long as the account is open, and for a period afterwards as needed for accounting, dispute-resolution and legal purposes |
| Trip content and traveler information, including uploaded source documents | Kept while the account is open, so advisors can revisit and reuse past trips and so we can investigate a reported problem. An advisor can ask us to delete specific trip content, or all of theirs, at any time — see section 13 |
| The offline copy of a trip on your device | Until you sign out, the trip is removed from your account, or you delete the app — see section 7.4 |
| Notification tokens | Until you turn notifications off or uninstall the app, after which the token stops working and is discarded |
| Subscription, credit, usage and purchase records | Retained for billing, tax and audit purposes for the period applicable law requires. These records identify the account and the amounts — they do not contain traveler information |
| Server, app diagnostic and security logs | A short operational period, then discarded in the ordinary course |
| Support correspondence | Retained for a reasonable period after a matter is resolved |
We are working toward shorter, fixed retention windows for the source documents and generated content behind an import, after which traveler information is removed automatically while the account's billing and usage history is kept. When that change takes effect we will update this policy and the date at the top of it.
12. How we protect information
- Encryption in transit. The Platform and the apps communicate over HTTPS, and our connections to databases, file storage and processing providers are encrypted.
- Access control. Trip content is visible to the account that owns it, to colleagues that account has authorized, to the travelers it is shared with, and to authorized Axus administrators. Internal access is limited to staff who need it.
- Sign-in protection. Sign-in attempts are rate-limited to frustrate password guessing, and session cookies are protected against access by scripts in your browser.
- File checks. Uploaded files are validated by their actual content, not only by their stated file type.
- Payment isolation. Card data is entered into the payment processor's own hosted fields, so it does not reach our systems.
- On your device. An app relies on your device's own protection for the copy of your trip it stores. A passcode or biometric lock, and keeping your operating system up to date, are the most effective safeguards there.
- Monitoring. We log and monitor access and activity to detect misuse.
No service can promise perfect security, and we won't. If we become aware of a breach affecting your information, we will notify you as required by law.
13. Your choices and rights
Whatever your location, you can ask us to:
- Access the personal information we hold about you.
- Correct information that is wrong or out of date.
- Delete trip content — specific trips and their source documents, or all of an advisor's. We will remove the submitted content, the generated itinerary and any uploaded file, and keep only the account, billing and usage records needed for accounting and audit.
- Export a copy of your information in a portable format.
- Close your account and have your information deleted, subject to records we must keep by law.
- Stop marketing email — use the unsubscribe link in any marketing message, or contact us. Service, security and billing messages continue while you hold an account.
Email support@axustravelapp.com and tell us what you need. We may ask you to verify your identity or that you control the account before we act, and we will respond within the time your local law allows.
13.1 If you are a traveler using one of our apps
Your quickest controls are on your own device: notifications and location can be switched off in device settings, and deleting the app removes the offline copy of your trip (see section 7.5).
For the trip information itself, your travel advisor or agency decides what is held and can change or remove it — so asking them is usually fastest. You can also contact us at the address above; where the information belongs to an agency's account, we will pass your request to them and support them in responding, and we will tell you that we have done so.
13.2 US state privacy rights
If you live in a US state with a comprehensive privacy law — including California, Colorado, Connecticut, Texas, Virginia and others — you may have rights to know what personal information we collect and disclose, to obtain a portable copy, to correct it, to delete it, and to opt out of the sale of personal information, targeted advertising and certain profiling.
We do not sell personal information, do not share it for targeted advertising or cross-context behavioral advertising, and do not profile people — so there is nothing for you to opt out of. You may designate an authorized agent to make a request on your behalf, and we will not discriminate against you for exercising these rights. California residents may also request information about disclosures to third parties for direct-marketing purposes.
13.3 EEA, UK and Swiss rights
If you are in the EEA, the UK or Switzerland, you may also have rights to object to or restrict processing, to data portability, to withdraw consent, and to lodge a complaint with your data protection authority.
Where we process traveler information, we do so on the instructions of the advisor or agency that submitted it. Requests about a traveler's information are best directed to that advisor, and we will support them in responding.
13.4 One limitation, stated plainly
Traveler information lives inside the trips belonging to the advisor who created them, and is not separately indexed by traveler. We can reliably find and delete information by account or by individual trip. We cannot reliably search every trip on the Platform for mentions of one particular person, so a request about a single traveler needs to identify the advisor, agency or trip concerned.
14. Responsibilities of advisors and agencies
When you put a traveler's information on the Platform, you are asking us to process it on your behalf. That means:
- You are responsible for having the right to share that information with us, and for giving any notice or obtaining any consent your own privacy policy or local law requires — including telling your travelers that AI tools are used to help prepare their itineraries, where that disclosure is required.
- Put in only what the trip needs. If a document contains information that has nothing to do with the trip, consider removing it first.
- Keep your sign-in credentials to yourself, manage your colleagues' access, and tell us promptly if you think an account has been accessed by someone else.
- Respond to your own travelers' privacy requests. We will help you where the information is held on the Platform.
If you offer one of our apps to your travelers, you are also responsible for:
- Telling your travelers what the app is, that Axus builds and operates it for you, and where to find this policy — the app store listing and your own privacy notice are the usual places.
- Making sure the privacy information in your app store listing matches what the app actually does. Apple and Google both require this, and we will tell you what the app collects so your listing is accurate.
- Not inviting anyone under 13 — or under the higher minimum age their local law sets — to hold their own account in the app. See section 15.
15. Children's information
The Axus Platform is a professional tool for travel advisors, and our traveler apps are not directed to children. You must be at least 13 to hold your own account in one of our apps, and where the law that applies to you sets a higher minimum — 16 in some European countries — that higher age applies instead. We do not knowingly collect personal information from anyone below the applicable age as a user of the Platform, and we comply with the Children's Online Privacy Protection Act (COPPA).
Advisors and agencies must not invite anyone below the applicable age to hold their own account in an app. A minor can of course be a traveler on a trip, which is a different thing.
A trip created by an advisor may include information about a minor traveling with their family. That information is in the trip because the advisor put it there; we handle it the same way as any other traveler information, on the advisor's instructions, and we do not use it for any purpose beyond providing the Platform's services.
If you believe someone below the applicable age has given us personal information directly, or holds an app account, contact us using the details in section 17 and we will delete it.
16. Changes to this policy
We may update this policy as the Platform changes. When we do, we will change the "Last updated" date at the top. If a change materially affects how we handle personal information, we will give account holders notice in the Platform or by email before it takes effect, and where a change affects an app we will make it available through the app as well. The current version is always available from the footer of our sites and from the privacy link in each app.
17. How to contact us
For any privacy question or request — including access, correction, deletion and export:
Email: support@axustravelapp.com
Phone: 1 201-902-2000
Mail:
Axus Travel App, a division of Northstar Travel Media, LLC
Attn: Privacy
301 Route 17 N, Suite 1150
Rutherford, NJ 07070
United States
If you are a traveler asking about information in an itinerary, please also tell us the name of the travel advisor or agency you booked with, and the name of the app if you are using one — see the limitation in section 13.4.
