Loupit Travel and Expense
Security and privacy

Security and privacy

Card protection, audit, LGPD, encryption and access control — explained clearly so you can trust the platform.

Loupit is a travel tech for corporate travel and expense management. Because we process quotes, bookings and traveler data, security and privacy are part of the product, not an add-on. Below we explain, without jargon, how we protect payments, decisions and personal information — and where to find the privacy policy and terms of use.

How we protect your operation

Six security fronts working together on every booking and decision.

Card protection

The card number is not exposed inside the booking flow. We work with payment providers that use tokenization, and every transaction goes through an anti-fraud layer before authorization.

  • Card number tokenization — the agency works with tokens, not the PAN
  • Real-time risk scoring before every authorization
  • Detection of cloned, suspicious or blocklisted cards
  • Geolocation, velocity and buyer usage-pattern analysis
  • Reduced chargebacks for the agency and the company

Encryption

Data is encrypted in transit and at rest, end to end, so sensitive information is not readable by anyone who should not see it.

  • Encrypted connections in transit (TLS)
  • Sensitive data encrypted at rest
  • Tokens instead of card data in the operational flow
  • Separation between payment data and travel data

Access control

Each person accesses only what their role allows. Access is role-based, so you control who quotes, who approves, who issues and who sees financial reports.

  • Role-based permissions (requester, approver, agency, finance, administrator)
  • Multi-company and multi-cost-center access isolated from each other
  • Control over who sees quotes, approves amounts and issues
  • Logging of who accessed and changed each record

Audit and decision trail

Request, quotes received, chosen option, approver, changes and amounts are timestamped, forming a complete trail for audit and accountability.

  • Timestamped history of every step in the flow
  • Fraud-hold reason and final decision recorded
  • Report export for internal audit and disputes
  • Records available while the account is active

LGPD and privacy

We process personal data only to quote, issue and report the trip, with legal basis and respect for data subject rights. Full details are in the privacy policy.

  • Personal data used only for the corporate travel purpose
  • Data minimization: we collect what is needed to quote and issue
  • Data subject rights set out in the privacy policy
  • Role-restricted access to traveler information
  • Privacy policy and terms of use available and kept up to date

Operational security

Continuous monitoring and security practices applied to operations, to detect anomalies and keep the platform available when your company needs to book.

  • Monitoring of transactions and anomalous behavior
  • Security updates and patches applied continuously
  • 24/7 human support to react to travel incidents
  • Isolated environments between companies and agencies

Frequently asked questions about security and privacy

Common questions on card protection, audit, LGPD, encryption and access control.

Your travel governance starts with security

Sign your company up for free and see the policy, audit trail and reports in action. Need the legal detail? Check the privacy policy and terms of use.

Back to home