TravelArt

Legal

Privacy Policy

Last updated 24 August 2026

TravelArt builds personalised city itineraries. This policy explains what personal data we collect when you use the service, why we collect it, who we share it with, and the choices you have. It covers our website and everything you can do on it.

Who we are

TravelArt is the controller of the personal data described here. You can reach us at any time at travelart@gmail.com.

We do not sell personal data, we do not share it with advertisers, and we do not build advertising profiles.

What we collect

We collect only what the product needs in order to work.

  • Account data. When you sign in with Google, Facebook or Apple we receive your name, email address, profile picture and the provider’s user ID. We never see or store the password you use with that provider.
  • Trip data. Your quiz answers — city, trip length, daily start and end times, where you are staying, trip format and interests — the itineraries generated from them, the edits you make, the two versions we keep of each itinerary, and the activities you add to your Wish List.
  • Anonymous session data. You can take the quiz, generate an itinerary and edit it without an account. Until you sign in, all of that lives in your browser’s local storage on your own device and never reaches our servers.
  • Usage data. Technical information your browser sends — IP address, device and browser type, referring page, pages viewed — together with product events such as generating an itinerary, opening a ticket link and downloading a PDF.
  • Messages you send us. If you email us, we keep your message and our reply.

We take no payments, so we never collect card or bank details. We do not ask for special-category data such as health, religious or political information — please do not put it into itinerary names or notes.

Why we use it

WhatWhyLegal basis
Account dataCreate your account, sign you in, and show your name and picture in the appPerformance of our contract with you
Trip dataGenerate, save, restore, export and reorder your itineraries and Wish ListPerformance of our contract with you
Usage dataKeep the service secure and reliable, find and fix problems, and understand which features are usedOur legitimate interest in running and improving the service
Analytics cookiesMeasure product usage at an aggregate levelYour consent, where local law requires it
Messages you send usAnswer your question and keep a record of what we agreedLegitimate interest
Any of the aboveMeet legal obligations and establish or defend legal claimsLegal obligation, legitimate interest

Where we rely on your consent you can withdraw it at any time. Withdrawing it does not affect processing that already happened.

Cookies and local storage

  • Essential cookies. Our authentication provider sets “sb-…” cookies that keep you signed in and rotate your session token. Sign-in cannot work without them, so they are not optional.
  • A short-lived sign-in marker. A “travelart.post-signin” cookie lives for two minutes after you sign in, so an itinerary you created anonymously can be attached to your account.
  • Local storage. Your quiz answers and any itinerary you have not saved are kept on your device so a reload does not lose them. Clearing your browser data for this site removes them permanently.
  • Analytics. Google Analytics sets cookies to measure product usage. You can block them in your browser or with an extension and the rest of the site keeps working.

Who we share it with

We share personal data only with the providers that run TravelArt for us, and only so they can do that job. Each is bound by a data processing agreement.

ProviderWhat it handlesWhere
SupabaseDatabase, authentication and file storage for avatarsAsia Pacific (Tokyo)
VercelWebsite hosting and content deliveryGlobal edge network
Google Maps PlatformMap rendering, travel times between activities, place details and photosGlobal
Google AnalyticsAggregate product usage measurementGlobal
Google, Meta, AppleSign-in. They learn that you signed in to TravelArt and give us the profile fields listed aboveGlobal
Ticket partners such as GetYourGuide or ViatorOnly the ticket links you choose to open, which load in a new tab under the partner’s own termsGlobal

We may also disclose data where the law requires it, where it is needed to protect our rights or someone’s safety, or as part of a merger or sale of the business — in which case we will tell you before it happens.

International transfers

Our providers operate globally, so your data may be processed outside the country you live in, including outside the European Economic Area and the United Kingdom. Where that happens we rely on an adequacy decision or on the European Commission’s Standard Contractual Clauses to protect it.

How long we keep it

  • Account and trip data — for as long as your account exists. When you delete your account we remove it within 30 days, and it drops out of encrypted backups within a further 90 days.
  • Anonymous itineraries — until you or your browser clear local storage.
  • Analytics data — in aggregate for up to 14 months.
  • Emails — up to 24 months after our last exchange.

Your rights

Depending on where you live, you have some or all of these rights over your personal data:

  • Access — get a copy of what we hold about you.
  • Rectification — correct anything wrong. Your display name and picture are editable in Profile Settings.
  • Erasure — have it deleted. Data Deletion explains how.
  • Restriction and objection — ask us to pause or stop processing, including anything we do on the basis of legitimate interests.
  • Portability — receive your data in a structured, machine-readable format.
  • Withdraw consent — at any time, for anything based on consent.

To exercise any of these, email travelart@gmail.com from the address you sign in with. We respond within 30 days. If you are in the EEA or the UK and you think we have handled your data badly, you can also complain to your local data protection authority.

How we protect it

  • All traffic runs over HTTPS, and data is encrypted at rest by our hosting providers.
  • We never handle your provider password — sign-in is delegated to Google, Facebook or Apple.
  • Every table holding user data is protected by database row-level security, so a query made by one account can only ever return that account’s own rows.
  • Administrative keys stay on the server and are never sent to the browser.

No online service can promise perfect security. If a breach ever affects your data we will notify you and the relevant regulator as the law requires.

Children

TravelArt is not intended for children under 16, or under 13 where local law sets a lower age. We do not knowingly collect their data. If you believe a child has given us personal data, email us and we will delete it.

Changes to this policy

We may update this policy as the product develops. The date at the top always shows the current version, and we will give notice in the app before a material change takes effect.

Contact us

Questions, requests or complaints about privacy: travelart@gmail.com.

Related pages

Still have a question?

Write to us at travelart@gmail.com and a human will answer.

Go to Home Page