Privacy · Last updated April 2026

Privacy Policy

We treat your travel data with the same discretion as a private concierge. This policy explains what we collect, why we collect it, and the choices you have.

1.Data We Collect

  • Account data: name, email, password hash, currency preference.
  • Trip data: destinations searched, saved trips, journals you create, reviews you post.
  • Device data: browser, OS, anonymised IP, approximate location for currency & weather.
  • Booking handoffs: the partner you were referred to and the package selected (no payment details — these stay with the partner).

2.How We Use Your Data

We use your data to personalise AI recommendations, surface price drops, save itineraries to your dashboard, send you transactional emails, and improve the platform. We never sell your personal data.

3.AI Processing

When you use AI features (Mystery, Smart Flights, Itinerary Builder), your prompts and recent trip context are sent to our Lovable AI gateway and underlying models (Google Gemini, OpenAI). These providers do not train on your data via our gateway.

4.Cookies & Analytics

We use a small number of essential cookies for authentication and currency preference, plus privacy-friendly analytics to understand which destinations and packages travellers love. You can clear cookies anytime in your browser settings.

5.Sharing With Partners

When you click through to a partner (Booking.com, Kiwi.com, Klook, GetTransfer) we share the minimum context needed (e.g. destination, dates, package id) so the partner can pre-fill your search. Payment and personal checkout information is collected by the partner under their own privacy policy.

6.Data Retention

Account & trip data is retained while your account is active. You can request deletion at any time — we'll remove your personal data within 30 days, except where we're legally required to keep booking records.

7.Your Rights

Subject to applicable law (UK GDPR, EU GDPR, CCPA), you can request access, correction, export, deletion or restriction of your data. Contact us via /contact and we'll respond within 30 days.

8.Security

Data in transit is encrypted with TLS. Passwords are hashed and salted. We follow least-privilege access for our backend and apply Row-Level Security on every database table.

9.Children

JetSetGo is not directed at children under 16. If you believe a child has created an account, contact us and we will delete it.

10.Updates

We may update this policy occasionally. Material changes will be communicated via email and a homepage banner. The "last updated" date at the top of this page always reflects the current version.