Privacy Policy
1. Who we are
GoGlobe is a travel-planning service operated by GoGlobe Limited (“GoGlobe”, “we”, “us”), a private company limited by shares incorporated in Ireland under company number 785708, with principal place of business at 46 The Flagsman, Marshall Yards, Dublin 3, D03 H2Y3, Ireland.
For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the UK GDPR, and any other applicable data-protection law, we act as the data controller for the personal data described in this Policy. Our contact details for data-protection matters are set out in Section 14.
At our current scale of operation we are not required under Article 37 GDPR to formally appoint a Data Protection Officer. Our principal contact for data-protection matters — including data-subject requests, breach reports, and queries from supervisory authorities — is reachable via the postal address in Section 14 and undertakes to respond within the statutory deadlines.
2. The personal data we collect
2.1 Data you give us directly
- Account details — your email address, chosen username, password (stored as a salted hash, never in plaintext), and any optional profile fields you fill in (display name, country, hometown, profile photo).
- Trip and travel data — the flights, hotels, places, photos, itineraries, and notes you save, search for, or book through the service.
- Booking and passenger data — when you place a real booking, the personal information airlines, hotels, and other travel suppliers require: passenger names, dates of birth, passport or ID numbers if a supplier requires them, contact details, and any special requests (e.g. dietary, accessibility).
- Payment information — when you pay for a booking or subscription, a regulated EU-licensed payment service provider collects and processes your card or wallet details directly. We receive a payment reference, the transaction outcome, and the last four digits of the card used. We never see, store, or have access to your full card number, expiry date, or CVV.
- Communications — messages you send through the in-app friend chat, AI assistant prompts, photo tags and captions, support requests, and any feedback you submit.
- Photos and uploaded media — images and short videos you upload to your profile, trip albums, or AI chat for analysis. EXIF metadata is stripped on upload; geolocation data is preserved only when you explicitly attach a place.
2.2 Data we collect automatically
- Technical and device data — IP address, user-agent string, device type, browser, operating system, language preference, screen resolution, and broad approximate location (country, derived from IP).
- Usage data — the pages you view, the features you use, search queries, click and tap patterns, the time and duration of your sessions, and (anonymously) the way you move through the product.
- Security and abuse-prevention logs — request logs, failed-login attempts, rate-limit triggers, suspected bot activity, and similar signals used to keep the service safe.
- Cookies and similar technologies — see Section 9.
2.3 Data we receive from third parties
- Travel suppliers and aggregators — booking confirmations, ticket changes, refund updates, and live status events from airlines, hotels, and the booking-aggregator partners we work with, when you have an active booking.
- Payment providers — transaction outcomes, fraud signals, and chargeback notifications from our payment service provider.
- Identity / sign-in providers — if you choose to sign in with a third-party identity (where supported), the basic profile information that provider exposes (email, name, avatar URL).
- Map and location services — geocoding, reverse geocoding, and routing results from third-party map-data providers, scoped to the search you initiated.
3. Why we use your data, and the legal basis for it
We rely on the following legal bases under Article 6 GDPR. Each row below describes a category of processing and the legal basis on which we rely.
| Purpose | Legal basis |
|---|---|
| Creating and operating your account, authenticating you, delivering the core trip-planning, search, AI, photo, and messaging features. | Performance of a contract (Art. 6(1)(b)) |
| Processing your bookings and payments, delivering tickets, communicating with airlines and hotels on your behalf, handling refunds and changes. | Performance of a contract (Art. 6(1)(b)) |
| Sending operational emails (booking confirmations, password resets, security alerts, billing notifications, policy changes). | Performance of a contract / legitimate interest (Art. 6(1)(b)/(f)) |
| Detecting and preventing fraud, abuse, account takeover, scraping, and other security threats; rate-limiting; logging suspicious activity. | Legitimate interest (Art. 6(1)(f)) — protecting our service, our users, and our partners |
| Complying with accounting, tax, anti-money-laundering, and travel-industry obligations; responding to lawful requests from authorities. | Legal obligation (Art. 6(1)(c)) |
| Anonymous product analytics: which features people use, conversion funnels, performance metrics. | Consent (Art. 6(1)(a)) — opt-in only |
| Marketing emails about new features, travel offers, and product updates. | Consent (Art. 6(1)(a)) — opt-in only, withdraw any time |
| Improving our AI and machine-learning models in an aggregated, de-identified form. We do not train on your private content without your explicit consent. | Legitimate interest (Art. 6(1)(f)) for aggregated/anonymous use; consent for any training that uses identifiable content |
4. AI features and automated decision-making
GoGlobe uses several AI services to power our product:
- Seol AI — our travel-planning chat and image/video analysis assistant. Prompts and uploaded media you send to Seol are processed to generate the response, then retained as part of your chat history so you can refer back to past conversations. They are not used to train third-party models.
- Eist Voice — speech-to-text transcription of voice notes you record. Audio is transcribed and the transcript is attached to your chat / itinerary; the original audio is discarded after transcription.
- Photo moderation — uploaded images are scanned for unlawful or unsafe content (sexual imagery involving minors, deepfakes, weapons-with-intent, etc.). Images that fail moderation are blocked and not stored.
None of these systems make legally significant or similarly significant automated decisions about you within the meaning of Article 22 GDPR. Where moderation blocks an upload, you can request human review through your account’s in-app help, or in writing at the postal address in Section 14.
We do not use your private content (chats, messages, uploaded photos, voice recordings, or trip data) to train third-party machine-learning models. We may use aggregated, de-identified usage signals (e.g., “how many users opened the trip planner this week”) to evaluate and improve our own product. Where we engage a third-party AI provider for a specific feature, your prompts are processed under that provider's standard terms which prohibit training on customer inputs.
5. Who we share your data with
We share personal data only as needed to operate the service, comply with the law, or protect our rights. The categories of recipient are:
- Service providers acting on our behalf (sub-processors) — we engage third parties under written contracts that meet GDPR Article 28 requirements to provide cloud and CDN infrastructure, security and DDoS protection, payment processing, email delivery, travel-content aggregation and booking, mapping data, and customer support tooling. They process personal data only on our documented instructions, with confidentiality and security controls appropriate to the data.
- Travel suppliers (independent controllers) — when you make a real booking, the airline, hotel, or other travel operator providing the service becomes an independent controller of the data needed to deliver that booking (passenger names, dates, contact details, special requests). They apply their own privacy policies to that booking.
- Authorities — tax authorities, law enforcement, courts, or regulators where we are legally compelled to disclose, or where disclosure is necessary to protect life or safety. We push back on overbroad or unlawful requests.
- Professional advisers — lawyers, auditors, and insurers under professional obligations of confidence.
- In a corporate transaction — if GoGlobe is involved in a merger, acquisition, asset sale, or financing, personal data may be transferred under appropriate confidentiality terms; you will be notified.
We treat the named identity of our service providers as commercially confidential. Active business customers (merchants using our API) may obtain the up-to-date named list and the relevant Data Processing Agreements upon written request to the postal address in Section 14, subject to a reasonable confidentiality undertaking.
We do not sell, rent, lease, license, trade, or otherwise commercially disclose your personal data to any third party for that party's own commercial purposes. We do not share your personal data with advertising networks, data brokers, or any “ad-tech” intermediary. We do not engage in cross-context behavioural advertising. This commitment applies regardless of whether such sharing would be lawful in any specific jurisdiction.
6. International transfers
Most of our infrastructure is operated inside the European Economic Area. Some service providers may route or store data via the United States or other third countries; for example, our edge security and CDN provider operates an Anycast network with global points of presence. Where transfers outside the EEA / UK take place, we rely on:
- The European Commission's Standard Contractual Clauses (Decision (EU) 2021/914);
- The UK Information Commissioner's International Data Transfer Addendum where the transfer involves UK personal data;
- Where applicable, the EU-US Data Privacy Framework certification of the recipient.
You can request a copy of the safeguards we rely on for any specific transfer in writing at the postal address in Section 14.
7. How long we keep your data
| Category | Retention |
|---|---|
| Active account data (profile, settings, preferences, friends, photos, chats, saved trips) | For as long as your account is open. On deletion, anonymised in place: identifying fields are replaced with placeholders, and aggregate trip statistics are kept with no link back to you. |
| Booking records (payments, invoices, tickets, hotel reservations) | Retained for 7 years after the booking date to satisfy accounting, tax, and travel-industry obligations, even after you delete your account. After deletion, identifying fields are anonymised; the financial record itself is retained. |
| Security and abuse logs | 90 days, then automatically deleted. |
| Daily-active-user pings | Hashed at write-time using a one-way function; the originals are not retained. |
| Marketing-consent records | For the duration of the consent plus 3 years after it lapses (so we can demonstrate the consent existed). |
| Service-provider logs (e.g. CDN and infrastructure access logs) | Per the relevant provider's policy, typically 30-90 days. |
8. Your rights
If the EU GDPR or UK GDPR applies to you, you have the rights below. We will respond within one calendar month of receiving a verifiable request, extendable by two further months for complex or numerous requests (we'll tell you if that happens).
- Right of access (Art. 15) — download a machine-readable copy of your data from Account → Privacy → Download my data.
- Right to rectification (Art. 16) — edit incorrect details directly in your account settings, or contact us for fields you can't edit yourself.
- Right to erasure (Art. 17) — delete your account from Account → Privacy → Delete account. As described above, booking records are anonymised but retained for 7 years for legal obligations.
- Right to restriction (Art. 18) — ask us to pause processing while a complaint or correction is investigated. Write to us at the postal address in Section 14.
- Right to data portability (Art. 20) — the export above is provided in a structured, machine-readable JSON format.
- Right to object (Art. 21) — opt out of marketing or analytics in Privacy settings. For processing based on legitimate interests, you can object on grounds relating to your particular situation.
- Right to withdraw consent — toggle off any consent in Account → Privacy. Withdrawal does not affect lawfulness of processing before withdrawal.
- Right to complain — you may complain to a supervisory authority. In the EU, your local Data Protection Authority. In the UK, the Information Commissioner's Office (ico.org.uk). Our lead supervisory authority is the Data Protection Commission (DPC) of Ireland (dataprotection.ie).
9. Cookies and similar technologies
We use a small number of cookies and equivalent local-storage entries:
- Strictly necessary — the session cookie that keeps you signed in, the CSRF token, and a per-browser cookie-consent token. These are required for the site to work and cannot be disabled.
- Analytics — if and only if you opt in, an anonymous analytics identifier so we can see which features people use. Off by default.
- Marketing — only used if you have asked to receive marketing email. Off by default.
Our security infrastructure provider may set a bot-detection cookie (__cf_bm) to distinguish humans from automated traffic; this is a strictly-necessary security cookie.
You can change your cookie choices any time at Account → Privacy, or by clearing the goglobe_cookie_consent_v1 entry from your browser's local storage to be re-prompted.
10. Children
GoGlobe is not directed at, marketed to, or intended for children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you are a parent or guardian and believe a child has provided us with personal data, contact us at the postal address in Section 14 and we will delete it promptly.
11. Data breaches
If a personal-data breach occurs and is likely to result in a risk to your rights and freedoms, we will:
- Notify the competent supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33 GDPR;
- Notify you, the affected data subject, without undue delay where the breach is likely to result in a high risk to your rights and freedoms (Article 34 GDPR);
- Document the breach internally, including its facts, effects, and the remedial action taken, so that the supervisory authority can verify our compliance.
Notification will include the nature of the breach, the categories and approximate number of records concerned, the likely consequences, and the steps taken or proposed to address it.
12. Security
We protect your data with measures appropriate to its sensitivity, including:
- HTTPS with TLS 1.2+ on all traffic; HSTS preload; modern cipher suites.
- Bcrypt password hashing; per-account login throttling and brute-force rate limits at the edge.
- Mandatory two-factor authentication (TOTP) for administrator access, with bcrypt-hashed recovery codes.
- Identity-aware proxy gating all administrator endpoints.
- Per-request Content Security Policy with nonces; X-Frame-Options DENY; cross-origin isolation; magic-byte validation on uploads.
- Idempotency and replay-protection on payment webhooks; webhook-signature verification on all inbound provider events.
- Role-based access controls inside the company; principle of least privilege for staff.
No security regime is perfect. If you discover a vulnerability, please report it responsibly in writing at the postal address in Section 14, marked “Security”.
13. Changes to this policy
We may update this Privacy Policy. Material changes will be announced in-product, and where you have an account we will email you. The cookie banner will re-prompt for fresh consent when the underlying policy version changes; your previous consent will not silently carry over to a materially different policy.
The current version is shown at the top of this page. Earlier versions are available on request.
14. Contact
Most rights described in this Policy can be exercised directly from your account settings under Account → Privacy — you do not need to contact us at all. For anything that cannot be self-served, or for complaints about how we handle your data, write to us at:
GoGlobe Limited
46 The Flagsman
Marshall Yards
Dublin 3, D03 H2Y3
Ireland
We treat written requests as we would email requests — we will respond within the statutory one-month deadline (extendable by two further months for complex requests).