TravvioTravvio

Privacy Policy

Last updated: June 5, 2026

1. Introduction & Scope

Travvio ("we", "us", "our") is a Delaware (USA) business that provides an AI-powered travel planning service. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our web application at travv.io and travelhelper.lovable.app (collectively, the "Service"). It applies to all users of the Service.

2. Information We Collect

  • Account data: name, email address, and a securely hashed password managed through Supabase Auth.
  • Profile and preferences: travel style, interests, home location, preferred destinations, 1–5 preference ratings, and loyalty or preferred-brand selections.
  • Trip data: destinations, dates, traveler counts, generated itineraries, hotel selections, and notes you save.
  • Payment metadata: Stripe customer ID and purchase history. We do not store or process payment card numbers; Stripe handles them directly.
  • Communications: contact-form submissions and support emails you send us.
  • Technical data: IP address, browser user-agent, application logs, error reports, and session cookies.

3. How We Use Your Information

  • Provide, operate, and maintain the Service.
  • Generate personalized AI itineraries and hotel recommendations.
  • Process credit purchases and maintain your credit balance.
  • Send transactional emails (account, itinerary exports, receipts, support replies).
  • Detect, prevent, and respond to fraud, abuse, and security incidents.
  • Improve product quality through aggregate analytics and debugging.
  • Comply with legal obligations and enforce our Terms of Service.

4. AI-Generated Content

When you generate or edit an itinerary, the inputs you provide — destination, dates, traveler information, free-text activities, and your saved preferences — are sent to our AI provider via the Lovable AI Gateway / OpenAI for processing. The resulting itinerary is stored in our database and tied to your trip. Under our provider agreements, your prompts and outputs are not used to train third-party AI models. We may retain limited request logs for abuse prevention and debugging.

5. Subprocessors & Third Parties

We rely on the following service providers to operate the Service. Each is bound by their own privacy and security commitments:

  • Supabase — authentication, database, storage, and edge functions.
  • Stripe — payment processing for credit purchases.
  • Resend — transactional email delivery (from hello@travel-helper.io).
  • OpenAI / Lovable AI Gateway — AI itinerary generation.
  • Google Maps Platform — map rendering and place data.
  • Sentry — error monitoring.
  • Lovable — application hosting and deployment.

We do not sell or rent your personal information, and we do not share it for cross-context behavioral advertising.

6. Cookies & Similar Technologies

We use only strictly necessary and functional cookies — primarily the session cookies set by Supabase Auth to keep you signed in, and local-storage entries that remember preferences such as your selected trip view. We do not set advertising cookies. Because only essential cookies are used, we do not currently display a consent banner. You can disable cookies in your browser, but doing so will prevent you from signing in.

7. Data Retention

  • Account and profile data: retained while your account is active.
  • Trip data: retained until you delete the trip or your account.
  • Deleted accounts: purged from our active systems within 30 days. Stripe payment records are retained per Stripe's terms and applicable tax law.
  • Error logs: retained for up to 90 days.
  • Email delivery logs: retained for up to 12 months.

8. Data Security

We use TLS encryption in transit, encryption at rest through Supabase, role-based access controls, Row-Level Security on user-scoped data, and the principle of least privilege for staff access. No system is 100% secure; we cannot guarantee absolute security but work continually to protect your information.

9. International Data Transfers

Our Service is hosted primarily in the United States. If you access the Service from the European Economic Area, the United Kingdom, or another jurisdiction outside the US, your information may be transferred to, stored, and processed in the US. Where applicable, we rely on Standard Contractual Clauses with our subprocessors to safeguard such transfers.

10. Your Rights

Depending on where you live, you may have the following rights under GDPR, UK GDPR, CCPA/CPRA, or similar laws:

  • Access a copy of the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete your data ("right to be forgotten").
  • Port your data in a structured, machine-readable format.
  • Restrict or object to certain processing.
  • Withdraw consent at any time, where processing is based on consent.

Most rights can be exercised directly in the app: update your data on the Profile page, and delete your account from Account → Delete Account. For any other request, email hello@travel-helper.io.

11. Children's Privacy

The Service is not directed to children under 13 (or under 16 in the EEA/UK), and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.

12. California Residents (CCPA/CPRA)

In the past 12 months we have collected the categories of information described in Section 2 for the purposes described in Section 3. We do not sell personal information and we do not share it for cross-context behavioral advertising. California residents may exercise the rights to know, delete, correct, and to non-discrimination for exercising those rights, as described in Section 10.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above. For material changes, we will notify you by email or with an in-app notice before the changes take effect.

14. Contact Us

Travvio — Delaware, USA.
Email: hello@travel-helper.io
Or use our Contact page.