Hey — we're Wrovo. We built this app to make travel planning easier, and that means treating your personal information with the same respect we'd want for our own. This page explains, in plain English, what we collect, why we collect it, and the promises we make to protect it.
Last updated September 2026 · GDPR Art. 13/14 · CCPA §1798.100 · COPPA 16 CFR §312 · Questions? privacy@wrovo.app
The short version
We don't sell your data. We don't share it. We don't rent, trade, or broker it. Not now, not ever, not to anyone.
That's not a promise we'll quietly walk back someday. It's why we started Wrovo in the first place. We earn money from referral commissions when you book travel — not from selling your information. We never needed to track you to make a living, and we never will.
GDPR Compliant
EU Regulation 2016/679
CCPA Compliant
California Civil Code §1798
COPPA Compliant
16 CFR Part 312
SOC 2 Ready
Security controls in place
We only ask for what we genuinely need to make Wrovo work for you:
That's the whole list. No contacts, no background location tracking, no browsing history — nothing you didn't hand us on purpose.
These aren't policies we can change on a whim — they're the lines we won't cross:
Only when you ask us to do something that needs it. There are exactly four situations:
That's it. No "we may share with partners to improve your experience" language — because we don't.
We use WebAuthn — the same tech behind Face ID, Touch ID, and security keys — to lock down sensitive actions like payments, bookings, and account changes.
Maya is our AI support assistant. She uses context from your account — your trips, bookings, wallet, and open tickets — to help you without making you repeat yourself.
If you've ever used an app and felt like it was watching you afterward — that won't happen here.
GDPR Art. 25: Data protection by design and by default — we collect less, limit who can see it, and anonymize wherever we can.
For EU travelers: Data transferred outside the EU is protected by Standard Contractual Clauses (SCCs) with every vendor.
We hold onto data only as long as we need it — then it's gone:
We keep consent and financial records longer than the rest because the law requires it. Everything else disappears when you say so.
You're in the driver's seat. Here's what you can do anytime:
We respond to every rights request within 15 days. No legal runaround — just action.
When you book through Wrovo, your data travels to our partners — Duffel Technologies Ltd (flights, Ireland with US operations), Travelgate (hotels, Spain), and to airlines and hotel chains worldwide. Here's how we keep it safe in transit:
Transfer Impact Assessment (TIA): We've done a thorough TIA following the Schrems II ruling (Case C-311/18). We looked at US surveillance laws (FISA 702, EO 12333) and concluded that commercial travel booking data has minimal intelligence value and very low risk of government access.
GDPR Chapter V: All transfers outside the EU comply with Articles 44–50. SCCs and TIA documentation are available on request from privacy@wrovo.app.
Anything about your data, our practices, or this page — just email privacy@wrovo.app. A human will read it and write back.
We don't hand privacy off to a legal chatbot. We care about it because it's the right thing to do — and because we'd want the same if we were you.