Legal
Privacy Policy
Last updated: June 4, 2026
1. Who we are
Elite Travel Buddy ("we", "us", "our") operates the Elite Travel Buddy website and application (the "Service"). For the purpose of EU/UK data-protection law, we act as the data controller of personal data we collect from you directly through the Service. Contact: privacy@elitetravelbuddy.com.
2. Data we collect
- Account data: name, email, hashed password, language, country.
- Travel data: trips you log, planning requests, itineraries, AI prompts and outputs.
- Billing data: subscription tier, transaction IDs, last 4 digits of card (full card data is handled by our payment processor — we never store it).
- Technical data: IP address, device, browser, OS, timestamps, error logs (used for security and abuse prevention).
- Communications: messages you send to support and our replies.
We do not knowingly collect data from children under 16. If you believe a child has provided personal data, contact us and we will delete it.
3. Why we use it (legal bases — GDPR Art. 6)
- Contract: to provide the Service you signed up for.
- Legitimate interests: security, fraud prevention, product improvement, analytics in aggregate.
- Legal obligation: tax, accounting, responses to lawful requests.
- Consent: optional cookies, marketing emails, certain AI features. You can withdraw consent at any time.
4. Sharing
We share personal data only with: (a) processors acting on our instructions (hosting, database, email, payments, AI inference); (b) authorities when legally required; (c) successors in a merger, acquisition or asset sale, under equivalent protections. We do not sell or rent personal data. We do not share data with advertising networks.
5. International transfers
Personal data may be processed outside your country, including in the EEA, UK and the United States. Where required, we rely on Standard Contractual Clauses, UK IDTA / Addendum, or equivalent safeguards. A copy of the safeguards is available on request.
6. Retention
We keep personal data only as long as needed for the purposes above: account data while your account is active and up to 36 months after closure for legal/tax reasons; trip and itinerary data until you delete it or close your account; billing records for up to 10 years where required by law; logs up to 12 months.
7. Security
We use industry-standard measures including TLS in transit, encryption at rest, hashed passwords, least- privilege access, row-level security and audit logging. No system is 100% secure; you are responsible for keeping your credentials confidential and notifying us promptly of any unauthorized use.
8. Your rights
Subject to applicable law, you may have the right to: access, rectify, erase, restrict or object to processing, port your data, withdraw consent, and lodge a complaint with your supervisory authority (e.g. your national Data Protection Authority in the EU/UK, or the California AG / CPPA). To exercise any right, email privacy@elitetravelbuddy.com. We respond within 30 days.
9. California residents (CCPA / CPRA)
In the last 12 months we collected the categories of personal information listed in section 2 for the business purposes listed in section 3. We did not sell or "share" (as defined by CPRA) personal information. You have the right to know, delete, correct, and to limit use of sensitive personal information.
10. AI features
When you use AI features, your prompts and selected context may be sent to AI providers acting as our processors solely to generate a response. We do not use your prompts to train third-party foundation models. AI outputs are recommendations only — always verify visa, weather, health and safety information with official sources.
11. Changes
We may update this Privacy Policy. The "Last updated" date reflects the most recent version. Material changes will be communicated by email or in-app notice.
12. Contact
Data Protection contact: privacy@elitetravelbuddy.com. See also the Legal Center.