Privacy Policy — Aventura
Last updated: [DATE] Version: 1.0
This Policy explains how Aventura collects, uses, shares and protects personal data. It is written to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the Brazilian General Data Protection Law (LGPD, Law 13.709/2018) and the California Consumer Privacy Act as amended (CCPA/CPRA).
1. Controller and contacts
Controller: [LEGAL ENTITY NAME], CNPJ [CNPJ], [FULL ADDRESS], Brazil. Data Protection Officer: [NAME] — [DPO EMAIL] EU representative (GDPR Art. 27): [NAME / ADDRESS] UK representative (UK GDPR Art. 27): [NAME / ADDRESS]
2. Data we process
2.1. Account data
Name, email address, account identifier and, where you use social login, the identifier supplied by the provider (Google, Apple). Passwords are stored in hashed form by our authentication provider — we never have access to your password.
2.2. Planning data (User Content)
Destinations, dates, city of origin, budget and currency, group composition (number of adults, number and age range of children), interests, pace, transport preference, accommodation type, and free-text notes.
Please note: the notes field is free text. Do not enter special-category data (health, religion, sexual orientation, political or trade union affiliation, biometrics), third-party data without authorisation, or confidential information. Anything you enter will be processed as part of your request and transmitted to the AI providers listed in Section 5.
2.3. Payment data
Subscription status, plan, billing cycle, transaction identifiers and billing history. We do not collect or store card numbers, CVV or expiry dates — these are handled directly by Stripe as an independent controller.
2.4. Technical and usage data
IP address, country inferred from IP (used to set language and currency), device and browser type, access timestamps, pages visited, usage counters (generations and edits performed), error and request logs.
2.5. Cookies
See Section 9.
2.6. What we do not collect
We do not collect precise device geolocation. We do not access your calendar, contacts, camera or microphone. We do not perform cross-site tracking for behavioural advertising.
3. Purposes and legal bases
| # | Purpose | Data | GDPR basis | LGPD basis |
|---|---|---|---|---|
| 1 | Create and maintain your account | Account | Art. 6(1)(b) contract | Art. 7, V |
| 2 | Generate and edit itineraries | Planning, account | Art. 6(1)(b) contract | Art. 7, V |
| 3 | Save and display your itineraries | Planning, itineraries | Art. 6(1)(b) contract | Art. 7, V |
| 4 | Process subscriptions and billing | Account, payment | Art. 6(1)(b) contract | Art. 7, V |
| 5 | Enforce usage limits, prevent abuse | Technical, counters | Art. 6(1)(f) legitimate interest | Art. 7, IX |
| 6 | Set language and currency by country | IP, inferred country | Art. 6(1)(f) legitimate interest | Art. 7, IX |
| 7 | Security, fraud prevention, logging | Technical | Art. 6(1)(f) legitimate interest | Art. 7, IX |
| 8 | Improve the service using aggregated/anonymised data | Aggregated usage | Art. 6(1)(f) legitimate interest | Art. 7, IX |
| 9 | Customer support | Account, context | Art. 6(1)(b) contract | Art. 7, V |
| 10 | Comply with legal, tax and regulatory obligations | Account, payment | Art. 6(1)(c) legal obligation | Art. 7, II |
| 11 | Establish, exercise or defend legal claims | As necessary | Art. 6(1)(f) | Art. 7, VI |
| 12 | Marketing communications | Art. 6(1)(a) consent | Art. 7, I |
Legitimate interest. We have carried out balancing assessments weighing our interests against your rights and freedoms. You may object to any processing based on legitimate interest (Section 7).
Marketing consent is optional, separately obtained, and withdrawable at any time without affecting your use of the Platform.
4. Automated decision-making
4.1. Itinerary generation is an automated process driven by artificial intelligence. It produces suggested travel content. It does not produce legal effects concerning you and does not similarly significantly affect you within the meaning of GDPR Article 22.
4.2. We also use automated processing to enforce plan limits and detect abuse.
4.3. Your rights. Under GDPR Article 22 and LGPD Article 20, you may request human review of decisions based solely on automated processing, express your point of view, contest the decision, and request information on the criteria used, subject to trade secret protections. Contact the DPO.
5. Who we share with — processors and sub-processors
We share data only with providers necessary to operate the service, under contract and on our instructions.
| Provider | Role | Data transmitted | Location |
|---|---|---|---|
| Supabase | Authentication and database | Account, itineraries | [REGION] |
| Google Cloud Run | Application server | Requests, planning data | United States |
| Cloudflare (Workers, R2) | Site delivery, image storage, protection | Technical, images | Global / US |
| Stripe | Payments and subscriptions | Account, billing | United States / Ireland |
| DeepSeek | Language model (itinerary generation) | Planning data, including free-text notes | People's Republic of China |
| OpenAI | Language model (fallback) | Planning data | United States |
| Geoapify | Venue verification | Venue and city names | European Union |
| HERE Technologies | Venue verification (secondary) | Venue and city names | [REGION] |
| Google Places | Venue verification (fallback) and venue photos (last resort) | Venue and city names | United States |
| Bright Data | Image sourcing | Search terms (no personal data) | [REGION] |
| Apify | Venue image sourcing | Search terms (no personal data) | United States / EU |
| Brave Search | Image sourcing (fallback) | Search terms (no personal data) | United States |
Transfer to China — please read. Our primary language model provider is established in the People's Republic of China. The planning data you provide, including free-text notes, is transmitted to that provider in order to generate your itinerary. China is not the subject of an adequacy decision by the European Commission, the UK government or Brazil's ANPD. We rely on [DESCRIBE SAFEGUARD — standard contractual clauses, data minimisation, pseudonymisation] and have carried out a transfer impact assessment. If you do not wish your data to be transferred on this basis, do not use the Platform, or contact the DPO to request processing by an alternative provider where available.
Other disclosures: public authorities in response to a valid legal request; legal and accounting advisers under a duty of confidentiality; an acquirer in the event of a corporate reorganisation, with prior notice.
We do not sell personal data and do not share it with data brokers or advertising networks.
Booking Partners. When you click a Partner link you are taken to their website. From that point, processing is governed by the Partner's privacy policy, not this one. We may pass an affiliate identifier; we do not pass your personal data.
6. International transfers
Some data is processed outside the EEA, the UK and Brazil, as set out above. We rely on: Standard Contractual Clauses (GDPR Art. 46(2)(c)), the UK International Data Transfer Addendum, contractual guarantees under LGPD Art. 33(II), and, where applicable, the necessity of the transfer for performance of our contract with you (GDPR Art. 49(1)(b) / LGPD Art. 33(VI)). Copies of the safeguards are available from the DPO on request.
7. Your rights
Under GDPR / UK GDPR you have the right to: access; rectification; erasure; restriction of processing; data portability; objection (including to processing based on legitimate interest); withdrawal of consent; and not to be subject to solely automated decisions with legal or similarly significant effects.
Under the LGPD (Art. 18) you additionally have the right to: confirmation of processing; anonymisation or blocking of unnecessary or excessive data; information about data sharing; information about the consequences of refusing consent; and review of automated decisions.
Under the CCPA/CPRA, California residents have the right to know, delete, correct, and to opt out of the "sale" or "sharing" of personal information, and to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined. We do not discriminate against users who exercise their rights. You may use an authorised agent.
How to exercise: write to [DPO EMAIL] or use the options in your account settings. We respond within 30 days (GDPR/CCPA) or 15 days (LGPD). We may ask you to verify your identity. There is no charge for a reasonable request.
Complaints. You may complain to your local supervisory authority: the ICO (United Kingdom), your national data protection authority (EEA), or the ANPD (Brazil). We would appreciate the chance to address your concern first.
8. Retention
| Category | Period |
|---|---|
| Account and registration data | For as long as the account exists |
| Saved itineraries | For as long as the account exists, or until you delete them |
| Planning data sent to AI providers | Retained by us while the itinerary exists; retention by the AI provider is governed by its own policy |
| Billing and tax records | 5 years after the transaction (legal obligation) |
| Application access logs | 6 months (Brazilian Internet Civil Framework, Art. 15) |
| Error and security logs | [X] months |
| Marketing data | Until consent is withdrawn |
On account closure we delete or anonymise data within the periods above, except where retention is necessary to comply with a legal obligation or to establish, exercise or defend legal claims.
9. Cookies
We use:
- Strictly necessary: session, authentication, security, language and currency preference. No consent required.
- Analytics: [DESCRIBE OR REMOVE IF UNUSED]. Consent required in the EEA/UK.
- Advertising: none.
You can manage cookies in your browser and via our consent banner where applicable. Blocking necessary cookies will prevent sign-in.
10. Security
We apply appropriate technical and organisational measures, including encryption in transit (TLS), role-based access control, server-side token verification, credential segregation, least-privilege access and access logging.
No system is completely secure. In the event of a personal data breach likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours where required (GDPR Art. 33) and notify you without undue delay where the risk is high (GDPR Art. 34 / LGPD Art. 48).
11. Children
The Platform is not intended for anyone under 18 and we do not knowingly collect their data. When describing your travel group you may indicate the number and age range of children — used only to tailor suggestions, and not identifying any child. Do not enter a minor's name, document number or photograph. If we learn that we have collected such data, we will delete it.
12. Changes to this Policy
We may update this Policy. Material changes will be notified by email and/or in-Platform notice 30 days in advance. The last updated date appears at the top.
13. Contact
Data Protection Officer: [NAME] — [DPO EMAIL] Support: [SUPPORT EMAIL] Address: [LEGAL ENTITY NAME], CNPJ [CNPJ], [FULL ADDRESS], Brazil