Who we are
TravelArt is the controller of the personal data described here. You can reach us at any time at travelart@gmail.com.
We do not sell personal data, we do not share it with advertisers, and we do not build advertising profiles.
What we collect
We collect only what the product needs in order to work.
- Account data. When you sign in with Google, Facebook or Apple we receive your name, email address, profile picture and the provider’s user ID. We never see or store the password you use with that provider.
- Trip data. Your quiz answers — city, trip length, daily start and end times, where you are staying, trip format and interests — the itineraries generated from them, the edits you make, the two versions we keep of each itinerary, and the activities you add to your Wish List.
- Anonymous session data. You can take the quiz, generate an itinerary and edit it without an account. Until you sign in, all of that lives in your browser’s local storage on your own device and never reaches our servers.
- Usage data. Technical information your browser sends — IP address, device and browser type, referring page, pages viewed — together with product events such as generating an itinerary, opening a ticket link and downloading a PDF.
- Messages you send us. If you email us, we keep your message and our reply.
We take no payments, so we never collect card or bank details. We do not ask for special-category data such as health, religious or political information — please do not put it into itinerary names or notes.
Why we use it
| What | Why | Legal basis |
|---|---|---|
| Account data | Create your account, sign you in, and show your name and picture in the app | Performance of our contract with you |
| Trip data | Generate, save, restore, export and reorder your itineraries and Wish List | Performance of our contract with you |
| Usage data | Keep the service secure and reliable, find and fix problems, and understand which features are used | Our legitimate interest in running and improving the service |
| Analytics cookies | Measure product usage at an aggregate level | Your consent, where local law requires it |
| Messages you send us | Answer your question and keep a record of what we agreed | Legitimate interest |
| Any of the above | Meet legal obligations and establish or defend legal claims | Legal obligation, legitimate interest |
Where we rely on your consent you can withdraw it at any time. Withdrawing it does not affect processing that already happened.
International transfers
Our providers operate globally, so your data may be processed outside the country you live in, including outside the European Economic Area and the United Kingdom. Where that happens we rely on an adequacy decision or on the European Commission’s Standard Contractual Clauses to protect it.
How long we keep it
- Account and trip data — for as long as your account exists. When you delete your account we remove it within 30 days, and it drops out of encrypted backups within a further 90 days.
- Anonymous itineraries — until you or your browser clear local storage.
- Analytics data — in aggregate for up to 14 months.
- Emails — up to 24 months after our last exchange.
Your rights
Depending on where you live, you have some or all of these rights over your personal data:
- Access — get a copy of what we hold about you.
- Rectification — correct anything wrong. Your display name and picture are editable in Profile Settings.
- Erasure — have it deleted. Data Deletion explains how.
- Restriction and objection — ask us to pause or stop processing, including anything we do on the basis of legitimate interests.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent — at any time, for anything based on consent.
To exercise any of these, email travelart@gmail.com from the address you sign in with. We respond within 30 days. If you are in the EEA or the UK and you think we have handled your data badly, you can also complain to your local data protection authority.
How we protect it
- All traffic runs over HTTPS, and data is encrypted at rest by our hosting providers.
- We never handle your provider password — sign-in is delegated to Google, Facebook or Apple.
- Every table holding user data is protected by database row-level security, so a query made by one account can only ever return that account’s own rows.
- Administrative keys stay on the server and are never sent to the browser.
No online service can promise perfect security. If a breach ever affects your data we will notify you and the relevant regulator as the law requires.
Children
TravelArt is not intended for children under 16, or under 13 where local law sets a lower age. We do not knowingly collect their data. If you believe a child has given us personal data, email us and we will delete it.
Changes to this policy
We may update this policy as the product develops. The date at the top always shows the current version, and we will give notice in the app before a material change takes effect.
Contact us
Questions, requests or complaints about privacy: travelart@gmail.com.