Travu Logo

Global Privacy Policy & Legal Terms

Last Updated & Effective Date: March 2025

1. Introduction & Overview

Welcome to Travu: Travel Map & Tracker, operated by T3Pixel LTD ("Travu," "we," "our," or "us"). We provide mobile applications, websites, interactive scratch maps, travel itineraries, companion features, and travel tracking services (collectively, the "Services").

We respect your privacy and are committed to protecting personal data across all jurisdictions where our Services are operated, including North America, the European Union, the United Kingdom, Asia-Pacific, Africa, Latin America, and worldwide. This Privacy Policy outlines how we collect, use, store, transfer, and safeguard your information, and explains your statutory rights under applicable global data protection regulations.

2. Global Jurisdictional Compliance Framework

This Privacy Policy is designed to comply with data privacy laws and regulations globally, including but not limited to:

  • United States: California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), Utah Consumer Privacy Act (UCPA), and Children's Online Privacy Protection Act (COPPA).
  • European Union & United Kingdom: EU General Data Protection Regulation (EU GDPR), UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018, and UK Age-Appropriate Design Code (AADC).
  • Canada: Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation.
  • Asia-Pacific: Japan Act on the Protection of Personal Information (APPI), Singapore Personal Data Protection Act (PDPA), South Korea Personal Information Protection Act (PIPA), Australia Privacy Act 1988 (Privacy Amendment), and India Digital Personal Data Protection Act (DPDP Act 2023).
  • Latin America: Brazil Lei Geral de Proteção de Dados (LGPD).
  • Africa & Middle East: South Africa Protection of Personal Information Act (POPIA), Nigeria Data Protection Act (NDPA), and applicable regional frameworks.

3. Information We Collect

We collect personal information through direct interactions, automated usage technologies, and authorized third parties:

A. Information Provided Directly By You

  • Account & Registration Details: Email address, display name, profile identifiers, and authentication data provided via third-party identity providers (e.g., Sign in with Apple, Google Sign-In).
  • Travel Logs & Preferences: Countries, regions, cities, and attractions marked as visited; travel dates; personal notes; travel stats; and custom map settings.
  • Social & Buddy Connections: Unique buddy invite codes, linked companion user IDs, and shared travel stats when utilizing collaborative travel features.
  • User-Generated Content & Media: Photos or attachments voluntarily uploaded to travel logs (including photo EXIF metadata, if present).
  • Support & Communications: Correspondence, feedback, or support tickets submitted to us.

B. Information Collected Automatically

  • Device & Network Data: Device hardware model, operating system version, unique device identifiers (IDFV/GAID), network information, IP address, and browser type.
  • Approximate Location & CDN Privacy Inspection: Country or city derived from IP address or country selections within the app for localized service provision (e.g., currency, regional travel recommendations). We utilize edge network infrastructure (such as Cloudflare Workers and Google Cloud Platform) to inspect request headers, route API requests securely, verify connection safety, and determine approximate IP-based location without storing precise tracking logs. Precise GPS location is processed only when explicitly granted by device permission settings.
  • Usage & Performance Analytics: Feature interactions, screen views, session durations, diagnostic logs, crash reports, and aggregate usage metrics collected via Firebase Analytics, Google Analytics, and Firebase Crashlytics to evaluate app performance, fix errors, and improve product functionality.
  • Push Notification Tokens: Firebase Cloud Messaging (FCM) or Apple Push Notification Service (APNs) device tokens required for sending account updates, buddy invites, or travel reminders.

C. Financial & Subscription Information

All in-app purchases, recurring premium subscriptions, and transactions are processed directly by official app marketplaces (Apple App Store / Google Play Store). We do not collect, store, or process raw credit card or bank account details. We receive non-sensitive transaction metadata (e.g., original transaction ID, purchase token, subscription status, dynamic cohort tier) to grant access to premium features.

4. Legal Bases for Processing Data (GDPR / UK GDPR / LGPD / POPIA)

Where required under applicable law (e.g., EU/UK GDPR, LGPD, POPIA), we process your personal data under the following legal bases:

  • Contractual Necessity: To deliver the core travel tracking, syncing, and account management services agreed upon in our Terms of Service.
  • Legitimate Interests: To improve app features, enhance security, prevent fraud, troubleshoot technical glitches, and analyze aggregate user patterns.
  • Consent: Where you have explicitly granted permission (e.g., push notifications, precise device location access, marketing communications). You may withdraw consent at any time in device or app settings.
  • Legal Obligation: To comply with applicable laws, judicial orders, or regulatory enforcement inquiries.

5. How We Use Your Information

We process collected data exclusively for legitimate business and service delivery purposes:

  • To render, synchronize, and display your personalized scratch map and travel stats across your devices.
  • To facilitate buddy connections and travel recaps ("Travu Wrapped").
  • To deliver push notifications regarding account events or travel updates.
  • To diagnose technical errors, improve app performance, and optimize user experience.
  • To prevent unauthorized access, security incidents, fraudulent activities, and terms violations.
  • To comply with statutory legal, accounting, and tax obligations.

6. Data Sharing, Selling & Third-Party Disclosures

We do not sell your personal information or travel history to third parties or data brokers. We do not share personal information for cross-context behavioral advertising.

We share information only with trusted service providers bound by strict confidentiality and data protection agreements, required to operate our Services:

  • Cloud Infrastructure & Database Hosting: Google Cloud Platform / Firebase (data hosting, database management, cloud functions).
  • Edge Network Security & Geolocation: Cloudflare (CDN routing, web application firewall security, request privacy inspection, and edge IP location processing).
  • App Store Operations: Apple App Store and Google Play Store for account authentication, app distribution, and subscription management.
  • Analytics & Performance: Firebase Analytics and Google Analytics (for measuring app engagement, feature usage, and session performance), and Firebase Crashlytics (for real-time crash monitoring and stability debugging). These analytics providers process pseudonymous device identifiers and usage metrics strictly on our behalf.
  • Affiliate Partners & Travel Services: External service partners such as Airalo (eSIM travel connectivity) and Viator (experience and itinerary search). When you interact with partner links (e.g., Airalo partner offers), you may be redirected to third-party platforms subject to their respective privacy policies. In compliance with Federal Trade Commission (FTC) guidelines, we disclose that we may earn affiliate commissions from partner links.
  • Legal & Regulatory Authorities: We may disclose information if required by law, subpoena, court order, or governmental mandate, or to protect the rights, safety, and property of Travu, our users, or the public.

7. International Data Transfers

Travu is operated globally, and your information may be processed and stored on cloud servers located in the United States, Europe, or other global regions. If you reside outside the United States, please note that local data protection laws may differ from those in your jurisdiction.

When transferring personal data internationally from the European Union, European Economic Area, United Kingdom, Switzerland, or other jurisdictions requiring transfer safeguards, we rely on standard contractual mechanisms approved by relevant authorities (such as European Commission Standard Contractual Clauses (SCCs) and UK International Data Transfer Agreements) to ensure your data receives equivalent protection.

8. Data Retention & Account Deletion

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this policy, maintain active user accounts, resolve disputes, and enforce legal agreements.

Account Deletion: You have full ownership and control of your data. You may request complete account deletion and data erasure at any time directly within the mobile application settings, or by submitting a written request to support@travu.app. Upon processing, all associated account profile data, travel logs, visit records, and buddy links are permanently erased or irrevocably anonymized from our production databases.

9. Your Global Privacy Rights

Depending on your country, state, or jurisdiction of residence, you possess specific legal rights regarding your personal data:

  • Right to Access / Know: Request details regarding what personal data we hold about you and receive a copy of your information.
  • Right to Rectification / Correction: Request correction of inaccurate, outdated, or incomplete personal data.
  • Right to Erasure / Deletion ("Right to be Forgotten"): Request permanent removal of your personal data.
  • Right to Data Portability: Request export of your travel data in a structured, commonly used, and machine-readable format.
  • Right to Restrict or Object to Processing: Limit or object to our processing of your personal data under specific legal grounds.
  • Right to Withdraw Consent: Revoke previously granted permissions (e.g., location, push notifications) at any time without affecting prior lawful processing.
  • Right to Non-Discrimination: You will not receive discriminatory treatment, altered pricing, or diminished service quality for exercising any of your statutory privacy rights.
  • Right to Opt-Out of Sale / Targeted Advertising: We do not sell data or engage in cross-context targeted advertising.

To exercise any of these rights, please contact us at support@travu.app. We will authenticate your request in accordance with applicable statutory timelines.

10. Children's Privacy (COPPA / GDPR / AADC)

Our Services are directed at general audiences and are not directed to children under 13 years of age (or under 16 years of age in the European Union, United Kingdom, or applicable jurisdictions). We do not knowingly collect or solicit personal information from children under these ages.

If we discover that a child under the relevant age threshold has provided us with personal information without verifiable parental consent, we will immediately take steps to delete such data from our systems. Parents or guardians who believe their child has submitted personal data may contact us at support@travu.app.

11. Cookies, Local Storage & Tracking Technologies

Our website and web applications use essential local storage, session cookies, and basic web analytics to ensure proper functionality, store user session states, and remember user site preferences. We do not use third-party tracking cookies for targeted behavioral advertising.

12. Data Security Measures

We maintain appropriate technical, administrative, and physical safeguards designed to protect personal data against unauthorized access, loss, misuse, disclosure, or alteration. These measures include TLS/SSL transport layer encryption, encrypted data storage at rest on cloud servers, strict access controls, and periodic security evaluations. However, no internet-based transmission or electronic storage method can be guaranteed 100% secure.

13. Disclaimers, Limitation of Liability & Legal Protections

To the fullest extent permitted by applicable law in your jurisdiction:

  • "AS IS" Disclaimer: The Services, travel information, maps, and itineraries are provided on an "AS IS" and "AS AVAILABLE" basis without warranties of any kind, whether express, implied, or statutory.
  • Limitation of Liability: T3Pixel LTD, its directors, officers, employees, and affiliates shall not be liable for any indirect, incidental, consequential, special, punitive, or exemplary damages arising out of or in connection with your use of or inability to use the Services.
  • Indemnification: You agree to defend, indemnify, and hold harmless T3Pixel LTD from and against any claims, liabilities, damages, judgments, awards, losses, costs, expenses, or fees arising out of your violation of this Privacy Policy or misuse of the Services.
  • Dispute Resolution & Governing Law: Any dispute or legal claim arising from or relating to this Privacy Policy or the Services shall be governed by and construed under applicable laws, without giving effect to conflict of law principles.

14. Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time to reflect legal changes, technological advancements, or updates to our Services. When updates occur, we will post the revised policy on this page with an updated "Last Updated" date. Your continued use of the Services after any changes signifies your acknowledgement and acceptance of the updated Privacy Policy.

15. Contact Us & Privacy Inquiries

If you have questions, feedback, statutory data rights requests, or concerns regarding this Privacy Policy or our data handling practices, please reach out to us at:

T3Pixel LTD (Travu: Travel Map & Tracker)

Data Protection & Privacy Team

support@travu.app

Travu Partner Perk

Stay Connected Abroad with Airalo eSIM

Get 15% OFF your international mobile data with code NEWTOAIRALO15 at checkout.

Claim 15% OFF open_in_new