Privacy Policy
Last updated : 16/07/2026 · Version française
The Voyage: Travel Together application (the "App"), published by Voyage: Travel Together ("we"), helps users plan trips and manage an itinerary, tasks and shared expenses. This policy describes the data we collect, how we use it, and your rights.
1. Data controller
- Publisher: Voyage: Travel Together
- Contact: support@voyagetogether.com
2. Data we collect
Account data. When you sign up and log in: your e-mail address, your full name, and your password (sent securely and stored hashed on the server — we never have access to the plaintext password). You may also sign in with Google; in that case we receive your Google account identifier, e-mail and name to create or link your account, and (if you have none) your Google profile picture.
Content you create. Trips, itineraries, tasks, lists and notes; expenses and shared expenses (amounts, currencies, participants, dates); your profile picture and the photos and documents you choose to upload (receipts, travel documents) via the camera or the gallery/files; places you enter or select (place names and, where applicable, coordinates linked to an itinerary item).
Technical data. Authentication tokens stored securely on the device (encrypted system storage); a device push token (via Firebase Cloud Messaging) when you enable notifications, used to deliver them; your IP address, used only transiently in memory to rate-limit requests and protect against abuse — it is never written to our logs or stored; server request logs used to diagnose errors, which record the request path, the outcome, and your account identifier — never your IP address, name or e-mail; a copy of your trips kept on your device so the App works offline.
3. How we use the data
To create and manage your account and authenticate you; to provide the App's features (itineraries, tasks, expenses, documents) and sync your data; to show maps and search for places; to convert amounts between currencies; to send you push notifications about your shared trips and expenses (when you enable them); and to ensure security and fix issues.
4. Third-party services
The App communicates with the following services, each governed by its own privacy policy:
| Service | Purpose | Data sent |
|---|---|---|
| Our servers — OVHcloud (Singapore, outside the EU) | Account and content storage | Account, created content, uploaded files |
Maileroo (smtp.maileroo.com) |
Sending the App's e-mails: sign-up verification, password reset, trip invitations | The recipient's e-mail address and name, and the content of the message |
Google Sign-In (accounts.google.com) |
Optional sign-in / account linking | Your Google account id, e-mail and name |
| Firebase Cloud Messaging — Google | Push notifications | A device push token |
Open-Meteo (api.open-meteo.com, archive-api.open-meteo.com) |
Weather forecast and past weather for the places on your itinerary | The coordinates of the place, IP address |
OpenStreetMap / Nominatim (nominatim.openstreetmap.org) |
Place search (geocoding) | The search text you type |
OpenStreetMap tiles (tile.openstreetmap.org) |
Map background tiles | Coordinates of the displayed area, IP address |
Frankfurter (api.frankfurter.app) |
Exchange rates | Currency codes only (no personal data) |
Google Maps (maps.google.com, external open) |
Directions to a place, on your request | The place you open |
5. Data sharing
We do not sell your data. Content in a shared trip or expense group is visible to the members you invite. Otherwise data is only shared with the technical providers needed to run the App (hosting) and where required by law.
International transfer: Our server is hosted on OVHcloud in Singapore, outside the European Union. By using the App, your account and content are stored there. We apply appropriate safeguards (encrypted transport, access controls).
6. Data retention and deletion
We keep the content you create while your account is active. Sign-in tokens expire on their own: the access token after 15 minutes, the session (refresh) token after 30 days. A password-reset code expires after 30 minutes and an e-mail verification code after 24 hours.
You can delete your account and its data directly in the App (Settings → Delete account), or by contacting us at support@voyagetogether.com. Deletion from the App is immediate and irreversible; requests by e-mail are handled within 30 days, subject to legal retention obligations.
In three cases the App will refuse to delete your account, because doing so would destroy data belonging to other people: when you have an unsettled balance in a shared expense group, when you own a shared expense group others still use, or when you own a trip other members have joined. The App tells you exactly which applies, and each can be cleared by settling up, removing the other members, or deleting the trip or group. If you cannot clear it yourself, e-mail us and we will erase your account manually — you will never be prevented from exercising your right to erasure. Full details: Delete your account.
Content you added to a trip or expense group that other people also use is not removed when you leave, because it forms part of their records too; it is no longer linked to your identity.
7. Security
Traffic to our servers is encrypted (HTTPS). Authentication tokens are stored in the operating system's secure storage. No method of transmission or storage is fully infallible.
8. Your rights
Under the GDPR (and depending on your jurisdiction) you have the right to access, rectify, erase, restrict, object to, and port your data. To exercise these rights, contact us at support@voyagetogether.com.
9. Children
The App is not intended for people under 16 and we do not knowingly collect their data. If you believe someone under 16 has created an account, contact us and we will delete it.
10. Changes
We may update this policy. The "last updated" date above reflects the current version. We will notify you in the App of any material change.
11. Contact
For any question about this policy or your data: support@voyagetogether.com.