Privacy Policy
Last updated: July 2026
Your JP Adventure (“we”, “our”, “us”) respects your privacy. This policy explains what we collect, why we collect it, and what choices you have. If anything is unclear, email us via the contact page.
What we collect
We collect only what we need to run the site:
- Account data - when you sign up we store your email address, your display name, and your authentication provider (Google or magic link).
- Trip data - itineraries you build, places you add to your travel log, and preferences you set in the planner wizard.
- Newsletter subscriptions - your email and the date you subscribed.
- Server logs - short-lived request logs (HTTP method, path, status, response time, country) that help us spot outages and abuse.
- Analytics (opt-in) - if you accept analytics cookies in the banner, third-party analytics SDKs (Google Analytics 4 and, where used, PostHog) record aggregated page-view counts, referrer paths, and rough country. We use this to see which articles and features people use. You can change your mind via Cookie preferences in the footer.
- Advertising (opt-in) - if you accept marketing cookies, Google AdSense serves contextual ads on some pages and may use cookies to measure ad performance and frequency- cap. If we run Google Ads, Meta (Facebook/Instagram) Ads or TikTok Ads campaigns, those platforms' pixels are loaded only after consent and report aggregate conversions back to us - never personal data.
How we use it
- To run the planner and save your trips between sessions.
- To send the newsletter you subscribed to (you can unsubscribe in one click from any email).
- To understand which articles and features people use, so we can improve them.
- To measure the performance of advertising campaigns we run, on an aggregate basis.
- To detect abuse and keep the service available.
Legal bases for processing
Under the UK GDPR and EU GDPR, we rely on the following legal bases:
- Contract - to create your account, run the planner, save your trips, and process payments for paid plans.
- Consent - for the newsletter and for analytics/advertising cookies. You can withdraw consent at any time.
- Legitimate interests - to secure the service, prevent abuse, and improve features using aggregate, privacy-respecting analytics, balanced against your rights.
- Legal obligation - to keep limited records (for example payment records) where the law requires.
What we don't do
- We do not sell your data.
- We do not run analytics or advertising trackers before you opt in.
Cookies and similar technologies
We use a small number of strictly-necessary cookies to keep you signed in and protect your account. Analytics and advertising cookies only fire after you accept them in the banner. The full list - including every third-party cookie and SDK we may load on consent - is on the cookies page.
Third-party services
We use trusted infrastructure providers that process limited data on our behalf:
- Supabase - database, authentication, and storage.
- Vercel - hosting, edge delivery, and server logs.
- Google Maps Platform - Maps and Places APIs for location data and photos. Tile requests reveal your approximate IP location to Google.
- Google Identity - “Sign in with Google” (only if you choose it).
- Google Analytics 4 - page-view analytics. Loaded only after consent.
- Google AdSense - contextual advertising on some pages. Loaded only after consent.
- Google Ads - when we run paid campaigns, Google Ads' conversion tracking measures whether visitors from our ads completed key actions. Loaded only after consent.
- Google Search Console - site verification for organic search appearance. Does not collect visitor data.
- Meta Ads (Facebook/Instagram) - if we run paid campaigns on Meta, the Meta Pixel reports aggregate conversions. Loaded only after consent.
- TikTok Ads - if we run paid campaigns on TikTok, the TikTok Pixel reports aggregate conversions. Loaded only after consent.
- PostHog - product analytics for funnel and feature usage, where used. Loaded only after consent.
- Stripe - payment processing for paid plans (we never see your card details).
- Resend - transactional and newsletter email delivery.
- Anthropic - the AI model that generates itinerary suggestions. Your prompts and the resulting routes are sent to Anthropic for processing.
Each provider has its own privacy policy and is contractually required to handle data securely. We pass them the minimum information needed for the feature you're using.
Advertising audiences. We may share a hashed (irreversible) version of your email address with advertising platforms - currently Meta (Facebook/Instagram) and TikTok - so we can reach people like you and avoid advertising to existing customers. The hash is only used for matching; we never sell your data. You can opt out any time by contacting us or through the platforms' own ad settings.
International data transfers
Some of our providers (for example Vercel, Stripe, Google, Anthropic and PostHog) process data on servers outside the UK/EEA, including in the United States. Where data is transferred internationally we rely on appropriate safeguards - such as the UK/EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision (including the UK-US and EU-US Data Privacy Framework where the provider is certified).
Your rights
If you are in the UK or EU, the UK GDPR and GDPR give you the right to:
- Access - download a copy of your data anytime from Settings → Your data → Download my data.
- Portability - that export is structured, machine-readable JSON you can take elsewhere.
- Rectification - correct inaccurate data by editing your profile in Settings, or contact us.
- Erasure - delete your account and personal data from Settings → Delete account (completed within 30 days).
- Restriction & objection - ask us to limit or stop certain processing.
- Withdraw consent - change analytics/advertising choices via “Cookie preferences” in the footer, or unsubscribe from the newsletter in one click.
To exercise any right that isn't self-service, email us via the contact page; we respond within 30 days. You also have the right to complain to your data protection authority - in the UK, the Information Commissioner's Office (ICO) at ico.org.uk.
Data retention
We keep account and trip data for as long as your account is active. If you delete your account from the settings page, we remove your personal data within 30 days. Aggregate, anonymised analytics may be retained indefinitely.
Children
Your JP Adventure is not intended for children under 13. We do not knowingly collect personal data from children. If you believe a child has signed up, contact us and we will delete the account.
Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top will change when we do. Material changes will be announced in the newsletter and on the site.
Contact
Privacy questions or requests: use the contact page.