1. Introduction
This Privacy Policy explains how personal data is collected, used, shared, retained and protected when you use Event Trekker — the Event Trekker mobile app and its related services (together, the "Service"). It also describes the choices and rights you have over your data.
This policy applies to everyone who uses Event Trekker: people who create an account, plan or join trips, upload attachments, track expenses, or otherwise interact with the app and its services.
Event Trekker is a product of NeuralNest Solutions (NNS), which is the data controller responsible for your personal data under this policy. The full controller details are set out in §2.
If anything here is unclear, or you want to exercise any of your rights, you can reach us using the contact details in §13.
2. Who Runs Event Trekker
Event Trekker is operated by NeuralNest Solutions (NNS) ("we", "us"), an India-based company and the data controller (and, under the Indian Digital Personal Data Protection Act, 2023 ("DPDP"), the "Data Fiduciary") responsible for your personal data. For our Indian users, the DPDP Act applies. Where Event Trekker is used by people in the EU or UK, we also aim to align with the EU General Data Protection Regulation 2016/679 ("GDPR") and the UK GDPR. Our contact details, Grievance Officer, and Data Protection Officer details are in §13.
3. What We Collect and Why
3.1 Account Data
- Email address (required) — to authenticate you and to email you about your account.
- Display name (optional · used to introduce you to other Members of an Organizer).
- Username handle (optional · used so other people can invite you by @handle instead of email).
- Hashed password or social-sign-in token (Google / Apple) — never the raw password.
- Device locale + time zone (auto-detected, stored as a preference).
3.2 Trip Data
Trip data is the heart of the app. We treat it as sensitive personal data in line with the EDPB's view that travel itineraries can reveal location, family composition, and religious-cultural affiliations. We hold:
- Events (your trips) — name, dates, destination, your role.
- Activities — flight numbers, hotel names, attraction venues, ticket-collection windows.
- Attachments you upload — PDFs, QR codes, voucher images. Scanned with ClamAV at upload time.
- Expenses — amount, currency, FX-rate snapshot at capture time, payer, split allocation.
- Group membership — which Organizer you belong to, which Members you share with.
- Messages / edits made by you against any of the above (for audit + change history).
3.3 Operational Data
- Service logs — IP address, user-agent, request path, response code, request timing. Logged at TRACE/DEBUG only on staging; on production we redact the IP after 30 days.
- Audit log — append-only WORM record of authorisation-relevant actions (logins, attachment uploads, AI-call consents, account deletions). Required by ISO 27001 §A.12.4.
- Crash reports — only if you opt in (off by default). Crash reports include stack traces, OS version, app version, last 10 navigation events. Personally identifying values are stripped client-side before upload.
3.4 What We Explicitly Do NOT Collect
- We do NOT collect biometric data (no Face-ID payload leaves your phone — auth is delegated to the OS).
- We do NOT collect precise GPS continuously. The app reads your current time zone from the OS (which is coarse-grained — a city, not a street) and only when you open the app.
- We do NOT collect payment card data. There are no in-app payments at launch.
- We do NOT collect ad-attribution identifiers (no IDFA, no GAID for advertising).
- We do NOT collect data from third-party analytics SDKs that fingerprint users.
4. Our Legal Bases
Under GDPR Art. 6 and DPDP §7 the legal bases we rely on are:
- Contract (GDPR 6(1)(b)) — to provide the service you signed up for (creating your account, syncing your timeline, storing your attachments).
- Legitimate interest (GDPR 6(1)(f)) — for service-quality logging, fraud prevention, audit-log retention, and product analytics from privacy-friendly tooling (Plausible). We have weighed our interests against yours; you may object (§8.4).
- Consent (GDPR 6(1)(a) · DPDP §7(1)) — for optional features: AI assistance via Gemini (consent prompt on first use), push notifications, crash-report opt-in, and any marketing email beyond a single one-time launch email.
- Legal obligation (GDPR 6(1)(c)) — to retain audit-log entries required by ISO 27001 / SOC 2-style controls, and to respond to lawful requests from EU / Indian data-protection authorities.
5. How We Use AI (Gemini) and What We Strip
Event Trekker uses Google's Gemini API for two specific features: drafting a full timeline from a natural-language prompt, and scaffolding a single activity from a short description. Both are consent-gated: the first time you tap an AI button we show a consent modal explaining what data flows, where it goes, and how to opt out. The choice is reversible from Settings → Privacy → AI assistance.
Before any prompt leaves our backend, our TripDataSanitizer service strips:
- Passport numbers, national-ID numbers, and any field tagged as a government ID;
- Payment-card numbers (PAN, CVV — though we do not collect these intentionally; the sanitizer is defense-in-depth);
- Email addresses and phone numbers of you or any other Member;
- Booking-reference / PNR codes;
- Free-text notes that contain anything looking like the above (regex-defended).
Gemini API calls are made from our servers, not from your device. Google's processing of the sanitized prompt is governed by Google's Privacy Policy and our Data Processing Addendum with Google Cloud. We use the paid tier of the Gemini API, under which Google states that customer prompts are not used to train its models; we rely on this and do not intend for your prompts to be used for model training.
6. Who We Share Data With
We keep your data to ourselves as much as possible. We share only what a handful of trusted companies need to make specific features work, and each of them may use it only for the job we hired them to do — nothing else. We never sell your data, to anyone, ever. Here is the full list of who we share with and why:
Google's Gemini AI
Used only when you choose to use the AI helper — for example, to draft a trip timeline or fill in the details of an activity. Before we send anything to Google, we strip out the personal bits (names, emails, phone numbers, passport and booking references). See §5 for exactly what we remove.
Our email delivery service
Handles the emails the app needs to send you — confirming your sign-up, passing along a trip invite, or helping you reset your password. It only delivers the message; it does not read or reuse what's inside.
Our push-notification service (from Google)
Delivers the alerts that pop up on your phone — a reminder that a ticket window is opening, or that a trip-mate added something. We send only the words of the notification, never your trip details.
Plausible, our privacy-friendly analytics
Gives us a rough sense of which screens people use and on which days, so we can improve the app. It uses no cookies and does not track you or store your identity. See our Cookie Policy for more.
The Apple App Store and Google Play
Involved only when you download or update the app from their stores. What they collect during that download is covered by their own privacy policies, not ours.
Our own servers
Your data lives on servers we own and run ourselves — we don't hand it to a third-party host. It's kept scrambled so that even if someone got hold of the raw files they couldn't read them, and your uploaded attachments get an extra lock tied to your device.
One more thing worth being clear about: when you plan a trip together in a shared group (an Organizer), the people in that group can see each other's trip details — that's the whole point of planning together. People outside your group can't see any of it; each group is walled off from the others by default (see our Terms of Service §4).
7. How Long We Keep Things
- Active account data — for as long as your account exists.
- Soft-deleted account — 30-day grace window after you delete the account in-app (you can restore in that window). After 30 days, the hard-purge job runs (see §8.5).
- Hard-purged account — within 72 hours of the 30-day grace expiring, we erase all personal data including attachments. The audit-log entries that retain ISO-27001-required metadata (timestamp, audit verb, anonymised user-id hash) survive, because we are obliged to retain them; they contain NO substantive trip content after purge.
- Backups — daily encrypted backups are retained 35 days, then deleted. A deleted account that lands on backup is purged when the backup ages out.
- Operational logs — 90 days for application logs, 1 year for the audit log (and forever for ISO-required entries).
- Crash reports (opt-in) — 180 days, then aggregated and the raw report is deleted.
8. Your Rights and How to Exercise Them
Under GDPR (Articles 15–22), UK GDPR, and DPDP (§11–§14), you have the following rights. To exercise any of them, email support@neuralnestsolutions.com or use the in-app form at Settings → Privacy → My data. We respond within 30 days (DPDP timeline) or one month (GDPR), free of charge unless requests are manifestly unfounded or excessive.
8.1 Right of access (Art. 15 / DPDP §11)
You can request a copy of all personal data we hold about you. We deliver it as a machine-readable JSON bundle plus PDFs of each of your trips. The in-app Export my data button does the same thing without contacting us.
8.2 Right to rectification (Art. 16)
You can correct any factual error directly inside the app, or ask us to do it for you.
8.3 Right to erasure ("right to be forgotten" · Art. 17 / DPDP §12(3))
You can delete your account in-app at any time (Settings → Account → Delete). Soft-delete is immediate; hard-purge runs after the 30-day grace window. See §7. If you prefer, email support@neuralnestsolutions.com; we will execute the same flow.
8.4 Right to object & right to restrict (Art. 18 / 21)
You can object to processing based on legitimate interest (notably product analytics) and we will stop unless we can show compelling legitimate grounds — for example, an active fraud investigation. You can also ask us to restrict (freeze) processing while we resolve a dispute.
8.5 Right to data portability (Art. 20)
Your Export my data bundle is in JSON + PDF, both portable formats. You can re-import the JSON into a future version of Event Trekker or transfer it to a competing service.
8.6 Right to withdraw consent (Art. 7(3) / DPDP §6(4))
Where we rely on your consent (AI features, push, crash reports, marketing email), you can withdraw consent at any time in-app or by email. Withdrawal does not affect the lawfulness of processing that happened before withdrawal.
8.7 Right not to be subject to automated decision-making (Art. 22)
Event Trekker uses AI to draft itineraries — it does not make decisions about you (no credit scoring, no insurance underwriting, no profiling for ads). You can edit, accept, or reject every AI-drafted activity individually.
8.8 Right to complain to a supervisory authority
You can lodge a complaint with your local supervisory authority (in the EU) or the Data Protection Board of India (under DPDP). Please consider writing to us first so we can try to resolve directly. Contact addresses are in §13.
9. Children
Event Trekker is not intended for children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has created an account, please write to support@neuralnestsolutions.com and we will delete the account and any associated data.
10. How We Protect Data
- TLS 1.2+ in transit for every endpoint; HSTS preloaded on the marketing site.
- Encryption at rest for all databases and object storage.
- We use appropriate security measures to protect uploaded attachments and personal information from unauthorized access.
- Passwords hashed with bcrypt (cost factor 12); we never store reversible secrets.
- 2-factor authentication mandatory for staff with production access.
- Annual penetration testing against the OWASP ASVS Level 2 baseline.
- OWASP MASVS conformance for the mobile apps (anti-tamper, secret storage, TLS pinning).
- Quarterly disaster-recovery drills with RPO 1 hour, RTO 4 hours for the customer tier.
11. International Transfers
NeuralNest Solutions is based in India, and our processing takes place on NNS-managed infrastructure. Some processors we rely on operate outside India: Google Cloud (Gemini API) processes in regions that you can review at cloud.google.com/about/locations, and our email-delivery provider processes in the region it sends from. Where personal data of EU / UK users is transferred, we aim to put appropriate safeguards in place, such as Standard Contractual Clauses (SCCs) per the European Commission's 2021 decision, together with supplementary measures where applicable (encryption at rest, pseudonymisation, and contractual restrictions on model training for Gemini). For transfers of Indian users' data, we aim to comply with the DPDP Act and any restrictions the Central Government may notify under it.
12. Changes to This Policy
If we make a material change (a new category of data, a new processor, a longer retention period), we will notify you in-app at least 30 days before the change takes effect and we will email anyone affected. Non-material changes (typo fixes, clarifications) are summarised in the changelog at the bottom of this page.
13. How to Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, contact us:
NeuralNest Solutions (NNS) — India-based data controller / Data Fiduciary. Our registered postal address is available on written request to the email below.
Privacy / data-request enquiries: support@neuralnestsolutions.com
Security concerns: support@neuralnestsolutions.com
General support: support@neuralnestsolutions.com
India — DPDP Grievance Officer: Indian users may raise a grievance under the DPDP Act by writing to support@neuralnestsolutions.com with the subject "DPDP Grievance". Where a GDPR/UK-GDPR representative or Data Protection Officer is required for our EU/UK users, we aim to designate one and will publish the details here.
Changelog
- 2026-05-19 · v1.0 · Initial publication.
Acknowledgment
By using Event Trekker, you acknowledge that you have read, understood, and agree to this Privacy Policy, including how we collect, use, share, retain and protect your personal data, and the rights and controls available to you as described above.