Privacy Policy
Last updated October 10, 2026
Who is responsible
Deep Buha, trading as GoPlanly, is the data controller for personal data processed through GoPlanly. Contact: info@goplanly.com or deep.buha@gmail.com.
What we collect and why
- Account data (name, email, login credentials or Google sign-in) — to create and secure your account (contract).
- Trip data (destinations, dates, activities, budgets, expenses, preferences such as dietary needs) — to provide the Service (contract).
- AI requests (the trip details and wishes you send to Plan with AI or AI guides) — to generate itineraries (contract).
- Subscription status (plan, renewal date, Paddle customer reference) — to give you the right features (contract).
- Technical data (IP address, device and browser details, error logs) — for security, fraud prevention and fixing problems (legitimate interests).
- Support messages — to answer you (legitimate interests).
We don't sell your data or use it for advertising.
Who we share it with
- Service providers who host our app and database, and AI model providers that generate itineraries, under confidentiality and data-processing terms.
- Paddle.com, our Merchant of Record, for selling the product, subscription management, payments, tax compliance and invoicing. Paddle handles your payment details; we never see your card number.
- Map providers (OpenStreetMap tile, routing and place-search servers) receive map requests.
- Professional advisers (legal, accounting) where needed, and authorities where required by law.
Some providers are outside India or your country; we rely on appropriate safeguards such as contractual clauses for these transfers.
How long we keep it
We keep your data while your account is active. When you delete your account in Settings, your trips, profile and login are deleted straight away; limited billing records are kept by Paddle and us as required by tax law, then deleted or anonymised.
Your rights
You can access, correct, export (Settings → Export my data) or delete your data, object to or restrict processing, and withdraw consent at any time. Under India's Digital Personal Data Protection Act 2023 and, where applicable, GDPR, you may also complain to your data protection authority. Email us to exercise any right; we reply within one month.
Security
We use encryption in transit, access controls so only you (and people you share a trip with) can see your trips, and limited staff access.
Cookies and storage
We use only essential browser storage to keep you signed in and remember settings. We don't use advertising or third-party analytics cookies.