Legal
Privacy Policy
How MyTravelPeace collects, uses, shares, and retains personal information.
- Version
- 2.0.0
- Effective Date
- August 7, 2026
- Last Updated
- August 7, 2026
Introduction
This Privacy Policy describes how MyTravelPeace (“MyTravelPeace”, “we”, “us”, or “our”) collects, uses, shares, and retains information when you use our websites, applications, and related software services (the “Service”).
MyTravelPeace is a software-as-a-service travel planning platform. We provide software tools for discovery, itinerary organization, collaboration, and AI-assisted features. We are not a travel agency, we do not sell flights or hotels, and we do not provide visa, insurance, or booking-fulfillment services.
By using the Service, you acknowledge this Policy. Related documents include our Terms of Service, Refund Policy, Cookie Policy, AI Notice, and Subprocessors list.
Definitions
- Personal Information
- Information that identifies, relates to, or could reasonably be linked to an identifiable individual, as defined under applicable privacy laws.
- Account
- A registered MyTravelPeace user identity managed through our authentication provider (Supabase Auth).
- Customer Content
- Trips, itineraries, checklist items, notes, destinations, dates, collaborator relationships, and related materials you create or store in the Service.
- AI Features
- Features that send prompts or structured requests to machine-learning providers (currently Google Gemini) to generate informational outputs, including Public Radar search and in-product assistant experiences where enabled for your plan.
- Public Radar
- AI-assisted event and culture search experiences that may be available to visitors and authenticated users according to product entitlements and usage limits.
Information Collected
We collect information that you provide, information generated by your use of the Service, and limited technical information needed to operate and secure the Service. We do not operate an advertising network and do not intentionally collect information unrelated to providing the Service.
Account Information
When you register or sign in, our authentication provider processes credentials and account identifiers. This typically includes email address, authentication tokens/session data, and account identifiers (such as a user UUID).
Profile fields you choose to provide in the Service (for example display preferences shown in the product) are stored as part of your Account experience.
Password handling is performed by the authentication provider according to its security practices. MyTravelPeace application code is designed not to store plaintext passwords.
Trips / Itineraries
If you use trip features, we store Customer Content you create, such as trip titles, destinations, dates, itinerary items, checklist items, and related metadata needed to render and sync your trips.
Trip content is associated with your Account and may be visible to people you invite or to anyone who can open a share link you create.
Collaborators
You may invite collaborators to a trip. Collaboration records associate another Account with a trip and a role (such as editor or viewer, as implemented in the product).
Collaborators can access trip content consistent with their role. Removing a collaborator updates access going forward; historical copies outside the Service (for example screenshots) are outside our control.
AI Requests
When you use AI Features, the Service transmits the prompts, filters, or structured inputs you submit (and related context needed to fulfill the request) to our AI model provider to generate a response.
We may also store usage metering records (for example category and units consumed in a billing period) to enforce plan allowances. We do not treat AI outputs as verified facts; see the AI Notice and Terms of Service.
Public Radar
Public Radar requests may be made while signed out or signed in, subject to product limits. Request parameters you submit (such as location text, coordinates when you choose to provide them, date ranges, categories, and budget filters) are processed to return informational results.
Authenticated Radar usage may count toward your plan’s AI allowance. Anonymous or public usage may be subject to separate rate or quota controls implemented in the product.
Subscription Information
If you subscribe to a paid plan, we maintain a local subscription projection associated with your Account. This may include plan identifiers (such as free, premium, or vip), subscription status, period end timestamps, cancellation-at-period-end flags, and related billing state needed to show your plan in the product.
Authoritative payment transactions are processed by Paddle. Our systems receive subscription and transaction events via webhooks to update your local projection.
Billing Identifiers
To operate subscriptions, we may store billing customer and subscription identifiers issued by Paddle and link them to your Account UUID. We do not store full payment card numbers in MyTravelPeace application databases.
Invoices, tax documents, and card details are handled in Paddle’s systems according to Paddle’s role as payment provider / Merchant of Record where applicable.
Log Information
We and our infrastructure providers generate technical logs related to requests, errors, and service operation. Logs are used to maintain reliability and security.
Security Logs
MyTravelPeace maintains an internal operations event system used by authorized administrators. Security-category events may include authentication and authorization outcomes for the Admin Platform (for example successful or failed admin login attempts, unauthorized admin route or API access, and related security signals).
Where IP addresses are processed for security events, the application is designed to store hashed values rather than plaintext IPs. User-agent strings may be stored in truncated or limited form for operational context.
System Monitoring
System-category operational events and related incident records may capture technical failures (for example provider outages, projection failures, or configuration issues) for internal monitoring. These records are intended for operators, not for public profiles.
Public Radar Aggregates
For Public Radar, the Service may store aggregate usage counters (such as request, success, failure, quota, and blocked counts by day or month). These aggregates are designed as operational metrics and are not a transcript of individual prompts.
Admin Platform Access
A separate Admin Platform is available only to users listed as active internal administrators. Administrators may access operational monitoring views (for example clients, trips metadata, activity, security logs, system health, Public Radar aggregates, settings summaries) as needed to operate the Service.
Admin access is not a public feature and is not granted by ordinary customer signup.
How Information Is Used
We use information to:
- Provide, maintain, and improve the Service and Account features.
- Authenticate users and protect against abuse, fraud, and unauthorized access.
- Enable trips, collaboration, and sharing that you initiate.
- Operate AI Features you request and enforce plan usage limits.
- Process subscriptions, renewals, upgrades, downgrades, cancellations, and related billing state with Paddle.
- Provide customer-facing plan status and billing management entry points.
- Monitor reliability and security through operational logging.
- Comply with law and enforce our Terms and Acceptable Use Policy.
Legal Bases (General Architecture)
Pending Legal ReviewDepending on your location, we rely on one or more recognized bases to process Personal Information, such as: performance of a contract (providing the Service you request); legitimate interests in securing and operating the Service; compliance with legal obligations; and consent where required (for example certain optional processing).
- Pending Legal Review — this section requires counsel confirmation for jurisdiction-specific wording.
- Jurisdiction-specific lawful-basis tables (for example GDPR Article 6 mappings) will be confirmed by counsel for your launch markets.
Third-Party Processors
We use subprocessors to host and operate the Service. Current categories include:
A current list also appears on our Subprocessors page. Providers may change as we operate the Service; material updates will be reflected in document versions when practicable.
- Supabase — authentication, application database, and related backend services.
- Paddle — payment processing and subscription billing.
- Google (Gemini) — AI model inference for AI Features.
- Application hosting provider — delivery of the web application (for example when deployed on a platform such as Vercel).
International Transfers
Pending Legal ReviewOur subprocessors may process information in the United States and other countries where they operate. If you access the Service from another country, your information may be processed outside your home country.
- Pending Legal Review — this section requires counsel confirmation for jurisdiction-specific wording.
- Specific transfer mechanisms (for example standard contractual clauses) will be confirmed by counsel where required.
Data Retention
We retain Account data and Customer Content while your Account remains active and as needed to provide the Service. Subscription and billing records may be retained as required for accounting, dispute resolution, and legal compliance.
Operational security and system logs are retained for a period appropriate to security and reliability needs. Public Radar aggregates are retained as operational metrics.
A more detailed schedule appears on our Data Retention page and may be refined after legal review. We do not promise indefinite retention or customer-facing backup downloads.
Account Deletion
Pending Legal ReviewYou may request deletion of your Account by contacting MyTravelPeace through the designated support channel when published.
Self-serve account deletion workflows may be added in a later product phase. Until then, deletion requests are handled as an operator process. Residual copies may remain in limited operational backups for a period after deletion from primary systems.
- Pending Legal Review — this section requires counsel confirmation for jurisdiction-specific wording.
- Response timelines and verification steps for deletion requests will be confirmed by counsel and operations.
User Rights
Pending Legal ReviewDepending on applicable law, you may have rights to access, correct, delete, or restrict certain Personal Information, to object to certain processing, to withdraw consent where processing is consent-based, and to lodge a complaint with a supervisory authority.
To exercise rights, contact us using the Contact Information section. We may need to verify your identity before fulfilling a request.
- Pending Legal Review — this section requires counsel confirmation for jurisdiction-specific wording.
- Market-specific rights disclosures (for example GDPR, CCPA/CPRA, or Philippines DPA wording) will be finalized by counsel.
Security
We use administrative and technical measures appropriate to a SaaS application, including encrypted transport (HTTPS) for the Service, authenticated access controls, separation of customer Accounts from the Admin Platform, and privacy-conscious operational logging practices described above.
No method of transmission or storage is completely secure. We do not claim specific third-party certifications (such as SOC 2 or ISO 27001) unless separately published as current.
Children
Pending Legal ReviewThe Service is not directed to children and is intended for users who can lawfully enter into the Terms of Service. We do not knowingly collect Personal Information from children for a child-directed product.
- Pending Legal Review — this section requires counsel confirmation for jurisdiction-specific wording.
- Exact minimum age (for example 16 or 18) will be confirmed by counsel for launch markets.
Changes to This Policy
We may update this Privacy Policy by publishing a new version with revised version metadata. Material changes may be communicated in-product or by email when appropriate. Continued use after the effective date constitutes acceptance where permitted by law; some changes may require renewed acceptance when acceptance recording is enabled.
Contact Information
Pending Legal ReviewFor questions about this document, contact MyTravelPeace through the support channel designated by the operator (for example, the email address published on the Service when available).
Pending Legal Review — this section requires counsel confirmation for jurisdiction-specific wording.
Formal legal notice requirements, registered office, and entity name will be confirmed by counsel. Until then, do not treat informal messages as formal legal service of process.
Revision History
| Version | Date | Notes |
|---|---|---|
| 2.0.0 | August 7, 2026 | LGL-2 core Privacy Policy aligned to current MyTravelPeace architecture. |
| 1.0.0 | August 7, 2026 | LGL-1 architecture baseline. |