Skip to main content

Trust & Security

Trust and Security at Sayyad

At Sayyad (sayyad.travel) the trust of travelers and commercial partners is foundational to our business. This page describes the technical and operational controls currently in place to protect user data, preserve the integrity of search results, and describe how we work with travel partners and affiliate networks when those relationships are enabled. The content is maintained by the Sayyad team and is updated as the product evolves; it is not a third-party certification.

Access and identity

  • Sign-in via a secure magic link (OTP) or Google account. We do not store passwords on our servers.
  • Each user has an isolated profile; no account can read another account's data.
  • Administrative privileges are stored in a dedicated roles table and verified server-side via security-definer functions.
  • Admin sessions are protected by an additional auth gate and logged for audit purposes.

Data we collect

  • Account data voluntarily provided by the user (name, email, avatar).
  • Search parameters (destinations, dates, traveler count) used to produce accurate results.
  • Anonymized technical data (device, browser, partner-link click events) used for performance analytics.
  • Error logs to improve reliability. We never collect card numbers or banking credentials.

Data protection and infrastructure

  • All traffic between the user and the platform is encrypted using modern TLS/HTTPS certificates.
  • The database enforces row-level security (RLS) policies that prevent cross-account access.
  • Commercial partner keys and identifiers are stored in server-side secret vaults and are never exposed to the browser.
  • Backup and recovery capabilities depend on our cloud infrastructure provider’s configuration and are not independently certified on this page.

Cookies and analytics

We use browser local storage to remember language and session, and lightweight first-party analytics events to measure partner-link performance and improve search quality. For commission attribution we may load affiliate scripts from networks such as Travelpayouts and Awin on Sayyad pages; those scripts may set or read referral-related identifiers according to each network’s setup. They are used for affiliate attribution, not cross-site advertising retargeting. We do not sell users’ personal data to any party.

Our relationship with travel partners

Sayyad is a metasearch and comparison engine only; we are not a travel agency and we do not complete bookings ourselves. When a user selects a partner offer they are redirected to the partner's official site, where booking and payment are completed under that partner's terms. Affiliate identifiers may be appended server-side through networks such as Travelpayouts and Awin when enabled; naming a network is not by itself evidence of a direct brand partnership with every seller shown in results.

Privacy requests and account deletion

To request a copy of your data, delete your account, or raise any privacy question, please contact the privacy team at hello@sayyad.travel . We respond within 7 business days.

Responsible vulnerability disclosure

We welcome responsible disclosure of security vulnerabilities. Please do not publish details publicly and contact our security team at hello@sayyad.travel . All reports are handled in strict confidence.