Your data belongs to you. Learn how we collect, protect, and give you control over your information.
TLS 1.3 Encryption
All data encrypted in transit
Row Level Security
Database-level access control
JWT Authentication
Secure token-based auth
Supabase Hosting
SOC 2 compliant infrastructure
Travlyo is built on the principle that your travel data is yours. We will never sell your personal information, and we provide full transparency about how your data is used. You can export or delete everything at any time.
Account information: email address, display name, and profile photo (optional).
Trip data: destinations, dates, itineraries, journal entries, and uploaded photos.
Expense data: amounts, categories, and traveler assignments for budget tracking.
Usage data: page views and feature usage for improving the product (anonymized).
We do NOT collect: payment card details (handled by Stripe), precise real-time location, contacts, or browsing history outside Travlyo.
All data is encrypted in transit using TLS 1.3 and at rest using AES-256.
Row Level Security (RLS) on Supabase ensures only you can access your data.
Authentication uses secure JWT tokens with automatic session refresh.
API keys and secrets are stored in environment variables, never in client code.
Regular security audits and dependency vulnerability scanning.
We never sell your personal data to advertisers or data brokers.
Trip journals are private by default. Only you decide what to publish to the community.
Affiliate links (Booking.com, etc.) do not share your Travlyo data with partners.
AI features use Google Gemini API. Your prompts are processed but not stored by Google for training.
Analytics data is aggregated and anonymized before any processing.
Right to Access: Export all your data at any time from Settings.
Right to Rectification: Edit or update any personal information in your profile.
Right to Erasure: Delete individual trips or your entire account with all associated data.
Right to Data Portability: Export data in standard formats for use with other services.
We comply with GDPR (EU), CCPA (California), and LGPD (Brazil) data protection laws.
Delete individual trips: removes all entries, photos, and expense data for that trip.
Delete journal entries: remove specific entries while keeping the trip structure.
Clear wishlist: remove all saved Hidden Gems from your wishlist.
Delete account: permanently removes your account and all data within 30 days.
Published community content is de-identified upon account deletion.
Travlyo uses Stripe, Inc. to process all payments. When you make a purchase, your payment information is collected and stored directly by Stripe in accordance with their privacy policy (stripe.com/privacy) and PCI DSS compliance standards.
Travlyo only receives non-sensitive data from Stripe such as subscription status, plan type, and transaction confirmation.
We do not receive or store your full card number, CVV, or banking details.
For questions about how Stripe handles your data, visit stripe.com/privacy.
Travlyo uses essential cookies for authentication and session management. We use IndexedDB for offline data caching (paid plan feature). No third-party tracking cookies are used. Affiliate links may set cookies from partner sites (Booking.com, etc.) when you click through.
Questions about this policy? Contact us at hello@travlyo.com.
Last updated: February 22, 2026. This policy applies to all Travlyo services.