Legal
Privacy Policy
GEOVEA, INC., a Delaware corporation
Effective: 1 September 2026
Last updated: 1 September 2026
Terms and Conditions·Cookies Policy·Copyright Take-Down Notice
In short
This summary is for convenience only and is not part of the policy.
- We collect what we need to run a trip planning tool: your account details, the trips you build, what you ask our AI tools, and standard technical information about your visit.
- We do not sell your personal information, and we do not share it for targeted advertising.
- We do not train AI models on your trips or your prompts, and neither do our AI providers. We may use aggregated, de-identified information to improve the Services.
- Stripe handles payment. We never see or store your full card number.
- We are a planning tool, not a booking service. When you follow an affiliate link to a hotel or supplier, you are on their site under their privacy policy.
- Your trips are yours. Delete your account at any time and we delete your content after a 30 day grace period.
- Travel professionals: End Client information you enter belongs to you. You are the controller of it, we are your processor.
1. About This Policy
1.1 This policy explains what personal information GEOVEA, INC., a Delaware corporation ("Geovea," "we," "us"), collects, why we collect it, who we give it to, and what you can do about it. Our business address is 4950 E 177th Dr, Thornton, CO 80233, United States, and you can reach us at [email protected].
1.2 It covers the geovea.com website and our subdomains and blog, the Geovea trip planning platform, our AI travel tools, The Daily Feed and Daily Inspiration, our Weekly Travel Ideas and Inspiration newsletter, and all consumer, travel professional, agency, enterprise, and white label plans (the "Services").
1.3 It does not cover anyone else's site. Hotels, suppliers, affiliates, and other sites we link to have their own policies, and we are not responsible for them.
1.4 This policy forms part of our Terms and Conditions. Terms defined there, including Business User, Consumer User, End Client, User Content, and Output, have the same meaning here.
1.5 The Services are aimed primarily at users in the United States. We also serve users in Canada, the European Economic Area, and the United Kingdom, and Sections 11 and 12 set out the additional rights that apply there.
2. Information We Collect
2.1 Information you give us.
- Account. Your name, email address, and password. If you sign in with a social account instead, we receive your name, email address, and that account's identifier from the provider rather than a password, and we never receive your password for it. Sign in with Google is available today. We have offered Facebook sign-in in the past and may offer it again.
- Profile and preferences. Travel preferences, saved traveler profiles, units, home location, and anything else you choose to add to your profile.
- Business details. For travel professional, agency, and enterprise plans: company name, role, seats, and the branding assets you upload for white label use.
- Payment. Billing name, billing address, and country. We do not collect or store card information of any kind. Card details go directly to Stripe and never touch our systems.
- Trips and content. The trips, destinations, stops, routes, itineraries, roadbooks, proposals, notes, favorites, library entries, and uploads you create or store.
- AI prompts. What you type into our AI travel tools, including Discover That Dream Trip, Daily Itinerary Creator, Destination Research, and the Luxury Travel Search and Library.
- End Client information. If you are a Business User, whatever you enter about the travelers you serve. Section 8 explains how that is handled.
- Correspondence. Emails, support requests, survey responses, and anything you send us.
2.2 Information we collect automatically.
- Technical and usage data. IP address, browser and device type, operating system, screen resolution, referring page, pages viewed, features used, dates and times, and error logs.
- Approximate location. We can estimate your city or region from your IP address.
- Precise location, only if you allow it. Features like Explore Around Me ask your browser for your device location. Your browser will ask you first, you can say no, and you can withdraw the permission at any time in your browser settings. We use it to show you what is nearby and we do not build a location history from it.
- Cookies and similar technologies. Described in Section 6 and in our Cookies Policy.
2.3 Information from others.
- Google, and Meta (Facebook) where we offer Facebook sign-in, when you use one of those accounts to sign in.
- Stripe, which tells us whether a payment succeeded and the status of your subscription. We do not receive your card number.
- ActiveCampaign, which tells us whether a marketing email was delivered, opened, or clicked, so we can see what is worth sending and stop emailing people who are not reading.
- Affiliate networks and suppliers, which may tell us that a referral resulted in a booking, usually as a transaction identifier and a commission amount rather than as your name.
2.4 What we ask you not to give us. Do not enter payment card numbers, government identifiers, health information, or other sensitive categories into trips, prompts, notes, or library entries. Our Terms prohibit it. If you send it to us anyway, we will delete it when we find it.
3. How We Use Information
We use personal information to:
- create and run your account, and authenticate you;
- provide the Services, including building, saving, routing, mapping, sharing, and exporting your trips;
- generate Outputs from our AI travel tools when you ask for them;
- take payment, manage subscriptions, renewals, seats, and refunds, and prevent payment fraud;
- send you account, billing, security, and legal notices, which are not optional while you have an account;
- send you marketing email through ActiveCampaign, including the Weekly Travel Ideas and Inspiration newsletter and The Daily Feed, where you have signed up or where the law otherwise allows it, and always with an unsubscribe link;
- answer support requests;
- keep the Services secure, investigate abuse, enforce our Terms, and defend legal claims;
- understand how the Services are used, fix problems, and improve features; and
- comply with law, tax, and accounting obligations.
3.1 Improving the Services. We use aggregated and de-identified information about how the Services are used to make them better. Aggregated and de-identified means it no longer identifies you and we do not try to re-identify it.
3.2 What we do not do. We do not sell your personal information. We do not share it for cross-context behavioral advertising or targeted advertising. We do not run advertising pixels on our sites. We do not use your trips or prompts to build a profile of you for advertisers.
3.3 Legal bases (EEA and UK). Where the GDPR or UK GDPR applies, we rely on: contract, to give you the Services you signed up for and to bill you; legitimate interests, to secure the Services, prevent fraud and abuse, understand usage, improve features, and market to existing customers, balanced against your rights; consent, for precise location, for non-essential cookies, and for marketing email where consent is required, which you can withdraw at any time; and legal obligation, for tax, accounting, and lawful requests.
4. AI Features, Your Content, and Training
4.1 How the AI tools work. When you use an AI tool, your prompt and relevant context from your trip are sent to a third party AI provider, which returns an Output. Our AI providers are OpenAI and Anthropic, both in the United States, and we use their business and enterprise API services rather than their consumer chat products.
4.2 We do not train on your content. We do not use your trips, prompts, Outputs, uploads, or End Client information to train AI models. OpenAI and Anthropic are contractually barred from using content sent through our API accounts to train their models. This is the default position under their API terms and is not something we have to opt out of.
4.3 What we do use. We use aggregated and de-identified information about how the AI tools are used, such as which tools are used, how often, error rates, and response quality signals, to improve the Services. This does not identify you and is not fed back to any provider as training data.
4.4 Providers may retain briefly. OpenAI and Anthropic keep inputs and Outputs for a limited period for abuse and safety monitoring before deleting them, under their own API terms. They do not use them for training.
4.5 Outputs are not verified. Section 9 of the Terms explains this. An AI Output can be wrong, out of date, or invented. Verify anything that matters before you rely on it.
4.6 Do not paste confidential information into a prompt, and do not enter personal information about anyone else that you are not authorized to share.
5. Who We Share Information With
We share personal information only as described here. We do not sell it.
5.1 Service providers. These are the companies that help us run the Services, each under a contract limiting them to what we ask.
| Provider | What it does | Where |
|---|---|---|
| Amazon Web Services | Hosting, storage, backups | United States |
| Cloudflare, Inc. | Content delivery, DNS, TLS, and protection against bots and attacks. All traffic to our sites passes through it | United States |
| Stripe, Inc. | Payments, subscriptions, billing portal | United States |
| Mapbox, Inc. | Maps, routing, geocoding | United States |
| Microsoft Azure Maps | Geocoding and place lookup | United States |
| Google LLC | Google Analytics 4, Sign in with Google, reCAPTCHA | United States |
| Meta Platforms, Inc. | Facebook sign-in, where we offer it | United States |
| Automattic, Inc. | Jetpack Stats on our WordPress blog | United States |
| OpenAI, L.L.C. | Generating Outputs from your prompts | United States |
| Anthropic PBC | Generating Outputs from your prompts | United States |
| Twilio SendGrid | Sending account, billing, and security email | United States |
| ActiveCampaign, LLC | Sending and managing our marketing email and subscriber lists | United States |
5.2 People you choose. When you create a share link or a live trip link, anyone with the link can see what you put in it. Those links are not password protected. When you send a proposal or itinerary to a client, you are the one sending it.
5.3 Business accounts. On agency and enterprise plans, administrators can see and manage content created under the account, including content you created. Section 7.6 of the Terms covers this.
5.4 Legal and safety. We disclose information where we reasonably believe the law requires it, in response to valid legal process, to enforce our Terms, or to protect the rights, safety, or property of anyone.
5.5 Business transfers. If we are involved in a merger, financing, acquisition, or sale of assets, personal information may transfer as part of it. We will tell you if it happens and if the handling of your information would materially change.
5.6 With your permission. Anything else, only if you ask us to.
6. Cookies, Analytics, and Do Not Track
6.1 We use cookies and similar technologies to keep you signed in, remember your settings, keep the Services secure, and understand how they are used. Our Cookies Policy lists them and explains how to control them.
6.2 Analytics. We use Google Analytics 4 on geovea.com and Jetpack Stats on our blog to see how many people visit, which pages and features they use, and where things break. We have turned off Google Signals and advertising personalization in Google Analytics, so this data is not used to build advertising audiences or to target you elsewhere.
6.3 No advertising trackers. We do not run Meta, LinkedIn, TikTok, or other advertising pixels on our sites.
6.4 Global Privacy Control. We honor the Global Privacy Control signal where the law requires it. Since we do not sell or share personal information for advertising, there is nothing for it to switch off, but we will keep honoring it.
7. Affiliate Links
Some links to hotels, accommodation, services, activities, and tours are affiliate links, and we may receive a commission if you book through one. Following one may set a cookie or pass a tracking parameter so the supplier can attribute the referral. That tracking belongs to the supplier or its affiliate network, not to us, and once you leave our site you are on theirs under their privacy policy. A commission never affects what we show you or how it is ranked. Section 3.3 of the Terms sets out the full rule and our Cookies Policy explains the tracking.
8. Business Users and End Client Information
8.1 If you are a travel advisor, agency, tour operator, car club, or corporate travel team using the Services for your business, then for the personal information you enter about your End Clients you are the controller and we are your processor. In United States terms, you are the business and we are a service provider.
8.2 That means you decide what to collect and why, you are responsible for having a lawful basis and for giving your clients the notices and choices the law requires, and you should enter no more than you need.
8.3 We process End Client information only to provide the Services to you, on your instructions, and we do not use it for our own purposes.
8.4 When your account or plan ends, retrieve End Client information before the grace period in Section 9 expires.
9. How Long We Keep Information
- Account and profile: while your account is open.
- Trips and User Content: while your account is open. After you delete your account, or after a paid term ends without renewal, we keep it for a 30 day grace period so you can reactivate or request an export, then delete it. This matches Section 10.4 of the Terms.
- Billing and tax records: as long as tax and accounting law requires, generally seven years. Stripe keeps its own records under its own policy.
- Support correspondence: up to three years.
- Marketing lists: until you unsubscribe, plus a suppression record so we do not email you again by mistake.
- Security and server logs: generally up to 12 months.
- Backups: deleted content can persist in encrypted backups for a limited period before those backups roll over.
- Aggregated and de-identified data: indefinitely, because it no longer identifies anyone.
We may keep information longer where we need it for a legal claim, an investigation, or a legal obligation.
10. Security
We use encryption in transit, access controls, least privilege access for our own team, hosting on Amazon Web Services, and Cloudflare in front of our sites for TLS and protection against bots and attacks. Payment card data goes directly to Stripe, a PCI DSS Level 1 provider, so we never hold it.
No system is perfectly secure, and we cannot guarantee absolute security. Use a strong unique password, do not share credentials, and email [email protected] immediately if you think your account has been accessed without permission. Remember that share links and live trip links work for anyone holding the link.
11. Your Rights and Choices
11.1 Everyone.
- Access and correct. View and edit your profile, trips, and content in the Services at any time.
- Delete. Delete your account at geovea.com/delete_account or by emailing us. Section 9 explains what happens next.
- Export. Export itineraries as PDF while your plan is active, or email us for a copy of your account data.
- Marketing. Unsubscribe from any marketing email using the link in it, or email us. You will still receive account, billing, and security messages.
- Location. Turn off the browser location permission at any time.
- Cookies. See the Cookies Policy.
11.2 United States state privacy rights. If you live in California, Colorado, Connecticut, Virginia, Texas, Oregon, or another state with a comprehensive privacy law, you have the right to know what we collect and why, to get a copy, to correct it, to delete it, and to not be discriminated against for exercising those rights. Sections 2, 3, 5, and 9 together are our notice at collection: they list the categories of personal information we collect, why we collect each one, who receives it, and how long we keep it.
- We do not sell personal information and we do not share it for cross-context behavioral advertising, including of anyone under 16. There is no "Do Not Sell or Share My Personal Information" link because there is nothing to opt out of.
- The only sensitive personal information we handle is precise geolocation, and only when you grant the browser permission, only to show you what is nearby, and only for as long as that feature is on your screen. Because we use it solely to deliver the feature you asked for, no right to limit its use arises. We do not infer characteristics from it.
- We do not profile you in ways that produce legal or similarly significant effects.
- Californians may designate an authorized agent to make a request. We will verify the agent and the request.
- To exercise any right, email [email protected]. We verify requests against your account email. We respond within 45 days and may extend once where the law allows. If we refuse, you may appeal by replying to our response, and we will answer the appeal within the period your state's law sets.
11.3 Canada. Under PIPEDA and provincial law, including Quebec's Law 25, you may access and correct your personal information, withdraw consent (which may mean we can no longer provide the Services), and complain to the Office of the Privacy Commissioner of Canada or your provincial regulator. We do not use automated decision making that produces a decision about you.
11.4 EEA and UK. Under the GDPR and UK GDPR you have the right to access, rectification, erasure, restriction, portability, and objection, including to processing based on legitimate interests and to direct marketing at any time. Where we rely on consent you may withdraw it, without affecting processing already carried out. You may complain to your supervisory authority or, in the UK, the Information Commissioner's Office.
We do not make decisions about you by automated means alone that produce legal or similarly significant effects. AI Outputs are travel suggestions, not decisions about you.
We have not appointed an Article 27 representative because our EEA and UK activity is limited and occasional. Contact us at [email protected] and we will handle your request directly.
11.5 No charge. We do not charge for these requests unless they are manifestly unfounded or excessive, and we will tell you first if that ever applies.
12. International Transfers
We are based in the United States and our systems and providers are in the United States. If you use the Services from Canada, the EEA, the UK, or anywhere else, your personal information is transferred to and processed in the United States, which may not give the same protection as your home country.
For transfers out of the EEA and the UK we rely on the European Commission's Standard Contractual Clauses with the UK International Data Transfer Addendum where required, together with the safeguards our providers offer. Email [email protected] for details.
13. Children
The Services are for adults. You must be 18 or older to open an account, and we do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, email [email protected] and we will delete it. Parents planning family travel may of course include children in a trip, but do not enter more about a child than the trip needs.
14. Changes to This Policy
We may update this policy. For a material change we will give at least 30 days notice by email or in product before it takes effect. We keep the "Last Updated" date current, and continuing to use the Services after the effective date means you accept the update.
15. Contact Us
Questions, requests, or complaints about privacy:
Email: [email protected]
Post: GEOVEA, INC., 4950 E 177th Dr, Thornton, CO 80233, United States
We answer privacy requests within 45 days, and sooner where the law requires it.
Terms and Conditions·Cookies Policy·Copyright Take-Down Notice
GEOVEA, INC. · Last updated 1 September 2026