1. Introduction
Welcome to GoPhuot. We help travelers — particularly backpackers and independent explorers — plan trips, build itineraries, discover destinations, tours, and local dishes, and collaborate with friends along the way. This Privacy Policy describes how we collect, use, store, and share personal information (also called “personal data”) when you use our website, mobile experiences, and related services (collectively, the “Services”).
By using the Services, you acknowledge the practices described here. If you do not agree, please do not use the Services.
2. Who We Are
GoPhuot is an independent project operated by an individual sole operator based in Vietnam. For the purposes of the EU and UK General Data Protection Regulation (“GDPR” and “UK GDPR”), the California Consumer Privacy Act (“CCPA”, as amended by the CPRA), and the Australian Privacy Act 1988, the operator of GoPhuotacts as the controller (or, under California law, the “business”) of your personal information.
You can reach the operator using the contact details in Section 16.
Where required by Article 27 of the EU GDPR or UK GDPR, the operator will designate an EU and/or UK representative. To request the current representative details, contact us at the address in Section 16.
3. Information We Collect
We collect the following categories of personal information (using CCPA categories where applicable):
- Identifiers — name, email address, account username, profile photo, IP address, device identifiers, and third-party sign-in IDs.
- Account credentials — passwords (hashed) or tokens from sign-in providers such as Google, Apple, or Facebook.
- Commercial information — bookings or referrals you initiate to third-party tour and experience partners (we do not process payment card numbers ourselves — see Section 6).
- Internet or network activity — pages viewed, features used, search terms, referring URLs, browser type, OS, language, time spent, and interaction events.
- Geolocation— approximate location derived from your IP, or precise location only if you grant your device’s “Location” permission.
- Audio, electronic, visual information — photos and other media you upload to trips and itineraries.
- Inferences — preferences derived from your activity, used to personalize destination, tour, and itinerary suggestions.
- User-created content — destinations saved, itineraries, notes, packing lists, budgets, comments, collaboration invites, and messages.
Sensitive personal information. We do not intentionally collect sensitive categories such as government IDs, financial account credentials, precise geolocation (without permission), racial or ethnic origin, religion, health data, sexual orientation, or biometric identifiers. If you choose to include such information in your trip notes, you do so voluntarily and we treat it with the same care as other personal information.
4. Sources of Information
- Directly from you — when you register, build trips, contact support, or subscribe to communications.
- Automatically from your devices — through cookies, SDKs, and server logs as you use the Services.
- From third parties — sign-in providers (Google, Apple, Facebook), affiliate and tour-booking partners (e.g. Viator) who confirm referrals, analytics and crash reporting providers, and fraud-prevention services.
5. How We Use Your Information
We use the information we collect for the purposes below. For EEA and UK users, the legal basis (GDPR Art. 6 / UK GDPR Art. 6) is shown in parentheses.
- Operate, maintain, and improve the Services (performance of a contract; legitimate interests).
- Create and authenticate your account; keep the Services secure (performance of a contract; legitimate interests in security).
- Build, sync, and share trips, itineraries, saved places, and collaboration features (performance of a contract).
- Personalize recommendations, including AI-generated suggestions for destinations, tours, dishes, and routes (legitimate interests; consent where required).
- Send transactional messages (confirmations, invitations, password resets) (performance of a contract), and marketing communications (consent — you can opt out at any time).
- Measure usage and product performance, debug issues, and plan new features (legitimate interests; consent for non-essential analytics in the EEA/UK).
- Detect, prevent, and respond to fraud, abuse, and violations of our Terms (legitimate interests; legal obligation).
- Comply with legal obligations and enforce our rights (legal obligation; legitimate interests).
8. AI Features & Automated Decisions
Some features of the Services use artificial intelligence to suggest destinations, build itineraries, recommend tours and dishes, and optimize routes. To do so, we may process your account profile, saved trips, preferences, and interaction history.
We do not make decisions that produce legal or similarly significant effects on you based solely on automated processing (GDPR Art. 22). AI suggestions are inspirational — you decide whether and how to act on them. You can request human review of any AI-driven decision that materially affects your use of the Services by contacting us.
9. Data Security
We use industry-standard administrative, technical, and physical safeguards — including encryption in transit (HTTPS), encrypted storage of credentials, role-based access controls, audit logging, and regular security reviews of our infrastructure. No system is perfectly secure, so we cannot guarantee absolute security.
If we ever experience a personal data breach affecting your information, we will notify you and the relevant supervisory authority as required by applicable law (including GDPR Arts. 33–34, UK GDPR, the Australian Notifiable Data Breaches scheme, and US state breach-notification laws).
10. Data Retention
We keep your personal information for as long as your account is active and as needed to provide the Services. Typical retention periods:
- Account and profile data — for the lifetime of your account.
- Trip content and itineraries — until you delete the content or your account.
- Booking referrals, server logs, and security data — for the lifetime of your account.
- Marketing data — until you withdraw consent or after 24 months of inactivity, whichever comes first.
- Anonymized analytics data — kept indefinitely. It has already been stripped of any link to your account, so it cannot identify you or be traced back to a deleted profile.
When you delete your account, everything tied to it is deleted within 30 days — nothing is retained beyond that except the anonymized analytics data described above. See our account deletion guide for the exact steps and what is removed.
Where we no longer need personal information, we delete or anonymize it.
11. International Data Transfers
GoPhuot operates globally, and your information may be stored and processed in countries other than your own — primarily in regions where our cloud providers operate (such as the United States, Singapore, and the European Union), as well as in Vietnam where the operator is based.
Where we transfer personal data out of the EEA, UK, or Switzerland to a country that has not been deemed by the relevant authority to provide an adequate level of protection, we rely on appropriate safeguards — most commonly the European Commission’s Standard Contractual Clauses and, for UK transfers, the UK International Data Transfer Addendum or the IDTA. A copy of the relevant safeguards is available on request.
Australian users: cross-border disclosures are made consistent with Australian Privacy Principle 8.
12. Your Rights & Choices
Subject to applicable law, you may have the right to:
- Access the personal information we hold about you and receive a copy.
- Correct inaccurate or incomplete information.
- Delete your account and personal information.
- Port your data in a structured, commonly used, machine-readable format.
- Object to or restrict certain processing, including processing based on legitimate interests and direct marketing.
- Withdraw consent at any time, where processing is based on consent. Withdrawal does not affect prior processing.
- Not be discriminated against for exercising your rights.
You can exercise most of these rights directly from your account settings, or by contacting us at the address in Section 16. We will respond within the timeframes required by applicable law (typically within 30 days for the EEA/UK/Australia and 45 days for California, with permitted extensions). We may need to verify your identity before fulfilling a request.
You can also designate an authorized agent to submit requests on your behalf, where permitted by law.
13. Regional Disclosures
13.1 European Economic Area, United Kingdom & Switzerland
In addition to the rights above, you have the right to lodge a complaint with your local data protection authority — for example, the UK Information Commissioner’s Office (ICO) at ico.org.uk, or your national authority in the EEA. We encourage you to contact us first so we can try to resolve your concerns directly.
13.2 California Residents (CCPA / CPRA)
California residents have the right to:
- Know what personal information we have collected, the sources, the purposes, and the categories of third parties we disclose it to (see Sections 3, 4, 5, and 6 above).
- Delete personal information we collected from you, subject to certain exceptions.
- Correct inaccurate personal information.
- Opt outof the “sale” or “sharing” of personal information. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.
- Limit the use of sensitive personal information. We do not use sensitive personal information for purposes that trigger this right.
- Be free from discrimination for exercising your rights.
To submit a verifiable request, contact us at the address in Section 16 or use the in-app account controls. We will not require you to create an account to submit a request.
“Shine the Light” (California Civil Code §1798.83).We do not share personal information with third parties for their direct marketing purposes.
13.3 Other US States
If you reside in a US state with a comprehensive privacy law (such as Virginia, Colorado, Connecticut, Utah, Texas, or Oregon), you have rights similar to those listed in Section 12 and may appeal a denied request by contacting us at the address in Section 16.
13.4 Australia
Our practices are designed to comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). If you believe we have breached the APPs, please contact us so we can investigate. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
14. Children's Privacy
The Services are not directed to children under the minimum age set by applicable law — generally 13 (US/UK/most of the world) or 16 in certain EEA member states. We do not knowingly collect personal information from children below the applicable age without verifiable parental consent. If you believe a child has provided us with personal information, please contact us so we can delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email, by an in-product notice, or by updating the “Last updated” date above, at least 30 days before the change takes effect where required by law. Your continued use of the Services after the changes take effect means you accept the updated policy.
16. Contact Us
If you have questions about this Privacy Policy or how we handle your information, or to exercise any of your rights, please reach out: