Skip to content
voyade
Policies

Who processes your data

Last updated July 28, 2026

Draft for legal review — not yet in force. Every entry below must be checked against the signed agreement before this page is published.

Last updated 28 July 2026.


This page lists every company that touches your data on our behalf, what it does, what actually reaches it, and where it processes. It is the detail behind the privacy policy §6.

Two things to know before the tables.

Default is EU. Your account, your trips, your photos and your files are stored in the EU — Heroku’s EU region and AWS eu-west-1, both in Ireland. The companies below that process outside the EU do so for a specific, named purpose.

“Processor” and “controller” are different jobs. A processor acts only on our instructions, under a contract, and cannot use your data for its own purposes. An independent controller decides for itself. The affiliate networks in §4 are independent controllers, and we say so rather than blurring it, because the difference determines who you complain to.


1. Infrastructure

Heroku (Salesforce)

What it does Runs the Voyade application, the database, the background jobs and the realtime connections. This is the product.
What reaches it Everything you put in Voyade: your account, your trips, ideas, votes, constraints, budget caps, chat, notes, bookings, the earnings ledger.
Where it processes EU region — Ireland. Selected deliberately for data residency.
Role Processor
Transfers Salesforce is US-parented; support and platform operations may involve US access under Standard Contractual Clauses.

Amazon Web Services — S3

What it does Stores photos, videos, uploaded booking confirmations, exports, and offline map packs.
What reaches it Your media files and their metadata, including EXIF capture time and location where present.
Where it processes eu-west-1, Ireland.
Role Processor
Transfers EU storage. AWS’s EU SCCs and supplementary measures cover any support access from outside the EU.

Cloudflare

What it does CDN and edge caching for the public pages — the feed, template pages, guides, community. Bot protection and DDoS mitigation. Optionally, inbound email routing for [email protected].
What reaches it Your IP address, the page you requested, your browser and device type, and a short-lived bot-management cookie set on our own domain. Not your trip content: a signed-in response is marked never-store and does not enter a shared cache. If email routing is used, a booking confirmation you forward passes through it.
Where it processes Globally distributed; requests from Europe are served from European edge locations.
Role Processor
Transfers Standard Contractual Clauses.

To confirm before publishing. No CDN is configured in the application today, and the inbound-mail adapter can be Postmark or Cloudflare. Confirm which of these two jobs Cloudflare actually does at launch, and delete this row entirely if it does neither. A named processor that turns out not to process anything is the wrong kind of over-disclosure: it teaches a reader that the list is approximate.

2. AI

Anthropic

What it does The whole AI layer: adapting a template to your dates and group, drafting an itinerary from your votes and constraints, parsing a link or a forwarded confirmation email, estimating costs, the concierge, and generating the recap.
What reaches it The trip content needed for the specific task — ideas, votes, dates, destinations, itinerary items, the constraints your group set, and the budget band. Not your private budget cap as a number, not your payment data, not your location shares, not your email address.
Where it processes Outside the EU. Anthropic’s direct API processes in the United States.
Role Processor
Transfers Standard Contractual Clauses under Anthropic’s data processing agreement.
Training Anthropic does not train models on what we send through the API. That is contractual, not a preference setting.

To confirm before publishing. If we deploy through AWS Bedrock in an EU region rather than the direct API, this row becomes EU-only processing and the transfer line changes. Engineering and counsel must agree which one is true on launch day.

3. Places, maps, routing and photography

Google — Places API

What it does Place details, opening hours and prices — the highest-confidence source we have, and the reason a suggested restaurant is actually open when you get there.
What reaches it Place searches and coordinates. A query is about a place, not about you: no account identifier, no trip identifier, no name. Your IP reaches Google as part of the request.
Where it processes Globally, including the United States.
Role Processor
Transfers Standard Contractual Clauses; EU–US Data Privacy Framework where it applies.

OpenStreetMap / Overpass API

What it does Covers what Google does not: trails, viewpoints, swimming spots, the free things that are first-class citizens in this product.
What reaches it Geographic queries. Nothing about you.
Where it processes Germany (overpass-api.de) — EU.
Role Processor / public data source

OpenRouteService

What it does Travel times, driving and walking durations, reach and isochrones — the numbers behind “leave by 14:20”.
What reaches it Coordinate pairs. Not who you are, not which trip.
Where it processes Germany (EU) — operated by the Heidelberg Institute for Geoinformation Technology.
Role Processor

Two other routing engines are supported in the code and are not in use: Mapbox (United States) and a self-hosted Valhalla. Either would replace OpenRouteService entirely rather than sit beside it, and switching to one is a change to this page before it is a change to a configuration file.

Transitous

What it does Train, bus and ferry reach — public transport as a first-class way to get somewhere, which matters in Europe.
What reaches it Origin, destination and time. Nothing identifying.
Where it processes EU, community-operated.
Role Processor / public data source

Protomaps map tiles

What it does The map itself. Tiles are served from our own storage, so panning a map does not report you to a tile vendor.
What reaches it Nothing external.
Where it processes Our own S3 eu-west-1.

Unsplash

What it does Licensed destination photography for template covers and destination pages.
What reaches it A search term, from our servers — “Ring of Kerry”, “Lisbon rooftop”. Never your data, and never your IP: we fetch and cache server-side rather than embedding their script.
Where it processes United States.
Role Processor / content licensor
Transfers Standard Contractual Clauses.

Pexels

What it does The same job as Unsplash, for coverage.
What reaches it A search term from our servers. Nothing about you.
Where it processes Germany and internationally.
Role Processor / content licensor

4. Payments, email and monitoring

Stripe

What it does Two separate jobs: Premium subscriptions (billing you), and Stripe Connect (paying creators).
What reaches it For subscriptions: your name, email, card details entered directly into Stripe’s own form, billing country, VAT status, and the subscription record. Card numbers never touch our servers. For creators: identity and tax details Stripe collects to pay you, and your bank details, which we never see.
Where it processes Stripe Payments Europe Ltd, Ireland is the contracting entity for EU customers; processing also involves Stripe’s US infrastructure.
Role Processor for subscription data; independent controller for its own regulatory obligations — anti-money-laundering, payment-network rules, fraud prevention.
Transfers Standard Contractual Clauses.

Postmark (ActiveCampaign)

What it does Sends everything we send you — invites, magic links, deadline reminders, digests, receipts. Receives what you forward to [email protected].
What reaches it Your email address, the message content, and delivery metadata. A forwarded booking confirmation includes whatever the airline or hotel put in it — your name, your reference, your dates.
Where it processes United States. Postmark offers an EU data-residency option.
Role Processor
Transfers Standard Contractual Clauses.

To confirm before publishing. Whether we have enabled Postmark’s EU region. Forwarded confirmations are the most identifying content in the whole product and this row should not stay as “United States” if it does not have to.

Sentry

What it does Tells us when something breaks, with enough context to fix it.
What reaches it A stack trace, the URL, your browser and device type, your IP address, and an internal account identifier. We scrub trip content, photos, budget figures and message bodies from error reports before they are sent.
Where it processes Sentry offers an EU data region.
Role Processor
Transfers Standard Contractual Clauses where processing is in the US.

To confirm before publishing. Which Sentry region the DSN points at.

Apple and Google — sign-in

What it does “Sign in with Apple” and “Sign in with Google”, if you choose them.
What reaches them The fact that you signed in to Voyade, at that time. We receive back an identifier and an email address, which may be Apple’s relay address.
Where they process Globally, including the United States.
Role Independent controllers for their own sign-in service.
Alternative An email magic link, which involves neither of them.

Web push services

If you turn on push notifications, your browser registers with its vendor’s push service — Apple, Google or Mozilla. The notification content is routed through them. We store the subscription; we do not choose the route.

5. Affiliate networks and booking partners — not our processors

This section works differently, and the difference matters to you.

When you tap “Book →”, you leave Voyade. From that moment you are the partner’s visitor, under the partner’s privacy policy and the partner’s consent banner. They are independent controllers. We do not instruct them, we cannot see what they set, and we cannot delete it for you. If you want your data out of Booking.com, you have to ask Booking.com.

What we send them: an anonymous click identifier and our partner code. Not your name, not your email, not your payment details, not your trip, not who else is on it.

What comes back: a postback — that identifier, an amount, a currency, a status. We generally do not learn what you booked, and we never learn your booking reference or your card.

Affiliate networks (they run the tracking and pay the commission):

Network Where
Awin Germany / United Kingdom
CJ Affiliate (Publicis) United States
Partnerize United Kingdom / United States
Impact United States
Travelpayouts Operates internationally
Webgains United Kingdom / Germany

Booking partners (you contract with these directly):

Partner What Where
Booking.com Stays Netherlands
Agoda Stays Singapore
Hostelworld Hostels Ireland
Viator (Tripadvisor) Activities, tours, tickets United States
GetYourGuide Activities, tours Germany
Tiqets Museum and attraction tickets Netherlands
Discover Cars Car hire Latvia
Expedia Stays, packages United States
Travelpayouts (Aviasales, Kiwi) Flights Operates internationally
Excess-insurance and travel-insurance partners Insurance Confirmed at signup
eSIM partners Connectivity Confirmed at signup

We add and remove partners as programmes change. This list is updated when we do.

6. When this list changes

  • We update this page before a new processor starts handling your data, not after.
  • For a change that materially affects what happens to your data — a new category of data, a new country, a new purpose — we give 30 days’ notice in the app and by email, and you can object at [email protected]. If we cannot resolve your objection, you can export and delete, and if you were paying us we will refund the unused part.
  • Routine changes (a vendor moves a region, an entity is renamed) appear in the change log below.

Related: Privacy · Cookies and tracking · How we rank things · Terms of use


Change log

Date What changed
2026-07-28 First draft. Not yet in force. Every row pending verification against the signed DPA. The Cloudflare row now carries a to-confirm note, because no CDN is configured in the application today and the inbound-mail adapter may be Postmark instead. The two alternative routing engines the code supports but does not use are named, so switching to one is visibly a change to this page.