Legal
Privacy Policy
Last updated 12 August 2026
Effective date 11 August 2026 · Last updated 12 August 2026
Introduction
This Privacy Policy describes how Itinera collects, uses, stores, discloses, and protects personal information when you use Itinera services, the Itinera Live Journey™ traveller portal and mobile applications, future connected Itinera web services, and the related travel-planning and Journey functionality we provide.
Your use of the services is subject to this Privacy Policy and to the applicable Itinera Terms of Service. If you do not agree with this policy, please do not use the services.
Itinera and Itinera Live Journey™ are operated by Itinera Journey LLC, a limited liability company formed in the State of Wyoming, United States, with its registered address at 30 Gould St Ste R, Sheridan, WY 82801, United States. Itinera Journey LLC is the controller responsible for personal information processed through the services.
1. Information we collect
The categories below describe the information the services may collect. Not every category applies to every customer — what we hold depends on the Journey you have and the features you use.
A. Account and contact information
- Name
- Email address
- Phone number
- Account and login information
- Profile information you or your advisor provide
B. Journey and travel information
- Destinations, departure and return dates, and traveller count
- Itineraries, flights, accommodations, transportation, and reservations
- Activities, and meetings for business Journeys
- Travel preferences and advisor communications
C. Travel Wallet information
- Boarding passes, tickets, and vouchers
- Reservation confirmations and travel insurance documents
- Travel documents you or your advisor upload
- QR, barcode, or check-in information contained within those documents
Some Wallet information contains sensitive travel credentials. It is treated as private Journey information, is restricted to you and the Itinera personnel supporting your Journey, and is not published publicly by us.
D. Payment and billing information
- Package and payment status
- Transaction references
- Amounts paid and amounts due
- Payment history and travel charges recorded by your advisor
Payment-card processing is handled by our payment processor, Stripe, and is governed by Stripe's own privacy and legal terms. Itinera does not store full payment-card numbers or card security codes.
E. Trip Budget and expense information
- Budget figures and expense entries
- Business and personal classifications for Briefcase Journeys
- Receipt images you capture or upload
- Expense descriptions, dates, and notes
Trip Budget information is your own record-keeping and is distinct from Itinera billing for your Journey package.
F. User-generated content
- Travel Story photos, videos, and notes
- Journey memories and Journey Highlights
- Documents you upload
This content remains private unless you intentionally use a sharing or publication feature within the application.
G. Sora interactions
Information you provide to Sora, together with relevant Journey context, may be processed to provide AI-assisted travel support, planning help, summaries, recommendations, and other Sora functionality you request.
H. Device and technical information
- Device or browser type and operating system
- IP address
- Application and session information
- Push notification registration and token information
- Error and performance diagnostics
I. Permission-based information
- Camera — to capture receipts and travel documents.
- Notifications — to deliver Journey alerts.
- Location — only where existing location-based Journey functionality, such as Journey Map sharing or SOS, requires it.
We request permissions only when they are relevant to a feature you are using, and you can decline or withdraw any permission through your device settings.
2. How we use information
- Create and manage customer accounts
- Plan and manage Journeys, and build and display itineraries
- Provide Travel Wallet functionality
- Process and track applicable payments, including Group Payments
- Provide Sora functionality
- Send operational Journey notifications
- Provide safety and SOS functionality
- Maintain Trip Budget and expense tools
- Provide Briefcase business-travel functionality
- Generate Journey recaps and Journey Highlights you request
- Provide customer support
- Detect and prevent fraud or misuse, and maintain application security
- Diagnose errors and improve reliability and functionality
- Comply with legal obligations
We do not sell personal information, and we do not use it to build advertising profiles.
3. How information may be shared
We disclose information only as reasonably necessary to operate the services, and only to the categories of recipient below.
- Travel providers involved in arrangements you request
- Our payment processor, Stripe
- Hosting and cloud infrastructure providers
- Email and communications providers
- Mapping and location service providers
- AI technology and service providers
- Application error and runtime reporting providers
- Professional and legal advisers
- Government or legal authorities where required by law
Travellers you invite to your Journey can see the Journey information their role allows. Live location is visible only to participants on the same Journey while sharing is on.
4. Service providers and subprocessors
Itinera Journey LLC uses third-party providers to operate and deliver Itinera and Itinera Live Journey™. These providers may process information on our behalf, or — where applicable — under their own responsibilities as described in their respective terms, privacy notices, and data-processing documentation. They are authorized to process personal data only as needed to provide their services to us.
The table below lists each provider, what it helps us do, and where you can read that provider's current official privacy and data-processing documentation. Those documents remain the authoritative source for the provider's own practices.
| Provider | Purpose | Privacy / legal information |
|---|---|---|
| Lovable | Application hosting and deployment, backend/runtime infrastructure, transactional email, AI Gateway, and application error/runtime reporting. | Privacy PolicyData Processing Addendum |
| Supabase | Database, authentication, realtime functionality, and file/document/media storage, used through the Lovable Cloud architecture. | Privacy PolicyData Processing Agreement |
| Google Sign-In, Gemini AI models accessed through the Lovable AI Gateway, Google Fonts, and Firebase Cloud Messaging when Android push notifications are activated. | Privacy PolicyCloud Data Processing AddendumFirebase privacy & securityGoogle Fonts & privacy | |
| Mapbox, Inc. | Journey Map rendering, geocoding, and place/location functionality. | Privacy PolicyData Processing Addendum |
| Stripe, Inc. | Payment processing, checkout and payment transactions, and applicable Journey and Group Payment processing. | Privacy PolicyData Processing Agreement |
| Apple Inc. | Apple Push Notification service when native iOS push is activated, and applicable native Apple services when introduced. | Privacy PolicyApple Push Notifications & privacy |
Linking to a provider's documentation does not reduce our own responsibilities. This Privacy Policy remains our description of what we collect, why, how we use it, who we share it with, and your rights.
External map and direction hand-offs. Mapbox is our service provider for in-app mapping. When you intentionally open directions in an external app such as Apple Maps or Google Maps, you are interacting directly with that third-party service under its own terms and privacy practices. Those hand-offs are not server-side Itinera subprocessors.
5. Artificial intelligence processing
Itinera uses artificial intelligence features to provide services including Sora-assisted travel support, itinerary-related assistance, document and receipt processing, Journey recaps, and other AI-enabled functionality.
AI requests are processed through the Lovable AI Gateway, which routes requests to third-party AI model providers. Google Gemini models are currently used within our AI architecture; the Gateway may route requests to other model providers it supports, and not every provider receives every request. We minimize the information transmitted to AI services and use technical safeguards designed to exclude or redact unnecessary sensitive information before AI processing.
Lovable states that its AI Gateway does not retain prompt or response content for model-training purposes. We select AI services whose applicable API terms prohibit using customer API content to train general-purpose AI models. AI service providers may nevertheless process or temporarily retain limited information for security, abuse prevention, debugging, or similar operational purposes, and limited human review may occur where necessary for those purposes.
AI processing may involve limited Journey context necessary to provide the requested feature. Information transmitted to AI providers is minimized but should not be understood to be fully anonymized.
Please avoid submitting unnecessary highly sensitive information through conversational features. Use the structured parts of the application, such as your Travel Wallet, for travel documents.
For information about each provider's own processing practices, including Lovable's and Google's, see the Service providers and subprocessors section above and the provider documentation linked there.
6. Data security
We maintain reasonable administrative, technical, and organizational safeguards, including authentication, authorization and access controls, role-based access for Itinera personnel, restricted access to private Journey information, secure transport of data, secure document storage, separation of payment-card processing to our payment provider, and security monitoring where implemented.
No electronic system or method of transmission can be guaranteed to be completely secure, and we cannot promise absolute security.
7. Data retention
We retain personal information only for as long as reasonably necessary for the purpose it was collected. Our baseline retention schedule is set out below. Retention may be shorter where you delete information or your account earlier, and longer where applicable law, an unresolved dispute, or a legitimate security, fraud-prevention, or accounting requirement genuinely requires it.
| Information | Baseline retention |
|---|---|
| Account and profile information | While the account remains active, subject to deletion requests and legal obligations. |
| Active Journey information | Throughout the Journey and while required to deliver the purchased travel service. |
| Completed Journey history | 3 years after Journey completion. |
| Travel Wallet documents | 12 months after Journey completion. |
| Boarding passes, barcodes, and similar check-in credentials | 90 days after Journey completion. Expired boarding credentials are not preserved simply because general Journey history remains available. |
| Receipts and expense attachments | 3 years after Journey completion. |
| Sora conversation history | 12-month rolling retention for conversation history stored by Itinera. This is not a statement about third-party AI provider retention, which is described in the Artificial intelligence processing section. |
| Travel Story, Journey Highlights, and other media you create | Kept while your account is active and you choose to keep the content, until you delete the content or your account, or until another applicable retention rule requires removal. Your own Journey memories are not automatically deleted merely because the underlying Journey passes the 3-year Journey-history period. |
| Support and advisor communications | 3 years after the last relevant interaction, unless a dispute, legal obligation, or fraud/security matter legitimately requires longer. |
| Push notification registrations | Only while operationally needed to deliver notifications — removed or deactivated on sign-out where applicable, when a token becomes invalid or is replaced, when the notification relationship ends, or on account deletion. |
| Security and system logs | 12 months, unless a specific incident, investigation, legal obligation, or operational requirement legitimately requires longer preservation. |
| Account-deletion request records | 3 years after completion, limited to what is reasonably necessary to demonstrate the request was received and processed. Your deleted account data is not preserved because this record is retained. |
| Financial, payment, tax, and accounting records | 7 years, or longer where applicable law requires. Limited to what is reasonably necessary for accounting, tax, payment, dispute, fraud-prevention, or other legal requirements. |
Backups. Deleted information may remain temporarily in protected backups until it expires through the normal backup lifecycle. Information that exists only in backups is not restored into active production systems except where technically necessary for legitimate disaster recovery, and applicable deletion requirements continue to be honoured if that occurs.
You may request deletion of your account at any time. Certain records may need to be retained where required for legitimate legal, tax, accounting, fraud-prevention, security, or regulatory reasons.
8. Account and data deletion
You can initiate deletion of your Itinera account in the application at Profile → Account Settings → Delete Account. You can also request deletion without signing in through our publicly available Delete your data page, or by emailing privacy@itinerajourney.com.
Deletion means deletion of your account and the personal data associated with it — not deactivation — except information Itinera is legally required or legitimately permitted to retain. Where a Journey still has unresolved travel services, payments, or operational obligations, your request is recorded and completed once those obligations are resolved, and we confirm when deletion is complete.
Deletion overrides our ordinary retention periods. If you delete your account before a retention period above has elapsed, we delete or anonymise the personal information that no longer needs to be kept, rather than holding it for the remainder of that period. We preserve only what is legitimately required for financial and accounting obligations, tax, fraud prevention, security, legal claims and disputes, and other regulatory or legal requirements. Where retained records do not require continued identification of you, we anonymise or minimise them. Retained legal or accounting records are not an active customer account, and are not used to contact you or to keep unrelated Wallet, Travel Story, Sora, or other personal Journey data.
9. Your privacy rights
Depending on where you reside, applicable law may provide rights such as access, correction, deletion, portability, restriction of processing, objection to processing, withdrawal of consent where processing relies on consent, and the right to complain to an applicable data-protection authority. Not every right applies to every customer or in every jurisdiction.
To exercise a right, contact privacy@itinerajourney.com. We respond to verified requests as required by applicable law.
10. Legal basis, where applicable
Where applicable data-protection law requires us to identify a legal basis for processing personal information — for example the GDPR or similar frameworks — we rely on the bases described below. These frameworks do not apply identically to every customer or in every jurisdiction.
Performance of a contract. Where processing is objectively necessary to provide the Itinera services you asked for: account creation and administration; Journey creation and travel planning; itinerary creation and management; advisor service; Travel Wallet functionality; reservations and travel arrangements and the related travel documents; operational Journey communications and required Journey notifications; package, Briefcase Journey, and group travel functionality; Sora functionality where necessary to deliver a feature you requested; and processing and tracking applicable payments.
Legitimate interests. For reasonable business and security operations that are not strictly necessary to perform your travel contract: application security, fraud and abuse prevention, service reliability, error diagnosis and troubleshooting, protecting Itinera and our customers and systems, internal operational administration, preventing duplicate or fraudulent transactions, improving the reliability and functionality of our existing services, and maintaining appropriate business records where permitted. We consider the rights, interests, and reasonable expectations of the people affected when relying on this basis; it does not override your privacy rights.
Consent. Only where processing genuinely depends on an optional choice you make and applicable law requires or supports consent — for example optional marketing communications, optional device permissions such as camera, location, and notifications through your device's normal permission controls, and certain optional sharing or publication choices. Withdrawing an optional consent does not stop processing that is independently necessary to perform an existing contract or to comply with law.
Legal obligation. Where we must process or preserve information to comply with applicable law, including required tax and accounting records, legally required transaction records, responding to valid legal process, and applicable regulatory obligations.
Vital interests. Where applicable law recognises it, processing may exceptionally be necessary to protect someone's vital interests in a genuine emergency. This is not the routine basis for SOS or ordinary travel support.
| Purpose | Primary basis |
|---|---|
| Providing accounts and purchased Journey services | Performance of a contract |
| Payments, bookings, and service fulfilment | Performance of a contract and, where applicable, legal obligation |
| Security, fraud prevention, and system integrity | Legitimate interests and, where applicable, legal obligation |
| Optional marketing | Consent where required, or another lawful basis where applicable |
| Optional customer-controlled sharing and features | Consent or your request, depending on the feature and applicable law |
| Sora and other AI-assisted features you request | Performance of a contract where necessary to deliver the requested service; another applicable basis where the feature and the information are genuinely optional |
| Legal and accounting compliance | Legal obligation |
| Emergency processing | Vital interests where the applicable legal standard is met |
11. International processing and data transfers
Itinera Journey LLC is based in the United States and provides services internationally. Personal information may therefore be processed in the United States and in other countries where our service providers operate. Where required by applicable law, we use appropriate legal and contractual safeguards for international transfers.
For additional information about where and how individual providers process information, see the Service providers and subprocessors section above and each provider's own privacy and data-processing documentation.
12. Children's privacy
Itinera accounts are intended for individuals 18 years of age or older. We do not knowingly permit anyone under 18 to independently create or control an Itinera account, and we do not offer independent accounts to minors.
Persons under 18 may take part in Journeys when their information is provided by an appropriate adult account holder — a parent, guardian, or other responsible adult working with an advisor. We may therefore process limited information concerning minor travellers where necessary to arrange or manage family and group travel, including reservations, flights, accommodation, transportation, activities, and travel documents.
A minor traveller on a Journey is not an independent Itinera account holder. The adult account holder remains responsible for the information they provide about travellers in their party. If you believe a person under 18 has created an account independently, contact privacy@itinerajourney.com.
13. Public sharing
Some features let you intentionally create and share public Journey content, such as approved Journey Highlights or a recap link. Sharing is always your choice, and you control it through the existing sharing functionality.
- Private Travel Story content is not automatically made public.
- Private Wallet credentials are not intended for public sharing.
- Boarding and check-in codes are not intended for public publication.
- Payment information is never part of public Journey Highlights.
14. Changes to this Privacy Policy
We may update this policy as our services, legal requirements, or data practices change. The Last updated date at the top of this page always reflects the current version, and material changes will be communicated where required.
15. Contact
For privacy questions, rights requests, and deletion questions relating to Itinera and Itinera Live Journey™, contact privacy@itinerajourney.com.
Itinera Journey LLC
30 Gould St Ste R
Sheridan, WY 82801
United States