Privacy Policy

Last updated: December 23, 2024

We respect your privacy and are strongly committed to keeping secure any information we obtain from you or about you. This Privacy Policy describes our practices with respect to Personal Data that we collect from or about you when you use our website, applications, and services (collectively, "Services").

1. Personal Data We Collect

Personal Data You Provide

We collect Personal Data if you create an account to use our Services or communicate with us as follows:

  • Account Information: When you create an account, we collect your name, email address, account credentials, payment information, subscription status, and transaction history.
  • User Content: We collect the content you provide to our AI travel assistant, including your travel queries, preferences, itinerary requests, and uploaded files such as images or documents.
  • Communication Information: If you contact us via email or social media, we collect your name, contact information, and message contents.
  • Travel Preferences: Information about your travel style, dietary requirements, budget preferences, and destination interests that you share with our AI assistant.

Personal Data We Receive from Your Use of Services

  • Log Data: Your IP address, browser type and settings, device information, date and time of requests, and interaction patterns with our Services.
  • Usage Data: Information about how you use our Services, including features used, content viewed, time spent, and user preferences.
  • Device Information: Device name, operating system, device identifiers, browser type, and device settings.
  • Location Information: General location derived from IP address for security and service improvement. Precise location only if you explicitly provide it.
  • Cookies and Similar Technologies: We use cookies to operate our Services, maintain preferences, and improve your experience.

Information from Other Sources

We receive information from trusted partners for fraud prevention, marketing purposes, and from publicly available sources to improve our travel recommendation models.

2. How We Use Your Personal Data

We may use Personal Data for the following purposes:

  • To provide and maintain our Services: Including responding to your travel planning requests, generating itineraries, and providing personalized recommendations through our AI assistant.
  • To improve and develop our Services: Including training and improving our AI models, developing new features, and conducting research to enhance user experience.
  • To communicate with you: Including sending service updates, travel recommendations, marketing communications (with your consent), and responding to your inquiries.
  • To ensure security and prevent fraud: Including detecting and preventing unauthorized access, fraud, illegal activity, or misuse of our Services.
  • To comply with legal obligations: Including responding to legal requests and protecting the rights, privacy, and safety of our users and third parties.
  • To process payments and manage subscriptions: Including processing transactions, managing billing, and tracking subscription status.

AI Model Training: We may use your travel queries and preferences to improve our AI travel assistant, but we maintain strict privacy protections and do not associate this data with your personal identity when used for training purposes.

3. Disclosure of Personal Data

We may disclose your Personal Data in the following circumstances:

  • Vendors and Service Providers: We share data with trusted partners including hosting providers (Supabase), payment processors (FastSpring), analytics services (PostHog, Plausible), and other service providers who assist us in operating our Services.
  • Business Transfers: If we are involved in a merger, acquisition, bankruptcy, or other transaction, your Personal Data may be transferred as part of that transaction.
  • Government Authorities: We may share data to comply with legal obligations, protect and defend our rights, detect fraud, ensure safety and security, or protect against legal liability.
  • Affiliates: We may share data with our affiliates who will use it consistently with this Privacy Policy.
  • Third-Party Integrations: When you use features that connect with third-party services (such as Google authentication or Telegram integration), information may be shared according to your choices and their privacy policies.
  • Anonymous and Aggregated Data: We may share anonymized or aggregated data that cannot identify you for research, analytics, or business purposes.

Important: We do not sell your Personal Data to third parties for marketing purposes. We only share data as necessary to provide our Services or as required by law.

4. Data Retention

We retain your Personal Data only as long as necessary to provide our Services or for other legitimate business purposes such as:

  • The duration of your account and any applicable retention periods after account deletion
  • Legal requirements and compliance obligations
  • Fraud prevention and security purposes
  • Resolving disputes or enforcing our agreements

Chat Data: Your conversations with our AI assistant are retained according to your settings. You can delete individual conversations or your entire chat history at any time through your account settings.

5. Security of Your Information

We implement commercially reasonable technical, administrative, and organizational measures designed to protect Personal Data from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. Our security measures include:

  • Encryption of data in transit and at rest
  • Access controls and authentication systems
  • Regular security monitoring and updates
  • Secure hosting infrastructure (Supabase)

However, no Internet or email transmission is ever fully secure. Therefore, you should take special care in deciding what information you provide to our Services.

6. Your Privacy Rights

Depending on where you live, you may have certain statutory rights in relation to your Personal Data:

  • Access: Request access to your Personal Data and information about how it is processed
  • Correction: Request correction of inaccurate or incomplete Personal Data
  • Deletion: Request deletion of your Personal Data from our systems
  • Portability: Request transfer of your Personal Data to a third party
  • Restriction: Request that we limit how we process your Personal Data
  • Object: Object to our processing of your Personal Data
  • Withdraw Consent: Withdraw consent where we rely on consent for processing
  • Lodge Complaints: File complaints with your local data protection authority

How to Exercise Your Rights

You can exercise many of these rights directly through your TravelBot account settings. For other requests, please contact us at privacy@travelbot.me or info@travelbot.me.

Account Controls: You can access, update, and delete much of your Personal Data directly through your account settings, including your travel preferences, chat history, and account information.

7. Children's Privacy

Our Services are not directed to children under 13 years of age. We do not knowingly collect Personal Data from children under 13. If you believe a child under 13 has provided Personal Data to us, please contact us at privacy@travelbot.me and we will promptly delete such information.

Users between 13 and 18 years of age must have permission from their parent or guardian to use our Services.

8. International Data Transfers

TravelBot processes your Personal Data on servers located in various jurisdictions, including the United States. While data protection laws vary by country, we apply the protections described in this policy to your Personal Data regardless of where it is processed. We only transfer data pursuant to legally valid transfer mechanisms and appropriate safeguards.

9. Third-Party Services

Google User Data

When you use Google authentication, we access and store your Google profile information (name, email) securely on Supabase for:

  • Account creation and authentication
  • Managing token limits and subscription status
  • Providing personalized travel recommendations

Other Integrations

  • Telegram: When you use Telegram integration, we process your Telegram user information according to your preferences
  • Memobase: Our memory system stores your travel preferences and conversation history to provide personalized recommendations
  • Payment Processors: FastSpring and Google Play handle payment information according to their privacy policies

10. U.S. State Privacy Rights

Residents of certain U.S. states may have additional privacy rights under state laws such as the California Consumer Privacy Act (CCPA) and Virginia Consumer Data Protection Act (VCDPA). These may include:

  • The right to know what Personal Data we collect and how we use it
  • The right to delete Personal Data we have collected
  • The right to correct inaccurate Personal Data
  • The right to opt out of "sale" or "sharing" of Personal Data (we do not sell or share Personal Data)
  • The right to non-discrimination for exercising these rights

To exercise these rights, please contact us using the information provided below. We may need to verify your identity before processing your request.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by email (if you have provided an email address) or by posting a prominent notice on our website before the changes take effect.

We encourage you to review this Privacy Policy periodically to stay informed about how we collect, use, and protect your information.

12. How to Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

We will respond to your inquiry within a reasonable timeframe and in accordance with applicable law.