Draft: pending legal review
Privacy Policy
Last updated 23 August 2026.
This is a working draft describing what Travelmad actually collects and does today, published while Travelmad is in closed, invite-only sandbox testing. It has not yet been reviewed by counsel. Travelmad is intended to be operated by a Spanish single-member limited company (S.L.U.) established in Valencia. Its registered name, NIF, registered address and Mercantile Registry details must be inserted here after incorporation and before Travelmad opens to the public. If you have questions about your data, contact us directly.
1. Who is responsible for your data
Travelmad’s operator is the controller of the personal data described in this policy. Once incorporated, the controller will be the Spanish S.L.U. identified above. Until those company details are published, Travelmad remains a closed sandbox service and must not take public or production bookings. Privacy enquiries and requests can be sent to arjen@travelmad.app.
We have not appointed a data protection officer because we do not currently consider one legally required. We will reassess this if the nature or scale of our processing changes.
2. What we collect
If you visit our public landing page: we record that the production page loaded, together with campaign labels in the URL and the referring website’s domain when your browser provides it. This record contains no IP address, account or user identifier, cookie identifier, browser fingerprint, or full referring URL. It is counted as a raw page load, not a unique person.
If you join the waitlist: your email address, the country you’re currently based in, and which of three short descriptions best fits how you travel and work. If the link you followed includes campaign labels (source, medium, campaign, or content), we store those labels with your request so we can understand which outreach led to meaningful use. We use a security check (Cloudflare Turnstile) on that form to block automated submissions.
If you’re invited and create an account: your email (via Supabase Auth, for passwordless sign-in), and the profile details you give us during onboarding: starting city, work schedule and timezone, travel interests, and preferences like whether you need a desk. If you go on to book a stay, we also collect the details our accommodation supplier requires: your last name, phone number and nationality. We do not currently require passport details for accommodation bookings.
How you use Travelmad: the suggestions created for you, feedback you provide, whether you open booking review, payment attempts, and completed or cancelled bookings. Opening booking review is stored only as the first time you pressed “Let’s go” for that suggestion, not as a record of every page view.
We do not collect or store your card details. Payment for a stay is entered directly into our accommodation supplier’s payment processor (Stripe, via LiteAPI). That data goes straight to them, not through Travelmad’s servers.
3. Who we share it with
- Supabase: hosts our database and handles authentication (magic-link sign-in).
- Nuitée / LiteAPI: our accommodation booking and payment supplier. Under the intended Payment SDK model, Nuitée acts as Merchant of Record, receives the guest and booking details needed to make and manage the reservation, and collects payment directly. This role and its own privacy terms must be confirmed in our production agreement before launch.
- Anthropic, Google, and/or OpenAI: one of these AI providers generates the written explanation accompanying each suggestion, from destination and property data. We don’t send your name, email, or contact details to them.
- Resend: sends transactional email (including waitlist, access and cancellation messages) on our behalf.
- Cloudflare (Turnstile): provides the security check used on our waitlist and sign-in forms to block automated abuse.
We don’t sell your data or use third-party advertising or analytics trackers. Travelmad’s own aggregate landing-page measurement does not identify individual visitors or store data in their browser.
4. Cookies and similar technology
Travelmad only sets cookies/local storage that are strictly necessary for the service to work: keeping you signed in (Supabase), the security check (Turnstile), and payment/fraud-prevention data used by our payment processors. We don’t use marketing or analytics cookies, so there’s no cookie consent banner. If that changes, this policy and the banner will be updated together. Campaign labels are read directly from the waitlist page’s URL when you submit the form; Travelmad does not place them in a cookie or browser storage.
5. Why we process your data and our legal bases
- Taking and managing waitlist requests: taking steps at your request and our legitimate interest in running a limited-access test safely and selecting suitable testers.
- Operating your account, personalising suggestions and arranging a booking you request: taking steps at your request and performing our contract with you.
- Transactional messages: performing that contract or taking requested pre-contract steps. We do not currently send marketing email.
- Security, abuse prevention, service measurement and improvement: our legitimate interests in protecting and improving Travelmad. Our measurement is limited and designed not to identify public visitors.
- Required booking, accounting and compliance records: complying with legal obligations and establishing, exercising or defending legal claims.
Providing waitlist data is optional, but we cannot process your request without it. Account profile fields and the guest details marked as required are necessary to make suggestions or a requested booking. Travelmad uses preferences and feedback to rank destinations and accommodation, but does not make solely automated decisions that have legal or similarly significant effects on you. You decide whether to book.
6. How long we keep it
Anonymous landing-page loads: we intend to keep these aggregate-only records for no more than 13 months so year-over-year campaign comparisons remain possible. Automatic deletion is not yet active during closed beta; this must be implemented or backed by a documented manual deletion process before public launch.
Waitlist entries that are never approved are currently removed on request. A fixed retention period must be selected, implemented and stated here before public launch.
Your account: you can delete it yourself at any time from Profile. If you have no current or upcoming booked trip, it’s deleted immediately. If you have one, deletion happens automatically once that trip ends.
Booking and payment records: once you’ve made a real booking, a minimal record of it (booking and payment details, not your full profile) is kept for up to six years after account deletion, in a restricted, pseudonymised form, for accounting and legal reasons. This is a current policy, not a statutory minimum, and may be revised.
7. Your rights
Under applicable data-protection law, you may ask us to access, correct, erase or restrict processing of your data, provide portable data, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time. You can exercise some rights from Profile or contact us. We may need to verify your identity and may retain information where the law requires it.
You may also complain to the Spanish Data Protection Agency (AEPD) at aepd.es, or to another competent supervisory authority.
8. Security
We restrict access to your data at the database level to only what each part of the app actually needs, and full payment-card details never pass through our own servers. No system is perfectly secure. If a personal-data breach occurs, we will notify the competent authority and affected people when applicable law requires it.
9. International transfers
Some of the providers above (including our AI providers) may process data outside your country. Where personal data is transferred outside the European Economic Area, we will use a lawful transfer mechanism, such as an adequacy decision or approved standard contractual clauses, and supplementary safeguards where required. Our production vendor review must record the relevant locations and mechanism before public launch; you may contact us for information about the safeguards used.
10. Changes to this policy
We’ll update this page as Travelmad develops and update the “last updated” date when we do. Material changes will be communicated to active users.
11. Contact
Questions about your data or this policy: arjen@travelmad.app.