Legal
Privacy Policy
This notice explains what personal data GlobeCapture collects when you use globe-capture.com, why we collect it, who else processes it, how long we keep it, and what you can ask us to do about it. It covers the website, the trip planner and the emails we send you.
1. Who is responsible for your data
GlobeCapture is operated by [registered company name and address — to be supplied before launch]. We are the data controller for everything described here. For any question about this notice — including a request to see, correct or delete your data — write to privacy@globe-capture.com.
2. What we collect, and why
We collect only what the service needs in order to work:
- Account data — your email address and your password. The password is stored only as a cryptographic hash by our authentication provider; nobody at GlobeCapture can read it. We also store your role (traveller, subscriber or admin), which is what decides what you are allowed to open.
- Trip data — the destination, the start and end dates, how many people are travelling, the language you chose, and anything you write in the free-text notes field. This is what your itinerary is generated from.
- Itinerary data — the day-by-day plan produced for you: place names, times, categories, short descriptions and map coordinates.
- Payment data — we never see or store your card details. Stripe collects them on its own hosted payment page and tells us only that a payment succeeded, together with the customer and subscription identifiers we need in order to manage your access. What we store is what you bought, when, and how long it stays valid.
- Usage and technical data — pages viewed and the four product events we measure (an itinerary generated, a payment completed, the map opened, a travel link clicked), plus the request logs our hosting and database providers keep, which include IP addresses.
About the notes field. Whatever you write there is sent to our AI provider so it can write your itinerary. Please do not put health information, religious beliefs or other sensitive details in it. If you choose to include something of that kind — a dietary requirement, for example — you are explicitly asking us to use it for that purpose, and we use it for nothing else.
3. The legal basis for each use
Under the GDPR every use of your data needs a legal basis. Ours are:
- Performance of a contract (Art. 6(1)(b)) — account, trip, itinerary and payment data. Without these we cannot deliver the service you signed up for.
- Legal obligation (Art. 6(1)(c)) — the payment and invoicing records that accounting and tax law require us to keep.
- Legitimate interests (Art. 6(1)(f)) — keeping the platform secure, preventing abuse, and the internal log of the actions our staff take on accounts. Our interest is in running a service that works and is not abused; we have weighed that against your interests and keep this data to a minimum.
- Consent (Art. 6(1)(a)) — analytics cookies, and any sensitive detail you choose to volunteer in the notes field. You can withdraw consent at any time, which does not affect what was already done lawfully before you withdrew it.
4. Who else processes your data
We use a small number of service providers. Each one acts on our instructions under a data processing agreement, and none of them sells your data. We do not sell your personal data, and we do not run advertising trackers.
| Recipient | What they do with it | Where |
|---|---|---|
| Supabase | Database, user accounts, file storage and server-side functions | European Union (Frankfurt, Germany) |
| Vercel | Hosts and serves the website | Global edge network; company established in the United States |
| Anthropic | The AI model that writes your itinerary | United States |
| Geoapify | Turns place names and addresses into map coordinates | European Union (Germany) |
| Mapbox | Draws the map in your browser | United States |
| Stripe | Takes payment and manages subscriptions | Ireland and the United States |
| Resend | Sends account email — confirmation and password reset | United States |
| Google Analytics | Measures how the site is used | Ireland and the United States |
We also disclose data where the law requires it — for example to a court or a competent authority acting within its powers.
5. Transfers outside the European Economic Area
Some of the providers listed above are established in the United States. Those transfers rely on the European Commission's standard contractual clauses, on the EU–US Data Privacy Framework where the provider is certified under it, or on both. You can ask us for a copy of the safeguards that apply to a particular transfer.
6. How long we keep it
- Account, trip and itinerary data — for as long as your account exists. Note that a one-time trip's access ends one day after the trip's end date, but the trip and its itinerary stay in your account until you ask us to remove them.
- Payment and invoicing records — for as long as accounting and tax law requires. This is longer than the account itself and we cannot shorten it.
- The internal log of staff actions on accounts — kept as an audit trail for as long as the account exists.
- Technical request logs held by our hosting and database providers — kept for their standard retention window, currently a matter of days to weeks.
- Analytics data — kept for the retention period configured on our Google Analytics property.
When you ask us to delete your account, we remove the account, your trips and your itineraries. Anything we are legally required to keep is kept, and nothing beyond that.
7. Your rights
Under the GDPR you can ask us to:
- give you a copy of the personal data we hold about you (access);
- correct anything that is wrong or incomplete (rectification);
- delete your data (erasure);
- restrict what we do with it, or object to processing we base on our legitimate interests;
- hand your data to you or to another provider in a machine-readable format (portability);
- withdraw a consent you previously gave.
Write to privacy@globe-capture.com. We answer within one month. If a request is complex we may extend that by two further months, and we will tell you why within the first month. Exercising these rights is free unless a request is manifestly unfounded or excessive.
If you believe we have handled your data badly, you can complain to the Romanian supervisory authority — ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal), B-dul G-ral. Gheorghe Magheru 28-30, Bucharest, dataprotection.ro — or to the supervisory authority of the country you live in.
9. AI-generated itineraries
Your destination, dates, number of travellers, language and notes are sent to Anthropic's Claude model, which writes the itinerary. Your email address and your payment details are never sent. Under our agreement with Anthropic, your data is not used to train their models and is retained only briefly, for security purposes.
An itinerary is a suggestion, not a decision about you. Nothing in this service produces a legal effect or a similarly significant effect within the meaning of Article 22 GDPR, and we do not profile you.
10. How we protect it
Your data is stored in the European Union, encrypted in transit and at rest. Access is enforced at the database level by row-level security, so one account cannot read another's trips even if the application were at fault. Passwords are hashed, never stored in readable form. Administrative access is limited to named staff, and every administrative action on an account is written to an audit log.
11. Children
The service is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us their data, write to us and we will delete it.
12. Changes to this notice
We update this notice when the service changes. The date at the foot of this page is the version you are reading. If a change materially affects you, we will announce it in the application or by email before it takes effect.
Last updated: September 2026