Privacy Policy

This Privacy Policy explains how Yanvara Pty Ltd (ACN 698 370 535) collects, uses and protects your information when you use the Yanvara website and travel planning service. Last updated: May 2026.

1. Who we are

Yanvara is operated by Yanvara Pty Ltd (ACN 698 370 535), an Australian company. We are the data controller for personal information collected through the Yanvara website and platform. You can contact us at [email protected] for privacy questions or to exercise your data rights.

2. Information we collect

When you create an account we collect your name, email address, password (stored hashed, never in plain text) and optional profile photo. If you sign in with Google, we receive your name, email address and profile picture from Google — we do not receive your Google password or access any other Google account data. When you use the trip planner we collect your trip prompts, guided setup inputs, generated itineraries, AI chat history, saved planning preferences and packing preferences. We also collect billing information processed by Stripe (we do not store card details ourselves), collaboration invitations and basic technical usage data such as IP address and browser type.

3. How we use your information

We use your information to provide the service: generate AI itineraries, run trip refinement chats, deliver email exports, process subscription billing, apply promo codes and referral rewards, provide customer support, secure your account, and send essential service communications. Information received from Google sign-in (name, email, profile picture) is used solely to create and identify your Yanvara account — it is not used for advertising or shared with third parties beyond what is described in this policy. We also use aggregated, de-identified data to improve our AI models and product features.

4. Legal basis (GDPR)

Where the EU GDPR applies, we process your data on the following legal bases: performance of our contract with you (to provide the service), our legitimate interests (to improve the platform and prevent abuse), your consent (for marketing emails, which you can withdraw anytime), and compliance with legal obligations.

5. Sharing with third parties

We do not sell your personal data. We share data only with service providers needed to run the platform: Google (sign-in authentication via OAuth 2.0, and Google/Firebase Analytics — governed by Google's Privacy Policy), Stripe (subscription billing), our transactional email provider, AI providers (OpenAI for trip generation and chat refinement), our analytics and error-monitoring tools (PostHog and Sentry) and our hosting infrastructure (Amazon Web Services). In our mobile apps we also share app-event data and, where enabled, a device advertising identifier with Meta Platforms (Facebook) to measure advertising performance and attribute app installs and conversions. All providers are contractually required to keep your data confidential and use it only to deliver their service to us.

6. Public sharing

View-only trip share links and any trips you add to the public explore feed can be opened by anyone with the URL. These may display the trip title, destination, itinerary outline and preview image, but never your email, billing details, account preferences or AI chat history. You can remove a public share or delete a trip at any time.

7. Cookies and tracking

Yanvara uses essential cookies to keep you signed in, remember your preferences and prevent abuse. We use Google Tag Manager and PostHog for product analytics (page views, feature usage), and we do not use cross-site advertising cookies on our website. In our mobile apps we use a device advertising identifier (the Google Advertising ID on Android; on iOS the identifier for advertisers, and only if you allow tracking when prompted) together with the Meta and Google analytics SDKs to measure advertising performance and app conversions. You can reset or delete this identifier, or opt out of ad personalisation, in your device settings at any time. Where consent is required by law — including for users in the EEA and the UK — we do not use the advertising identifier for advertising without your consent. You can clear cookies in your browser at any time without affecting your saved data.

8. Data security

We protect your data with encrypted sessions (TLS), hashed passwords, signed and short-lived verification links, rate limiting on sensitive endpoints, login activity logging and optional two-factor authentication (TOTP). User-uploaded files (profile photos, trip documents) are stored on Amazon S3 with access restricted to your account.

9. Your rights

You can update your account details, change your password, upload or remove your profile photo, enable or disable two-factor authentication, unsubscribe from marketing, manage saved trips, request a full export of your data as JSON, and request account deletion. If you signed in with Google, you can disconnect your Google account from the Security section of your account settings at any time. Under GDPR and the Australian Privacy Act, you also have the right to access, correct, restrict and object to processing of your personal data — contact [email protected] to exercise these rights.

10. Account deletion

Account deletion runs on a 30-day grace period. When you request deletion your account is disabled immediately, but data is only permanently purged 30 days later. This gives you time to recover if you change your mind. To cancel a pending deletion contact [email protected] before the 30-day window closes.

11. Data retention

We keep your account data for as long as your account is active. Deleted accounts are purged 30 days after the deletion request. Anonymous usage logs may be retained longer for security and abuse prevention. Stripe retains billing records for tax compliance regardless of account deletion.

12. International transfers

Your data may be transferred to and processed in countries outside your home country (including the United States) by our service providers. We use providers with industry-standard security commitments and, where required, data transfer mechanisms approved under GDPR.

13. Children

Yanvara is not directed to children under 16. We do not knowingly collect personal information from children under 16. If we become aware that we have, we will delete it. Parents who believe their child has signed up should contact [email protected].

14. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified by email or in-app notice. Continued use of Yanvara after a change constitutes acceptance of the updated policy. The "Last updated" date at the top of this page reflects the current version.

15. Contact us

For privacy questions, data requests, or complaints, email [email protected]. You also have the right to lodge a complaint with your local data protection authority — in Australia, the Office of the Australian Information Commissioner (OAIC).