Traveldi

Privacy Policy

Last updated: 3 August 2026 · Version 2026-08-03

This Privacy Policy explains how we collect, use and protect your personal data when you visit the Traveldi website (traveldi-app.com), join our waitlist, and, from launch, use the Traveldi mobile application (the "App"). We process personal data in accordance with Regulation (EU) 2016/679 ("GDPR"). We extend the rights described in this Policy to all our users worldwide, regardless of where they live. We do not sell personal data.

1. Data controller

The controller of your personal data is TRAVELDI sp. z o.o., with its registered office at ul. Galenowa 1/55, 25-705 Kielce, Poland, entered in the Register of Entrepreneurs of the Polish National Court Register (KRS) under no. 0001256690, NIP (tax ID): 9592095274, REGON: 545336229 ("we", "us").

Contact for all personal-data matters: privacy@traveldi-app.com. General contact: info@traveldi-app.com.

2. What this Policy covers

A. Website & waitlist

3. Data we collect on the website

DataRequired?Purpose
E-mail addressYes (for waitlist)Notifying you about the launch and launch-related updates you signed up for; delivering waitlist perks
First nameOptionalPersonalising launch communications
CountryOptionalUnderstanding where our future users come from
Dream destinationOptionalUnderstanding user interests; anonymous aggregate display on the site
Consent record (checkbox + timestamp)YesDemonstrating that consent was given (GDPR accountability)
Server log data (IP address, browser type, request time)AutomaticHosting, security and abuse prevention: standard web-server logs of our hosting provider

The website stores your language preference in your browser's local storage (key traveldi.web.lang). This is a functional setting stored on your device at your request; it is not used for tracking. The website does not use analytics, advertising or tracking cookies, which is why no cookie banner is shown.

The site loads the Bricolage Grotesque and Inter typefaces from Google Fonts (Google Ireland Ltd.). When fonts load, your browser transmits standard connection data (including your IP address) to Google. Details: Google Privacy Policy.

4. Legal basis and retention (waitlist)

We process waitlist data on the basis of your consent (Art. 6(1)(a) GDPR), given by ticking the consent box. You may withdraw consent at any time; every e-mail we send contains an unsubscribe link, or you can write to privacy@traveldi-app.com. Withdrawal does not affect the lawfulness of processing before withdrawal.

Server logs are processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in keeping the site secure.

Retention: waitlist data is kept until launch communications are complete, and no longer than 12 months after the App's launch, unless you delete it earlier by withdrawing consent or you convert your waitlist entry into an App account. Hosting-level server logs are retained for the standard period applied by our hosting provider.

5. How waitlist data is protected

B. The Traveldi App (from launch)

6. Data we process in the App

7. Purposes and legal bases (App)

Providing data is voluntary but necessary to use the relevant App features.

8. Retention (App)

9. Automated processing and profiling (App)

The App selects the profiles shown to you based on your stated preferences (e.g. country, shared interests). We do not make decisions about you based solely on automated processing that would produce legal effects or similarly significantly affect you.

C. Common provisions

10. Recipients of data (processors and providers)

We work with the service providers listed below. Open the list for the full breakdown of each provider's role and where they process data.

See the full list of providers (10)
ProviderRoleLocation of processing
VercelWebsite hosting and delivery (server logs, IP address)EEA / USA, see Section 11
home.pl S.A. (Szczecin, Poland)E-mail for the traveldi-app.com domain and DNS (server logs)Poland / EEA
SupabaseDatabase hosting, authentication, file storage (waitlist and App backend)EEA and/or USA, see Section 11
ResendSending waitlist e-mails (e-mail address, name, delivery data)Ireland (EEA); provider established in the USA, see Section 11
AppleApp distribution, in-app payments, push notificationsEEA / USA
RevenueCatSubscription and purchase management in the App (purchase data, app user identifier)USA
ExpoPush-notification and app-update infrastructureUSA
SentryCrash diagnostics (technical error data)USA
GoogleFonts on the website (IP address); in-App translation feature: sends the selected message text to the translation service, only at your requestEEA / USA
flagcdn.comCountry-flag graphics in the App (standard connection data, e.g. IP)varies

We share data with these providers only to the extent necessary for them to perform their services for us, under data processing agreements where required. We do not sell your personal data and we do not share it with third parties for their marketing purposes.

We may also disclose data where required by law (e.g. to competent authorities on a lawful request).

11. Transfers outside the EEA

Some providers (e.g. Vercel, Supabase, Resend, Apple, RevenueCat, Expo, Sentry, Google) may process data outside the European Economic Area, including in the USA. Such transfers rely on European Commission adequacy decisions (including the EU-US Data Privacy Framework for certified providers) or Standard Contractual Clauses (SCC), supplemented where appropriate by additional safeguards. You can request a copy of the relevant safeguards at privacy@traveldi-app.com.

12. Your rights

You have the right to: access your data and obtain a copy, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, objection to processing based on legitimate interest, and withdrawal of consent at any time (without affecting the lawfulness of prior processing).

We honour these rights for all users worldwide. To exercise them, write to privacy@traveldi-app.com. We respond within one month (extendable by two further months for complex requests, in which case we will inform you).

From launch, you will also be able to delete your account and data directly in the App (Profile → Settings → "Delete account").

You have the right to lodge a complaint with a supervisory authority, in Poland: the President of the Personal Data Protection Office (Prezes UODO, uodo.gov.pl) — or with the authority of your habitual residence.

13. Security

We apply technical and organisational measures appropriate to the risk, including: encrypted connections (HTTPS/TLS), encrypted session storage on the device (Keychain), row-level access control in the database (Row Level Security), data minimisation (including location rounding in the App and the write-only waitlist), and the rule that push tokens never reach other users.

14. Children

The website and the App are not directed at children. The App may only be used by persons aged 18 or over, and we do not knowingly collect data of younger persons. If you believe a child has provided us with personal data, contact us at privacy@traveldi-app.com and we will delete it.

15. Changes to this Policy

We may update this Policy as the service evolves (in particular at App launch). The current version is always available at this address; material changes will be announced on the website or in the App. The "Last updated" date and version identifier above indicate the version in force.

16. Contact

Personal-data matters: privacy@traveldi-app.com
General enquiries: info@traveldi-app.com

← Back to Traveldi