TRAVELYZER PRIVACY POLICY
Effective date: January 2025 Last updated: January 2025
1. INTRODUCTION
1.1 Our commitment
Nathan Bardi, individual - Travelyzer project (company in the process of being incorporated), residing in France (hereinafter "TRAVELYZER", "we", "our" or "the Publisher"), publisher of the TRAVELYZER platform, is committed to protecting the privacy and personal data of its users.
1.2 Scope
This Privacy Policy describes how we collect, use, store and protect your personal data when you use:
- Our website accessible at https://gotravelyzer.com
- Our TRAVELYZER mobile application
- All of our services and features (hereinafter "the Services")
1.3 Consent
By using our Services, you accept the practices described in this Privacy Policy. If you do not accept these practices, please do not use our Services.
2. DATA CONTROLLER
2.1 Identity
The controller of personal data processing is: Nathan Bardi Individual - Travelyzer project (company in the process of being incorporated) Residence: France Email: [email protected] Website: https://gotravelyzer.com
2.2 Contact for Data Protection
For any question relating to the protection of your personal data, you can contact us: Email: [email protected]
3. DATA COLLECTED
3.1 Data provided directly by the user
When creating an account:
- Identifiers: Email address, username
- Authentication: Password (stored in encrypted form)
- Public profile: Profile picture (optional), display name, bio (optional)
- Preferences: Language, time zone, notification settings
When using the Services:
- Travel data: Destinations visited, travel dates, favorite places
- Itineraries: Routes created, points of interest, personal notes
- Social interactions: Users followed, itinerary shares
- Generated content: Photos, comments, reviews
- Searches: Search history of destinations and places
3.2 Data collected automatically
Technical data:
- Device: Device type, operating system, application version
- Connection: IP address, Internet service provider
- Browser: Type, version, language settings
- Unique identifiers: Device UUID, advertising identifiers
Usage data:
- Navigation: Pages visited, time spent, browsing paths
- Interactions: Clicks, taps, scrolls, zoom
- Performance: Loading times, errors, crashes
- Features used: Tools and services activated
3.3 Geolocation data
- Precise location: With your explicit consent, in order to:
- Display your position on the map
- Suggest nearby places
- Record your place visits
- Automatically create itineraries
- Approximate location: Based on IP address to personalize content
You can withdraw your consent to geolocation at any time within the application. This withdrawal does not affect the lawfulness of processing already carried out. You can allow approximate location without enabling precise location.
3.4 Data from third parties
Social authentication:
If you log in via Google, Apple, Facebook, we receive:
- Basic profile information (name, email, photo)
- Unique identifier of the third-party service
Partner services:
- Weather data for your destinations
- Information on points of interest
- Public transport data
3.5 Cookies and similar technologies
We use cookies in order to:
- Essential cookies: Authentication, security, preferences
- Analytical cookies: Understand the use of the platform
- Personalization cookies: Tailor content to your interests
- Advertising cookies: Display relevant advertisements (where applicable)
4. DATA VISIBILITY AND PUBLIC PROFILES
4.1 Default visibility
By default, your profile is public (username, photo, bio, shared itineraries/visits, stats, following/followers). You can restrict certain visibility elements (see 14.2 bis – Visibility settings).
4.2 Information that always remains private
The following data is NEVER visible to other users:
- Email address
- Password
- Phone number
- IP address
- Payment information
- Personal notes on places
- Unshared itinerary drafts
- Search history
- Technical and device data
4.3 Following system
Any user can follow you and see your public content. Items made unlisted or hidden via 14.2 bis are not included in these feeds.
4.4 Recommendation transparency (DSA)
Our rankings (news feed/explore) use signals such as your interactions, your preferences and the context (if authorized). You can disable certain signals or choose a non-personalized ranking (e.g. chronological/general relevance) in Settings > Privacy.
5. PURPOSES OF PROCESSING
5.1 Legal basis and purposes
We process your personal data on the following legal bases:
Performance of the contract:
- Creation and management of your account
- Provision of travel planning services
- Backup and synchronization of your data
- Customer support and technical assistance
Legitimate interests:
- Improvement and optimization of our Services
- Statistical analysis and usage trends
- Fraud prevention and security
- Development of new features
Consent:
- Precise geolocation
- Sending of newsletters and marketing communications
- Sharing with specific partners
- Non-essential cookies
Legal obligations:
- Retention of connection data
- Response to requests from authorities
- Compliance with tax and accounting obligations
5.2 Specific uses
- Personalization: Tailor recommendations based on your past travels
- Social: Enable interactions between users
- Mapping: Display your routes and places visited
- Statistics: Generate your personal travel statistics
- Notifications: Inform you of relevant activities
- Research: Improve our algorithms and services
6. DATA SHARING
6.1 With other users
As described in Section 4, some of your data is public and visible to all TRAVELYZER users.
6.2 With our service providers
We share your data with carefully selected service providers:
- Artificial Intelligence: OpenAI for processing GPT requests (anonymized data)
- Hosting: Cloud services to store your data
- Analytics: Usage analysis tools (Google Analytics, Mixpanel)
- Communication: Email and notification sending services
- Payment: Secure payment processors (if paid services)
- Mapping: Map services (Mapbox, Google Maps)
- CDN: Content delivery networks
6.3 With our partners
Unless otherwise stated, partners act as independent data controllers for their own purposes. Their processing is governed by their privacy policies.
With your consent, we may share data with:
- Tourist offices
- Transport companies
- Booking services
- Commercial partners
6.4 Legal transfers
We may disclose your data if required by:
- A legal or regulatory obligation
- A court decision
- The protection of our rights and interests
- The prevention of fraud or illegal activities
- An emergency situation threatening safety
6.5 Merger or acquisition
In the event of a merger, acquisition or sale of assets, your data may be transferred. You will be informed before any transfer and of the new applicable privacy policy.
7. INTERNATIONAL TRANSFERS
7.1 Data location
Your data may be transferred to and stored in countries outside the European Union, in particular:
- United States: OpenAI (GPT API), AWS/Google Cloud cloud services
- Other countries where our service providers operate
IMPORTANT - Transfer to OpenAI (United States): The use of the GPT API involves a transfer of your data to OpenAI servers in the United States. This transfer is governed by the Standard Contractual Clauses (SCC) between TRAVELYZER and OpenAI.
7.2 Safeguards
For these transfers, we ensure an adequate level of protection through:
- Standard Contractual Clauses (SCC) approved by the European Commission, in particular with OpenAI
- Adequacy decisions of the European Commission
- Approved certification mechanisms
- Specific data protection agreements with our processors
7.2 bis Supplementary measures
Transfers outside the EU are governed by the Standard Contractual Clauses and may be supplemented by additional measures (encryption in transit/at rest, access control, pseudonymization, minimization). The up-to-date list of processors involved in these transfers as well as the processing locations is available in the "Processors" Appendix and may be updated.
8. DATA SECURITY
8.1 Technical measures
- Encryption: SSL/TLS encryption for transmissions
- Hashing: Passwords stored with secure hashing algorithms
- Authentication: Strong authentication systems available
- Backups: Regular and secure backups
- Surveillance: Continuous monitoring of intrusion attempts
8.2 Organizational measures
- Limited access: Only authorized personnel access the data
- Confidentiality: Confidentiality agreements for all employees
- Training: Regular awareness of data protection
- Audits: Periodic security assessments
- Incident: Data breach management procedures
8.2 bis Data breach notification
In the event of a personal data breach, we will notify the competent supervisory authority (in France: CNIL) within 72 hours of becoming aware of it, where required by the GDPR, and will inform the data subjects where there is a high risk to their rights and freedoms, describing the nature of the breach, the likely consequences and the measures taken.
8.3 Your role in security
- Use a strong and unique password
- Never share your credentials
- Enable two-factor authentication if available
- Keep your application up to date
- Report any suspicious activity
9. RETENTION PERIOD
9.1 General principles
We retain your data only for as long as necessary for the purposes described:
- Active account: For the entire duration of use of your account
- Inactive account: Deletion after 3 years of inactivity (with prior notification)
- After account deletion:
- Personal data: Immediate deletion
- Anonymized data: Possible retention for statistics
- Legal obligations: Retention according to legal periods
9.2 Specific periods by type of data
- Active account: For the entire duration of use
- Inactive account: Deletion after 3 years of inactivity (prior notification 6 months)
- Connection data/logs: 12 months (on the basis of our legitimate interest in ensuring security and abuse prevention, and in accordance with applicable regulations)
- Cookies: Maximum 13 months
- Geolocation data: Until deletion by the user or account closure
- Shared user content: Until deletion by the user
- AI conversation history: 2 years maximum
- Payment data (if applicable): 5-10 years according to tax and accounting requirements
- Technical backups: Maximum 90 days after definitive deletion
- Anonymized data: Unlimited retention for statistical purposes
10. YOUR RIGHTS
10.1 Rights guaranteed by the GDPR
You have the following rights regarding your personal data:
Right of access
Obtain confirmation of processing and a copy of your data
Right to rectification
Correct inaccurate or incomplete data
Right to erasure ("right to be forgotten")
Request the deletion of your data in certain cases
Right to restriction
Restrict processing in certain circumstances
Right to portability
Receive your data in a structured and interoperable format
Right to object
Object to processing for legitimate grounds or direct marketing
Right to withdraw consent
Withdraw at any time a consent given
Right to define post-mortem directives
Define the fate of your data after your death
10.2 Exercising your rights
To exercise your rights:
- Email: [email protected]
- Online form: In your account settings
We will respond within a maximum period of 30 days. This period may be extended by two months given the complexity and number of requests; we will inform you of any extension. Proof of identity may be requested.
10.3 Complaint
If you believe that your rights are not being respected, you can:
- Contact us directly
- Refer the matter to the CNIL (www.cnil.fr)
- Refer the matter to the data protection authority of your country of residence
11. DATA OF MINORS
11.1 Minimum age
The Service is not intended for children under 16 years of age, subject to local legislation. In France, the age of digital consent is 15 years.
11.2 Parental consent
For minors who have not reached the applicable age of digital consent, use of the Service requires the authorization of the holder of parental authority.
11.3 Deletion
If the data of a minor has been collected without appropriate authorization, we will proceed with its prompt deletion after notification.
12. CHANGES TO THE POLICY
12.1 Updates
This Policy may be modified in order to:
- Reflect changes in our practices
- Comply with new regulations
- Integrate new services or features
12.2 Notification
Substantial changes will be communicated by:
- Email to your registered address
- Notification within the application
- Banner on the website
12.3 Acceptance
Continued use of the Services after modification constitutes acceptance of the new Policy.
13. SPECIFIC TECHNOLOGIES
13.1 Artificial Intelligence (OpenAI GPT API)
We use the OpenAI GPT API for: recommendations, itinerary generation, conversational assistant, and improvement of the experience.
Processing and retention: requests (prompts, travel context, technical metadata) are transmitted to OpenAI for execution. OpenAI processes this data in accordance with its Terms and Privacy Policy. Depending on the contractual configuration in force, OpenAI may retain certain technical data for a period limited to security, audit or service improvement needs. We minimize the data sent (no email/name in plain text) and enable, where available, the non-retention or reduced-retention options.
You can request human intervention for automated processing and object to certain personalizations in your settings.
Where the option is contractually available, we disable the use of customer data for the purpose of training OpenAI's models.
13.2 Third-party APIs
We integrate APIs to enrich your experience:
- Weather APIs
- Transport APIs
- Point of interest APIs
- Currency conversion APIs
13.3 Local storage
The mobile application stores locally:
- Map cache for offline use
- Unsynchronized drafts
- Display preferences
- Session data
14. PRIVACY SETTINGS
14.1 Available controls
From your account, you can:
- Manage your notification preferences
- Control cookies (via the consent banner)
- Download your data
- Delete your account
- Manage the permissions of the mobile application
14.2 Profile visibility
Reminder: There is currently no option to make your profile private. All profiles are public with visits visible to everyone.
14.2 bis – Visibility settings (privacy by default)
At any time, in Settings > Privacy, you can:
- Make your visits and itineraries unlisted (visible only via link);
- Hide your following/followers;
- Hide your profile from internal search results and request de-indexing from search engines (noindex tags, as far as possible);
- Disable the display of your real-time location.
Certain deactivations may limit social features.
14.3 Communications
You can unsubscribe from:
- Marketing emails via the unsubscribe link
- Push notifications in the settings
- Newsletters in your account area
15. COOKIES AND TRACKERS
15.1 Types of cookies used
Strictly necessary cookies
- Authentication and security
- Language preferences
- Cart and payment
Performance cookies
- Google Analytics
- Error monitoring
- Performance analysis
Functionality cookies
- Remembering choices
- Interface personalization
Targeting cookies (where applicable)
- Personalized advertisements
- Remarketing
15.2 Cookie management
- Consent banner: On your first visit
- Browser settings: Block or delete cookies
- Account settings: Manage your preferences
- Opt-out: Deactivation links for third-party trackers
Our consent banner (CMP), compliant with the IAB TCF v2.2 framework, allows you to manage your choices. Proof of consent is timestamped and retained for a maximum of 6 months.
In France, non-strictly-necessary analytics cookies are only placed after consent.
We re-request your cookie consent choice at most every 6 months.
15.3 Consequences of refusal
The refusal of certain cookies may:
- Limit certain features
- Require frequent reconnection
- Reduce personalization
16. PROCESSORS AND SERVICE PROVIDERS
16.1 List of main processors
Artificial Intelligence:
- OpenAI (GPT API) - United States
- Purpose: Content generation and recommendations
Infrastructure:
- European cloud services
- Purpose: Data storage and processing
Analytics and Audience Measurement:
- Google Analytics - United States
- Purpose: Anonymized usage statistics
Communication:
- European email sending services
- Purpose: Sending transactional and marketing emails
16.2 Commitments of the processors
All our processors undertake to:
- Comply with the GDPR and applicable regulations
- Use the data only according to our instructions
- Ensure security and confidentiality
- Notify any data breach
TRAVELYZER remains responsible for the processing carried out by its processors.
The updated list of our processors is available in this privacy policy. We will notify any significant change affecting data protection.
17. CONTACTS AND SUPPORT
17.1 General questions
For any question about this Policy: Email: [email protected] Website: https://gotravelyzer.com
17.2 Data protection
To exercise your rights or for specific questions: Email: [email protected]
17.3 Reports
To report a data breach: Urgent email: [email protected]
18. LEGAL INFORMATION
18.1 Record of processing activities
In accordance with the GDPR, we maintain a detailed record of our processing activities, available on request to the competent authorities.
18.2 Impact assessment (DPIA)
For high-risk processing, we carry out data protection impact assessments.
18.3 Certification and compliance
We are committed to maintaining our compliance with:
- The GDPR (General Data Protection Regulation)
- The French Data Protection Act (loi Informatique et Libertés)
- The recommendations of the CNIL
- International security standards
Version history:
- Version 1.0: January 2025 - Initial version
Related documents:
- Terms and Conditions of Use
- Legal Notice
APPENDIX – TABLE OF LEGAL BASES
| Purpose | Data concerned | Legal basis |
|---|---|---|
| Account creation/management | Identifiers, profile | Performance of the contract |
| AI recommendations/personalization | History, preferences, interactions | Legitimate interest (with right to object) / Consent if cookies |
| Precise geolocation | GPS position | Consent |
| Analytics/measurement | Cookie identifiers, usage | Consent (in particular in France when cookies/trackers are used), or legitimate interest only when implemented without trackers or in accordance with local exemptions |
| Direct marketing | Email, preferences | Consent (B2C) / Legitimate interest (B2B) |
| Security/anti-fraud | Logs, IP addresses | Legitimate interest / Legal obligation |
| Payment/Billing | Payment identifiers | Performance of the contract / Legal obligation |
This Privacy Policy has been drafted in compliance with European Regulation 2016/679 (GDPR) and amended Act No. 78-17 of 6 January 1978 relating to information technology, files and civil liberties.
For any question, please do not hesitate to contact us. Your privacy is our priority.