Privacy Policy
Last Updated: September 2026
Our Privacy Commitment
At Dayravel, your privacy is fundamental to how we build our software. We believe travel discovery should be inspiring, intuitive, and private.
1. Platform Breakdown: Mobile Apps vs. Web
To provide total transparency, here is exactly how our different platforms operate:
Mobile Apps (iOS & Android)
Our mobile applications currently operate in a 100% account-free, anonymous discovery mode:
- No registration or login required.
- No collection of names, email addresses, or phone numbers.
- No access to device contacts, cameras, or photo libraries.
- No tracking of GPS location or advertising identifiers (IDFA/AAID).
- Saved items and preferences remain exclusively on your device hardware.
Web Platform (Dayravel.com)
You can browse all destination guides without an account. If you choose to create an account, we collect only the minimal details necessary to manage your profile and sync your saved trips across devices.
2. Information We Collect When You Use the Web Platform
When using the optional user features on Dayravel.com, we collect:
- Account Information: When you register, we collect your name, email address, and a securely salted password hash (we never have access to your plaintext password).
- Third-Party Sign-In (Google): If you choose Google One-Tap or Google Sign-In, we receive your basic verified profile token (name, email, and avatar image) from Google.
- Travel Preferences & Saved Items: Your chosen origin country passport, preferred vibes (e.g. Beaches, Culture), travel companions, and curated bookmarks.
- Technical Telemetry & Log Data: General device attributes (browser type, operating system) and coarse geographic indicators (city or country level derived from IP) used strictly for service reliability, load balancing, and cyber defense.
3. Purpose & Use of Data
Any data collected is strictly utilized to:
- Authenticate your identity and maintain your active user session.
- Deliver essential transactional emails (account verification, password reset links, and security alerts).
- Provide personalized travel intelligence based on your selected home country and favorite travel vibes.
- Detect, prevent, and mitigate fraud, spam, automated scraping, and unauthorized system abuse.
4. Industry-Standard Security Safeguards
We implement industry-standard security architectures to protect your credentials:
- Encryption in Transit: All data is transmitted over secure TLS/HTTPS protocols.
- Secure Password Hashing: Passwords are irreversibly hashed with modern cryptographic algorithms before storage.
- Strict Rate Limiting: Verification and password reset forms are restricted to 60-second cooldowns and maximum 5 attempts per day to neutralize credential-stuffing bots.
- Secure Cookies: Authentication refresh tokens use
HttpOnly,Secure, andSameSiteflags, protecting against Cross-Site Scripting (XSS).
5. Your Privacy Rights & Data Control (GDPR & CCPA/CPRA)
Regardless of your location, you have complete control over your account data:
- Access & Update: You can edit your profile name, change your password, and update travel preferences directly in your Account Settings.
- Account Deactivation & Deletion: You can deactivate or permanently delete your account directly from the Account page. Deactivation immediately terminates your active sessions.
- Right to Erasure: To request permanent deletion of any remaining backend records, email at [email protected] and the request will be processed within 30 days.
6. Children's Privacy (COPPA)
Dayravel is not directed to children under the age of 13 (or 16 in the European Union/UK). We do not knowingly collect personal information from minors. If a minor has created an account without parental consent, please email at [email protected] for prompt deletion.
Privacy Inquiries
For any questions or data requests regarding Dayravel.com or the mobile apps, email at:
[email protected]