Legal · Privacy
Privacy Policy
This Privacy Policy explains how Go! Trip collects, uses, stores, shares, and protects your personal information when you use our AI-powered travel itinerary planning application. It applies to all users worldwide and addresses your rights under the General Data Protection Regulation (GDPR), the Brazilian General Data Protection Law (LGPD), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the Personal Information Protection and Electronic Documents Act (PIPEDA), the Children's Online Privacy Protection Act (COPPA), and other applicable data protection laws.
Table of Contents
Introduction
Go! Trip ("we," "us," "our," or the "Company") is an AI-powered travel itinerary planning application available on iOS and Android. We are a technology company based in Brazil. Go! Trip is NOT a travel agency, tour operator, or booking platform. We use artificial intelligence, publicly available data, and third-party APIs to help users plan travel itineraries based on their stated preferences.
This Privacy Policy describes how we collect, use, disclose, store, and protect your personal data when you access or use the Go! Trip mobile application and any associated websites or services (collectively, the "Service"). It also explains your rights regarding your personal data and how you can exercise those rights.
By using Go! Trip, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please do not use our Service.
For the purposes of the GDPR and LGPD, the data controller responsible for your personal data is Go! Trip, contactable at [email protected]. For the purposes of the CCPA/CPRA, we are a "business" that collects personal information from California consumers.
Information We Collect
We collect several categories of information in order to provide, maintain, and improve the Service. In accordance with GDPR Article 13 and LGPD Article 9, we disclose below the specific categories of personal data we collect, the source of each category, and whether the provision of such data is required or optional.
Account Information: When you create an account, we collect your email address (required) and your name (optional). Your password is cryptographically hashed using bcrypt before storage; we never store or have access to your plaintext password.
Trip Preferences and Planning Data: When you create or customize a travel itinerary, we collect information you provide such as destination cities or countries, travel dates, dietary needs or restrictions, accessibility requirements, travel party type (solo, couple, family, group), budget range, and activity preferences. Some of this information, including dietary needs and accessibility requirements, may constitute sensitive personal data under the LGPD and special category data under the GDPR. We process this data only with your explicit consent provided at the time of input.
User-Generated Content: If you use the "Moments" feature, you may upload photographs to the Service. These photos are stored in Cloudflare R2 cloud storage and are associated with your account and the relevant trip.
Usage Data: We automatically collect information about how you interact with the Service, including pages and features viewed, actions taken within the app, timestamps of activity, session duration, and referring sources.
Device Information: We collect device type and model, operating system and version, unique device identifiers, app version, language and locale settings, and timezone.
Session and Authentication Data: We use Redis-based sessions and authentication tokens to maintain your logged-in state and provide a secure experience. These are functional in nature and are not used for advertising or profiling.
Categories of personal information collected, as defined by the CCPA/CPRA:
- Identifiers: email address, name, unique account ID, device identifiers.
- Internet or other electronic network activity: usage data, session information, device information, app interaction data.
- Geolocation data: only the city-level destinations you choose for trip planning; we do not track your real-time location.
- Sensory data: photographs you voluntarily upload via the Moments feature.
- Inferences drawn: AI-generated itinerary suggestions based on your stated preferences.
- Sensitive personal information (CPRA): dietary restrictions and accessibility needs you voluntarily provide.
How We Use Your Information
We use the personal data we collect for the following specific purposes:
- Account Management: To create, authenticate, and maintain your account, process password resets, and communicate account-related information. We use your email address and hashed password for this purpose.
- Itinerary Generation: To generate personalized, AI-powered travel itinerary suggestions based on your trip preferences, including destinations, dates, dietary needs, accessibility requirements, and travel party type. This is the core function of our Service.
- Photo Storage and Display: To store and display photographs you upload through the Moments feature, associating them with the relevant trip in your account.
- Service Improvement: To analyze aggregated and anonymized usage patterns, diagnose technical issues, and improve the features, performance, and reliability of the Service.
- Transactional Communications: To send you essential service communications such as account verification emails, password reset links, and critical security notifications via Resend, our transactional email provider.
- Future Paid Features: When paid subscription plans become available, to process payments, manage subscriptions, and provide premium features. Payment processing will be handled by RevenueCat and the respective app store (Apple App Store or Google Play Store). No charges will be made without your explicit consent.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, or governmental requests, and to establish, exercise, or defend legal claims.
Legal Basis for Processing
Under the GDPR (Article 6) and LGPD (Article 7), we are required to have a valid legal basis for each processing activity involving your personal data. The following explains the legal basis we rely on for each category of processing:
Performance of Contract (GDPR Art. 6(1)(b) / LGPD Art. 7(V)): Account creation and authentication, itinerary generation based on your preferences, photo storage and display within the Moments feature, and providing core Service functionality. These processing activities are necessary to deliver the Service you have requested.
Explicit Consent (GDPR Art. 6(1)(a), Art. 9(2)(a) / LGPD Art. 7(I), Art. 11(I)): Processing of sensitive personal data such as dietary restrictions that may reveal health conditions or religious beliefs, and accessibility requirements that may reveal disability status. You provide this information voluntarily and may withdraw consent at any time by deleting the relevant trip data or contacting us. Withdrawal of consent does not affect the lawfulness of processing performed before the withdrawal.
Legitimate Interests (GDPR Art. 6(1)(f) / LGPD Art. 7(IX)): Collecting usage data and device information to improve Service reliability, security, and performance; analyzing anonymized and aggregated patterns to enhance features; and detecting and preventing fraud or abuse. We have conducted balancing tests to ensure our legitimate interests do not override your rights and freedoms.
Legal Obligation (GDPR Art. 6(1)(c) / LGPD Art. 7(II)): Retaining certain data to comply with tax, accounting, or other legal requirements; responding to valid legal processes; and fulfilling mandatory data breach notification obligations.
CCPA/CPRA Categories and Business Purpose: Under the CCPA/CPRA, we collect identifiers, internet activity information, geolocation data (city-level only), sensory data (user-uploaded photos), inferences, and sensitive personal information — all for the business purposes described above. We do NOT sell or share your personal information as those terms are defined under the CCPA/CPRA.
PIPEDA Compliance: In accordance with Canada's PIPEDA and its ten fair information principles, we collect personal information only for identified purposes, obtain meaningful consent, limit collection to what is necessary, use data only for stated purposes, retain it only as long as needed, ensure accuracy, implement appropriate safeguards, maintain transparency about our policies, provide access to your data upon request, and offer a complaint mechanism. You may challenge our compliance by contacting [email protected] or the Office of the Privacy Commissioner of Canada.
Third-Party Services
We use the following third-party services to operate Go! Trip. Each service receives only the minimum data necessary to perform its function:
Google Places API: We send destination names and preference parameters to the Google Places API to retrieve place information, points of interest, ratings, reviews, operating hours, and other publicly available venue data. This data is used to populate your itinerary with relevant suggestions. Google processes this data in accordance with the Google Privacy Policy [Google Privacy Policy]. Your use of the Service is also subject to the Google Maps/Google Earth Additional Terms of Service.
Google Routes API: We use the Google Routes API to calculate travel times, distances, and directions between points of interest in your itinerary. Route queries include origin and destination coordinates or addresses. Google processes this data in accordance with the Google Privacy Policy [Google Privacy Policy].
OpenRouter (AI Inference): We send your trip preferences — such as destination, dates, dietary needs, accessibility requirements, travel party type, and activity preferences — to OpenRouter, which routes requests to large language model providers for AI inference. OpenRouter processes this data to generate itinerary suggestions. No directly identifying information such as your email address or name is sent to OpenRouter; only trip context necessary for itinerary generation is transmitted.
Cloudflare R2 (Photo Storage): Photographs you upload through the Moments feature are stored in Cloudflare R2 object storage. Cloudflare processes this data in its role as a data processor under applicable data protection agreements.
Resend (Transactional Email): We use Resend to deliver transactional emails such as account verification, password resets, and critical service notifications. Resend receives your email address and the content of the specific email being sent.
Redis (Session and Cache): We use Redis for server-side session management and caching. Session tokens are stored in Redis to maintain your authenticated state. Redis operates as infrastructure and does not independently process your personal data.
RevenueCat (Future Payment Processing): When paid subscription plans become available, we will use RevenueCat to manage subscriptions and process payments through the Apple App Store and Google Play Store. RevenueCat will receive only the information necessary for billing and subscription management. This Privacy Policy will be updated before any paid features are activated.
AI and Automated Processing
Go! Trip uses artificial intelligence to generate travel itinerary suggestions. When you create a trip, we send your stated preferences — including destinations, dates, dietary restrictions, accessibility needs, travel party type, and activity interests — to AI language models via OpenRouter. The AI processes these preferences alongside publicly available information about destinations to generate day-by-day itinerary suggestions.
The AI does not make decisions that produce legal effects or similarly significant effects on you. Itinerary suggestions are recommendations only and do not constitute professional travel advice, booking confirmations, or binding commitments of any kind. You retain full control over whether to follow, modify, or disregard any suggestion. No travel, financial, or legal decision is made automatically on your behalf.
LGPD Compliance: Under the LGPD, you have the right to request a review of decisions made solely on the basis of automated processing of your personal data that affect your interests, including decisions intended to define your personal, professional, consumer, or credit profile, or aspects of your personality. While our AI itinerary suggestions do not fall into these categories, we respect your right to request human review of any automated output by contacting us.
AI-generated itinerary content may include inaccuracies regarding operating hours, prices, availability, accessibility of venues, or current conditions at destinations. We make reasonable efforts to provide useful suggestions but cannot guarantee the accuracy, completeness, or timeliness of AI-generated content. You should independently verify all information before making travel decisions.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. The specific retention periods for each category of data are as follows:
- Account Information (email, name, hashed password): Retained for the duration of your active account. Upon account deletion, this data is permanently deleted within 30 days, except where retention is required by law.
- Trip Preferences and Itinerary Data: Retained for the duration of your active account. You may delete individual trips at any time. Upon account deletion, all trip data is permanently deleted within 30 days.
- User-Uploaded Photos (Moments): Retained for the duration of your active account. You may delete individual photos at any time. Upon account deletion, all photos are permanently deleted from Cloudflare R2 within 30 days.
- Usage Data and Device Information: Retained in identifiable form for up to 12 months from the date of collection. After this period, data is either permanently deleted or irreversibly anonymized and aggregated for statistical analysis.
- Session Data (Redis): Authentication sessions expire automatically after 30 days of inactivity. Session data is transient and is not retained beyond its functional lifespan.
- Transactional Email Logs: Delivery metadata retained for up to 90 days for troubleshooting purposes. Email content is not retained beyond delivery.
- Legal and Compliance Records: Where we are required by law to retain certain data (such as for tax or accounting obligations), we will retain the minimum necessary data for the legally mandated period, which may extend beyond the periods stated above.
When data is no longer needed and no legal retention obligation applies, we securely delete or irreversibly anonymize it. Anonymized data, which cannot be used to identify you, may be retained indefinitely for analytical and statistical purposes.
International Data Transfers
Go! Trip is based in Brazil. By using our Service, your personal data may be transferred to, stored in, and processed in countries other than your country of residence. These transfers are necessary to provide you with the Service and occur in the following contexts:
- United States: Data may be processed by our third-party service providers including Google (Places and Routes APIs), OpenRouter (AI inference), Cloudflare (R2 photo storage), Resend (transactional email), and RevenueCat (future payment processing), whose servers and infrastructure may be located in the United States.
- European Economic Area (EEA): If you are located in the EEA, data transfers to countries outside the EEA that have not received an adequacy decision from the European Commission are safeguarded by Standard Contractual Clauses (SCCs) approved by the European Commission, or other legally recognized transfer mechanisms under GDPR Chapter V.
- Brazil: As our company is based in Brazil, your data is stored and processed in Brazil. The LGPD permits international transfers of personal data when the receiving country provides an adequate level of data protection, when appropriate safeguards are in place, or when specific consent is given.
For transfers of personal data from the EEA to third countries, we rely on Standard Contractual Clauses (SCCs) as our primary transfer mechanism under GDPR Article 46(2)(c). We also conduct transfer impact assessments where required to evaluate the level of data protection in the recipient country and implement supplementary measures where necessary.
For transfers of personal data from Brazil, we comply with LGPD Article 33, which permits transfers when the recipient country or international organization provides an adequate level of protection, when appropriate safeguards are ensured by the controller (including standard contractual clauses and binding corporate rules), or when the transfer is necessary for the performance of a contract at the data subject's request.
You may request information about the specific safeguards applied to transfers of your personal data by contacting us at [email protected].
Your Rights
Depending on your location and applicable law, you have certain rights regarding your personal data. We are committed to facilitating the exercise of these rights. Below is a comprehensive summary of your rights under each applicable legal framework.
Rights Under the GDPR (EU/EEA Residents):
- Right of Access (Art. 15): You have the right to obtain confirmation as to whether we process your personal data and, if so, to receive a copy of that data along with information about the purposes, categories of data, recipients, retention periods, and your rights.
- Right to Rectification (Art. 16): You have the right to have inaccurate personal data corrected and incomplete data completed.
- Right to Erasure / Right to Be Forgotten (Art. 17): You have the right to request the deletion of your personal data when it is no longer necessary for its original purpose, when you withdraw consent, when you object to processing and there are no overriding legitimate grounds, when the data was unlawfully processed, or when deletion is required by law.
- Right to Restriction of Processing (Art. 18): You have the right to restrict the processing of your data while the accuracy of the data is contested, when processing is unlawful but you prefer restriction to erasure, when we no longer need the data but you need it for legal claims, or when you have objected to processing pending verification of legitimate grounds.
- Right to Data Portability (Art. 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance.
- Right to Object (Art. 21): You have the right to object to processing based on legitimate interests or public interest. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
- Right Not to Be Subject to Automated Decision-Making (Art. 22): You have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect you. As noted, Go! Trip does not engage in such decision-making.
- Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
Rights Under the LGPD (Brazilian Residents):
- Confirmation of the existence of processing of your personal data.
- Access to your personal data.
- Correction of incomplete, inaccurate, or outdated data.
- Anonymization, blocking, or deletion of unnecessary or excessive data, or data processed in violation of the LGPD.
- Portability of your data to another service or product provider.
- Deletion of personal data processed with your consent.
- Information about public and private entities with which your data has been shared.
- Information about the possibility of denying consent and the consequences thereof.
- Revocation of consent.
- Right to petition the ANPD (Autoridade Nacional de Protecao de Dados) regarding your data.
- Right to request review of decisions made solely on the basis of automated processing.
Rights Under the CCPA/CPRA (California Residents):
- Right to Know: You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purposes for collection, and the categories of third parties with whom we share your data.
- Right to Delete: You have the right to request deletion of personal information we have collected from you, subject to certain exceptions.
- Right to Correct: You have the right to request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing: We do NOT sell or share your personal information. However, if this practice were to change in the future, you would have the right to opt out.
- Right to Limit Use of Sensitive Personal Information: You have the right to limit the use and disclosure of sensitive personal information to purposes necessary to provide the Service.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights. You will not receive different pricing, a different quality of service, or be denied the Service for exercising your rights.
How to Exercise Your Rights: To exercise any of the above rights, please contact us at [email protected]. You may also exercise certain rights directly within the app, such as deleting your account, editing your profile, or deleting individual trips and photos.
Response Timeline: We will acknowledge your request within 5 business days and provide a substantive response within 30 days (or 15 days for LGPD requests). If the complexity or volume of requests requires additional time, we will notify you and may extend the response period by an additional 60 days (GDPR) or 45 days (CCPA/CPRA), informing you of the reason for the extension.
Verification: To protect your data, we may need to verify your identity before fulfilling a request. We will ask you to confirm the email address associated with your account. We will not require you to create a new account to submit a request.
Authorized Agents: California residents may designate an authorized agent to submit requests on their behalf. We may require written proof of the agent's authorization and may still verify your identity directly.
Children's Privacy
Go! Trip is not directed at children under the age of 13. We do not knowingly collect, use, or disclose personal information from children under 13 years of age. This is in compliance with the United States Children's Online Privacy Protection Act (COPPA), which prohibits the collection of personal information from children under 13 without verifiable parental consent.
In the European Economic Area, in accordance with the GDPR, we do not knowingly process personal data of children under the age of 16 without the consent of a parent or legal guardian. Member States may provide by law for a lower age limit, but not below 13 years. We apply the age of 16 as our threshold for users in the EEA unless specific national legislation provides otherwise.
Under the LGPD, processing of personal data of children (under 12) and adolescents (12 to 17) requires specific consent from at least one parent or legal guardian. Go! Trip requires users to be at least 13 years of age globally and 16 years of age in the EEA.
If we become aware that we have inadvertently collected personal data from a child below the applicable age threshold without appropriate consent, we will take prompt steps to delete such data from our systems. If you believe that a child has provided us with personal data, please contact us immediately at [email protected] so we can take appropriate action.
Cookies and Tracking Technologies
Go! Trip uses only strictly necessary, functional cookies and session tokens to operate the Service. These are essential for authentication, session management, and security, and cannot be disabled without impairing the core functionality of the app.
Specifically, we use:
- Session Cookies / Authentication Tokens: Used to keep you logged in and maintain your session state. These are server-side sessions managed via Redis and expire after 30 days of inactivity.
- Security Tokens: Used to prevent cross-site request forgery (CSRF) and other security threats.
Because we use only strictly necessary cookies, consent under the ePrivacy Directive (EU) is not required for these cookies. However, we disclose their use here for full transparency.
Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, destruction, or accidental loss. These measures include but are not limited to:
- Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS (Transport Layer Security) 1.2 or higher.
- Encryption at Rest: Personal data stored in our databases and file storage systems is encrypted at rest using industry-standard encryption algorithms.
- Password Security: User passwords are hashed using bcrypt with appropriate cost factors before storage. We never store plaintext passwords and cannot recover your original password.
- Access Controls: Access to personal data within our organization is restricted to authorized personnel on a need-to-know basis. Administrative access is protected by multi-factor authentication.
- Infrastructure Security: We use reputable cloud infrastructure providers that maintain comprehensive security certifications and undergo regular audits.
- Regular Security Reviews: We conduct periodic reviews of our security practices and update our measures as threats evolve.
Despite our efforts, no method of electronic transmission or storage is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, as required by GDPR Article 34.
Under the LGPD, we will notify the ANPD and affected data subjects within a reasonable time period of any security incident that may cause significant risk or harm to data subjects, as required by LGPD Article 48. Our notification will include a description of the nature of the affected data, information about the data subjects involved, the technical and security measures used for data protection, the risks related to the incident, and the measures taken or to be taken to reverse or mitigate the effects of the incident.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes, we will update the "Last Updated" date at the top of this policy.
For material changes that significantly affect how we collect, use, or share your personal data, we will provide at least 30 days' advance notice before the changes take effect. Notice will be provided via email to the address associated with your account and/or through a prominent in-app notification.
Your continued use of the Service after the effective date of a revised Privacy Policy constitutes your acceptance of the updated terms. If you do not agree with the changes, you should discontinue use of the Service and delete your account before the effective date of the revised policy.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Email: [email protected]
We aim to respond to all inquiries within 5 business days.
Right to File a Complaint with a Supervisory Authority: If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with a supervisory authority. In particular:
- EU/EEA Residents (GDPR): You may file a complaint with the Data Protection Authority (DPA) in your EU/EEA Member State of residence, place of work, or place of the alleged infringement. A list of EU DPAs is available on the European Data Protection Board website.
- Brazilian Residents (LGPD): You may file a complaint with the Autoridade Nacional de Protecao de Dados (ANPD) at www.gov.br/anpd.
- Canadian Residents (PIPEDA): You may file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at www.priv.gc.ca.
- California Residents (CCPA/CPRA): You may file a complaint with the California Attorney General's Office or the California Privacy Protection Agency (CPPA).
We encourage you to contact us first so that we can try to resolve your concern directly.