Privacy Policy (Aviso de Privacidad Integral)
This comprehensive privacy notice (Aviso de Privacidad Integral) is issued in compliance with Mexico’s current Ley Federal de Protección de Datos Personales en Posesión de los Particulares (the “LFPDPPP”, published in the Official Gazette of the Federation on March 20, 2025) and its applicable implementing provisions, and explains how personal data is processed when you use the Traveluns mobile app and the website traveluns.com (together, the “Service”). It is additionally written to satisfy the EU/UK General Data Protection Regulation (GDPR), the Swiss FADP, the California Consumer Privacy Act (CCPA/CPRA), Japan’s APPI and South Korea’s PIPA, as well as the privacy-disclosure requirements of the Apple App Store and Google Play. The Spanish version governs; the English, German and French versions are courtesy translations.
1. Identity and Address of the Controller (Responsable)
The party responsible for the processing of your personal data (the “Controller” or “Operator”) is:
Kevin Meda Rodriguez, an individual (persona física) of Mexican nationality
Address: Paseo de los Fresnos 182, Col. Paseos de Taxqueña, C.P. 04250, Alcaldía Coyoacán, Ciudad de México, Mexico
Email: contact@traveluns.com
Kevin Meda Rodriguez is the sole person responsible for the treatment of personal data collected through the Service. We have not appointed a Data Protection Officer (not required at our current scale). Direct all privacy inquiries to the email above.
2. What Data We Process, Why & on What Legal Basis
| Category | Data | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| Account | Email, username, first/last name, date of birth, home country/city, password (stored only as a salted hash), avatar photo, preferred language/currency/units | Create and operate your account; verify you are 18+; personalize content | Art. 6(1)(b) contract; age check: Art. 6(1)(c) legal obligation |
| Technical device data | Device model, operating system and version, app version, device or installation identifiers used by integrated SDKs, IP address, user-agent | Operate the app, diagnose errors, security and abuse prevention | Art. 6(1)(b)/(f) |
| Trips & planning | Destinations, dates, itineraries, notes, reservations, tracked flights, preferences you enter as part of a trip (e.g. interests or dietary requirements for that trip), trip members | Provide the planning features you use | Art. 6(1)(b) contract |
| Files & receipts | Files you upload (tickets, confirmations, receipts, photos) | Store and display them in your trips; malware scanning | Art. 6(1)(b); scanning: Art. 6(1)(f) legitimate interest (security) |
| Secure vault | End-to-end encrypted files and metadata | Encrypted storage. Zero-knowledge: we store only ciphertext and cannot read it | Art. 6(1)(b) |
| Expenses | Expense amounts, splits, group members, receipt images | Expense-splitting features | Art. 6(1)(b) |
| AI features | Your chat messages to the travel assistant, trip parameters, and content needed to generate itineraries/tips/translations | Generate AI content you request (processed by the AI providers in Section 6) | Art. 6(1)(b) |
| Device location | Precise or approximate device location (only if you grant the OS permission), processed via Google Maps/Google Places services and the app’s map components | Solely for the app’s core functionality: showing your position on maps, suggesting your departure city, and showing nearby places and content. Precise location is not stored on our servers and is never sold to third parties. When you tap a travel-deal link we record the interaction with an approximate (roughly city-level) location to measure deal relevance | Art. 6(1)(a) consent (revocable in OS settings) |
| Advertising (free tier) | Advertising identifier and device data processed by Google AdMob when ads are shown; your ad-consent choices (EEA/UK/CH) and iOS tracking permission; completion signal of rewarded ads (to grant the feature credit) | Show ads that fund the free tier; personalized ads only where you consent; grant rewarded-ad credits. First Class subscribers see no ads | Art. 6(1)(a) consent (personalized ads); Art. 6(1)(f) legitimate interest (non-personalized ads and fraud prevention) |
| Security & audit logs | IP address, device/user-agent, timestamps for logins and security-relevant changes (email/username changes), terms acceptances | Security, abuse and fraud prevention, rate limiting, legal evidence of consent | Art. 6(1)(f) legitimate interest; Art. 6(1)(c) |
| Subscription status | App-store transaction identifiers and entitlement status (no card data — payments are handled by Apple or Google) | Activate and verify Premium | Art. 6(1)(b) |
| Notifications | Push token (if you enable push), notification preferences | Send the notifications you opted into (e.g. flight alerts) | Art. 6(1)(a)/(b) |
| Emails | Email address, delivery events for transactional mail (verification codes, password reset, account activity); marketing only per your opt-in settings | Operate the account; optional product news | Art. 6(1)(b); marketing: Art. 6(1)(a) consent |
| Support & feedback | Messages you send us, feedback text | Respond to you; improve the Service | Art. 6(1)(b)/(f) |
For LFPDPPP purposes, the processing described rests on the consent you give by accepting this notice and, where applicable, on the exceptions provided by the LFPDPPP itself (data necessary for the existence, maintenance and performance of the legal relationship between you and the Controller). The categories above correspond to the privacy declarations published on the app’s store listings in the Apple App Store (“App Privacy” / privacy nutrition labels) and Google Play (“Data safety”).
We do not use your data for automated decision-making with legal or similarly significant effects, and we do not process special categories of data on purpose (do not upload health or similar sensitive data outside the encrypted vault).
3. What We Deliberately Do Not Do
- We do not sell personal data, and your location data is never sold to third parties. Note: showing personalized ads through Google AdMob may qualify as “sharing” for cross-context behavioral advertising under the CCPA/CPRA — you can opt out as described in Sections 11 and 16.
- Apart from Google AdMob (advertising, Section 17) and Sentry (crash diagnostics, Section 6), we run no third-party advertising or tracking SDKs inside the mobile app, and we run none at all for First Class subscribers with ads disabled.
- We do not store your precise GPS coordinates on our servers (deal-link taps record only an approximate, roughly city-level location — Section 2).
- We do not read your encrypted vault — technically impossible without your passphrase.
4. Purposes of Processing
Primary purposes (necessary for the legal relationship that gives rise to the processing):
- creating, authenticating, operating and maintaining your account, including verifying you are an adult;
- providing the Service features you use (trip planning, itineraries, reservations, expenses, files, vault, flight tracking, weather, AI content you request);
- managing your Premium subscription and verifying your entitlements;
- showing the advertising that funds the free tier (non-personalized where no consent has been given) and granting rewarded-ad credits;
- sending indispensable transactional communications (verification codes, password resets, security and account notices) and the notifications you enable;
- securing the Service, preventing fraud and abuse, and preserving evidence of consent;
- complying with applicable legal obligations.
Secondary purposes (not necessary for the legal relationship):
- sending our own product news and promotional communications (only with your express opt-in consent);
- showing personalized advertising (only with the consent you give in the ad-consent dialog and, on iOS, the tracking permission);
- internal, first-party analytics to improve the product, collected at two levels. Anonymous measurement runs for everyone: counts of which screens and features are opened and whether an action succeeded. Nothing is stored on your device for it. So that a day’s devices can be counted rather than double-counted, our server derives a short-lived key from the technical details your request already carries (network address, app version, device family); that key is computed with a secret that is replaced every 24 hours and then destroyed, so it cannot connect one day’s activity to the next and cannot be traced back to you or to any account. The network address itself is used to compute the key and discarded — it is never stored. Identified analytics — the same events tied to a durable identifier and, once you sign in, to your account — runs only if you switch it on, and you can switch it off again at any time in Settings (app) or at traveluns.com/privacy-settings (web). Switching it off also deletes the identified events already collected for you. We never use either level for advertising, and we never sell or share it. Some information you volunteer separately, such as an account-deletion reason, is also used for product analysis.
You may refuse processing for secondary purposes at any time without affecting the Service: disable the communications in the app settings or email contact@traveluns.com with the subject “Limitación de finalidades secundarias” (limitation of secondary purposes).
5. Sensitive Personal Data
We do not collect or request sensitive personal data within the meaning of the LFPDPPP (racial or ethnic origin, health status, religious beliefs, union membership, political opinions, sexual preference, among others). Please do not include such information in free-text fields; if you need to store documents containing delicate information, use the zero-knowledge encrypted vault.
6. Processors & Recipients
We use the following service providers (processors within the meaning of the LFPDPPP and GDPR or, in some cases, independent controllers) to run the Service:
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Google Cloud (Google Ireland/LLC) | Hosting: servers, database, file storage, task queues (region europe-west1, Belgium) | All server-side data | EU (hosting); Google LLC US support |
| Google (Gemini / Vertex AI) | AI content generation (itineraries, chat, tips, translations, deals) | Chat messages, trip parameters, content to translate | EU/US |
| xAI, OpenAI, Groq | Backup/auxiliary AI providers for specific generation tasks | Same categories as above (no account identifiers sent) | US |
| Langfuse (Langfuse GmbH) | Technical logging of AI requests (quality & cost monitoring); prompts/responses are recorded | AI inputs/outputs, pseudonymous identifiers | EU |
| Google Maps / Google Places / Distance Matrix | Place search, details, photos, travel times, map features | Search terms, place queries, queried coordinates | US/global |
| Mapbox | Maps and routing | Map tile requests, route coordinates | US |
| Open-Meteo | Weather forecasts | Destination coordinates (no personal identifiers) | EU |
| AeroDataBox (via MagicAPI) | Flight status for flights you track | Flight numbers, dates | US/EU |
| MailerSend | Transactional and (opt-in) product emails | Email address, name, delivery events | EU/US |
| Firebase Cloud Messaging (Google) | Push notifications (if enabled) | Push token, notification payloads | US/global |
| Apple / Google Play | App distribution, in-app subscription billing | Purchase/transaction data (they are independent controllers) | US/global |
| Google AdMob (Google Ireland Ltd / Google LLC) | In-app advertising in the free tier: ad delivery, measurement, fraud prevention, and — only with consent — ad personalization | Advertising identifier, device data, IP address, coarse location derived by Google, consent signals (Google acts as an independent controller for personalized ads under its own policy) | US/global |
| Sentry (Functional Software, Inc.) | Crash and error diagnostics for the app and website | Device/OS data, app version, stack traces and technical state at the time of an error (no chat or trip content is intentionally included) | EU/US |
| Cloudflare | Content delivery (images, website) | IP address, requested URLs | Global |
| VirusTotal (Google) / self-hosted ClamAV | Malware scanning of uploads | File hashes / file content of uploads (not vault files) | US / EU |
| exchangerate-api.com | Currency rates | None (generic rate queries) | US |
When you open a booking partner’s site or app through a link in the Service (e.g. Expedia, Trip.com, Check24, GetYourGuide, Viator, Klook, Tiqets, Civitatis), that partner processes your data as an independent controller under its own privacy policy. Outbound links may carry an affiliate identifier so the partner can attribute the referral; we do not receive your booking details from partners.
7. International Transfers
Our servers are in the European Union (Belgium). Some providers above process data in the United States or globally. The transfers to processors described in this notice are necessary to operate the Service and are made as permitted under the LFPDPPP; by providing your data and accepting this notice you consent to those transfers. Where data leaves the EU/UK/Switzerland, we rely on European Commission adequacy decisions (including the EU–US Data Privacy Framework for certified providers) and/or Standard Contractual Clauses with supplementary measures. The Controller, based in Mexico, accesses the systems for administration; the LFPDPPP and our contractual safeguards apply to that access.
8. Google Maps and Google Places
The Service’s map, place-search and geographic features use Google Maps and Google Places services. By using these features you are additionally bound by the Google Maps/Google Earth Additional Terms of Service and the Google Privacy Policy. Google may receive the place queries and coordinates needed to answer your searches; Google acts under its own terms. Google Maps, Google Places and other Google marks are the property of Google LLC.
9. Links and Redirections to Third-Party Sites
The Service contains links that redirect you to external third-party websites and platforms that are entirely outside the Controller’s control. When you leave the Service through such a link, this privacy notice ceases to apply: the processing of your data is governed exclusively by the privacy notice or policy of the external site concerned. We recommend reading the privacy policies of every third-party site you visit. The Controller assumes no responsibility for the privacy practices of such third parties.
10. ARCO Rights (Mexico)
You or your legal representative may at any time exercise the rights of Access, Rectification, Cancellation and Objection (ARCO rights) provided by the LFPDPPP. Procedure:
- Send a request by email to contact@traveluns.com with the subject “Solicitud ARCO”.
- Under the LFPDPPP the request must contain: (a) your full name and a means of communicating the response to you (email); (b) a copy of a document proving your identity (INE/IFE, passport) or, where applicable, the legal representation of the person acting on your behalf; (c) a clear and precise description of the personal data concerned and of the right you wish to exercise; and (d) any element that helps locate the data (e.g. the email you registered with).
- Deadlines: we will communicate our determination within a maximum of 20 business days from receipt of the request; if granted, it will be carried out within the following 15 business days. These periods may be extended once for an equal period where justified.
- Exercising ARCO rights is free of charge; only justified shipping costs or the cost of reproduction in copies or other formats may be charged.
- If the response does not satisfy you or you do not receive it in time, you may initiate a rights-protection procedure before Mexico’s Secretaría Anticorrupción y Buen Gobierno — the data-protection guarantor authority that replaced INAI as of March 2025 — via www.gob.mx/buengobierno, within the following 15 business days.
11. Rights in Other Jurisdictions
EU/UK/Switzerland (GDPR/FADP): you have the right of access, rectification, erasure, restriction, data portability, and objection (including to legitimate-interest processing), and the right to withdraw consent at any time with future effect. You may lodge a complaint with your local supervisory authority.
California (CCPA/CPRA): you have the rights to know, delete, correct, opt out, and to non-discrimination. We do not sell personal information. Personalized in-app advertising via Google AdMob may constitute “sharing” for cross-context behavioral advertising; you can opt out at any time by declining or withdrawing ad personalization in the app’s ad-consent settings, denying the iOS tracking permission, using your device’s ads settings (e.g. “Delete advertising ID” on Android), or emailing contact@traveluns.com. We do not use sensitive personal information beyond what is necessary to provide the Service, and we do not knowingly share the personal information of consumers under 16.
Japan (APPI) / South Korea (PIPA): you have equivalent rights of access, correction, deletion, and objection/revocation under your local law.
How to exercise: most rights are self-service in the app (edit profile; Account → Delete Account). For anything else email contact@traveluns.com; we will verify your identity and respond within the statutory deadline (one month under GDPR, extendable as permitted).
12. Revocation of Consent and Limitation of Use or Disclosure
You may revoke the consent you have given for the processing of your personal data, and limit the use or disclosure of that data, by emailing contact@traveluns.com with the subject “Revocación de consentimiento” (revocation of consent) or “Limitación de uso” (limitation of use), following the same procedure and deadlines as Section 10. Note that revocation has no retroactive effect and that, where the processing is necessary to provide the Service, revocation may mean we can no longer provide it to you (in which case you may delete your account as described in Section 13). The location permission can be revoked at any time directly in your operating-system settings, with no request needed.
13. Data Retention and Deleting Your Account
How to delete your account: in the app, go to Account → Delete Account, confirm with your password and the verification code emailed to you, and the request is executed immediately. Alternatively, you may request deletion by emailing contact@traveluns.com (we will verify your identity). This path satisfies the account-deletion requirement of the Apple App Store and Google Play guidelines.
- What is irreversibly anonymized: deleting your account permanently and irreversibly scrubs your personally-identifying information — name, email address, profile photo, date of birth, and home city/state — which can never be recovered, by us or anyone else. Your password is invalidated and your access is revoked immediately. Your email address is freed for reuse (for example, to create a new, unrelated account) as soon as deletion completes.
- What is fully erased, not just anonymized: your AI travel-assistant conversation history, the contents of your encrypted document vault, and your device’s push-notification registration.
- What is kept, re-attributed to “Deleted User”: trips, itineraries, reservations, expenses, and other content you created or owned are retained under an anonymized placeholder identity that can no longer be linked back to you — so that (a) trips you share with other people keep working for them without disruption, and (b) we retain aggregate, non-identifying product analytics. If you own a trip shared with others, you can choose during deletion to transfer ownership to a specific member instead of leaving it under the anonymized placeholder.
- Other survivors: (a) your stated deletion reason with your email, kept for product analytics; (b) security audit logs of identity changes (IP, user-agent); (c) records of your terms/privacy acceptances — kept as legal evidence, then erased when no longer needed (at most the applicable limitation period); and (d) short-lived encrypted backups (rotated automatically, so any copy of your prior data remaining in a backup ages out shortly after deletion).
- Deactivation (as opposed to deletion) keeps your data unchanged so you can return; you can request full deletion at any time instead.
- Email delivery logs and server logs are retained for short technical periods.
- Why anonymization satisfies your right to erasure: once data has been irreversibly stripped of everything that could identify you, it is no longer “personal data” under GDPR (Art. 4(1); Recital 26) — anonymizing it is a recognized way of satisfying the right to erasure (Art. 17) once genuine re-identification is impossible. The same principle underlies the Apple/Google account-deletion requirements: what they require is that you can no longer be identified or contacted through the Service, not that every database record referencing your former account be physically removed.
14. Security
Measures include: TLS for all transport (with certificate pinning in the app), bcrypt password hashing, encrypted storage, EU data residency, strict access controls, rate limiting and brute-force lockout, malware scanning of uploads via an isolated quarantine pipeline, append-only audit logs, and a zero-knowledge encrypted vault (AES-256-GCM, argon2id key derivation on your device). No internet service is 100% secure; keep your password unique and confidential.
15. Children
The Service is for adults (18+). Before anything is generated — including as a guest, without an account — you must confirm that you are at least 18, and we record when you did. Where a date of birth is given at signup, the signup flow rejects dates under 18. We do not knowingly process children’s data. If you believe a minor has an account or a guest session, contact us and we will delete it.
16. Using Traveluns Without an Account (Guest Sessions)
You can plan one trip without creating an account. When you tick the age and terms confirmation on the New Trip screen, we create a temporary guest profile — not an account — so that the itinerary can be generated. What this involves:
- A device identifier generated on your device and held in its secure keychain. We store only a keyed hash (HMAC) of it, never the identifier itself. It exists to enforce one free trip per device and to limit abuse, and it persists if you reinstall the app. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in protecting a costly free feature from abuse.
- The trip details you enter, and the messages you send if you use the AI Guide. These go to the AI providers listed in Section 6 to build your itinerary, on the same terms as for account holders. Legal basis: Art. 6(1)(b) GDPR — providing the service you asked for.
- A keyed hash of the IP address the guest session was created from, kept to investigate abuse. We do not store the address itself.
As a guest we do not ask for your name, email address or date of birth. You confirm that you are 18 or older (Section 15); no birth date is collected at that point.
Retention. Guest data is deleted automatically 30 days after the guest session is created — the temporary profile, the trip it generated and the device ledger entry. To delete it sooner, open Account → Delete my trip and data in the app, or write to contact@traveluns.com. Deleting also frees the device to plan a new trip.
If you create an account from a guest session, the trip carries over and the temporary profile becomes your account. The 30-day guest deletion then no longer applies and Section 13 governs instead.
17. Advertising, Cookies & the Website
In-app advertising (free tier). The free tier of the mobile app shows ads served by Google AdMob. How this works:
- Consent first (EEA/UK/Switzerland): before any personalized ad is shown, the app presents a Google-certified consent dialog (IAB TCF-compatible). If you decline, you still get the free tier — with non-personalized ads that use only contextual and coarse technical data.
- iOS App Tracking Transparency: on iOS, linking your activity across apps for ad personalization additionally requires the tracking permission; if you deny it, ads are not personalized using cross-app data.
- Changing your mind: you can review or withdraw your ad-consent choices at any time in the app and in your device’s ads settings (iOS: Settings → Privacy & Security → Tracking; Android: Settings → Google → Ads).
- Rewarded ads: some features can be unlocked by voluntarily watching an ad; we receive only a completion signal to grant the credit — watching is always optional.
- No ads for subscribers: First Class subscribers see no ads and no ad SDK requests are made for them.
- Google processes ad data under the Google partner sites policy and its own privacy policy.
Beyond advertising, the mobile app does not use cookies or third-party trackers; our product analytics are first-party (Section 4) and can be switched off.
The website traveluns.com (including the web version of the app) shows no ads and sets no advertising or tracking cookies. It does use your browser’s local storage for your signed-in session and for your privacy choices. A first-party analytics identifier is written there only after you switch identified analytics on; until then, and again if you switch it back off, no analytics identifier and no session record is stored on your device at all. It also loads a crash and error reporter (Sentry, Section 6) and makes requests to the map and image providers in Section 6, which receive your IP address when serving content. Product analytics and crash diagnostics have separate switches at traveluns.com/privacy-settings, and the app has the same two under Settings. Product analytics is off until you turn it on; crash diagnostics is on by default and can be turned off. If you are signed in, your analytics choice is stored against your account as well, so it applies on every device and survives a reinstall. We use no third-party advertising or cross-site tracking network on the website. If that changes, we will add a consent banner first.
18. Changes to This Notice
We will update this notice as the Service evolves. The version and effective date appear at the top; any change will be published on this page (traveluns.com/privacy) and material changes will be announced in the app, where you will be asked to confirm the new version. Records of the version you accepted are kept.
19. Contact
contact@traveluns.com — Kevin Meda Rodriguez, Alcaldía Coyoacán, Ciudad de México, Mexico (the Controller’s full address appears in Section 1 and is additionally provided on request for ARCO purposes and official notifications).