🔒 Privacy Policy

Last updated: June 2025

Simi Travel ("we", "us", "our") is committed to protecting your personal data and respecting your privacy in accordance with the General Data Protection Regulation (GDPR) (EU 2016/679) and applicable national data protection laws.

1. Who We Are

Simi Travel is a travel planning application that helps you organise trips and share events with friends and circles.

Data controller: Simi Travel (contact: privacy@simitravel.com).

2. What Data We Collect

Account data: your name, email address, and profile picture URL provided via Google Sign-In.

Usage data: events you create or join, comments, planning items, photos you upload, and friendship connections.

Device data (mobile): push notification token, solely to deliver notifications you have enabled.

We do not collect payment data, precise location, or any special-category personal data.

3. Legal Basis for Processing

Contract performance (Art. 6(1)(b) GDPR): processing necessary to provide the service (account, events, circles).

Legitimate interests (Art. 6(1)(f) GDPR): security logging, abuse prevention, and service improvement.

Consent (Art. 6(1)(a) GDPR): push notifications — you may withdraw consent at any time in Settings.

4. How We Use Your Data

To authenticate you and display your profile to connected friends.

To let you create, share, and manage travel events within your circles.

To send push notifications about events and social activity, only when you have enabled them.

We do not sell, rent, or share your data with third parties for marketing purposes.

5. Data Sharing

Google Sign-In (Google LLC): used for authentication; governed by Google's Privacy Policy.

Cloud infrastructure: your data is stored on servers within the EU/EEA or with standard contractual clauses in place.

Other users: your username and profile picture are visible to members of your circles and events.

6. Data Retention

Your account and associated data are kept for as long as your account is active.

If you request account deletion, your personal data will be erased within 30 days, except where retention is required by law.

Push notification tokens are deleted immediately when you disable all push notifications or delete your account.

7. Your Rights Under GDPR

Access (Art. 15): request a copy of the personal data we hold about you.

Rectification (Art. 16): ask us to correct inaccurate data.

Erasure (Art. 17): request deletion of your account and data ('right to be forgotten').

Restriction (Art. 18): ask us to restrict processing in certain circumstances.

Portability (Art. 20): receive your data in a structured, machine-readable format.

Objection (Art. 21): object to processing based on legitimate interests.

Withdraw consent: disable push notifications at any time in Settings → Notification Settings.

To exercise any right, email privacy@simitravel.com. We will respond within 30 days.

8. Cookies

The web app uses a session cookie strictly necessary for authentication. No advertising or tracking cookies are used.

9. Security

All data in transit is encrypted using TLS. Passwords are not stored — authentication is handled entirely via Google Sign-In.

Access to production data is restricted to authorised personnel only.

10. Changes to This Policy

We may update this policy from time to time. The date at the top of this page indicates when it was last revised.

Continued use of Simi Travel after changes constitutes acceptance of the updated policy.

11. Right to Lodge a Complaint

You have the right to lodge a complaint with your local data protection supervisory authority at any time.

For any privacy-related enquiries please contact us at privacy@simitravel.com.