Last updated February 7, 2023
Navan, Inc. and its affiliates (collectively, “Navan,” “we,” “us,” and "our") respect your privacy. We are a travel management platform that helps companies manage all of their corporate travel and expense management in one place as described in our Terms of Service. “You” may be a visitor to one of our Websites, a corporate customer of one or more of our Services (“Corporate Customer”), or an employee, traveller, or guest of a Corporate Customer (“Corporate Users”), or an independent business traveller ("Independent User").
Navan obtains Personal Information about you from various sources to manage our Website and provide our Services. There are two primary ways you may interact with Navan online.
Our Website at navan.com is publicly available and allows visitors to learn more about Navan, request a demo, submit questions, join a discussion thread on our community pages, and contact us. Personal Information may be collected through webforms where you type in your information, comments you choose to post on our community discussion boards, or automatically using tracking technologies, like cookies.
Our Services include our web application at app.navan.com and Navan mobile applications made available by us. The web application and our mobile applications (collectively, our “Apps”) provide the ability to search for and book travel, access traveller support, trip consolidation, as well as corporate administrative functionality including real-time reporting, traveller tracking, spend reconciliation, travel continuity, and traveller customer support. Navan Expense, a payments and expense application, provides the ability to make travel payments, track and submit business expenses, reconcile expense reports, link to personal accounts for expense submittals and reimbursements, import transactions, manage business expenses, and access customer support. These Services are offered through a corporate subscription.
“Personal Information” is information that identifies you as an individual or relates to an identifiable individual. The types of Personal Information we collect vary according to your interactions with us, for example, depending on whether you are a visitor to our website, a Corporate Customer of Navan, or an employee of Customer using our Services. The Personal Information we collect from our Corporate Customers or Corporate Users booking business travel or using our payment services is “Corporate Customer Data,” and the Personal Information we collect from our Website visitors, Corporate Users booking personal travel, Independent Users, or otherwise apart from providing Services is “Other Information.”
Website Visitors. If you visit or use our Website, you can fill out web forms to ask for a demo, sign-up for a newsletter, register for a Navan event or account, or take a survey. The specific Personal Information you provide on these forms, as well as any Personal Information you choose to provide on our community discussion boards, will be treated as Other Information. For example, when you respond to Navan emails or surveys, or create a user account to participate in our community discussion boards, we collect your name, contact details, profile photo, and any other information you choose to include in your email, survey response, or account profile.
Navan Services. When you use our Services, the Personal Information that you provide directly to us through our Services will be apparent from the context in which you provide the data. You may provide Personal Information to us when you book travel or use our expense management services. Personal Information may be provided to us directly by you or others, such as our Corporate Customer (e.g., your employer), a designated travel admin, or a travelling companion, on your behalf.
When you use Navan to register an account (“Account”) on our Services, we collect Personal Information, such as name, email, postal address, telephone number, financial data (payment card information and billing address), date of birth, gender, and emergency contact information (optional). When you use our Services for personal travel, we collect Personal Information such as your personal payment card information, billing address, and your personal email address. You may customise your travel profile by providing additional Personal Information, such as passport data, marital status, travel preferences, Known Traveler Number, TSA-Pre number, special meal preference, travel loyalty programmes, and COVID-19-related health data.
When you contact us for travel support through our chat feature on our Apps or by telephone, we collect Personal Information to verify your identification and help with your travel issue. In addition, we may record telephone calls between you and our representatives for training and quality assurance purposes. To the extent you may choose to provide us with feedback, suggestions, or recommendations about your experience, we collect that information and treat it as Other Information.
Other Methods. You may also choose to submit Other Information to us via other methods, including in response to marketing or a survey, through social media or online forums, through participation in an offer or promotion, or by giving us your business card or contact details at trade shows or other events.
Information Automatically Collected
In addition to the information you provide when you visit our Website and use our Services, we automatically collect Other Information about how you access and interact with our Website and Services. This information is a key part of how we improve your experience on Navan and provide you with personalised insights, recommendations, and travel notices. These may include things like cookies, browser web storage, web beacons, and similar technologies. These technologies record information about your use of our Website and Services.
• Browser and Device Information. Certain information is collected by most browsers or automatically through your device, such as your Media Access Control (MAC) address, IP address for purposes of connecting, computer type (Windows or Mac), screen resolution, operating system name and version, device manufacturer and model, language, Internet browser type, add-ons, and version and the name of the website or app you are using. We use this information to ensure that our Website and Services function properly.
• Log Information. When you use our Website, certain information is automatically collected in system logs about how you interact with our Website, such as your online activity, search terms, pages you visit, date and time of access, and cookie information, such as mouse clicks and keystrokes. This information is used to improve your experience on our Website and keep the Website free of bugs or errors. When you use our Services, we also may collect information about your online activity, such as trips viewed, travel reservations made, and other actions within our App. When you download and use one of our Apps, we and our service providers may track and collect App usage data, such as the date and time the App on your device accesses our servers and what information and files have been downloaded to the App based on your mobile device's identifier.
• Cookies. Navan uses a variety of cookies and similar technologies on our Websites and Services to help us collect Other Information. For more details about how we use these technologies, and your opt-out opportunities and other options, please see our Cookies Policy.
• Geolocation. When you use certain features of the Services, we may collect certain information like IP address, device information, or log information to estimate your location (e.g., city or state) and to offer you an improved user experience and provide you with personalised location-based services, such as identifying nearby hotels, airports, or merchants. For Navan Expense, you have the option to share location information when uploading receipts. Most mobile devices allow you to control or disable the use of location services for applications in device settings menu.
Information From Third Parties
We may obtain and rely on Personal Information about you from third parties and other sources, such as our business partners, Corporate Customers, and other Corporate and Independent Users of our Services. For example, Navan Corporate Customers may provide Personal Information about Corporate Users when they create new Accounts for their employees or guests. Organisers of meetings and events may share Personal Information when they are organising business travel for attendees. Corporate and Independent Users may provide Personal Information about their travel companions when booking personal travel. We may also work with different third-party partners to supplement information we collect directly from you.
As a travel management platform, when we conduct fraud monitoring, prevention, and detection activities, we may also receive Other Information about you from our business partners, financial service providers, identity verification services, and publicly available sources as necessary to confirm your identity and prevent fraud.
We use the information we collect from you and third parties to operate our Website and Services, communicate with you, conduct research and development to improve our Website and Services, and promote our Services.
Navan Services for Corporate Customers. Navan uses Corporate Customer Data for the purpose of providing our Services to Corporate Customers to enable their employees to book business travel and manage expenses. Corporate Customer Data will be used by Navan in accordance with Corporate Customer’s instructions, including any applicable terms in our agreements with our Corporate Customers, and as required by law. Navan is a processor of Personal Information and Corporate Customer is the controller. Some examples of how we use Corporate Customer Data:
• Account Information. To create, maintain, and secure accounts, including customising your travel profile.
• Reservations. To complete travel bookings, process your payments, provide travel confirmations, provide notifications and updates, and verify your information.
• Services Communications. To communicate with you regarding travel interruptions, flight changes, delays, travel alerts and restrictions, and cancellations; respond to inquiries and questions; and notify you of updates to our Services, product updates, and service announcements. Communications may be sent via email, push notifications, browser notifications, SMS, and postal mail.
• Payments and Expenses. To track and submit travel or other business expenses, reconcile expense reports, link to personal accounts for expense submittal and reimbursement, and manage expenses.
• Corporate Customer Support. To provide customer support when you contact us via chat, telephone, or email. We use this Corporate Customer Data to verify your identity and retrieve travel records related to your inquiries.
• Providing Personalised Services. To personalise your experience on our Services, such as to curate booking recommendations, identify nearby hotels and airports, record travel meal and seating preferences, and optimise search results. We provide these personalised services in accordance with the terms of our agreement with our Corporate Customer.
• Navan Digital Health Passport. To enable access to health documents required to meet airline and state/country requirements for travel.
Navan Services for Corporate Users Booking Personal Travel and Independent Users. Navan uses Other Information for the purpose of providing our Services to Corporate Users booking personal travel and Independent Users booking their own travel. Navan is the controller of Other Information and uses it, for example, as follows:
• Account Information. To create, maintain, and secure accounts, in order to manage our contractual relationship with you and/or to comply with a legal obligation.
• Reservations. To complete travel bookings, process your payments, provide travel confirmations, provide notifications and updates, and verify your information, in order to manage our contractual relationship with you or to comply with a legal obligation.
• Services Communications. To communicate with you regarding travel interruptions, flight changes, delays, travel alerts and restrictions, and cancellations; respond to inquiries and questions; and notify you of updates to our Services, product updates, and service announcements. Communications may be sent via email, push notifications, browser notifications, SMS, and postal mail. We engage in these communications to manage our contractual relationship with you, where we have a legitimate interest, or to comply with a legal obligation.
• Payments and Expenses. To track and submit travel or other business expenses, reconcile expense reports, link to personal accounts for expense submittal and reimbursement, and manage expenses, in order to manage our contractual relationship with you, where we have a legitimate interest, or to comply with a legal obligation.
• Traveller Support. To provide traveller support when you contact us via chat, telephone, or email. We use Other Information to verify your identity and retrieve travel records related to your inquiries. We engage in travel support in order to manage our contractual relationship with you or where we have a legitimate interest.
• Providing Personalised Services. To personalise your experience on our Services, such as to curate booking recommendations, identify nearby hotels and airports, record travel meal and seating preferences, customise your travel profile, and optimise search results. We provide these personalised services based on our legitimate interests, and with your consent to the extent required by applicable law.
• Navan Digital Health Passport. To enable access to health documents required to meet airline and state/country requirements for travel, in order to manage our contractual relationship with you or to comply with a legal obligation.
Accomplishing Our Business Purposes. Navan uses Other Information in furtherance of our legitimate interest in operating our Services, Websites, and business, as well as to comply with our legal obligations. Our business purposes include:
• Data analysis to improve our Services, develop new products and services, enhance, modify, and maintain our current products and Services, as well as undertaking quality and safety assurance measures;
• Security of our Website and Services. To protect the safety, integrity of our Corporate Customers and our Corporate and Independent Users, including monitoring, detecting, and preventing fraud, cyberattacks, attempts to commit identity theft, and unauthorised or illegal use of our Website or Services;
• Identification of usage trends. To better understand which parts of our Services are of most interest to users and focus our energies on meeting our users’ interests;
• Determine the effectiveness of our promotional campaigns, so that we can adapt our campaigns to the needs and interests of our users;
• Audits. To verify that our internal processes function as intended and to address legal, regulatory, or contractual requirements;
• Aggregated reports. To analyse and/or predict preferences in order to prepare aggregated trend reports on how our Website and Services are used, so we can improve our Website and Services.
Legal compliance. We use Other Information to verify the identity of our Corporate and Independent Users and Corporate Customers in order to comply with fraud monitoring, prevention and detection obligations, laws associated with the identification and reporting of illegal and illicit activity, such as AML (Anti-Money Laundering) and KYC (Know-Your-Customer) obligations, and financial reporting obligations. For example, we may be required to record and verify user identity for the purpose of compliance with legislation intended to prevent money laundering and financial crimes. These obligations are imposed on us by the operation of law, industry standards, and by our financial partners, and may require us to report our compliance to third parties, and to submit to third party verification audits.
Marketing and Events-Related Communications. When you use our Website or Services, we may use Other Information to send you marketing communications about our Services, products and features, and other news about Navan. Marketing communications may invite you to participate in our events, product demos, beta programme, or surveys. We will engage in marketing activities with your consent or where we have a legitimate interest.
Navan Events. When you participate in trade shows or other events, we may collect Other Information, such as your business contact details, to follow-up with you regarding an event, offer a demo of our Services, send you information that you requested, and, with your permission, include you in our marketing campaigns.
Consent. We may use Personal Information for other purposes that are clearly disclosed to you at the time you provide Personal Information or with your consent.
Aggregated and De-Identified Personal Information. We may aggregate and/or de-identify Personal Information such that it is no longer considered Personal Information. We do so to generate other data for our use, which we may use and disclose for any purpose, as it no longer identifies you or any other individual. We engage in these activities based on our legitimate interest.
We disclose your Personal Information in connection with providing our Services and the operation of our business.
Navan. We share Personal Information with other Navan entities in order to provide our Services and for internal administration purposes. These entities are Navan Labs BV (Netherlands), Navan BV (Netherlands), Reed & Mackay Travel Limited (UK), Navan Limited (UK), Comtravo GmbH, and Navan Pty Limited (Australia).
Service Providers. We share Corporate Customer Data and Other Information with a limited number of our service providers. We have service providers that provide services on our behalf, such as website hosting, data analysis, credit card payment processors, billing services, business analytics, distribution of surveys or sweepstakes programmes, information technology and related infrastructure, customer service, email delivery, identity verification, auditing, and fraud protection.
Your Choice to Disclose Personal Information. By participating in any community discussion boards, blogs, or other services to which you are able to post information and content, you may choose to disclose Personal Information. Please note that any information you post or disclose through these services will become public and may be available to other users and the general public.
Legal Compliance and Obligations. We share Personal Information as necessary or appropriate (i) to comply with applicable laws and regulation which may include laws outside your country of residence; (ii) to protect the rights, privacy, safety, and property of our Corporate Customers, you, others, or Navan and to enforce our Terms of Service; (iii) to collect amounts owed to us, and (iv) to respond to requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities (including national security requests) which may include authorities outside your country of residence.
Corporate Transactions. We may disclose or transfer Personal Information to a third party in the event we enter into, or intend to enter into, a transaction that alters the structure of our business, such as a reorganisation, merger, sale, joint venture, assignment, transfer, or disposition of all or any portion of our business, assets, or stock (including in connection with any bankruptcy or similar proceedings).
Underwriting/Risk management. We share Personal Information of our Corporate Customers who are purchasing Navan services with third parties for the purposes of setting credit limits and managing financial risk.
You have choices regarding our use and disclosure of your Personal Information. You may opt out from:
• Receiving marketing-related emails from us. If you no longer want to receive marketing-related emails from us, you may opt-out via the “unsubscribe” link included in such emails. Please note that if you opt-out of receiving marketing-related emails from us, we may still send you important administrative messages that are required to provide you with our Services, from which you cannot opt-out. We will try to comply with your request(s) as soon as reasonably practicable.
• Receiving Travel Alerts from Us. You can manage your communication preferences by visiting your Account Profile and then Settings. You can choose which types of travel alerts to receive and the method for receiving the alerts. You may also opt-out of SMS alerts in your Account Settings.
Accessing and Changing Your Personal Information. You may access, update, correct, or delete your profile information and preferences at any time by logging in to your Account through our Apps.
Your Data Protection Rights. In accordance with applicable law and depending on where you reside, you may have the right to: (i) request confirmation of whether we are processing your Personal Information; (ii) obtain access to or a copy of your Personal Information; (iii) receive an electronic copy of Personal Information that you have provided to us, or ask us to send that information to another company (the “right of data portability”); (iv) object to or restrict our uses of your Personal Information; (v) seek correction or amendment of inaccurate, untrue, incomplete, or improperly processed Personal Information; (vi) withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal; and (vii) request erasure of Personal Information held about you by us, subject to certain exceptions prescribed by law.
If you would like to exercise any of these rights, please email us at [email protected] or contact us as specified in the Contact Us section below. We will respond to your request consistent with applicable law and as soon as reasonably practicable. To protect your privacy, we will verify your request using the information associated with your account, including email address.
Please note that if you use our Services on behalf of an organisation that is our Customer (e.g., your employer), that Customer may be responsible for fulfilling the rights listed above.
We maintain commercially reasonable technical and organisational measures designed to protect Personal Information within our organisation. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure, please Contact Us immediately.
We retain Personal Information for as long as needed or permitted in light of the purpose(s) for which it was obtained and consistent with applicable law. If you are a Corporate Customer or a Corporate or Independent User, we retain your Personal Information as long as we are providing Services to you. We may retain Personal Information and certain records of your transactions to the extent necessary to comply with our legal and regulatory obligations. We may also retain Personal Information in light of our legal position such as in regard to applicable statute of limitations, litigation, or regulatory investigations.
In addition, we are not responsible for the information collection, use, disclosure, or security policies or practices of other organisations, such as Facebook, Apple, Google, Microsoft, or any other app developer, app provider, social media platform provider, operating system provider, wireless service provider, or device manufacturer, including with respect to any Personal Information you disclose to other organisations through or in connection with our Apps or social media pages.
Our Website and Services are not directed to individuals under the age of sixteen (16), and we do not knowingly collect Personal Information from individuals under 16.
Unless we request it, we ask that you not send us, and you not disclose, any sensitive Personal Information (e.g., social security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background, or trade union membership) on or through the Services or Website, or otherwise to us.
Your Personal Information may be stored and processed in any country where we have facilities or in which we engage service providers, and by using our Website or Services you understand that your information may be transferred to countries outside of your country of residence, including the United States, which may have data protection laws that are different from those of your country. In certain circumstances, courts, law enforcement agencies, regulatory agencies or security authorities in those other countries may be entitled to access your Personal Information.
European Economic Area. Some non-EEA countries are recognised by the European Commission as providing adequate level of data protection according to EEA standards (the full list of these countries is available here). For transfers from the EEA to countries not considered adequate by the European Commission, we endeavour to put in place adequate measures to ensure your Personal Information is safeguarded consistent with the requirements of applicable laws. You may obtain more information by contacting us in accordance with the “Contact Us” section below.
You may contact our Data Protection Officer at [email protected]. You may also lodge a complaint with the EU/EEA data protection authority for your country or region where you have your residence, place of work, or where an alleged infringement of applicable data protection law occurs.
In compliance with the Privacy Shield Principles, Navan commits to resolve complaints about our collection or use of your personal information. EU individuals with inquiries or complaints regarding our Privacy Shield practices should first contact [email protected].
Navan has further committed to refer unresolved privacy complaints under the Privacy Shield Principles to an independent dispute resolution mechanism, the BBB EU PRIVACY SHIELD, operated by BBB National Programs. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit https://bbbprograms.org/privacy-shield-complaints for more information and to file a complaint. This service is provided free of charge to you.
As part of our participation in Privacy Shield, we are subject to the investigatory and enforcement powers of U.S. The Federal Trade Commission and other authorised statutory bodies. Under certain conditions, more fully described on the Privacy Shield website, you may be entitled to invoke binding arbitration when other dispute resolution options do not satisfactorily resolve your concerns.
Although Navan complies with Privacy Shield, it does not rely on it as a transfer mechanism for transfers of data to the United States.
Russian Federation. The services hereunder are not intended for use by Russian citizens who are resident in Russia. If you are a Russian citizen residing in Russia, any Personal Information that you provide to us through our Website or Services will be solely at your own risk and responsibility. You expressly agree that we may gather your Personal Information and will process this data in the United States and in other countries, and that you will not hold us accountable for any potential non-observance of Russian law.
Because email communications are not always secure, please do not include credit card or other sensitive information in your emails to us.
Already have an account? Log in.