Version 2026-08-31

Privacy Policy — Aventura

Last updated: [DATE] Version: 1.0

This Policy explains how Aventura collects, uses, shares and protects personal data. It is written to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the Brazilian General Data Protection Law (LGPD, Law 13.709/2018) and the California Consumer Privacy Act as amended (CCPA/CPRA).


1. Controller and contacts

Controller: [LEGAL ENTITY NAME], CNPJ [CNPJ], [FULL ADDRESS], Brazil. Data Protection Officer: [NAME] — [DPO EMAIL] EU representative (GDPR Art. 27): [NAME / ADDRESS] UK representative (UK GDPR Art. 27): [NAME / ADDRESS]

2. Data we process

2.1. Account data

Name, email address, account identifier and, where you use social login, the identifier supplied by the provider (Google, Apple). Passwords are stored in hashed form by our authentication provider — we never have access to your password.

2.2. Planning data (User Content)

Destinations, dates, city of origin, budget and currency, group composition (number of adults, number and age range of children), interests, pace, transport preference, accommodation type, and free-text notes.

Please note: the notes field is free text. Do not enter special-category data (health, religion, sexual orientation, political or trade union affiliation, biometrics), third-party data without authorisation, or confidential information. Anything you enter will be processed as part of your request and transmitted to the AI providers listed in Section 5.

2.3. Payment data

Subscription status, plan, billing cycle, transaction identifiers and billing history. We do not collect or store card numbers, CVV or expiry dates — these are handled directly by Stripe as an independent controller.

2.4. Technical and usage data

IP address, country inferred from IP (used to set language and currency), device and browser type, access timestamps, pages visited, usage counters (generations and edits performed), error and request logs.

2.5. Cookies

See Section 9.

2.6. What we do not collect

We do not collect precise device geolocation. We do not access your calendar, contacts, camera or microphone. We do not perform cross-site tracking for behavioural advertising.

3. Purposes and legal bases

#PurposeDataGDPR basisLGPD basis
1Create and maintain your accountAccountArt. 6(1)(b) contractArt. 7, V
2Generate and edit itinerariesPlanning, accountArt. 6(1)(b) contractArt. 7, V
3Save and display your itinerariesPlanning, itinerariesArt. 6(1)(b) contractArt. 7, V
4Process subscriptions and billingAccount, paymentArt. 6(1)(b) contractArt. 7, V
5Enforce usage limits, prevent abuseTechnical, countersArt. 6(1)(f) legitimate interestArt. 7, IX
6Set language and currency by countryIP, inferred countryArt. 6(1)(f) legitimate interestArt. 7, IX
7Security, fraud prevention, loggingTechnicalArt. 6(1)(f) legitimate interestArt. 7, IX
8Improve the service using aggregated/anonymised dataAggregated usageArt. 6(1)(f) legitimate interestArt. 7, IX
9Customer supportAccount, contextArt. 6(1)(b) contractArt. 7, V
10Comply with legal, tax and regulatory obligationsAccount, paymentArt. 6(1)(c) legal obligationArt. 7, II
11Establish, exercise or defend legal claimsAs necessaryArt. 6(1)(f)Art. 7, VI
12Marketing communicationsEmailArt. 6(1)(a) consentArt. 7, I

Legitimate interest. We have carried out balancing assessments weighing our interests against your rights and freedoms. You may object to any processing based on legitimate interest (Section 7).

Marketing consent is optional, separately obtained, and withdrawable at any time without affecting your use of the Platform.

4. Automated decision-making

4.1. Itinerary generation is an automated process driven by artificial intelligence. It produces suggested travel content. It does not produce legal effects concerning you and does not similarly significantly affect you within the meaning of GDPR Article 22.

4.2. We also use automated processing to enforce plan limits and detect abuse.

4.3. Your rights. Under GDPR Article 22 and LGPD Article 20, you may request human review of decisions based solely on automated processing, express your point of view, contest the decision, and request information on the criteria used, subject to trade secret protections. Contact the DPO.

5. Who we share with — processors and sub-processors

We share data only with providers necessary to operate the service, under contract and on our instructions.

ProviderRoleData transmittedLocation
SupabaseAuthentication and databaseAccount, itineraries[REGION]
Google Cloud RunApplication serverRequests, planning dataUnited States
Cloudflare (Workers, R2)Site delivery, image storage, protectionTechnical, imagesGlobal / US
StripePayments and subscriptionsAccount, billingUnited States / Ireland
DeepSeekLanguage model (itinerary generation)Planning data, including free-text notesPeople's Republic of China
OpenAILanguage model (fallback)Planning dataUnited States
GeoapifyVenue verificationVenue and city namesEuropean Union
HERE TechnologiesVenue verification (secondary)Venue and city names[REGION]
Google PlacesVenue verification (fallback) and venue photos (last resort)Venue and city namesUnited States
Bright DataImage sourcingSearch terms (no personal data)[REGION]
ApifyVenue image sourcingSearch terms (no personal data)United States / EU
Brave SearchImage sourcing (fallback)Search terms (no personal data)United States
Transfer to China — please read. Our primary language model provider is established in the People's Republic of China. The planning data you provide, including free-text notes, is transmitted to that provider in order to generate your itinerary. China is not the subject of an adequacy decision by the European Commission, the UK government or Brazil's ANPD. We rely on [DESCRIBE SAFEGUARD — standard contractual clauses, data minimisation, pseudonymisation] and have carried out a transfer impact assessment. If you do not wish your data to be transferred on this basis, do not use the Platform, or contact the DPO to request processing by an alternative provider where available.

Other disclosures: public authorities in response to a valid legal request; legal and accounting advisers under a duty of confidentiality; an acquirer in the event of a corporate reorganisation, with prior notice.

We do not sell personal data and do not share it with data brokers or advertising networks.

Booking Partners. When you click a Partner link you are taken to their website. From that point, processing is governed by the Partner's privacy policy, not this one. We may pass an affiliate identifier; we do not pass your personal data.

6. International transfers

Some data is processed outside the EEA, the UK and Brazil, as set out above. We rely on: Standard Contractual Clauses (GDPR Art. 46(2)(c)), the UK International Data Transfer Addendum, contractual guarantees under LGPD Art. 33(II), and, where applicable, the necessity of the transfer for performance of our contract with you (GDPR Art. 49(1)(b) / LGPD Art. 33(VI)). Copies of the safeguards are available from the DPO on request.

7. Your rights

Under GDPR / UK GDPR you have the right to: access; rectification; erasure; restriction of processing; data portability; objection (including to processing based on legitimate interest); withdrawal of consent; and not to be subject to solely automated decisions with legal or similarly significant effects.

Under the LGPD (Art. 18) you additionally have the right to: confirmation of processing; anonymisation or blocking of unnecessary or excessive data; information about data sharing; information about the consequences of refusing consent; and review of automated decisions.

Under the CCPA/CPRA, California residents have the right to know, delete, correct, and to opt out of the "sale" or "sharing" of personal information, and to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined. We do not discriminate against users who exercise their rights. You may use an authorised agent.

How to exercise: write to [DPO EMAIL] or use the options in your account settings. We respond within 30 days (GDPR/CCPA) or 15 days (LGPD). We may ask you to verify your identity. There is no charge for a reasonable request.

Complaints. You may complain to your local supervisory authority: the ICO (United Kingdom), your national data protection authority (EEA), or the ANPD (Brazil). We would appreciate the chance to address your concern first.

8. Retention

CategoryPeriod
Account and registration dataFor as long as the account exists
Saved itinerariesFor as long as the account exists, or until you delete them
Planning data sent to AI providersRetained by us while the itinerary exists; retention by the AI provider is governed by its own policy
Billing and tax records5 years after the transaction (legal obligation)
Application access logs6 months (Brazilian Internet Civil Framework, Art. 15)
Error and security logs[X] months
Marketing dataUntil consent is withdrawn

On account closure we delete or anonymise data within the periods above, except where retention is necessary to comply with a legal obligation or to establish, exercise or defend legal claims.

9. Cookies

We use:

  • Strictly necessary: session, authentication, security, language and currency preference. No consent required.
  • Analytics: [DESCRIBE OR REMOVE IF UNUSED]. Consent required in the EEA/UK.
  • Advertising: none.

You can manage cookies in your browser and via our consent banner where applicable. Blocking necessary cookies will prevent sign-in.

10. Security

We apply appropriate technical and organisational measures, including encryption in transit (TLS), role-based access control, server-side token verification, credential segregation, least-privilege access and access logging.

No system is completely secure. In the event of a personal data breach likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours where required (GDPR Art. 33) and notify you without undue delay where the risk is high (GDPR Art. 34 / LGPD Art. 48).

11. Children

The Platform is not intended for anyone under 18 and we do not knowingly collect their data. When describing your travel group you may indicate the number and age range of children — used only to tailor suggestions, and not identifying any child. Do not enter a minor's name, document number or photograph. If we learn that we have collected such data, we will delete it.

12. Changes to this Policy

We may update this Policy. Material changes will be notified by email and/or in-Platform notice 30 days in advance. The last updated date appears at the top.

13. Contact

Data Protection Officer: [NAME] — [DPO EMAIL] Support: [SUPPORT EMAIL] Address: [LEGAL ENTITY NAME], CNPJ [CNPJ], [FULL ADDRESS], Brazil