Privacy Policy
Last updated: 15 July 2026
This Privacy Policy explains how DreamTrips ("DreamTrips", "we", "us") collects, uses and protects your personal data when you use our AI travel-planning application (the "App"). We are committed to collecting as little personal data as possible (data minimisation) and to keeping the most sensitive details on your own device.
Controller: [Company legal name], [registered address], [country]. Contact: [privacy@yourdomain]. If we have appointed a Data Protection Officer, their contact is [DPO contact].
Data we keep on your device only
Your home address, date of birth and passport number are stored only on your device and are never transmitted to or stored on our servers. We use them solely to prefill booking forms. They are shared directly with the relevant travel provider only at the moment you make a booking, and only to the extent that booking requires. You can erase them at any time in Settings → "Clear device data", or by uninstalling the App.
Data we process on our servers
- Account: your e-mail address (used to sign you in) and, if you provide them, first name, last name and phone number.
- Membership: your eligibility and membership level, verified with the DreamTrips back-office at sign-in.
- Bookings: minimal records needed to manage your orders and provide support (e.g. a booking reference, status, provider reference, dates and the name/e-mail on the booking). We do not store your card details or the device-only data listed above.
- Usage: AI usage metering to apply fair-usage limits, plus standard technical logs. Content you enter in the AI chat is processed to answer you; we do not put your passport, date of birth or payment data into the AI.
- Travel Wallet: documents you choose to upload are stored privately and served only to you.
- Luggage tracking link:if you choose to add one, the Apple "Share Item Location" link for your tracker is saved to your profile so it is available on all your devices. Anyone holding that link can see the tracker's location, so we accept it only from
find.apple.com. Clear the field at any time to delete it.
Payments
We do not collect or store your payment card data. Payments are handled by the relevant travel provider or their payment processor via a hosted checkout, so card details never pass through our systems.
Lawful basis
We process your data to perform our contract with you (providing the App and bookings), to comply with legal obligations, and on the basis of our legitimate interests in operating and securing the service. Where required, we rely on your consent, which you can withdraw at any time.
Providers we share data with
To search and book travel and run the App, we share the minimum necessary data with service providers acting as processors or independent controllers, including: Viator/Tripadvisor (attractions & tickets), Inspira (hotels & payments), Duffel (flights), Anthropic (AI assistant), Vercel and Turso (hosting & database), Google (places & maps data; Cloud Text-to-Speech, which receives the assistant's reply text when you play it aloud; and Firebase, which carries the notification text when we send you a push), Mapbox (maps), Foursquare (venue details, photos & ratings), Wikimedia/Wikipedia (landmark descriptions & photos), Open-Meteo (weather forecasts for the places in your trip), ElevenLabs (voice input & output), Resend (transactional e-mail), and Ticketmaster / RapidAPI (events, flight status & visa information). When you book, the provider receives the traveller details that booking requires and becomes responsible for that data under its own privacy policy.
Mapbox also collects its own usage telemetry from the map component, as its terms require. When you tap "open in Google Maps" or order a ride, we hand your starting point and destination to that app — that transfer only ever happens because you asked for it.
International transfers
Some providers may process data outside your country/the EEA. Where they do, we rely on appropriate safeguards such as Standard Contractual Clauses. [Confirm and list transfer mechanisms with your legal advisor.]
Retention
We keep account and booking records only as long as needed to provide the service, support you and meet legal obligations, then delete or anonymise them. Device-only data lives on your device until you clear it.
Your rights
Subject to applicable law (including the GDPR), you have the right to access, correct, delete, restrict or object to processing of your data, and to data portability. To exercise these rights, contact [privacy@yourdomain]. You may also lodge a complaint with your local data protection authority.
You can delete your account and its data yourself at any time in Settings → Delete account. See Delete your account & data for exactly what is erased, what is kept in anonymised form, and how to request deletion if you can no longer sign in.
Storage & cookies
The App uses on-device storage for the device-only data above, your preferences and offline features. We use only the cookies/storage strictly necessary to run the App and keep you signed in.
Changes
We may update this policy and will change the "last updated" date above. Material changes will be communicated in the App.