This policy explains what personal data Wanderplanner ("we", "us", "our") collects when you create an account, why we collect it, and the rights you have over it — in line with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and generally accepted global privacy practices.
1. What we collect
- Account data: email address, a securely hashed password (we never store your password in plain text), and, if you use Google Sign-In, your Google name/profile info.
- Trip data: destinations, dates, budget, group details, and preferences you share with Anya to generate itineraries.
- Usage data: basic session and interaction events (e.g. sign-up, login, itinerary generation) used to operate and improve the service.
2. Why we collect it
We process your personal data only for specific, informed purposes:
- To create and secure your account and let you log back in across sessions.
- To personalize the itineraries, tips, and recommendations Anya generates for you.
- To send you service-related communications (e.g. password reset emails) — never marketing emails without separate opt-in.
- To monitor and improve service reliability and quality (aggregated, where possible anonymized, analytics).
3. Who we share it with
We share the minimum data necessary with the following processors, solely to provide the service:
- Google Gemini — to generate itineraries and travel tips from your trip inputs.
- Google OAuth — only if you choose "Continue with Google," to verify your identity.
- Pexels — to fetch royalty-free destination photos (no personal data sent).
- Resend — to deliver password-reset emails.
We do not sell your personal data to any third party.
4. How long we keep it
We retain your account data for as long as your account is active. If you delete your account, your personal data (email, password hash, name, Google identifier) is permanently deleted immediately. Aggregated usage events are retained in anonymized form (with no link back to you) for service analytics.
5. Your rights
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate account information.
- Erase your account and personal data at any time, instantly, from your account settings — or by writing to us.
- Withdraw consent at any time, which will result in your account being deactivated/deleted, since an account is required to use the service.
6. Security
Passwords are hashed with Argon2id and never stored or logged in plain text. Sessions use short-lived, httpOnly, secure cookies. Data is encrypted in transit (TLS) and at rest via our database provider.
7. Grievance & contact
For any privacy questions, data access/deletion requests, or grievances regarding how your personal data is processed, please contact our Grievance Officer at privacy@wanderplanner.app. We aim to respond within 30 days, in line with the DPDP Act's grievance redressal requirements.