Skip to content

Legal

Privacy Policy

This policy explains what personal data Embirea collects, why, who we share it with, and the choices and rights you have. We've tried to keep it readable - not buried in legalese.

Last updated 21 June 2026

1Who we are

Embirea (“Embirea”, “we”, “us”) provides a collaborative travel-planning platform: itineraries you build with friends, a shared travel fund, smart local tips, and bookings with vetted local suppliers. For the purposes of the EU General Data Protection Regulation (GDPR) and equivalent laws, Embirea is the data controller of the personal data described in this policy.

You can reach our privacy team at [email protected] for anything relating to your data.

2What information we collect

Information you give us

  • Account details - your name, email address and password (stored only as a salted hash), plus any profile photo or display name you add.
  • Trip content - the destinations, dates, day-by-day items, notes, collaborators you invite, and the role you give them (owner, editor, viewer).
  • Travel fund & payment data - your contributions, the wallet you link (Revolut or PayPal), and the ledger of who paid in and what was booked. We do not store full card numbers - see section 6.
  • User-generated content - public itineraries you publish, articles (“stories”) you write, food reviews, ratings and helpful votes.
  • Supplier / partner details - if you register a business: company name, contact email, category, service area and listings.
  • Support & messages - anything you send us, including conversations with our in-app assistant.

Information we collect automatically

  • Usage data - pages and features you use, searches you run, and actions you take, so we can improve the product.
  • Device & log data - IP address, browser type, device and operating system, timestamps, and referring pages.
  • Cookies & similar technologies - see our Cookie Policy.
  • Approximate location - derived from your IP or the destinations in your trip, used to show relevant places, hours and supplier deals.

3How we use your information

  • To create and run your account and let you plan trips with others.
  • To operate the travel fund: process contributions, top-ups and supplier bookings.
  • To generate smart tips, opening-hours warnings and supplier deals matched to your plan.
  • To power the in-app AI assistant when you choose to use it.
  • To publish the content you choose to make public, and to moderate it.
  • To provide support, send service messages, and (with your consent) product updates.
  • To keep Embirea secure, prevent fraud and abuse, and meet legal obligations.
  • To analyse and improve the product, in aggregated or de-identified form where possible.

5Who we share your information with

We never sell your personal data. We share it only as needed to run Embirea:

  • Trip collaborators - people you invite can see the shared itinerary, fund ledger and your display name.
  • Payment providers - Revolut and PayPal process wallet linking and money movement under their own privacy policies.
  • Suppliers - when you book, we share the details needed to fulfil it (e.g. names, dates, party size). Anonymised, aggregated demand may be shared so partners can plan availability.
  • Service providers - hosting, mapping (Google Maps), analytics and our AI provider, acting as processors on our instructions.
  • Legal & safety - authorities where required by law, or to protect the rights and safety of users and the public.
  • Business transfers - if Embirea is involved in a merger or acquisition, data may transfer as part of that transaction.

6Payments and the travel fund

The travel fund is powered by regulated payment providers. When you link a wallet, you are authenticated directly by Revolut or PayPal; Embirea receives confirmation and a token, never your full card number, CVV or banking credentials. We store the record of contributions, top-ups and bookings so your crew has a transparent ledger, and we process those records to settle who owes whom.

Your money stays within your linked wallet until you authorise a contribution or booking. Provider fees and refund timelines are governed by the provider and the supplier you book with.

7The AI assistant (Aria)

When you chat with our in-app assistant, the messages you send - and the trip context you choose to share with it - are processed to generate a response. Where the assistant runs on a third-party model provider, that content is sent to the provider solely to produce your reply, under contractual terms that prohibit using it to train their models. If no AI key is configured, a built-in rule-based assistant answers locally instead. Please don't paste sensitive personal data into the assistant.

8International data transfers

Embirea is operated from the European Union. Some of our providers may process data outside the EU/EEA. Where that happens, we rely on appropriate safeguards - such as an adequacy decision or the European Commission's Standard Contractual Clauses - so your data keeps an equivalent level of protection.

9How long we keep your data

We keep personal data only as long as needed for the purposes above. Account and trip data are retained while your account is active; financial records are kept for the period required by tax and accounting law (typically several years). When data is no longer needed, we delete or anonymise it. You can delete your account at any time, subject to records we must retain by law.

10Your rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you, and receive a copy.
  • Rectify inaccurate or incomplete data.
  • Erase your data (“right to be forgotten”) where it no longer needs to be kept.
  • Restrict or object to certain processing, including direct marketing.
  • Port your data to another service in a structured, machine-readable format.
  • Withdraw consent at any time, without affecting prior processing.
  • Lodge a complaint with your local data protection authority (in Greece, the Hellenic Data Protection Authority).

To exercise any of these, email [email protected]. We'll respond within the timeframe the law requires (usually one month).

11How we protect your data

We use encryption in transit, access controls, hashed passwords and the principle of least privilege to protect your data. No system is perfectly secure, but we work hard to keep yours safe and will notify you and the relevant authority of a qualifying breach as the law requires.

12Children

Embirea is not intended for children under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

13Changes to this policy

We may update this policy as the product and the law evolve. We'll change the “last updated” date above and, for material changes, give you reasonable notice in the app or by email.

14Contact us

Questions, requests or complaints about your privacy? Email [email protected]. For everything else, see our Terms of Service and Cookie Policy.

Questions?

If anything here is unclear, write to us at [email protected] and we'll be glad to help.