skip to main content
Our Privacy Promise

Your trip.
Your data. Your call.

Hey — we're Wrovo. We built this app to make travel planning easier, and that means treating your personal information with the same respect we'd want for our own. This page explains, in plain English, what we collect, why we collect it, and the promises we make to protect it.

Last updated September 2026 · GDPR Art. 13/14 · CCPA §1798.100 · COPPA 16 CFR §312 · Questions? privacy@wrovo.app

The short version

We don't sell your data. We don't share it. We don't rent, trade, or broker it. Not now, not ever, not to anyone.

That's not a promise we'll quietly walk back someday. It's why we started Wrovo in the first place. We earn money from referral commissions when you book travel — not from selling your information. We never needed to track you to make a living, and we never will.

GDPR Compliant

EU Regulation 2016/679

CCPA Compliant

California Civil Code §1798

COPPA Compliant

16 CFR Part 312

SOC 2 Ready

Security controls in place

What we collect (and why)

We only ask for what we genuinely need to make Wrovo work for you:

  • •Your name and email — so you can log in and your travel crew knows who's who.
  • •Trip details you enter — destinations, dates, budget, itinerary. This stays in your account and nowhere else.
  • •Expense and split data — so the math is right and everyone stays squared up.
  • •Booking info — only when you book through Wrovo, so we can confirm your reservation and drop Wrovo Cash into your wallet.
  • •Price alert routes — the trips you're watching, so we can ping you when prices drop.
  • •Flight details for claims — flight numbers, delays, airline info — only when you ask us to file a compensation claim for you.
  • •Passkey credentials — we store a public key and credential ID to verify it's really you for sensitive actions. Your fingerprint or face scan never leaves your phone.
  • •Chats with Maya — our AI concierge uses your trip and booking context to help you faster. We keep conversations for 90 days, then they're gone.

That's the whole list. No contacts, no background location tracking, no browsing history — nothing you didn't hand us on purpose.

What we'll never do

These aren't policies we can change on a whim — they're the lines we won't cross:

  • •Sell your data — to data brokers, advertisers, or anyone else. Ever.
  • •Build advertising profiles — your travel habits aren't for sale.
  • •Use tracking pixels — no Facebook Pixel, no Google Ad tags, nothing that lets outside companies follow you around inside our app.
  • •Share your details for marketing — when you book, travel providers get only what they need to fulfill your reservation (name, dates, contact for confirmation). That's it.
  • •Train AI on your conversations — your chats with Maya help you, not some model training pipeline.
  • •Keep data you deleted — delete a trip or close your account, and your data is gone within 30 days. No "we keep it just in case" loopholes.

When your data goes somewhere else

Only when you ask us to do something that needs it. There are exactly four situations:

  • •Booking a trip. When you book a flight through Duffel or a hotel through Travelgate, the provider gets the minimum info to fulfill your reservation — your name, contact email, and booking details. They're contractually barred from using it for marketing or selling it on.
  • •Filing a claim. When you ask us to file an EU261/UK261 compensation claim, the airline gets your flight details and claim info. Nothing more — no marketing, no data sharing.
  • •Running the app. We use a few trusted services behind the scenes — cloud hosting, payments via Stripe, email via SendGrid, AI via Anthropic. They process data only on our say-so, under strict agreements and GDPR-compliant Standard Contractual Clauses, and can't use your data for their own purposes.
  • •Group trips. People you invite can see that trip's details, expenses, and shared messages. You control the guest list. Remove someone, and they lose access right away.

That's it. No "we may share with partners to improve your experience" language — because we don't.

Passkeys & biometric login

We use WebAuthn — the same tech behind Face ID, Touch ID, and security keys — to lock down sensitive actions like payments, bookings, and account changes.

  • •Your device creates a unique cryptographic key pair. The private key stays on your device, guarded by your biometric or PIN.
  • •We only store the public key and a credential ID — never your fingerprint, face scan, or biometric image. Those never leave your phone, and we don't want them.
  • •You can add or remove passkeys anytime from Profile → Security.
  • •Remove a passkey and your account keeps working — you'll just need another way to log in.

Maya, your AI concierge

Maya is our AI support assistant. She uses context from your account — your trips, bookings, wallet, and open tickets — to help you without making you repeat yourself.

  • •She can answer questions, suggest fixes, and create support tickets when something needs a human touch.
  • •Your messages are processed by our AI provider, Anthropic, under their GDPR-compliant terms.
  • •We don't use your conversations to train AI models.
  • •We keep conversations for 90 days so Maya can pick up where you left off, then they're permanently deleted.
  • •Maya's smart, but she's not a lawyer, doctor, or financial advisor — don't treat her advice as professional guidance.

Tracking & analytics

  • •We use Base44's built-in anonymized analytics to understand which features people love — things like "how many trips got planned this week." This data can't be traced back to you.
  • •We don't use Google Analytics.
  • •We don't use Meta's (Facebook's parent company) tracking tools.
  • •We don't run retargeting ads that follow you across the internet.

If you've ever used an app and felt like it was watching you afterward — that won't happen here.

GDPR Art. 25: Data protection by design and by default — we collect less, limit who can see it, and anonymize wherever we can.

How we protect your data

  • •Encryption: Your data is encrypted in transit (TLS) and at rest.
  • •Access control: Only team members with a real operational need can touch production data, and everything is role-restricted.
  • •Audit trail: Every significant financial event — reward allocations, commission payments, loan transactions — is logged in a tamper-proof record.
  • •Payments: Stripe handles all payments. We never see, store, or transmit your card number. Stripe is PCI-DSS Level 1 certified.
  • •Account security: Brute-force lockout after repeated failed logins, device fingerprinting to catch unusual access, and optional passkey verification for sensitive actions.
  • •Breach notification: If a breach ever happened, we'd tell affected users within 72 hours — directly, clearly, and with full details — as required by GDPR Art. 33.

For EU travelers: Data transferred outside the EU is protected by Standard Contractual Clauses (SCCs) with every vendor.

How long we keep things

We hold onto data only as long as we need it — then it's gone:

  • •Active account data — until you close your account.
  • •Deleted account data — wiped from active systems within 30 days. Backup copies are purged within 30 days as they cycle out.
  • •Booking records — 7 years (tax and legal requirements).
  • •Consent records — 7 years (GDPR Art. 7(1) requires proof of consent).
  • •Maya conversations — 90 days, then permanently deleted.
  • •Price alert data — until you delete the alert or the trip ends.
  • •Compensation claim records — 6 years (UK) or 3–10 years (EU, varies by country).
  • •Security logs (failed logins, device fingerprints) — 2 years.
  • •Passkey records — until you remove the passkey.

We keep consent and financial records longer than the rest because the law requires it. Everything else disappears when you say so.

Your rights, always

You're in the driver's seat. Here's what you can do anytime:

  • •See everything: Request a full export of everything we hold about you.
  • •Fix things: Update or correct any info in your account, right from the app.
  • •Delete your account: Close it from Settings and we'll wipe your data within 30 days — with a grace period in case you change your mind. We keep consent records for 7 years as GDPR Art. 7(1) requires.
  • •Take your data: Get a machine-readable export via our Rights Request Form or by emailing privacy@wrovo.app.
  • •Opt out of "sale" (CCPA): California residents can opt out. We don't sell data, but you can manage your preference at /do-not-sell.
  • •Withdraw consent: Pull consent for specific processing (marketing emails, analytics, sharing) anytime from your settings. It takes effect immediately, and we stop within 24 hours.
  • •Parental rights (COPPA): Parents can review, delete, or block further collection of their child's data. Kids under 13 need verifiable parental consent. Email privacy@wrovo.app to get started.
  • •Unsubscribe: One click in any email and you're off the list. The only messages we consider essential are trip-critical ones — booking confirmations and payment reminders your group set up.

We respond to every rights request within 15 days. No legal runaround — just action.

Traveling abroad with your data

When you book through Wrovo, your data travels to our partners — Duffel Technologies Ltd (flights, Ireland with US operations), Travelgate (hotels, Spain), and to airlines and hotel chains worldwide. Here's how we keep it safe in transit:

  • •EU Standard Contractual Clauses (SCCs): We use the 2021 SCCs approved by the European Commission with all US-based vendors.
  • •Technical safeguards: TLS 1.3 encryption in transit, AES-256 encryption at rest.
  • •Contractual safeguards: Data Processing Agreements (DPAs) with every processor.
  • •Organizational safeguards: Staff training, access controls, audit logging.

Transfer Impact Assessment (TIA): We've done a thorough TIA following the Schrems II ruling (Case C-311/18). We looked at US surveillance laws (FISA 702, EO 12333) and concluded that commercial travel booking data has minimal intelligence value and very low risk of government access.

GDPR Chapter V: All transfers outside the EU comply with Articles 44–50. SCCs and TIA documentation are available on request from privacy@wrovo.app.

Questions? Talk to a real person.

Anything about your data, our practices, or this page — just email privacy@wrovo.app. A human will read it and write back.

We don't hand privacy off to a legal chatbot. We care about it because it's the right thing to do — and because we'd want the same if we were you.

Ready to plan your next trip — knowing exactly where your data goes?