Draft: pending legal review

Privacy Policy

Last updated 11 August 2026.

This is a working draft describing what Travelmad actually collects and does today, published while Travelmad is in closed, invite-only sandbox testing. It has not yet been reviewed by counsel and will be revised (including our legal entity and formal retention periods) before Travelmad opens to the public. If you have questions about your data, contact us directly.

1. What we collect

If you visit our public landing page: we record that the production page loaded, together with campaign labels in the URL and the referring website’s domain when your browser provides it. This record contains no IP address, account or user identifier, cookie identifier, browser fingerprint, or full referring URL. It is counted as a raw page load, not a unique person.

If you join the waitlist: your email address, the country you’re currently based in, and which of three short descriptions best fits how you travel and work. If the link you followed includes campaign labels (source, medium, campaign, or content), we store those labels with your request so we can understand which outreach led to meaningful use. We use a security check (Cloudflare Turnstile) on that form to block automated submissions.

If you’re invited and create an account: your email (via Supabase Auth, for passwordless sign-in), and the profile details you give us during onboarding: starting city, work schedule and timezone, travel interests, and preferences like whether you need a desk. If you go on to book a stay, we also collect the details our accommodation supplier requires: your last name and phone number, and where relevant your passport/nationality.

How you use Travelmad: the suggestions created for you, feedback you provide, whether you open booking review, payment attempts, and completed or cancelled bookings. Opening booking review is stored only as the first time you pressed “Let’s go” for that suggestion, not as a record of every page view.

We do not collect or store your card details. Payment for a stay is entered directly into our accommodation supplier’s payment processor (Stripe, via LiteAPI). That data goes straight to them, not through Travelmad’s servers.

2. Who we share it with

  • Supabase: hosts our database and handles authentication (magic-link sign-in).
  • LiteAPI: our accommodation supplier; receives your booking and guest details to make and manage a reservation, and collects payment for it directly.
  • Anthropic, Google, and/or OpenAI: one of these AI providers generates the written explanation accompanying each suggestion, from destination and property data. We don’t send your name, email, or contact details to them.
  • Resend: sends transactional email (waitlist confirmation, access updates) on our behalf.
  • Cloudflare (Turnstile): provides the security check used on our waitlist and sign-in forms to block automated abuse.

We don’t sell your data or use third-party advertising or analytics trackers. Travelmad’s own aggregate landing-page measurement does not identify individual visitors or store data in their browser.

3. Cookies and similar technology

Travelmad only sets cookies/local storage that are strictly necessary for the service to work: keeping you signed in (Supabase), the security check (Turnstile), and payment/fraud-prevention data used by our payment processors. We don’t use marketing or analytics cookies, so there’s no cookie consent banner. If that changes, this policy and the banner will be updated together. Campaign labels are read directly from the waitlist page’s URL when you submit the form; Travelmad does not place them in a cookie or browser storage.

4. Why we process your data

To provide the service you’ve signed up for (generating suggestions, making bookings), to communicate with you about your account or a booking, to protect Travelmad and other users from abuse, to understand where the recommendation and booking journey needs improvement, and, for the waitlist, to decide who to invite next.

5. How long we keep it

Anonymous landing-page loads: we intend to keep these aggregate-only records for no more than 13 months so year-over-year campaign comparisons remain possible. Automatic deletion is not yet active during closed beta; we will remove records manually until it is.

Waitlist entries that are never approved: we intend to define an automatic deletion period for these and will update this policy once that’s finalised; today they’re removed on request.

Your account: you can delete it yourself at any time from Profile. If you have no current or upcoming booked trip, it’s deleted immediately. If you have one, deletion happens automatically once that trip ends.

Booking and payment records: once you’ve made a real booking, a minimal record of it (booking and payment details, not your full profile) is kept for up to six years after account deletion, in a restricted, pseudonymised form, for accounting and legal reasons. This is a current policy, not a statutory minimum, and may be revised.

6. Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your data, and to object to how we use it. You can exercise most of this yourself from your Profile, or contact us and we’ll handle it directly.

7. Security

We restrict access to your data at the database level to only what each part of the app actually needs, and payment details never pass through our own servers. No system is perfectly secure; if we ever become aware of a breach affecting your data, we’ll tell you.

8. International transfers

Some of the providers above (including our AI providers) may process data outside your country. Where that applies, we rely on their own standard safeguards for international transfers; we’ll confirm the specifics here once our legal entity and primary market are finalised.

9. Changes to this policy

We’ll update this page as Travelmad develops and update the “last updated” date when we do. Material changes will be communicated to active users.

10. Contact

Questions about your data or this policy: arjen@travelmad.app.

Terms of Service · Back to travelmad