PRIVACY POLICY
Last updated: September 22, 2025
1. INTRODUCTION
Welcome to Trave, the social travel app that allows you to document your adventures and discover those of others.
This Privacy Policy applies to the Trave mobile application (hereinafter “the Application”, “Trave” or “we”) and describes how we collect, use, protect and share your personal information.
By using Trave, you agree to the practices described in this policy. If you do not agree to these terms, please do not use our service.
2. DATA CONTROLLER
Company: Trave
Contact: contact@app-trave.com
3. INFORMATION WE COLLECT
3.1 Information you provide directly
Account and profile information:
- Identity: First name, last name, username, date of birth
- Contact: Email address, phone number (optional)
- Profile: Profile picture, cover picture, biography
- Location: Country of residence
- Authentication: Password (encrypted) or OAuth data (Google, Apple)
User-generated content:
- Trips: Destinations, dates, descriptions, costs
- Points of Interest (POI): Hotels, restaurants, activities with descriptions, photos, ratings, links
- Photos and videos: Images uploaded for your trips and POI
- Comments and interactions: Posts, likes, messages
3.2 Information collected automatically
Geolocation data:
- GPS position: Precise coordinates when adding POI (with your permission)
- Map data: Interactions with Mapbox maps
- Place searches: City and point of interest queries
Technical data:
- Device identifiers: Unique device identifier, IP address
- System information: Device type, OS version, app version
- Usage data: Pages visited, features used, time spent
- Error logs: Technical logs for debugging
Cookies and similar technologies:
- User preferences: Language, theme, settings
- Authentication: Secure session tokens
- Analytics: Aggregated and anonymized usage data
3.3 Information from third parties
Authentication services:
- Google: Name, email, profile picture (if you use Google sign-in)
- Apple: Name, email (if you use Apple sign-in)
Mapping services:
- Mapbox: Geolocation data and place searches
- Google Places: Place information (fallback service)
4. HOW WE USE YOUR INFORMATION
4.1 Service provision and improvement
- App operation: Account creation and management
- Social features: Trip sharing, content discovery
- Recommendations: Destination and POI suggestions based on your preferences
- Mapping: Display of your trips and POI on interactive maps
- Search: Search for places, users and content
4.2 Communication and support
- Notifications: Account activity alerts (configurable)
- Customer support: Answering your questions and solving problems
- Updates: Information about new features
4.3 Security and compliance
- Security: Fraud and abuse prevention
- Legal compliance: Meeting regulatory obligations
- Analytics: Improving performance and user experience
4.4 Marketing (with consent)
- Marketing communications: Newsletters, promotions (with unsubscribe option)
- Personalization: Content tailored to your interests
5. LEGAL BASIS FOR PROCESSING (GDPR)
We process your personal data based on:
- Contract performance: Providing Trave services
- Legitimate interest: Service improvement, security, analytics
- Consent: Marketing, non-essential cookies, precise geolocation
- Legal obligation: Regulatory compliance
6. SHARING YOUR INFORMATION
6.1 With other users
- Public profile: Username, profile picture, country, public trips
- Shared content: Trips, POI, photos according to your privacy settings
- Interactions: Comments and likes visible according to content
6.2 With our service providers
Technical infrastructure:
- Supabase: Database hosting (PostgreSQL)
- Cloud services: Data storage and processing
Mapping services:
- Mapbox: Mapping and geolocation
- Google Places: Place search (fallback service)
Authentication:
- Google: OAuth sign-in service
- Apple: OAuth sign-in service
Analytics and monitoring:
- Analytics services: Aggregated and anonymized usage data
6.3 Legal obligations
We may disclose your information if required by law or to:
- Respond to valid legal requests
- Protect our rights and security
- Prevent illegal activities
6.4 Business transactions
In case of merger, acquisition or asset sale, your data may be transferred as part of the transaction.
7. DATA STORAGE AND SECURITY
7.1 Data location
- Main servers: European Union (Supabase)
- Third-party services: According to providers (see section 6.2)
- International transfers: Governed by appropriate safeguards (standard contractual clauses)
7.2 Security measures
- Encryption: Data in transit (HTTPS/TLS) and at rest
- Authentication: Secure OAuth (Apple, Google) and passwordless authentication
- Access: Strict and secure access controls
- Monitoring: Regular monitoring of our systems and infrastructure
- Backups: Regular and secure backups
7.3 Data retention
- Active accounts: As long as your account exists
- Deleted accounts: Immediate and permanent deletion
- Backup data: Up to 90 additional days for technical reasons
- Anonymized data: Retained for legitimate statistical analysis
- Legal obligations: Retention according to regulatory requirements
8. YOUR RIGHTS
8.1 GDPR rights (EU/EEA residents)
- Access: Obtain a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data (“right to be forgotten”)
- Restriction: Restrict processing in certain cases
- Portability: Receive your data in a structured format
- Objection: Object to processing for legitimate reasons
- Consent: Withdraw your consent at any time
8.2 Control of your data
In the application:
- Privacy settings: Visibility of your profile and content
- Data management: Modification, deletion of your information
- Notifications: Alert configuration
Account deletion:
- Immediate deletion: From application settings
- Retained data: Anonymized for legitimate analytics
- Permanent deletion: No recovery possible after deletion
8.3 Exercising your rights
To exercise your rights, contact us at: **contact@app-trave.com **
We will respond within a maximum of 30 days. This period may be extended by 60 additional days for complex requests, in which case we will inform you of this extension within the first month.
9. CHILDREN’S PRIVACY
Trave is not intended for children under 13. We do not knowingly collect personal information from children under 13.
If you are between 13 and 16, you must obtain authorization from your parents or guardians before using Trave.
10. CHANGES TO THIS POLICY
We may modify this Privacy Policy from time to time. Significant changes will be notified to you by:
- In-app notification
- Email (if you have consented to receive our communications)
- Date update at the top of this policy
Your continued use of Trave after changes constitutes your acceptance of the revised policy.
11. COOKIES AND SIMILAR TECHNOLOGIES
11.1 Types of cookies used
Essential cookies:
- Authentication: Session maintenance
- Security: Protection against attacks
- Preferences: Language, display settings
Analytics cookies:
- Usage: Application performance measurement
- Errors: Technical problem detection and resolution
Functionality cookies:
- Geolocation: Memory of your location preferences
- Content: User experience personalization
11.2 Cookie management
You can control cookies via:
- Application settings: Privacy options
- Device settings: Browser/system configuration
12. GEOLOCATION
12.1 Use of geolocation
- Adding POI: Precise positioning of your points of interest
- Maps: Display of your position on maps
- Search: Nearby place suggestions
- Recommendations: Content adapted to your region
12.2 Geolocation control
- Explicit permission: Authorization request before collection
- Settings: Enable/disable in settings
- Accuracy: Choice between precise or approximate location
- History: No permanent storage of your real-time position
13. CONTACT AND COMPLAINTS
13.1 Contact
For any questions regarding this policy or your personal data:
Email: contact@app-trave.com
Support: contact@app-trave.com
13.2 Complaints
If you are not satisfied with our response, you can file a complaint with the competent supervisory authority:
- France: CNIL (www.cnil.fr)
- EU/EEA: Data protection authority of your country
14. ADDITIONAL INFORMATION
14.1 Payment security
Trave currently does not process any payment information. If this functionality is added in the future, we will use PCI-DSS certified payment processors.
14.2 Artificial intelligence
We may use AI technologies to enhance your experience through:
- Recommendations: Personalized destination and POI suggestions
- Content moderation: Detection of inappropriate content
- Analytics: User experience improvement
These processes are designed to use aggregated and anonymized data when possible.
14.3 Open Source
Some Trave components use open source libraries. These components are subject to their own licenses and terms of use.
15. PROFILING AND AUTOMATED DECISION-MAKING
15.1 Profiling
We use profiling for:
- Recommendations: Personalized destination and POI suggestions based on your previous trips
- Moderation: Automatic detection of inappropriate content
- Usage analysis: User experience improvement
15.2 Automated decision-making
No decision producing legal effects or significantly affecting you is made in a fully automated manner.
15.3 Your rights
You can request human intervention and challenge these automated decisions by contacting us at contact@app-trave.com .
16. INTERNATIONAL TRANSFERS - DETAILED SAFEGUARDS
16.1 Applied safeguards
- Standard Contractual Clauses from the European Commission (Decision 2021/914/EU)
- Transfer Impact Assessment (TIA) for at-risk countries
- Additional security measures if necessary (enhanced encryption)
16.2 Specific partners
- Google/Apple: Standard Contractual Clauses + Privacy Framework
- Mapbox (United States): European Commission Standard Contractual Clauses
- Other providers: Compliance certification or equivalent safeguards
17. DATA BREACH
17.1 User notification
In case of a personal data breach likely to result in a high risk to your rights and freedoms, we will inform you as soon as reasonably possible after discovery of the incident.
17.2 Corrective measures
We will take all necessary measures to:
- Contain the breach and assess its impact as quickly as possible
- Notify competent authorities (data protection authorities) in accordance with our legal obligations
- Implement appropriate corrective measures
- Cooperate with authority investigations if necessary
18. SENSITIVE DATA
18.1 General principle
We do not intentionally collect sensitive data (ethnic origin, political opinions, health data, religious beliefs, etc.).
18.2 Accidental collection
If you inadvertently share sensitive data in your travel descriptions or comments, we reserve the right to modify or delete them.
18.3 Geolocated photos
Photos with geolocation may reveal sensitive information (home, private places). You control their sharing through your privacy settings.
19. INTERNATIONAL COMPLIANCE
19.1 California residents (CCPA/CPRA)
You have the following rights:
- Right to know: Categories of data collected and their use
- Right to delete: Request deletion of your data
- Right to opt-out: We do not sell your personal data
- Non-discrimination: No differential treatment for exercising your rights
19.2 Brazilian residents (LGPD)
Compliance with the Lei Geral de Proteção de Dados, including:
- Legitimate and proportionate purpose of processing
- Free and informed consent for sensitive data
- Data subject rights (access, rectification, deletion)
19.3 Other jurisdictions
We strive to comply with data protection laws of all countries where Trave is available.
20. JURISDICTION AND APPLICABLE LAW
20.1 Applicable law
This Privacy Policy is governed by French law and European regulations (GDPR).
20.2 Judicial competence
In case of dispute, French courts shall have sole jurisdiction, subject to the mandatory rights of consumers in their country of residence.
20.3 Users outside EU/EEA
French law applies to the extent permitted by applicable local law.
21. CONTACT AND SUPPORT
21.1 Contact points
Privacy questions: contact@app-trave.com General support: contact@app-trave.com
21.2 Response times
- Rights exercise requests: 30 days maximum (may be extended to 90 days for complex requests with prior notification)
- General questions: We strive to respond as quickly as possible
- Security incidents: Priority processing upon detection by our monitoring systems
This policy is effective as of September 22, 2025.
Last major revision: September 22, 2025 Version: 1.0
For any questions, contact us at: **contact@app-trave.com **