Legal

Privacy Policy

Version 1.0 · Last updated 6 May 2026

The short version. We collect the data you give us when you sign up, plan trips, and book travel; we use it to deliver the service and (with your permission) to send marketing email. We don't sell your data. We don't share it with advertising networks. You can download or delete your data at any time from Account → Privacy. For anything else, our postal contact is in Section 14.

1. Who we are

GoGlobe is a travel-planning service operated by GoGlobe Limited (“GoGlobe”, “we”, “us”), a private company limited by shares incorporated in Ireland under company number 785708, with principal place of business at 46 The Flagsman, Marshall Yards, Dublin 3, D03 H2Y3, Ireland.

For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the UK GDPR, and any other applicable data-protection law, we act as the data controller for the personal data described in this Policy. Our contact details for data-protection matters are set out in Section 14.

At our current scale of operation we are not required under Article 37 GDPR to formally appoint a Data Protection Officer. Our principal contact for data-protection matters — including data-subject requests, breach reports, and queries from supervisory authorities — is reachable via the postal address in Section 14 and undertakes to respond within the statutory deadlines.

2. The personal data we collect

2.1 Data you give us directly

2.2 Data we collect automatically

2.3 Data we receive from third parties

3. Why we use your data, and the legal basis for it

We rely on the following legal bases under Article 6 GDPR. Each row below describes a category of processing and the legal basis on which we rely.

PurposeLegal basis
Creating and operating your account, authenticating you, delivering the core trip-planning, search, AI, photo, and messaging features.Performance of a contract (Art. 6(1)(b))
Processing your bookings and payments, delivering tickets, communicating with airlines and hotels on your behalf, handling refunds and changes.Performance of a contract (Art. 6(1)(b))
Sending operational emails (booking confirmations, password resets, security alerts, billing notifications, policy changes).Performance of a contract / legitimate interest (Art. 6(1)(b)/(f))
Detecting and preventing fraud, abuse, account takeover, scraping, and other security threats; rate-limiting; logging suspicious activity.Legitimate interest (Art. 6(1)(f)) — protecting our service, our users, and our partners
Complying with accounting, tax, anti-money-laundering, and travel-industry obligations; responding to lawful requests from authorities.Legal obligation (Art. 6(1)(c))
Anonymous product analytics: which features people use, conversion funnels, performance metrics.Consent (Art. 6(1)(a)) — opt-in only
Marketing emails about new features, travel offers, and product updates.Consent (Art. 6(1)(a)) — opt-in only, withdraw any time
Improving our AI and machine-learning models in an aggregated, de-identified form. We do not train on your private content without your explicit consent.Legitimate interest (Art. 6(1)(f)) for aggregated/anonymous use; consent for any training that uses identifiable content

4. AI features and automated decision-making

GoGlobe uses several AI services to power our product:

None of these systems make legally significant or similarly significant automated decisions about you within the meaning of Article 22 GDPR. Where moderation blocks an upload, you can request human review through your account’s in-app help, or in writing at the postal address in Section 14.

We do not use your private content (chats, messages, uploaded photos, voice recordings, or trip data) to train third-party machine-learning models. We may use aggregated, de-identified usage signals (e.g., “how many users opened the trip planner this week”) to evaluate and improve our own product. Where we engage a third-party AI provider for a specific feature, your prompts are processed under that provider's standard terms which prohibit training on customer inputs.

5. Who we share your data with

We share personal data only as needed to operate the service, comply with the law, or protect our rights. The categories of recipient are:

We treat the named identity of our service providers as commercially confidential. Active business customers (merchants using our API) may obtain the up-to-date named list and the relevant Data Processing Agreements upon written request to the postal address in Section 14, subject to a reasonable confidentiality undertaking.

We do not sell, rent, lease, license, trade, or otherwise commercially disclose your personal data to any third party for that party's own commercial purposes. We do not share your personal data with advertising networks, data brokers, or any “ad-tech” intermediary. We do not engage in cross-context behavioural advertising. This commitment applies regardless of whether such sharing would be lawful in any specific jurisdiction.

6. International transfers

Most of our infrastructure is operated inside the European Economic Area. Some service providers may route or store data via the United States or other third countries; for example, our edge security and CDN provider operates an Anycast network with global points of presence. Where transfers outside the EEA / UK take place, we rely on:

You can request a copy of the safeguards we rely on for any specific transfer in writing at the postal address in Section 14.

7. How long we keep your data

CategoryRetention
Active account data (profile, settings, preferences, friends, photos, chats, saved trips)For as long as your account is open. On deletion, anonymised in place: identifying fields are replaced with placeholders, and aggregate trip statistics are kept with no link back to you.
Booking records (payments, invoices, tickets, hotel reservations)Retained for 7 years after the booking date to satisfy accounting, tax, and travel-industry obligations, even after you delete your account. After deletion, identifying fields are anonymised; the financial record itself is retained.
Security and abuse logs90 days, then automatically deleted.
Daily-active-user pingsHashed at write-time using a one-way function; the originals are not retained.
Marketing-consent recordsFor the duration of the consent plus 3 years after it lapses (so we can demonstrate the consent existed).
Service-provider logs (e.g. CDN and infrastructure access logs)Per the relevant provider's policy, typically 30-90 days.

8. Your rights

If the EU GDPR or UK GDPR applies to you, you have the rights below. We will respond within one calendar month of receiving a verifiable request, extendable by two further months for complex or numerous requests (we'll tell you if that happens).

9. Cookies and similar technologies

We use a small number of cookies and equivalent local-storage entries:

Our security infrastructure provider may set a bot-detection cookie (__cf_bm) to distinguish humans from automated traffic; this is a strictly-necessary security cookie.

You can change your cookie choices any time at Account → Privacy, or by clearing the goglobe_cookie_consent_v1 entry from your browser's local storage to be re-prompted.

10. Children

GoGlobe is not directed at, marketed to, or intended for children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you are a parent or guardian and believe a child has provided us with personal data, contact us at the postal address in Section 14 and we will delete it promptly.

11. Data breaches

If a personal-data breach occurs and is likely to result in a risk to your rights and freedoms, we will:

Notification will include the nature of the breach, the categories and approximate number of records concerned, the likely consequences, and the steps taken or proposed to address it.

12. Security

We protect your data with measures appropriate to its sensitivity, including:

No security regime is perfect. If you discover a vulnerability, please report it responsibly in writing at the postal address in Section 14, marked “Security”.

13. Changes to this policy

We may update this Privacy Policy. Material changes will be announced in-product, and where you have an account we will email you. The cookie banner will re-prompt for fresh consent when the underlying policy version changes; your previous consent will not silently carry over to a materially different policy.

The current version is shown at the top of this page. Earlier versions are available on request.

14. Contact

Most rights described in this Policy can be exercised directly from your account settings under Account → Privacy — you do not need to contact us at all. For anything that cannot be self-served, or for complaints about how we handle your data, write to us at:

GoGlobe Limited
46 The Flagsman
Marshall Yards
Dublin 3, D03 H2Y3
Ireland

We treat written requests as we would email requests — we will respond within the statutory one-month deadline (extendable by two further months for complex requests).