Privacy
Draft for legal review — not yet in force. Written to be specific and complete, but not yet reviewed by a qualified lawyer.
Last updated 28 July 2026.
The short version
- You can browse the whole feed without telling us who you are. No account, no tracking wall.
- We hold what a trip-planning product needs to hold, and we have written down all of it below. There is no category hiding in a footnote.
- Your private budget cap is private from everyone — your group, your organizer, and every export they can run. We use it to compute one derived signal and nothing else.
- Location sharing is opt-in per person per trip and is deleted when the trip ends. Not archived. Deleted.
- We do not sell your data. We do not run advertising. There is no ad network, and no analytics tracker, anywhere in this product.
- Your private trip content is not used to train AI models. Not ours, not our provider’s.
- Export and delete are buttons in Settings, not a support ticket. You do not have to ask us, and you do not have to explain why.
- Everything is hosted in the EU.
1. Who is responsible for your data
The controller of your personal data is the company that operates Voyade, established in Denmark, in the European Union.
Company details. The controller’s registered name, company registration number and registered address belong in this box, and they are added here at incorporation — before this notice takes effect. Until then this document is a draft and binds nobody. Everything below is drafted on the basis of establishment in Denmark; if that changes, the lead supervisory authority in §9 and the statutory accounting period in §3.8 change with it.
Privacy questions, rights requests and complaints: privacy@voyade.com. A human reads that inbox, and answers within one month.
We have not appointed a Data Protection Officer. Our processing is not large-scale monitoring of the public and does not centre on special-category data, so Article 37 does not currently require one. If that changes as we grow, we will appoint one and say so here.
Under review. Trip-long, opt-in location sharing is the argument on the other side of the DPO question. Counsel should make the call rather than us.
2. Where your data lives
Everything we hold, we hold in the EU by default:
- Application and database: Heroku, EU region (Ireland).
- Photos, files and offline map packs: AWS S3,
eu-west-1(Ireland). - Background jobs, cache and realtime: the same Postgres database, same region.
Some of the companies that help us run Voyade process data outside the EU. Every one of them is named in the subprocessor list, with what it does, what reaches it, and where. §8 below explains the legal mechanism.
3. What we hold, why, and on what legal basis
This is the whole list.
3.1 Your account
| What | Display name, email address, avatar, the identifier from Apple or Google if you sign in that way, home airport or city, language, display currency, notification preferences, time zone. |
| Why | So you have an account, so we can show you your trips and email you about them. |
| Legal basis | Performance of our contract with you — Art. 6(1)(b). |
| How long | For as long as your account exists, then deleted within 30 days. |
3.2 Guest identity
| What | The first name you typed on an invite link, the invite token, and a session identifier. Nothing else — we do not ask a guest for an email address. |
| Why | So your contributions are attributed to a person rather than to “someone”, and so they survive if you later create an account. |
| Legal basis | Our legitimate interest, and yours, in a shared trip that makes sense — Art. 6(1)(f). |
| How long | For the life of that trip. If you create an account, the guest record merges into it. |
3.3 Trip content
| What | Trip titles, dates, destinations and cover images. Ideas — including links you paste and what our parser extracted from them. Itinerary items, days, travel legs, lodging stays. Comments, chat messages, shared trip notes. Booking tasks, booking confirmations you paste, upload or forward. Budget lines and expenses, including who paid and how it splits. Polls and their options. |
| Why | It is the product. This is the trip. |
| Legal basis | Contract — Art. 6(1)(b). |
| How long | For as long as the trip exists. Trips stay in your shelf indefinitely by design — a trip is a memory, and we are not going to garbage-collect one. You can delete a trip; an organizer can delete the whole trip; deleting your account removes your personal content from trips you shared (see §7). |
3.4 Votes, polls and group signals
| What | Your Must / Want / Fine / Skip on each idea, your poll answers, your RSVP status. |
| Why | Group decisions, and the AI draft that turns them into an itinerary. |
| Legal basis | Contract — Art. 6(1)(b). |
| Who sees it | Your trip. Votes are attributed and visible — that is the point, and conflicts are meant to surface (“3 must, 2 skip — talk about this one”). |
| How long | For the life of the trip. |
3.5 Your personal constraints — including your private budget cap
This is the most sensitive thing in a Voyade trip, so it gets its own treatment.
Your budget cap. The maximum you are willing to spend on a trip.
- It is never shown to anyone. Not your group, not the organizer, not a co-organizer, not an admin looking at the trip.
- It is used to compute exactly one thing: whether the current plan fits everyone’s budget. The group sees a derived state — “fits everyone’s budget ✓”, or a gentle warning to the organizer that the plan has drifted past someone’s ceiling. Never a number. Never a name.
- It never appears in a budget export, including one another member runs.
- It plays no part in ranking, suggestions or anything commercial.
- Legal basis: contract — Art. 6(1)(b). You can clear it at any time.
Your other constraints — dietary needs, mobility needs, must-dos, “I can only do ten days”. These you can keep private or share with the group; the choice is yours and it is per-field.
Some of these can reveal something protected. A halal or kosher note says something about your religion. A nut allergy, or “I can’t manage stairs”, says something about your health. Under GDPR those are special categories of data under Article 9, and the only basis we rely on for them is your explicit agreement, asked for in plain words at the moment you fill the field in. You can withdraw it by clearing the field, whenever you like, and nothing else about your trip breaks.
Not yet built, as of 28 July 2026. Today these are free-text boxes with no explicit-consent step in front of them and no record that you agreed. Until that step exists, do not put anything in them you would not want the trip to hold on an ordinary contractual basis, and if you already have, clear the field and it is gone. This box goes when the consent step ships, and this page will say so in the change log.
Retention: for as long as you are a member of that trip, or until you clear the field — and they are destroyed in full when you delete your account (§7).
3.6 Location sharing
| What | Your approximate position, while a trip is live, if you turned it on. |
| Why | The live map, “we’re at the pub on the corner”, split-up-and-meet, and the leave-by countdown on the Today view. |
| Legal basis | Your consent — Art. 6(1)(a). It is opt-in per person per trip, off by default, and one tap to turn off. |
| Who sees it | Only the members of that one trip, and only while it is live. Never a creator, never another trip, never us for any purpose but delivering it. |
| How long | It hard-expires when the trip ends. An expiry is required on every share — it is not optional and there is no share without one. If you turn sharing off mid-trip, the position we were holding is erased immediately, in that moment. See §7a for what is automated today and what is not. |
We hold one position per person per trip, not a trail: a new position replaces the old one rather than adding to a history. We do not build a location profile, we do not use location for advertising — there is no advertising — and we do not sell or share it with any partner.
3.7 Photos and what is inside them
| What | Photos and videos you add to a trip album, plus the technical data inside them: capture time, camera model and, where present, GPS coordinates (EXIF). |
| Why | To show them, and to attach them automatically to the right day and the right place — which is what the recap is built from. |
| Legal basis | Contract — Art. 6(1)(b). Reading a photo’s GPS is part of the album feature you asked for; if you would rather we did not, strip location on your phone before uploading, or turn the auto-attach setting off and place photos by hand. |
How long we keep the original file:
- Free accounts: we keep your full-resolution original for one year after upload. After that we keep a high-quality display version and delete the original, so your album still looks right but stops costing what a photo archive costs.
- Premium accounts: we keep the original for as long as your account exists.
- Either way, export before the year is up if you want the originals — export is in Settings and includes full-resolution files (§9a).
- We will email you before we downsize anything, and never on the day.
- See §7a: the rule is real, the job that carries it out is still being built, and until it exists nothing is being downsized at all.
When you publish a trip as a template, photo location EXIF is stripped from what goes public, and publishing is blocked until every member has approved their own photos. Nobody’s face goes into the feed because someone else pressed a button.
3.8 Payment and subscription data
| What | Your Stripe customer identifier, subscription status and plan, billing country, the card brand and last four digits, VAT status, invoices and amounts. |
| What we never hold | Your full card number, expiry or security code. Those go straight to Stripe and never touch our servers. |
| Why | To bill you, to give you an invoice, and to switch on what you paid for. |
| Legal basis | Contract — Art. 6(1)(b) — and legal obligation for the accounting records, Art. 6(1)(c). |
| How long | Subscription state for the life of your account. Invoices and accounting records for as long as tax law requires — currently five years from the end of the financial year. That period survives account deletion, because we are not allowed to delete a tax record on request. |
3.9 Creator earnings and payouts
| What | Your creator handle and public profile, your Stripe Connect account identifier, the earnings ledger for each of your templates (clicks, attributed clones, pending and confirmed commission, split bucket), payout history, and the tax identifiers Stripe collects to pay you. |
| Why | To calculate what you are owed and pay it. |
| Legal basis | Contract — Art. 6(1)(b) — and legal obligation for the payment and tax records, Art. 6(1)(c). |
| How long | Ledger and payout records for the statutory accounting period, currently five years. |
3.10 Affiliate click attribution
Worth explaining properly, because it is where a lot of products are vague.
| What we record | When you tap a booking link: a random click identifier, which trip, task and offer it came from, which template or creator the trip is attributed to, the partner, the time, and — for fraud detection — your browser and device string, the page you came from, your session identifier, and a hashed form of your IP address. We do not store your IP address itself; the hash is keyed with a secret and truncated, so it can tell two clicks apart without telling us who you are. If you are signed in, your account is recorded too, because that is how a creator’s attribution is honoured without a cookie. |
| What we send the partner | The click identifier and our partner code. Not your name, not your email, not your payment details, not your trip, not who else is on it, and not the hash above. |
| What comes back | If you book, the partner’s network sends us a postback days or weeks later: our click identifier, a commission amount, a currency and a status. We usually do not learn what you booked, and we never learn your booking reference or your card. |
| Why | It is how we get paid, and it is how a creator gets paid for a trip they wrote. |
| Legal basis | Our legitimate interest in being paid for the service we provide, and in paying creators accurately — Art. 6(1)(f). Where attribution needs something stored on your device across sessions, we ask for consent first — see the cookie policy. |
| How long | Click records: 24 months. Confirmed commission records: the statutory accounting period, because they are revenue. |
You can object to this processing at privacy@voyade.com, and you can decline the attribution cookie without losing any feature — see the cookie policy for exactly what changes.
3.11 Device, log and security data
| What | IP address, browser and device type, the pages you loaded and when, error reports when something breaks, and edge logs from our CDN. |
| Why | Keeping the service up, finding bugs, blocking abuse and fraud, rate-limiting. |
| Legal basis | Legitimate interest in a working, secure service — Art. 6(1)(f). |
| How long | Access and edge logs 30 days. Error reports 90 days. Abuse and fraud investigation records up to 12 months, longer only where an active case requires it. |
3.12 Messages you send us
| What | Support emails, bug reports, and booking confirmations you forward to trips@voyade.com. A forwarded confirmation is parsed for provider, dates, cost and cancellation deadline. |
| Why | To answer you, and to fill in your booking. |
| Legal basis | Contract, and legitimate interest in running support — Art. 6(1)(b) and (f). |
| How long | Support threads 24 months. The parsed booking lives with the trip; we delete the raw forwarded email 30 days after parsing it. |
3.13 Reports, moderation and appeals
| What | Reports you make about content, reports made about your content, the decision, the statement of reasons, and any appeal. |
| Why | We are required to run a notice-and-action process, and we would run one anyway. |
| Legal basis | Legal obligation under the Digital Services Act, Art. 6(1)(c), and legitimate interest in a safe platform, Art. 6(1)(f). |
| How long | Six months at minimum, because that is your window to appeal, and up to three years for the decision record where a pattern of abuse matters. |
3.14 Things that are public because you made them public
Your creator profile at /@handle, your published templates, your guides, your
community questions and answers, and your follower count are public web pages,
indexed by search engines. Publishing is always your choice, unpublishing is always
available, and the scrub screen shows you exactly what goes public before it does.
3.15 Data about you that did not come from you
Most of what we hold, you typed. Three things did not, and Article 14 says we should tell you where they came from.
| What | Where it came from |
|---|---|
| Your first name and the fact you exist, if you joined a trip as a guest on somebody’s invite link | The person who invited you, and then you, when you typed a name |
| Photographs you appear in, notes and comments about you, an expense someone recorded on your behalf | Other members of a trip you are on. They are that trip’s content and you can see all of it |
| The fact that a booking happened and what it earned us | The affiliate network, weeks later, as a postback against the anonymous click identifier in §3.10. It carries an amount and a status, and usually does not tell us what you booked |
| An email address and a name at sign-in | Apple or Google, if you chose one of them. Apple may send a relay address rather than your real one, and that is fine with us |
We do not buy personal data, we do not enrich your profile from data brokers, and we do not scrape anything about you from anywhere else.
4. What we do not do
- We do not sell your personal data. To anyone. Ever.
- We do not run advertising, and there is no advertising network in this product.
- We do not run a third-party analytics tracker. Not Google Analytics, not anything else.
- We do not profile you across other websites, and we cannot — we set nothing that follows you off Voyade.
- We do not use your private trip content, your photos, your notes or your chat to train AI models. Our AI provider processes what we send in order to answer, under a contract that forbids training on it.
- We do not let commission data anywhere near the systems that rank and suggest. That is enforced in the architecture. See How we rank things.
5. Automated decisions
Three things in Voyade are automated, and none of them is left to run unsupervised.
Feed personalisation. What you see in the feed is influenced by what you have saved, cloned and searched for. It never decides anything about you — it decides what order the trips appear in. Browse logged out for a completely unpersonalised feed. The parameters are listed in How we rank things.
The publishing similarity check. When you publish a trip, we compare it to existing templates to decide whether it is a new template or a traveller’s take on an existing one. That affects your earnings, so it is deliberately not a purely automated decision: the assessment is AI-assisted, you are told the outcome and the reason, and a human reviews it if you appeal. The Creator terms §6 set out the appeal.
Abuse detection. We look for self-clicking, fake clones and bought traffic. A flag never suspends anyone by itself — a person reviews before any payout is held or any account is restricted, and you are told, with reasons, and can appeal.
You have the right under Article 22 to ask for human involvement in any of these, to express your point of view, and to contest the outcome. Write to privacy@voyade.com, or use the in-product appeal, which goes to the same people faster.
6. Who else touches your data
The full list — every processor, what it does, what reaches it, and where it processes — is a separate page, kept current: subprocessor list.
In summary, and only for the purpose named:
- Hosting and storage: Heroku (EU), AWS S3 (
eu-west-1), Cloudflare. - AI: Anthropic, for drafting, adaptation, parsing and the concierge.
- Places, maps and routing: Google Places, OpenStreetMap/Overpass, OpenRouteService, Transitous, Protomaps tiles.
- Photography: Unsplash and Pexels, for licensed destination imagery. They receive a search term, never your data.
- Email: Postmark, for what we send you and what you forward to us.
- Payments and payouts: Stripe.
- Error monitoring: Sentry.
- Sign-in: Apple and Google, if you use them.
Affiliate networks are different, and we will be precise about it. Awin, CJ, Partnerize, Impact, Travelpayouts and the booking partners themselves are not our processors. They are independent controllers. We hand them an anonymous click identifier; the moment you land on their site you are their visitor, under their privacy policy and their consent banner, not ours. We are not able to see or control what they set.
7. What happens when you delete your account
Deletion is a button in Settings. No ticket, no phone call, no retention offer. You type “delete my account” once, and that is the whole ceremony.
There is a thirty-day pause, and it is for you. Confirming signs you out everywhere immediately and schedules the erasure for thirty days later. In that window you can sign back in and cancel it, and nothing has been lost. We do not use the window to sell you anything or ask why. When it ends, the erasure runs, and it is not reversible.
What the erasure destroys.
- Your identity. Your name and email address are overwritten with a marker that leads nowhere, your password is destroyed, and your home airport, time zone, language and account verification are cleared.
- Every way back into the account: sessions, sign-in connections to Apple or Google, magic-link tokens issued to your address, and push notification registrations.
- Your personal constraints in every trip, including your private budget cap and any dietary or mobility note.
- Any data export archive we were still holding for you.
- Your creator attribution comes off any published template. See the Creator terms §4.3 for what remains and why.
- The identifying detail in our own audit trail. The record that an action happened survives; the IP address, browser string and payload attached to it are destroyed.
What survives, and why.
- Trips shared with other people continue for them. Some entries stay behind attached to that marker rather than to you: the count on a vote, the payer on an expense that has already been settled, a budget split that other people’s numbers depend on, and a photograph you uploaded to a shared album. We do this because deleting them would rewrite four other people’s record of a trip they took, and their interest in that record is real. It is a legitimate-interest balancing decision under Art. 17(1)(c), it is the only discretionary exception we make, and you can challenge it at privacy@voyade.com.
- If you were the only organizer of a trip, we tell you before you confirm and name the trips. We do not delete them and we do not reassign them behind your back — make someone else an organizer first if you want the trip to carry on with somebody able to run it.
- Records the law makes us keep — invoices, payout records, tax data, and moderation decisions still inside their appeal window — stay for their statutory period and then go.
- Backups roll off within 35 days. Until then a deleted record may exist in a backup, which we cannot surgically edit; it is never restored into the live product.
7a. How long we keep things — the whole table
Everything above, in one place, so you do not have to reassemble it.
| What | How long |
|---|---|
| Account and profile | While the account exists; then the erasure in §7 |
| Trips, ideas, itinerary, chat, notes, photos | While the trip exists — indefinitely by design. A trip is a memory and we do not garbage-collect one |
| Guest identity on an invite | The life of that trip, or 30 days |
| Votes, polls, RSVPs | The life of the trip |
| Personal constraints and your budget cap | Until you clear the field, or the account erasure |
| Location shares | Deleted at trip end — not archived, not aggregated, not anonymised. Also on mid-trip opt-out |
| Photo originals | One year from upload on a free account, then a high-quality display version is kept and the original deleted. As long as the account exists on Premium |
| Invoices, payout and tax records | The statutory accounting period — currently five years from the end of the financial year. Survives account deletion; we may not delete a tax record on request |
| Affiliate click records | 24 months |
| Confirmed commission records | The statutory accounting period, because they are revenue |
| Access and edge logs | 30 days |
| Error reports | 90 days |
| Abuse and fraud investigation records | Up to 12 months, longer only while an active case needs it |
Raw emails you forwarded to trips@voyade.com |
Deleted 30 days after we parse them. The parsed booking lives with the trip |
| Support threads | 24 months |
| Moderation reports, decisions and appeals | Six months minimum, because that is your window to appeal; up to three years for the decision record where a pattern of abuse matters |
| A data export archive we generated for you | The download link expires after 7 days |
| Backups | Roll off within 35 days |
The periods we have committed to and have not yet automated
Some of the rows above are enforced by the product today and some are commitments a scheduled job has to keep. We would rather list the difference than let you assume.
Enforced today: the download link on an export expires; a location share stops being visible to anyone the moment it expires or you switch it off, and switching it off erases the position immediately; account erasure runs on its schedule.
Committed and not yet automated, as of 28 July 2026 — the rule is real, the scheduled deletion that carries it out is still being built:
- Deleting expired location rows, rather than only hiding them.
- Deleting photo originals after a year on a free account, and the email that warns you first.
- Deleting affiliate click records at 24 months.
- Deleting raw forwarded emails 30 days after parsing.
- Deleting export archives once their link has expired.
Nothing in that list is used for anything while it waits — an expired location is not readable by your group, by another trip, or by us for any other purpose. But held is held, and we are not going to describe a scheduled job that does not exist yet as though it does. This paragraph shrinks as the jobs ship, and it is dated so you can tell whether it has.
8. Data leaving the EU
Most processing happens in the EU. Where it does not — principally Anthropic, Google, Postmark, Sentry, Stripe’s US entities and the affiliate networks — the transfer runs on the European Commission’s Standard Contractual Clauses, or on an adequacy decision where one covers the country, together with the additional technical and organisational measures our agreements require. The subprocessor list names the mechanism for each one.
You can ask us for a copy of the transfer safeguards at privacy@voyade.com.
9. Your rights, and how to actually use them
You have all of these. The point of this section is that most of them are a button, not a request.
| Right | How, in the product |
|---|---|
| See what we hold | Settings → Your data → Export. Self-serve, no ticket, and §9a says exactly what is in it. |
| Fix something wrong | Edit it. Profile, constraints, trip content, expenses, your handle. If it is something you cannot reach, privacy@voyade.com. |
| Delete | Settings → Delete account. Self-serve. §7 explains exactly what happens. To delete one thing rather than everything, delete the thing. |
| Take it elsewhere | The same export, in machine-readable JSON with your media alongside it. |
| Restrict processing | privacy@voyade.com. We will freeze rather than delete while a dispute is open. |
| Object | privacy@voyade.com, for anything we do on legitimate interests — affiliate attribution and abuse analytics in particular. |
| Withdraw consent | Location sharing: the toggle in the trip. Special-category constraints: clear the field. Cookies: Settings → Privacy → Cookie choices, one tap, same prominence as accepting. Withdrawing is always as easy as giving. |
| Human review of an automated decision | The in-product appeal, or privacy@voyade.com. §5. |
We answer within one month. If a request is genuinely complex we can take two months more, and we will tell you why inside the first month. It is free, unless a request is repetitive to the point of being vexatious.
9a. What is actually in the export
Because “a complete archive” is the sort of phrase that hides things.
The export is a single compressed archive, generated on demand and emailed to you as a link that works for seven days. You can also download it in Settings while it is live. One export at a time, and one every 24 hours — that limit exists so an automated loop cannot use the exporter as a denial-of-service against our own storage, and if you genuinely need more, ask us.
Inside it:
account.json— everything in §3.1.sign_in_methods.json— which providers you connected and when; your sessions as metadata only (created, last active, IP, browser — never the session token itself); your push registrations without their keys.notification_preferences.jsonanddata_requests.json.- One folder per trip you are a member of, containing: the trip itself with its days and itinerary items; your role, RSVP and your own constraints, including your budget cap in cleartext — it is your data and Article 20 says you get it, and it is the only place it ever appears; the other members’ names, roles and RSVPs; every idea with every vote and who cast it; your own votes and comments separately; the whole trip’s chat, because it is a shared conversation you were part of; your trip notes; every booking task with estimates and actuals; the budget, every expense and your share of each.
- Your photographs, as the original files you uploaded — full resolution, not a web-sized copy. Only the ones you uploaded yourself: other people’s photographs are theirs to export.
- Your creator ledger, if you have one.
Two honest limits. Media in one archive is capped at 2 GB; anything skipped for size is listed by name in the archive with a note saying to ask us and we will send it separately. And another member’s private budget cap never appears in your export, in the same way yours never appears in theirs.
Complaining. If we get it wrong, please tell us first — privacy@voyade.com — and we will try to fix it. You do not have to. You can go straight to a supervisory authority: Datatilsynet, the Danish Data Protection Agency, as our lead authority, or the data protection authority in the EU country where you live, whichever you prefer. Either is fine with us.
10. Keeping it safe
- Everything encrypted in transit (TLS) and at rest.
- EU-region hosting and storage.
- Access to production data is limited to the people who need it, logged, and reviewed.
- The admin system is a separate account model with its own table and its own session. There is no path from a signed-in user account to an admin screen, even for us. That is a structural choice, not a permission flag.
- Card data never reaches our servers.
- If a breach ever puts you at risk, we notify our supervisory authority within 72 hours and we tell you, directly, in plain language, with what we know and what to do about it.
11. Children
Voyade is for people aged 16 and over. We do not knowingly collect data from anyone younger. If you think a child has an account, tell us at privacy@voyade.com and we will delete it quickly.
Children travel, obviously. A trip can be a family trip and a child can appear in your photos. That is your content and your judgement; the publishing scrub screen exists so you can decide deliberately what goes public.
12. Changes to this policy
If we change something material — a new category of data, a new purpose, a new country — we will tell you 30 days in advance, by email and in the app, and we will keep the previous version available so you can see what moved. Smaller changes appear in the change log below when they are published.
The companion documents: Terms of use · Cookies and tracking · Who processes your data · How we rank things · Reporting content · Creator terms · Premium terms · Accessibility
Change log
| Date | What changed |
|---|---|
| 2026-07-28 | First draft. Not yet in force. §1 controller details consolidated into one block to be completed at incorporation; Datatilsynet named as lead authority in §9. §3.5 now says out loud that the explicit-consent step for dietary and mobility notes is not built yet. §3.10 rewritten to list everything a click record actually holds, including the hashed IP, referrer, browser string and session identifier. §3.15 added: data that did not come from you (Art. 14). §7 rewritten to describe the thirty-day cancellable deletion the product performs, what it destroys and what survives. §7a added: the whole retention table, plus an explicit list of the periods committed to but not yet automated. §9a added: exactly what is inside a data export, including its 2 GB media cap and seven-day link. |