Privacy Notice
Last updated: July 21, 2026
Who we are
goando is operated by Mark Creighton, an individual sole proprietor based in the United States ("goando", "we", "us"). We are the data controller for personal data collected through the Service. You can reach us at briemark@gmail.com.
What we collect and why
We collect only what we need to run goando:
- Account data — name, email address, password hash, and (optionally) profile photo. Purpose: to create and secure your account. Legal basis: performance of contract.
- Trip content — destinations, dates, transport, lodging, activities, notes, quotes, costs, and files you upload. Purpose: to provide the core planning features. Legal basis: performance of contract.
- Collaboration data — trip shares, invitation tokens, and the email addresses you share trips with. Purpose: to enable co-planning. Legal basis: performance of contract.
- Usage and device data — log data such as IP address, browser type, pages viewed, and timestamps. Purpose: security, fraud prevention, and product improvement. Legal basis: legitimate interests.
- Support messages and feedback — anything you send us via feedback forms or email. Purpose: to respond to you and improve the product. Legal basis: legitimate interests.
- AI prompts and outputs — the trip context sent to our AI provider when you use "Draft with AI" or day tips. Purpose: to generate the requested suggestions. Legal basis: performance of contract.
We do not collect payment card details. All payment information is handled directly by Paddle (see below).
How we share your data
We share personal data only with the following categories of recipients:
- Paddle.com Market Ltd. — our Merchant of Record, which processes payments, subscription billing, sales tax, invoicing, and refunds. Paddle receives your name, email, billing address, and payment details when you make a purchase. See Paddle's Privacy Policy.
- Supabase Inc. — our database, authentication, and file-storage provider. Hosts account and trip data.
- Cloudflare Inc. — hosting and content-delivery provider for the goando web application.
- OpenAI, L.L.C. — AI provider used to generate itinerary drafts and day tips. Only the trip context you explicitly send to AI features is transmitted.
- Trip collaborators — people you explicitly share a trip with, at the access level you choose.
- Professional advisors and authorities — legal, accounting, or law-enforcement recipients where required by law.
We do not sell your personal data, and we do not use it for advertising profiling.
Cookies and analytics
goando uses only essential cookies required for authentication and to remember your session. We do not use third-party advertising or cross-site tracking cookies. Some third-party sites we link to (for example, affiliate travel partners) will set their own cookies once you visit them — that is governed by their policies.
Data retention
We retain account and trip data for as long as your account is active. When you delete your account or a specific trip, we remove the content from our production database within 30 days. Backup copies are purged on our backup rotation (up to 30 additional days). We may retain limited records longer where required by law (for example, tax and payment records held by Paddle for accounting).
Security
We apply appropriate technical and organisational measures to protect your data, including encryption in transit (HTTPS), encryption at rest for our database and file storage, hashed passwords, role-based access controls, and row-level security so that only you and people you explicitly share a trip with can access your trips.
International transfers
goando is operated from the United States, and our providers (Supabase, Cloudflare, OpenAI, Paddle) may process data in the United States, the European Economic Area, and other regions. Where personal data is transferred out of the UK or EEA, our providers rely on appropriate safeguards such as the EU Standard Contractual Clauses and UK Addendum.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, port, or object to processing of your personal data, and to withdraw consent where processing is based on consent. Residents of the UK/EEA have these rights under the GDPR; California residents have equivalent rights under the CCPA/CPRA. To exercise any of these rights, email us at briemark@gmail.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data-protection authority.
Children
goando is not directed to children under 13 (or 16 in the EEA/UK). We do not knowingly collect data from children. If you believe a child has provided us with data, contact us and we will delete it.
Changes to this notice
We may update this Privacy Notice from time to time. Material changes will be communicated in-app or by email. The "Last updated" date at the top reflects the most recent revision.
Contact
Questions or requests: briemark@gmail.com.
