Effective Date: June 30, 2026
This Mobile App Privacy Policy supplements our general Privacy Policy and applies specifically to the TravelCard mobile application for iOS and Android, operated by Travel Card Ltd. ("Travel Card", "we", "us", or "our").
Our general Privacy Policy governs all data practices across our platform. This supplement describes the additional information the mobile app collects and the device features it uses. Where this supplement conflicts with the general Privacy Policy on an app-specific matter, this supplement controls. It complies with Israeli privacy laws, including the Privacy Protection Law, 1981, and Amendment No. 13.
To sign you in and operate your account, we process your name, email address, and phone number. Authentication is handled via Firebase Authentication using phone number, one-time passcode (OTP), password, or Apple Sign-In.
The app processes data needed for corporate travel and expense management, including payment card details, transactions, receipts (including images you capture), allocations, and travel bookings (such as hotels and trips).
We collect device identifiers, operating-system version, a push-notification token, app usage and analytics events, and crash and diagnostic data to keep the app secure, reliable, and improving.
The app requests the following permissions, each only for the stated purpose:
You can grant or revoke any of these permissions at any time in your device settings.
Face ID, Touch ID, and equivalent biometric checks are performed entirely by your device's operating system. We never receive, see, or store your biometric data. When you enable biometric unlock, your authentication token is stored securely in your device's keychain / secure storage and is accessible only on that device while it is unlocked.
With your consent, we send push notifications about your card and account activity. Delivery uses Expo's push service together with Apple Push Notification service (APNs) and Google Firebase Cloud Messaging (FCM). You can disable notifications at any time in your device settings.
The app relies on the following service providers, each governed by its own privacy terms:
We share only the data necessary for these services to function, consistent with Section 5 of our general Privacy Policy.
Authentication and device tokens are kept in your device's secure keychain / encrypted storage. The app may also cache data locally for performance. This local data is removed when you log out or uninstall the app.
You download the app from the Apple App Store or Google Play. Those platforms process certain data (such as download and basic usage information) under their own privacy policies, which are outside our control.
The app is intended for business use by individuals aged 18 or older. We do not knowingly collect personal information from anyone under 18.
You can manage permissions and notifications at any time in your device settings. To exercise your rights to access, correct, or delete your personal information under Israeli law and our general Privacy Policy, contact us at privacy@travelcard.io.
We may update this supplement from time to time. Material changes will be reflected by updating the effective date above and, where appropriate, through an in-app notice.
Questions about this Mobile App Privacy Policy can be directed to privacy@travelcard.io. Travel Card Ltd., Tel Aviv, Israel.
© 2026 Travel Card Ltd. All rights reserved.