Trust & Security
Trust and Security at Sayyad
Access and identity
- Sign-in via a secure magic link (OTP) or Google account. We do not store passwords on our servers.
- Each user has an isolated profile; no account can read another account's data.
- Administrative privileges are stored in a dedicated roles table and verified server-side via security-definer functions.
- Admin sessions are protected by an additional auth gate and logged for audit purposes.
Data we collect
- Account data voluntarily provided by the user (name, email, avatar).
- Search parameters (destinations, dates, traveler count) used to produce accurate results.
- Anonymized technical data (device, browser, partner-link click events) used for performance analytics.
- Error logs to improve reliability. We never collect card numbers or banking credentials.
Data protection and infrastructure
- All traffic between the user and the platform is encrypted using modern TLS/HTTPS certificates.
- The database enforces row-level security (RLS) policies that prevent cross-account access.
- Commercial partner keys and identifiers are stored in server-side secret vaults and are never exposed to the browser.
- Backup and recovery capabilities depend on our cloud infrastructure provider’s configuration and are not independently certified on this page.
Cookies and analytics
We use browser local storage to remember language and session, and lightweight first-party analytics events to measure partner-link performance and improve search quality. For commission attribution we may load affiliate scripts from networks such as Travelpayouts and Awin on Sayyad pages; those scripts may set or read referral-related identifiers according to each network’s setup. They are used for affiliate attribution, not cross-site advertising retargeting. We do not sell users’ personal data to any party.
Our relationship with travel partners
Sayyad is a metasearch and comparison engine only; we are not a travel agency and we do not complete bookings ourselves. When a user selects a partner offer they are redirected to the partner's official site, where booking and payment are completed under that partner's terms. Affiliate identifiers may be appended server-side through networks such as Travelpayouts and Awin when enabled; naming a network is not by itself evidence of a direct brand partnership with every seller shown in results.
Privacy requests and account deletion
To request a copy of your data, delete your account, or raise any privacy question, please contact the privacy team at hello@sayyad.travel . We respond within 7 business days.
Responsible vulnerability disclosure
We welcome responsible disclosure of security vulnerabilities. Please do not publish details publicly and contact our security team at hello@sayyad.travel . All reports are handled in strict confidence.