Privacy Policy

Last updated: 2 August 2026

Who we are

JourneyComposer (“JourneyComposer”, “we”, “us”) operates the JourneyComposer trip-planning application. We are based in the EU/EEA and act as the data controller for the personal data described in this policy. If you have a question about this policy or your data, contact support@journeycomposer.com.

What we collect and why

We collect only what the service needs to work, plus what you choose to put into it.

  • Account data: name, email address, and password. Passwords are stored as a hash, never in plain text. Used to create and secure your account.
  • Date of birth: collected at sign-up so we can check you meet the minimum age for an account, which our Terms require. We keep the date rather than only a yes or no answer so the check stays correct as you get older, and so we can show it back to you.
  • Nationality: optional, and only if you choose to give it. We use it to show entry and visa information relevant to your trips. You can leave it blank, and doing so does not limit your account in any way.
  • Preferences: settings, theme, and default currency, used to display the app the way you’ve set it up.
  • Marketing email consent: whether you’ve opted in to receive occasional emails about new features and offers, chosen at sign-up and changeable anytime in your profile. This is separate from account emails (verification, password reset), which we always send regardless of this choice.
  • Agreement record: the date and time you accepted our Terms of Service and this Privacy Policy at sign-up, and which version of those documents was current at that moment. We record this so we can show that agreement was given, as data protection law requires.
  • Session and security data: session tokens, IP address, and browser, app, or device information (user agent), used to keep you signed in and to detect and investigate suspicious activity. A two-factor authentication secret and backup codes can also be stored.
  • Trip content: the places, roads, itineraries, notes, and coordinates you save. This is the core of the service.
  • Collaboration data: the email address of anyone you invite to a trip, and share-link tokens for anonymous view-only links you create.
  • Uploaded files: documents and photos you attach to a trip. Photos are resized if they are very large, and all embedded metadata is removed from the stored file. Before removing it we read two things and keep them with the photo: the date it was taken, and the location, if your camera recorded one. That location is shown to you and to anyone you share the trip with, and it is included when you download your data. Documents are stored exactly as you upload them.
  • Who added a photo: when you share a trip, everyone on it can see which member added each photo.
  • Expense data: amounts, currency, and who paid or owes what, if you use trip cost splitting. These are your own notes about money between travel companions. No money moves through JourneyComposer, and we never see card or bank details for them.
  • Billing data: if you subscribe to a paid plan, we keep your subscription status, which plan you are on, when the current period ends, and the card brand and last four digits so you can recognise the card on file. We never receive or store your full card number. The payment itself, your billing address, and your invoices are handled by our payment provider, described below.
  • Diagnostics: crash and runtime error reports from the web and native app, including source, page or screen path, app version, platform, and technical error details, used to fix bugs and keep the service reliable.
  • Support messages: anything you send us through in-app support.

Legal bases for processing

We rely on the following legal bases, depending on the data involved.

  • Performance of a contract: account data, trip content, collaboration, and support. All of this is needed to provide the service you signed up for. Accepting our Terms of Service when you create an account is what forms that contract, so the processing it covers rests on this basis rather than on consent.
  • Legitimate interest: session and security logs, audit logs, and rate-limit records. These are needed to keep the service secure and to prevent abuse, and we weigh this against your privacy.
  • Consent: used where we ask for it separately and you are free to decline without losing access to the service. Today that means opting in to marketing email, which you can withdraw at any time in your profile.
  • Legal obligation: we keep a record of when you accepted these documents, and which version you accepted, because data protection law requires us to be able to show that agreement was given. Your date of birth is kept on the same basis, so we can show that we checked the minimum age.
  • Performance of a contract, for billing: if you subscribe, the subscription data described above is needed to give you the plan you paid for and to renew or end it correctly. Tax records for the sale are kept by our payment provider, which is the seller of record, under its own legal obligations.

Sub-processors and third parties

We use a small number of external service providers to run the app. None of them see more than they need to do their job, and we do not sell your data to any of them.

  • A geocoding and routing provider: used for address search and driving directions. Called from our servers. Your search query is sent to this provider, but your account identity is not.
  • Public sight and points-of-interest data sources: used to show information and images about places, called from our servers.
  • Map tile providers: supply the map imagery you see. Map tiles are loaded directly by your browser or native app rather than through our servers, so these providers do receive your IP address whenever a map is shown. We do not control what happens with that request beyond the tile being served.
  • An email delivery provider: sends account emails such as verification and password reset messages, and would send any future marketing email you’ve opted in to.
  • A currency exchange rate provider: supplies exchange rates for expense splitting. No personal data is sent to this service.
  • Our hosting and database provider: runs the JourneyComposer application and the database behind it. Because everything described in this policy is stored and processed on that infrastructure, this provider is the one sub-processor with access to all of it. We use it under a data processing agreement and it does not use your data for its own purposes.
  • Cloud object storage: stores uploaded documents and photos.
  • Our payment provider: handles subscription checkout and billing, and is the merchant of record for the sale, meaning it is the seller for the transaction and issues your invoice. It collects your payment details and billing address directly, so those never pass through our servers, and it handles VAT and sales tax. Because it is the seller rather than merely acting on our instructions, it is an independent controller of that payment data under its own privacy policy, not only a processor for us. It tells us only what we need to give you access: your subscription status, plan, renewal date, and the card brand and last four digits.
  • An eSIM affiliate provider and its affiliate network: the optional eSIM panel shows mobile data plans for your destinations. Fetching plans sends only country codes and a currency choice, not your identity. On the web, if you click through to buy a plan, the affiliate network receives a pseudonymous click id derived from your account (not your raw account id or any profile data) so we can be credited for the referral. The native app uses generic affiliate links without an account-derived click id.
  • A flight-search affiliate widget and its affiliate network: a fly leg with both airports set shows a “Search flights” option. On the web, opening it loads an embedded flight-search widget. Unlike the other providers on this list, this one runs directly in your browser once you open it, not only when you book something: at that point it can see your IP address and set its own cookies, and it receives the two airport codes, an estimated travel date for that leg, and a pseudonymous click id. In the native app, the flight search opens an external Kiwi.com link with route/date prefill and generic affiliate attribution only.
  • A transport-ticket affiliate provider and its affiliate network: on the web, train, bus and ferry legs (and fly legs) show indicative Omio ticket prices. These prices come from our own servers, so this provider does not run in your browser and does not see you while you browse. Only if you click a “Book on Omio” link does the affiliate network receive a pseudonymous click id derived from your account (not your raw account id) so we can be credited for the referral. This feature is web only.

We do not use analytics or advertising services. The specific companies behind these categories are listed in our internal records and available on request to support@journeycomposer.com.

International transfers

Several of the providers listed above are based outside the EU/EEA, mainly in the United States. This includes our hosting and database provider, which means the data described in this policy is stored and processed in the United States, as well as our email delivery provider, our payment provider, and, depending on configuration, our object storage and map tile providers. Where personal data is transferred internationally, we rely on the safeguards GDPR requires, principally the European Commission’s standard contractual clauses, agreed with each provider.

How long we keep data

Trip content, uploaded files, and account data are kept for as long as your account exists. If you delete your account from Account settings, nearly all of your owned data (trips, places, routes, documents, photos, and expenses) is permanently deleted immediately.

One exception: when you have shared a trip with other people and logged expenses on it, those shared expense records (the amount, who paid, and the name you used) are kept after you delete your account. They are retained on the basis of our and the other travellers’ legitimate interest in an accurate, unaltered record of who owes whom, so deleting your account cannot silently change everyone else’s cost settlement. These records are only ever visible to the members of that specific shared trip.

Security audit logs are kept for a longer period to support abuse investigation. If you delete your account, those log entries are retained but are no longer linked to your identity.

Your rights

Under GDPR, and under similar laws in other countries, you have the right to the following.

  • Access the personal data we hold about you. The download described below covers almost all of it. Security and diagnostic records are not in that file, so email us if you want those too.
  • Rectify inaccurate data. Most account details can be edited directly in your profile.
  • Erase your data. This is available as self-service through account deletion in Account settings. If you cannot sign in to your account, email support@journeycomposer.com and we will delete it for you after confirming it is yours.
  • Port your data to another service. Use Download my data in Account settings to get a JSON file containing your profile, trips, saved places and routes, itineraries, expenses, packing lists, and support messages. Uploaded documents and photos are listed in the file, and you can download the files themselves from the trip they belong to.
  • Object to or restrict certain processing. Contact us and we will address your request.
  • Lodge a complaint with your local data protection supervisory authority.

To exercise any of these rights, contact support@journeycomposer.com.

Cookies and local storage

We use two cookies of our own on the web. One is a session cookie set when you sign in, which keeps you authenticated. The other remembers the width of a panel you have dragged to resize, and is cleared when you close your browser. The native app stores its session token in the device secure storage instead of a browser cookie.

We also store a few settings in your browser’s local storage so the app looks the way you left it: your light or dark theme, your chosen map style, whether saved places are shown on the map, your sight display settings, and whether you have dismissed an in-app hint. These stay on your device, are never sent to us as a profile, and are cleared when you clear your browser data.

All of the above is either strictly necessary for the app to work or a preference you set yourself, and none of it is used for tracking, analytics, or advertising. Storage of this kind does not require a cookie consent banner under GDPR and ePrivacy rules, which is why you will not see one.

The optional eSIM, flight-search, and Omio ticket affiliate features described above can result in third-party cookies from their own domains, but only once you actively use them on the web: the eSIM and Omio affiliate links only if you click them, and the flight-search widget only once you open its “Search flights” dropdown, since it then runs directly in your browser rather than through a plain link. In the native app these features open external provider pages instead of embedded widgets. None of these features is required to use JourneyComposer, and no first-party analytics, advertising, or tracking cookie is set by us.

Children’s privacy

JourneyComposer is not directed at children and is not intended to be used by anyone under 16 years old, or under the age of consent for data processing in their own country if that age is higher. We do not knowingly collect personal data from children. If we learn that we have collected personal data from a child under the applicable minimum age, we will delete it. If you believe a child has provided us with personal data, please contact us at support@journeycomposer.com and we will remove it.

Security

Passwords are hashed, not stored in plain text. We support two-factor authentication, apply rate limiting and abuse protections, and use standard web security headers across the app. No method of transmission or storage is perfectly secure, but we take reasonable technical measures to protect your data.

Changes to this policy

If we make a material change to how we handle your data, we will update this page and change the “last updated” date above.