Privacy

Last updated: 14 September 2026

You can use the public planning tools without creating a visitor account or providing an email address or phone number. If you join a Group Trip Decision Room, you choose a short display label; use a nickname rather than your full name. This page explains what the app records, including room participation and optional feedback.

Who operates My Travel Choices

My Travel Choices is operated by Osamah Albelaikhi in an individual capacity. He is responsible for deciding how the service uses personal data and for handling privacy requests.

What is recorded

The app records first-party usage events, optional feedback, and the trip setup and participant responses submitted to a Group Trip Decision Room. It also stores values in your browser so the tools can work. Hosting, security and database providers receive request data needed to deliver the service. Private owner and invited-tester areas have separate restricted activity.

Calculating recommendations and estimates

To calculate recommendations and estimates, the planning tools send trip inputs to the application server. Depending on the tool, these include your selected destination and departure location, budget and currency, travel dates or month, trip length, group size, travel style and preferences, including interests you type into a planning tool. These calculation inputs can be more precise than the coarse ranges stored in usage analytics. The server uses them to return results. A temporary counter derived from an IP address limits repeated computation requests; its identifier is pseudonymous, not anonymous. Hosting and network providers also process request data, and their retention arrangements are under review.

First-party usage events

We record events such as opening the questionnaire, reaching a step, viewing results and opening a destination. Each event carries random technical identifiers, your interface language, the page, whether you are on mobile or desktop, and coarse bands of your answers (for example a budget range rather than an exact figure). We describe these identifiers as pseudonymous rather than anonymous, because the same random value can link several events from the same browser.

Hosting-platform analytics

The hosting platform also offers separate website analytics, which sent a full page address, referring page, browser user-agent, language and a country estimate derived from the browser time zone to a hosting analytics endpoint, using its own session-id cookie with a 30-minute lifetime. That feature was switched off on 14 September 2026, and pages loaded after the change no longer deliver its script. Switching it off does not delete measurements the platform already collected, and a tab left open from before the change may keep running the earlier script until it is reloaded. We cannot verify what, if anything, that endpoint would still accept from a request sent directly to it. This platform measurement was always separate from the app’s own first-party events, which were unaffected, and from the Google Analytics choice.

The identifiers we use

A session identifier is created randomly for the browser tab you are using and stops applying when that tab is closed. A separate random visitor identifier is stored in that same browser and currently has no fixed expiry; it is used only to recognise that a visit comes from a browser we have seen before. Neither identifier is derived from anything about you: they do not identify you across devices or browsers, they do not use your name or any contact detail, and they are never used to build an advertising profile or to target advertising.

What first-party analytics does not store

First-party analytics stores no name, email or phone number. It stores no exact budget figure, no exact origin city, no GPS or precise location, no advertising identifiers and no raw match scores.

Optional feedback

If you answer “Was this useful?” we store your Yes or No, your optional comment, which page you were on, the destination if relevant, and your language. Feedback can carry the same random tab session identifier as your usage events, so it can be linked to that session. It is not linked to a visitor account, but a comment can contain personal information if you enter it. Please do not include names, contact details or other personal information.

Group Trip Decision Rooms

Rooms store the shared trip setup, including the departure city, travel month or dates, duration, group size and currency, together with participant identifiers, chosen display labels and responses such as budget bands, interests, preferred destinations and deal-breakers. Other people with access to the room can see the shared setup, display labels, response status and group results, including display labels of participants whose constraints affect a recommendation. The app returns your own full response to you, but does not return other participants’ full individual responses. Group results can still reveal preferences in a small group. A nickname can identify you to people who know you. Once responses close, each traveller can pick one destination from the shortlist; those picks are shared with the group, while the answers behind them are not. Anyone who answered can also create a view-only result link: it shows the shortlist, the named constraint summary and the picks, and it can never see anyone’s answers or write anything. Access credentials are kept in your browser so you can return to your group; share only the invitation link intended for participants.

Room access expires 30 days after creation. Expired records are removed through subsequent cleanup activity, so expiry does not mean that every stored copy disappears at that exact moment. The organizer can also delete the room. This is separate from the general usage-event and feedback retention process described below.

Invitation and view-only result links carry their access code after the “#” in the address. Browsers keep that part out of the request they send and out of the referring-page header, but it stays readable by code running in the page. Our own measurement records the page path only — never the query, never the part after “#”. Google Analytics is switched off in this version of the app and loads nothing and sends nothing; if that ever changes we will say so here first. Older invitation links carried the code in the visible address instead: they still work, and the app removes the code as soon as the page opens, but that cannot undo the request your browser already sent, or erase history entries or logs written earlier. A link that is incomplete, damaged or carries two different codes is refused rather than opening some other trip. While you are joining, the code waits in this tab only, for up to 30 minutes; it is never turned into membership by itself. Only after the server confirms your join, or confirms a view-only result link, is anything saved in your browser to let you return. If your browser blocks or refuses storage, the waiting code may not survive a reload, and we cannot promise a stored value has been deleted when the browser refuses to delete it. Anyone holding a working link can use it until the organizer replaces or revokes it.

Approximate location used to suggest a starting point

When you open a planning tool, we may use the approximate city or country that the network layer already attaches to your request to suggest a departure city. My Travel Choices does not store your IP address for this feature, never asks your browser for precise location, never saves the suggestion in our database and never sends it to analytics. Only the suggested departure city or country is kept inside your own browser for the current session, and it disappears when the session ends. It is a suggestion, not a statement about where you live: you can change the departure city at any time. This describes our own handling only and makes no promise about the request logs of the hosting and network providers listed below.

Cookies and browser storage

Our own measurement sets no cookies. Your language choice, your questionnaire answers, your saved searches and your analytics choice are stored in your own browser so the app can remember them. In addition to the hosting analytics cookie described above, platform cookies previously observed in production include: __cf_bm, set by Cloudflare for bot management and lasting roughly 30 minutes, and __dpl, used by the hosting layer to pin a deployment and lasting roughly 24 hours.

Who technically receives data

The hosting and database services used by the app include Lovable (hosting), Cloudflare (network and security) and Supabase on AWS, with the database recorded in the eu-west-3 Paris region. These providers can receive your IP address, user-agent and other request metadata while delivering the service. The app’s fonts are served from the site itself; the font styles no longer request files from Google Fonts. Provider retention and the arrangements for processing outside Saudi Arabia are being reviewed.

Some of this we checked ourselves, and some the hosting provider told us. Verified by us on 14 September 2026: the database region is recorded as Europe (Paris), no file storage exists, and no scheduled database jobs are configured; what the providers run internally is not visible to us. Repeated here as their statement rather than as something we verified: a data-processing agreement applies automatically, app-user data is excluded from model training, database backups stay in the same region, are taken roughly daily and kept about fourteen days with whole-database restore only, and their AI gateway is entered in the EU but may process in the United States. The provider did not say how long prompts, audio, outputs, support records or logs are kept, or where, and offered no Saudi-specific safeguards. None of this is a compliance clearance; a written clarification sent on 14 September 2026 is still unanswered.

Assistant connector requests

My Travel Choices has prepared a connector that lets an AI assistant reach two of its tools. The public connector endpoint is currently switched off, so no assistant request is being answered today; this section describes how it behaves if we turn it on. Two tools would be exposed: a destination comparison, which receives the two destinations and the language, and a trip cost estimate, which receives the calculator’s own structured inputs — destination, origin country and departure metro, trip length, travel month and year, party size, travel style, currency and whether flights are included. These are the same inputs the website tool uses, and the same server computation answers both.

We do not ask for, and the tools do not use, your conversation, your name or your account. We cannot promise that we never receive anything else: a request payload is sent by the assistant, not by us, so it can technically contain text beyond the declared fields, and the hosting and network providers described above receive request metadata, including an IP address, in the ordinary course of delivering the endpoint. Anything outside the declared fields is rejected by input validation and is not used to produce an answer.

Connector requests write nothing to our database: no usage event, no feedback record and no stored copy of the request. The app keeps only a short-lived counter in server memory, derived from the caller’s address, to limit how many tool calls a single server instance answers per minute; it is discarded when that instance restarts. This is the app’s own handling. Operational request logging by the hosting and network providers is separate, is outside our control, and its retention is under review rather than confirmed. No conversation text and no audio is collected.

Google Analytics

Google Analytics is currently held off in this version of the app. When this version is published, the integration will not load, will not run and will send nothing at all — not even for people who accepted it before. Any choice you made earlier is kept as it is, and nothing is deleted from the Google account or its past records. It can only be turned back on after a separate review of the Google property’s own settings and of what the browser actually sends.

Because the integration is held off, there is nothing to switch on or off here at the moment. Our own usage measurement is separate and continues as described above.

How long data is kept

The general retention policy targets 180 days for raw first-party usage events, 365 days for feedback and 730 days for stored Search Console summary records, counted in whole UTC days. When checked on 14 September 2026 this cleanup was still switched off and had never been activated, so those figures are proposed cutoffs, not a promise that anything is being deleted at those ages. Some owner, test and quarantined records are excluded from the process. Its planned clearing of inactive visitor identifiers concerns database records; the random visitor identifier stored in your browser currently has no fixed expiry.

If that cleanup is ever activated, one limit is worth stating plainly. Counts of distinct people are not additive: daily totals of distinct browsers cannot be added up to recover how many distinct browsers were seen across a longer period. So once identifier-level rows are deleted, a future count of distinct people covering the deleted period cannot be rebuilt from the summaries that remain, and any report reaching further back than the retention period would be labelled as limited by retention rather than restated as a smaller number.

Why we collect it

Usage events help us understand where visitors stop and whether the tools are useful. Optional feedback helps us investigate problems and improve the service. Room setup and participant responses are used to provide the shared planning tool and calculate group results. Browser storage remembers your choices and room access, while request data supports delivery and security.

Your privacy rights

You can use the contact details below to ask about your personal data, request access or a copy, ask for corrections or deletion, or withdraw consent where processing relies on it, in accordance with applicable requirements. We may need limited information to locate the relevant records and verify that they concern you. We will protect other participants’ information when responding. Do not send passwords, verification codes or private room access links.

Contact

Questions about this page or the app? Write to support@mytravelchoicesapp.com. Privacy requests will be handled in accordance with applicable requirements.

Back to home