Privacy Policy
Effective date: 20 June 2026
1. Who we are
Tabi is operated by Kube Tech Pte. Ltd. (UEN: 202345103C), a company incorporated in Singapore. References to “Tabi”, “we”, “us”, or “our” in this policy refer to Kube Tech Pte. Ltd..
Registered in Singapore.
We take your privacy seriously. This policy explains what personal data we collect, why we collect it, how we use it, and your rights over it.
2. What data we collect
We collect the following categories of personal data:
- Account data - your name, email address, and phone number when you create an account or sign in.
- Travel data - itineraries, destinations, dates, and travel preferences you enter or save within the platform.
- Booking data - booking references, passenger details, and transaction records for purchases made through the platform.
- Usage data - pages visited, features used, session duration, device type, and browser type, collected to improve the service.
- Communications - messages you send to our support team.
- Email communications - if you forward booking confirmations to your trip’s unique email address (trip-<token>@bookings.tabitour.com) or email support@tabitour.com, we collect and store the sender’s email address, subject, and message body. Forwarded booking confirmations are parsed heuristically to extract booking details (supplier, dates, confirmation code) which are stored as pending bookings for your review. Support emails are forwarded to our triage inbox and you receive an auto-generated acknowledgement. These features are optional and feature-flag controlled; see Section 4 for the email providers involved.
We do not collect or store payment card details. Payment processing is handled entirely by regulated third-party processors.
3. How we use your data
We use your personal data to:
- Provide, operate, and improve the Tabi platform and services.
- Generate personalised travel itineraries based on your inputs.
- Process and manage travel bookings you make through the platform.
- Send booking confirmations, updates, and essential service communications.
- Respond to support requests and resolve issues.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal obligations.
We do not sell your personal data to third parties. We do not use your data for targeted advertising.
4. How we share your data
We share personal data only where necessary to deliver the service:
- Service providers - we use third-party providers for hosting, authentication, payment processing, booking fulfilment, and operational monitoring. These providers process data on our behalf under contractual obligations and are not permitted to use your data for their own purposes.
- Travel bookings - booking and payment for flights, hotels, or experiences are completed on the hosted checkout of our travel-technology partner, where you enter your own passenger and payment details. Once a booking is confirmed, we receive and store the resulting booking record (including passenger names, contact details, and the confirmation reference) to manage your trip, subject to the retention periods in Section 8.
- Location estimation - when you visit the platform, your IP address may be sent to a third-party geolocation provider to estimate your country for currency and regional defaults. We do not use it to identify you personally.
- Legal requirements - we may disclose data if required by law, court order, or to protect the rights and safety of our users.
Subprocessors. We use third-party service providers to operate the platform. Each is bound by a written processing agreement and may only use your data to deliver the contracted service to us. The categories are:
- Cloud hosting, authentication, and database (data is hosted in Singapore)
- Payment processing (card data is entered on the processor’s hosted checkout and never reaches Tabi servers)
- AI model providers for itinerary generation, content moderation, and policy classification (see Section 7)
- Transactional email delivery and inbound email parsing for booking forwards and support
- Bot and abuse protection on high-cost endpoints (limited to your IP address and browser challenge signals)
- Product analytics, error tracking, and (with consent) session replay
- Geolocation estimation for currency and regional defaults
- Travel booking partners for flights, hotels, activities, eSIMs, transport, and insurance — when you click through, only a referral identifier is passed; any details you enter on their site are governed by their own privacy policy
A current list of named subprocessors, the countries where they process data, and the data they receive is available on request to privacy@tabitour.com. Where we use Google APIs, see Section 5a for the specific scope and data flow.
5. Signing in with a social provider
When you sign in with Facebook, Google, or Apple, we receive your email address, your public display name, and a stable provider user ID. We use these only to create and identify your account. We do not request, store, or post anything else on your behalf. You can revoke our access at any time in your provider account settings; see our Data Deletion page for details.
Facebook sign-in (optional) - if you choose to sign in with Facebook, we receive your name, email address, and Facebook profile ID from Meta Platforms, Inc. We use these only to create and identify your Tabi account, never for advertising. You can revoke this at any time via your Facebook settings, or request automated deletion via our endpoint at https://www.tabitour.com/api/auth/facebook/data-deletion.
5a. Connecting your Google Calendar
Connecting your Google Calendar is optional. If you choose to connect it, Tabi uses Google’s OAuth flow to request a single, narrowly-scoped permission:
https://www.googleapis.com/auth/calendar.app.created— this scope lets Tabi create a new, dedicated secondary calendar in your Google account (named “Tabi”) and read, create, change, and delete events only on that calendar. Tabi cannot see, read, or modify your primary calendar or any other calendar in your Google account. The scope is technically restricted to the calendar Tabi itself creates.
What we do with this access. When you mark a flight or hotel booking as confirmed, Tabi writes that booking to the “Tabi” calendar as a calendar event (title, date/time, location, and a link back to the trip in Tabi). If you later update or cancel the booking in Tabi, we update or delete the corresponding event. That is the only use we make of this access.
What we store. To keep the connection working we store, on our servers in Singapore, your Google OAuth refresh token (encrypted at rest), the identifier of the “Tabi” calendar we created for you, and the identifiers of the events we have written. We do not store the contents of any other calendar, and we do not copy events out of Google Calendar into Tabi.
Limited Use. Tabi’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not transfer or sell this data to third parties, we do not use it for advertising or any form of retargeting, we do not use it to assess credit-worthiness or for lending purposes, and we do not allow humans to read it except (i) with your affirmative consent for a specific message, (ii) where necessary for security purposes such as investigating abuse, (iii) to comply with applicable law, or (iv) where the data has been aggregated and anonymised and is used for internal operations. We do not use Google Calendar data to train AI models.
Disconnecting and deleting. You can disconnect Google Calendar from Tabi at any time from your account connections page. Disconnecting immediately revokes our refresh token on Google’s side, deletes the token from our database, and stops further writes. The “Tabi” calendar and the events we previously wrote remain in your Google account so you do not lose your travel history; you can delete the calendar yourself from Google Calendar at any time, which removes all events Tabi created. You can also revoke Tabi’s access directly at myaccount.google.com/permissions.
6. Affiliate relationships
Tabi earns commission when you book travel products (flights, hotels, tours, eSIMs, transport, insurance) through links on this site. The commission is paid by the partner, not by you - the price you pay is the same. This funds the AI itinerary generation that’s free to use. We never let commissions decide what we recommend.
7. AI-generated content
Trip itineraries are generated using artificial intelligence. To produce personalised suggestions, details you provide - such as destination, travel dates, budget, and preferences - are processed by AI services. Before your inputs are sent to an AI provider, we automatically remove identifiers we can reliably detect, such as email addresses, phone numbers, and identification numbers. This automated filtering is a safety measure, not a guarantee - it cannot reliably detect personal details written in ordinary prose (for example, a name you type into a free-text request). Please do not enter names, contact details, or other personal information about yourself or others into free-text fields. AI processing may take place on servers located outside Singapore, including in the United States and, as a fallback for availability, in other countries. We minimise the personal data sent to these providers as described above.
AI-generated content is processed in accordance with the applicable terms of our AI service providers. Where a provider offers the option, we choose configurations that do not use your inputs to train their models. We cannot control how every third-party provider handles data beyond the options it makes available to us, which is why we minimise the personal data we send.
Content policy. Before your inputs reach any generation model, they are screened by independent, automated safety filters, including a third-party content-moderation service and an AI classifier tuned to travel-specific harms (such as commercial sex tourism or serious-crime intent) while still permitting legitimate edgy travel (dark tourism, red-light districts, adult nightlife). If a request is flagged as harmful, it is declined immediately. This screening takes place server-side; we log only the outcome and the action taken, not the input text.
8. Data retention
- Account and travel data - retained for as long as your account is active. When you delete your account, the personal data that identifies you is deleted promptly. Some records we are required to keep for legal, accounting, or fraud-prevention reasons (such as booking and transaction records) are retained for the period stated below in a form that no longer identifies you.
- Booking records - retained for 7 years for financial and legal compliance purposes.
- Usage and analytics data - retained for 13 months on a rolling basis.
- Support communications - retained for 2 years after ticket resolution.
- Google Calendar connection - the encrypted Google OAuth refresh token, the “Tabi” calendar ID, and the event IDs we have written are retained for as long as the connection is active. When you disconnect Google Calendar from Tabi (or delete your Tabi account), the refresh token is revoked with Google and deleted from our database within 7 days, along with the stored calendar and event identifiers. Events previously written to the “Tabi” secondary calendar remain in your Google account until you delete them there.
- Support email handling - support messages and any automatic acknowledgements are processed by our third-party email provider and retained according to its own retention policy. We apply basic loop-prevention to automatic replies.
9. Cookies and tracking
We use strictly necessary cookies to maintain your session and keep you signed in. We also use functional cookies to remember your preferences. We do not use third-party advertising cookies.
We use a first-party monitoring and product-analytics tool to measure performance, diagnose errors, and improve reliability. This includes recording a sample of user sessions (session replay), with form inputs masked. Where you are signed in, this data is linked to your account identifier. We use it only to operate and secure the Service, never for advertising.
10. Data security
All data is encrypted in transit (TLS 1.2 or higher), and we use industry-standard safeguards to protect data at rest. Access to personal data is restricted to authorised personnel on a need-to-know basis. We conduct regular security reviews and maintain incident response procedures. If a data breach occurs that is likely to result in significant harm to you, we will notify you and the Personal Data Protection Commission as required by law.
Despite our measures, no system is completely secure. If you believe your account has been compromised, contact us immediately at privacy@tabitour.com.
11. Your rights
Depending on your location and the data-protection laws that apply to you, you may have some or all of the following rights:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Withdraw consent at any time where processing is based on consent.
- Where required by the data-protection law that applies to you (for example, the EU or UK GDPR), additional rights such as erasure, restriction of or objection to processing, and data portability.
To exercise any of these rights, email us at privacy@tabitour.com. We will respond within the timeframe required by the applicable law, and otherwise within a reasonable period.
12. International transfers
Your data may be processed by our service providers in countries other than Singapore, including the United States. To maintain availability we may also route de-identified trip inputs to AI providers with servers in other countries. Where data is processed outside Singapore, we take reasonable steps - including contractual protections and minimising the personal data sent - to ensure it is protected to a standard comparable to Singapore’s Personal Data Protection Act.
13. Children
The Tabi platform is not directed at children under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, please contact us and we will delete it promptly.
14. Changes to this policy
We may update this policy from time to time. If changes are material, we will take reasonable steps to notify you, for example by email or by displaying a prominent notice in the platform, before the changes take effect. The effective date at the top of this page indicates when the policy was last revised.
15. Contact us
For privacy-related questions, requests, or complaints, contact our data protection team:
We have designated a Data Protection Officer responsible for overseeing our compliance with applicable data-protection law, who can be reached at the contact details below.
Kube Tech Pte. Ltd.Email: privacy@tabitour.com
Singapore residents may also refer concerns to the Personal Data Protection Commission at pdpc.gov.sg.
