Skip to content

VoyPlan Privacy Policy

Updated and effective September 27, 2026. This policy explains what personal information we process, why we process it, and the choices and rights available to you.

1. Scope and operator

This policy applies to the VoyPlan website and related services from the same operator that expressly link to it. It does not govern independent third-party services. The personal-information controller is the VoyPlan operator identified in the site's legal disclosures and Contact page. We will ask separately where specific consent is required. You may refuse optional processing, though the related optional feature may not work.

2. Information we collect

We may process: • account and verification data, including email, username, display name, hashed credentials, codes, and account status; • account settings, including avatar, display name, and theme preference; • proposal data, including customer brief text, destinations, dates, travelers, budgets, preferences and constraints, day-by-day itineraries, place names or coordinates, lodging and transport notes, proposal text, and uploaded images; your browser handles proposal content when you print or save a PDF; • AI processing data, including prompts and context used to generate or revise proposals, task state, and generated results; • technical and security data, including IP address, device and browser type, access time, request logs, cookies, session identifiers, errors, and risk records; and • support messages, attachments, and contact details. Customer names, precise places, travel dates, lodging, and meeting points may be personal information. Provide only what is needed for planning and review personal information before sharing a proposal.

3. Collection, purposes, and legal bases

We collect information you enter, upload, generate, edit, or share, necessary logs and session data generated during use, and information received from third parties with authorization. We use it for accounts and security; understanding customer needs; generating, editing, storing, and sharing travel proposals; place search and map previews, AI, and browser printing or PDF saving; support; safety, debugging, and abuse prevention; and legal compliance. Proposals are not listed in a public route discovery page. Legal bases may include performing our agreement, consent, legal obligations, and other bases recognized by law.

4. Cookies, local storage, and logs

We use cookies, local storage, and similar technology for sessions, language and theme preferences, required security state, and unfinished actions. We do not use these tools to track you across unrelated websites. Blocking or clearing them may disable sign-in or preferences. Servers keep access and error logs needed to provide and secure the service. We do not use those logs for unrelated advertising profiles unless separately disclosed and lawfully authorized.

5. Processors, sharing, and providers

We do not sell personal information. We may provide only necessary data to contracted cloud hosting, database, storage, email, mapping, AI model, security, and technical support providers. Map requests may include place names, addresses, or coordinates; AI requests may include prompts, customer requirements, and structured itinerary content. Contracts, access controls, and security review restrict providers to our instructions. We may also disclose necessary information when law requires or to protect life, property, users, or the platform.

6. Proposal visibility, sharing, and collaboration

Your display name, username, and avatar may appear on proposals you own or collaborate on as shown in the product. Proposals are private by default. If you enable link sharing, anyone with the link may access the proposal; this does not list it in public route discovery. Private proposals are limited to you and collaborators authorized through the product. Recipients may copy or export content they can access. Closing your account deletes proposals you own and related uploaded files, but cannot remotely delete copies recipients already saved or exported. Do not include identity documents, phone numbers, exact home addresses, private lodging, or other unnecessary sensitive information in shared proposals.

7. Transfers and public disclosure

We do not transfer personal information to another controller or publicly disclose it without separate consent unless law allows. If a merger, acquisition, restructuring, asset transfer, or insolvency transfers personal information, we will identify the recipient as required and require continued protection under this policy. A material new purpose or method will trigger renewed notice and any required consent.

8. Location and retention

We retain personal information only as long as needed for the purposes above, considering account life, service needs, disputes, security audits, and mandatory periods. Closing your account deletes your profile, proposals you own, and related uploaded files. Content you contributed to proposals owned by other users may remain in those proposals, with your account attribution removed where supported. Backup deletion may follow a security rotation cycle. Storage locations follow applicable law. If personal information is provided across borders, we will use legally required assessments, contracts, or safeguards and provide separate notice and consent where required.

9. Security and incidents

We use risk-appropriate access controls, encrypted transport, credential hashing, backups, audit logs, least privilege, secure development, and confidentiality duties. No internet service is absolutely secure; use a strong unique password and review proposal sharing settings. If information is or may be leaked, altered, or lost, we will mitigate it and provide legally required notice about the event, effects, response, and protective steps, and report to authorities when required.

10. Your rights

Subject to applicable law, you may access, copy, correct, supplement, or delete information; change or withdraw consent; object to or constrain automated decisions; request an explanation; and close your account. Use account settings to close your account; this requires your current password and deletes your profile, proposals you own, and related uploaded files. Copies recipients already saved cannot be remotely deleted by us. You may also use the Contact page for other rights requests. We may verify identity for security and will respond within the period required by law. Withdrawal does not invalidate earlier lawful processing, and legally required or dispute-related records may be retained where permitted. You may also complain to an appropriate regulator.

11. Children

Users under 18 should use VoyPlan with guardian guidance. A child under 14 should provide personal information only after a guardian reads this policy and supplies verifiable consent where required. We do not knowingly target children with personalized commercial marketing. Guardians may use the Contact page to request correction or deletion of information processed without appropriate consent.

12. Updates, contact, and complaints

We may update this policy for legal, technical, or feature changes. Material changes to purposes, data categories, recipients, or rights will be communicated prominently and renewed consent obtained where required. Contact us using the email on the Contact page. Do not send original identity documents, passwords, or unnecessary sensitive data in ordinary email. You may complain to a competent privacy, cybersecurity, or consumer authority if dissatisfied with our response.