Privacy Policy
Last updated: June 19, 2026
Introduction
TravelMap ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our travel documentation platform.
Information We Collect
Personal Information
We collect information you provide directly, including:
- Name and email address (for account creation)
- Profile information (bio, avatar, location)
- Trip details (destinations, dates, descriptions, photos)
- Social interactions (comments, likes, follows)
Automatically Collected Information
- Device information and browser type
- IP address and general location
- Usage data and analytics
- Cookies and similar tracking technologies
How We Use Your Information
- To provide, maintain, and improve our services
- To create and manage your account
- To display your trips and content on maps and feeds
- To enable social features (following, liking, commenting)
- To send notifications about your account and activity
- To analyze usage patterns and optimize user experience
- To prevent fraud and ensure platform security
- To comply with legal obligations
Information Sharing
We do not sell your personal information. We may share your information in the following circumstances:
- Public Content: Trips marked as "Public" are visible to other users and may appear in search results
- With Your Consent: When you explicitly authorize us to share information
- Service Providers: With third-party vendors who help us operate the platform (hosting, analytics, email)
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In connection with a merger, sale, or acquisition
Your Privacy Controls
- Trip Privacy: Control whether trips are Private, Friends-Only, or Public
- Profile Visibility: Manage your profile information and visibility settings
- Account Data: Access, download, or delete your account data
- Notifications: Customize notification preferences in your settings
- Cookies: Manage cookie preferences through your browser settings
Data Security
We implement industry-standard security measures to protect your information, including encryption, secure servers, and regular security audits. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
Data Retention
We retain your information for as long as your account is active or as needed to provide services. Specific retention periods include:
- Account data: Retained until you delete your account, then purged within 30 days
- Trip content: Deleted with your account; public content may persist in backups for up to 90 days
- Activity logs: Retained for up to 12 months for security and fraud prevention
- Legal holds: Data subject to a legal hold or regulatory inquiry may be retained longer as required by law
- Anonymized analytics: May be retained indefinitely in de-identified form
You may request deletion of your account at any time through your account settings or by emailing labs@apf.cloud.
Children's Privacy
TravelMap is not intended for users under 13 years of age. We do not knowingly collect information from children under 13. If you believe we have collected information from a child, please contact us.
International Data Transfers
Your information may be transferred to and maintained on servers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ.
By using TravelMap, you consent to the transfer of your information to our facilities and those third parties with whom we share it as described in this policy. We take appropriate safeguards to ensure your data remains protected in accordance with this Privacy Policy.
Cookies and Tracking Technologies
What We Use
- Essential Cookies: Required for authentication and basic functionality
- Preference Cookies: Remember your settings and preferences
- Analytics Cookies: Help us understand how you use the platform
- Local Storage: Store data locally for improved performance
Your Choices
You can control cookies through your browser settings. Note that disabling certain cookies may impact platform functionality. Most browsers accept cookies by default, but you can modify your settings to decline cookies if you prefer.
AI Features and Data Processing
TravelMap uses AI to power features such as itinerary suggestions. Here is how we handle your data in connection with these features:
- What is sent to AI: When you use AI features, trip details, destinations, and your prompts are transmitted to a third-party AI provider for processing.
- No training on your data: We do not permit third-party AI providers to use your content to train their models. Requests are made under agreements that restrict such use.
- Transient processing: AI providers process your inputs to generate responses and do not retain your data beyond the scope of the request unless required by their own policies.
- Optional feature: Use of AI features is voluntary. You may use TravelMap without using any AI-powered functionality.
Third-Party Services and Links
TravelMap uses the following third-party services, each of which has its own privacy policy governing their data practices:
- Google OAuth — sign-in authentication; subject to Google's Privacy Policy
- UploadThing — media and photo storage; your uploaded images are stored on their servers
- Mapbox — interactive map rendering; map tile requests may include your approximate location
- Vercel — platform hosting and edge network; processes request metadata including IP addresses for routing and performance
- AI Provider (OpenAI or equivalent) — processes prompts and trip data for AI features
We are not responsible for the data practices of third-party services. We encourage you to review their respective privacy policies before using features that interact with them.
Your Rights Under GDPR (EU Users)
Legal Basis for Processing
We process your personal data under the following legal bases:
- Contract: Processing necessary to provide the service you signed up for (e.g., storing your trips, enabling your account)
- Legitimate Interests: Analytics, fraud prevention, and platform security, where these do not override your rights
- Consent: Marketing communications and optional features such as AI-powered suggestions
- Legal Obligation: Where required to comply with applicable law
Data Controller and Processor
APF Labs acts as the data controller for personal data collected through TravelMap. Third-party service providers (such as Vercel, UploadThing, and AI providers) act as data processors on our behalf and are bound by data processing agreements consistent with GDPR requirements.
Your Rights
- Right to Access: Request copies of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your data under certain conditions
- Right to Restrict Processing: Request limitation of data processing
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to processing of your personal data
- Right to Withdraw Consent: Withdraw consent at any time without affecting the lawfulness of prior processing
- Right to Lodge a Complaint: File a complaint with your local supervisory authority (e.g., your national Data Protection Authority)
To exercise these rights, please contact us at labs@apf.cloud.
California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- Right to Know: What personal information we collect and how we use it
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt-out of the sale of your personal information (we do not sell data)
- Right to Non-Discrimination: Not be discriminated against for exercising your rights
To submit a request, email us at labs@apf.cloud with "California Privacy Request" in the subject line.
Do Not Track Signals
Some browsers offer a "Do Not Track" (DNT) option. Currently, there is no industry standard for responding to DNT signals. We do not currently respond to DNT browser signals, but we provide you with choices about the collection and use of your information as described in this policy.
Email and Notification Communications
Transactional Emails
We send emails necessary to operate your account, including account verification, password resets, security alerts, and notifications about your trips and social activity. These cannot be fully disabled while your account is active.
Marketing Communications
With your consent, we may send product updates, feature announcements, or travel inspiration. You can opt out at any time using the unsubscribe link in any marketing email or through your notification settings.
Push and In-App Notifications
You can manage push and in-app notification preferences in your account settings at any time.
Data Breach Notification
In the event of a data breach that affects your personal information, we will notify you and relevant authorities as required by applicable law. We will provide information about the breach, the data affected, and steps you can take to protect yourself.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through the platform. Your continued use after changes indicates acceptance of the updated policy. The "Last Updated" date at the top of this policy indicates when it was last revised.
Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
Email: labs@apf.cloud
Website: labs.apf.cloud