Mastercard Tourism Insights Platform (MTI)
The Mastercard Tourism Insights platform uniquely combines & displays multiple sources of data (Behaviour, Accommodation, Air Connectivity, Spend, Sustainability) for robust and actionable insights into the travel lifecycle, to optimise tourism management & marketing for a Destination Marketing Organisation (DMO) or any tourism related organism or administration.
Features
- Webplatform providing aggregated and anonymised crossborder spend insights
- Data mined from Mastercard, social media, pricing and booking data
- AI machine learning algorithms to translate behavioural patterns into insights
- Customised dashboard views according to local needs
- Spend insights by national, regional or city level
- Accurate, timely data updated monthly from multiple sources
- Modular pricing to fit any budget
- Behavioural patterns analysis
- Data delivered in a report format or a platform
- Actionable insights on sustainability & Benchmark
Benefits
- Map tourists journeys with views of spend
- Benchmark tourist journeys & spend with any competitor destination
- Make smarter investments and marketing campaigns by analysing trends
- Access multiple data sources through a single platform or report
- Extract insights to identify and attract the greatest value travellers
- Identify the trends affecting you and your destination competitors
- Get data based inputs to enhance visitor experience
- Manage seasonal & in-journey traffic to optimise required investment
- Identify needed changes to happen given strategy, segments and preferences
- Make sure tourism benefits local businesses and SMEs
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 7 5 5 4 3 9 9 9 0 3 5 6 4 3
Contact
MASTERCARD EUROPE
Simon Wright-Lakin
Telephone: +447789877549
Email: simon.wrightlakin@mastercard.com
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Advanced and predictive analytics
- Location and geospatial data management and analytics
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- Mastercard will support the Platform through regular maintenance procedures, such as monitoring of servers, review of disk space usage and database fragmentation, addition of commercially available security patches and upgrades, and review of event log files. Mastercard may update a Platform from time to time in its sole discretion as part of its ongoing mission to improve such Platform.
- System requirements
-
- Ability for receipt of datasets by email, API or SFTP
- Internet connection
User support
- Email or online ticketing support
- Yes
- Support response times
- Service support is during regular UK office hours only i.e. Mon-Fri 0900-1700. Responses are within 48 hours.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
- Customers will be assigned an account manager for onward queries and service management. They will agree regular service updates at which provision can be reviewed to ensure the service is meeting the customers’ needs.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
- A signed SOW and completed order form are required for delivery to be scheduled. On receipt of a newly signed contract for data delivery, the Mastercard delivery team will onboard the new customer and set up the training sessions, in accordance with the customer's preference.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Customers have a right to extract past data even following contract termination (downloads directly from the platform).
- End-of-contract process
- At contract end, datasets will no longer be delivered and support will no longer be available for data already provided.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- We aim to make our documents accessible and easy to use for all readers. Onboarding and offboarding documentation is provided in PDF format and uses clear language, consistent headings, and readable formatting to support accessibility.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- User defines report type and the data to be shown. User modifies the parameters and runs the macro (clicking a button) to update the report.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- API sandbox or test environment
- No
- Customisation available
- No
Scaling
- Independence of resources
- Our service is already scaled to global levels of demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Insights on tourist spending patterns, insights on tourists sentiment (social networks), insights on booking (flights).
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
- Other
- Other data at rest protection approach
- Data centres are fully air-gapped and accessible only to authorised personnel. For users working remote from office locations, VPN access is mandatory. Further detail is available upon request however is limited due to the sensitive nature of the assets and infrastructure we must safeguard.
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Data is delivered within CSV file format so export should be straightforward.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- Other
- Other protection between networks
-
The platform has several layers of security to protect the data and ensure that it is only accessible to authorised users:
-Access: using a unique user ID and password.
-Data: fully aggregated and anonymised.
-Transmission: fully encrypted.
-Storage: secured behind firewall.
More details can be provided on demand. - Data protection within supplier network
- Other
- Other protection within supplier network
- We can deliver via password protected email, API or SFTP, to the customer's preference.
Availability and resilience
- Guaranteed availability
- This service does not have a guaranteed availability level but has suffered no unplanned outages in the past two years of operation. Refunds to be agreed by the account manager with the customer.
- Approach to resilience
- Available on request.
- Outage reporting
- Information will be provided to customers prior to any planned service outage and on a reasonable endeavours basis if unplanned. Planned maintenance on average denies service for three hours every six months.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- This is not relevant to this service.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
-
– Center for Internet Security (CIS) Critical Security Controls for Effective Cyber Defense (CIS Controls)
– American National Standards Institute/International Society of Automation (ANSI/ISA)-62443-2-1 (99.02.01)-2009
– International Organisation for Standardisation (ISO)/International
Electrotechnical Commission (IEC) 27001
– NIST Special Publication (SP) 800-53 Rev. 4 - NIST SP 800-53 - Information security policies and processes
-
– Center for Internet Security (CIS) Critical Security Controls for EffectiveCyber Defense (CIS Controls)
– American National Standards Institute/International Society of Automation(ANSI/ISA)-62443-2-1 (99.02.01)-2009
– International Organisation for Standardisation (ISO)/International
Electrotechnical Commission (IEC) 27001
– NIST Special Publication (SP) 800-53 Rev. 4 - NIST SP 800-53 - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Change Control and Configuration Management will include a registered take back plan, a testing process, management approval, and updated documentation, in line with PCI DSS guidelines for the payment industry. More detail is available on request.
- Vulnerability management type
- Undisclosed
- Vulnerability management approach
- Some limited further detail is available upon request but because of the sensitive nature of the business Mastercard conducts in the payment sphere we are not at liberty to provide detail publicly.
- Protective monitoring type
- Undisclosed
- Protective monitoring approach
- Some limited further detail is available upon request but because of the sensitive nature of the business Mastercard conducts in the payment sphere we are not at liberty to provide detail publicly.
- Incident management type
- Undisclosed
- Incident management approach
- Some limited further detail is available upon request but because of the sensitive nature of the business Mastercard conducts in the payment sphere we are not at liberty to provide detail publicly.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Aeb6b76d-4733-46a6-a52e-fbf754914a21
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-