Privacy Policy
Last updated: Aug 28, 2025
Who we are (Data Controller)
Controller: CARON Cynthia — Entrepreneur Individuel (EI), operating under the trade name My Travel Buddy.
Address: 37 Rue Seignemartin, 69008 Lyon, France
Email: hello@my-travel-buddy.com
We have not appointed a Data Protection Officer.
Personal data we collect
- Account data: name, email, authentication identifiers.
- Product data: content you create or upload in the app.
- Usage data: app events, device/browser info, IP-based approximate location, timestamps.
- Support: messages you send us (email/Discord) and related metadata.
- Diagnostics: error and performance data (e.g., Sentry).
- Cookies/Similar: session/auth cookies and, if enabled, analytics cookies (see “Cookies”).
Sources: data you provide; automatic collection from your device; third-party authentication/infrastructure providers.
Purposes & legal bases (GDPR)
- Provide and operate the service (account, features, security, availability) — Performance of a contract (Art. 6(1)(b)).
- Customer support, bug fixing, quality (incl. error reporting) — Legitimate interest (Art. 6(1)(f)).
- Analytics to improve product — Consent (Art. 6(1)(a)) when non-essential cookies are used.
- Compliance & enforcement (fraud/abuse, legal obligations) — Legal obligation (Art. 6(1)(c)) and/or Legitimate interest (Art. 6(1)(f)).
- Service communications (important updates, security) — Legitimate interest / contract.
Sharing & processors
We use vetted processors under data-processing agreements. We do not sell personal data.
- Vercel, Inc. (EU/US) — Hosting/CDN/logs (SCCs/DPF where applicable).
- Sentry (Functional Software, Inc.) (EU/US) — Error & performance monitoring (pseudonymized where possible).
- Clerk (EU/US) — Authentication & session management.
- Discord (US/EU) — Optional community space; data shared only if you choose to join.
International data transfers
When data is transferred outside the EEA/UK (e.g., to the US), we rely on appropriate safeguards such as the EU-US Data Privacy Framework and/or Standard Contractual Clauses, with supplementary measures as needed.
Data retention
We keep personal data only as long as necessary for the purposes above and to comply with legal obligations. You can request deletion; we will erase or anonymize the data unless we must retain it by law.
- Account data: while the account is active, then deleted/anonymized within 30 days.
- Security logs: up to 12 months.
- Error diagnostics (Sentry): up to 90 days.
- Support emails/tickets: up to 24 months after closure.
- Analytics (with consent): up to 25 months.
Your rights
- Access, rectification, deletion, restriction, portability, and objection (where applicable).
- Withdraw consent at any time for processing based on consent (without affecting prior lawful processing).
- Lodge a complaint with your supervisory authority. In France: CNIL.
To exercise rights, email hello@my-travel-buddy.com. We respond within 1 month (extendable by 2 months for complex requests). We may request information to verify your identity.
Cookies & similar technologies
We currently use only essential cookies required for authentication and security. No analytics or advertising cookies are set without your consent. If we later introduce non-essential cookies, we will request your consent via a banner and update this page.
Security
We apply appropriate technical and organizational measures (encryption in transit, access controls, least privilege, monitoring). No method of transmission or storage is 100% secure, but we continuously improve our safeguards.
Children
Our service is not intended for children under 15 in France (ages may vary between 13–16 depending on jurisdiction). We do not knowingly collect data from children. If you believe a child provided data, please contact us to delete it.
Changes to this policy
We may update this policy from time to time. We will post changes here and adjust the “Last updated” date. For material changes, we may notify you within the product or by email.
Contact
Privacy questions? Email hello@my-travel-buddy.com.