Skip to content

Travellers' personal data

A booking needs a lead traveller: name, email and phone. Some trips need more of every traveller, such as passports for a border crossing or weight for a balloon flight. tourpingo keeps this data for the seller; your site passes it through.

  • A booking never carries the lead’s contact details. Opening one shows its status, trip, price and payment, not the email or phone.
  • Sensitive details come back masked: passport numbers, dates of birth and medical notes. Only the seller’s staff with the right permission can see them in full, one record at a time, and each look is logged.
  • They are erased after the trip: passport numbers, dates of birth and medical notes are deleted a number of days after it ends, 30 by default. The travellers’ form says how many (erase_after_days); tell travellers.

Each option’s traveller_details says what the seller needs:

Field Meaning
scope lead: only the lead traveller. all: every traveller.
fields Which details, each required or not, and for which kinds of traveller.
collect checkout: before the booking is made. after_booking: by a deadline before the trip.
due_hours_before That deadline, in hours before the start.

Ask only what the option asks, and say why next to each field.

A traveller proves a booking is theirs with:

  • the booking’s token, from checkout’s answer or from the link in their emails: it opens the booking, sends a transfer receipt and cancels;
  • the lead’s email, with the reference: it opens the booking, never cancels it;
  • their session, when they are signed in to their account on the site.

The lead can also send each traveller a link of their own (POST /v1/public/bookings/{ref}/travellers/{position}/link), which opens only that traveller’s details, so passports aren’t passed around.

  • Treat a booking token like a password: keep it in the traveller’s session, not in page addresses you share, logs or analytics.
  • Keep contact_token only in the browser session that made the booking.
  • Don’t log request bodies with travellers’ details, and don’t copy them into your own database unless you need to and have told travellers.
  • Use HTTPS everywhere, and send travellers’ details only to tourpingo.