Privacy at TravelingWhere

Useful insight.
Less personal data.

We use optional, privacy-protected analytics to understand which guides help travelers. Analytics runs only after consent.

Analytics preference

Current setting: Not selected. You can change it at any time.

Visitor accounts

Visitor accounts use Supabase Auth for verified email registration, sign-in, secure sessions, and password recovery. TravelingWhere receives the verified email address and display name, but never receives or stores the visitor’s password. Signed-in destination saves and planning details are stored in the site database so they can appear across devices.

What we collect

Page paths, referring page, approximate country, region and city, and a masked network address. Signed-in accounts also store the verified email, display name, saved destinations, trip dates, party size, travel style, and notes the visitor explicitly supplies.

What we do not collect

We do not store full IP addresses, payment information, passwords, or translator text. Booking transactions happen with the external provider you choose.

Retention and deletion

Automatic daily deletion removes anonymous traffic and administrator login attempts after 90 days, plus account-security events and operational email-delivery logs after 180 days. Each deletion run is recorded in the protected administrator audit log. Expired encrypted snapshots are removed after 30 days. Account holders may remove saved destinations at any time and may request deletion of their account data.

Affiliate and external providers

Booking links may contain an affiliate identifier. The external provider receives the information normally sent when you follow a link and applies its own privacy policy. TravelingWhere does not receive your payment-card details.

Your choices

You may browse without an account and decline analytics. Device-only favorites can be removed by clearing site data; signed-in saves can be removed from the visitor account.

Return home →
Share