Privacy Policy

Last updated: May 6, 2026

What changed in this update

April 2026 update: Meera is now a planning-only service. We do not handle travel bookings, do not collect passport numbers or other travel documents, do not process payment for travel, and do not share personal information with airlines, hotels, or other suppliers. When you’re ready to book, you go directly to the provider on their site. We’ve removed the data categories and third-party data flows that related to booking and updated this policy to match.

1. Data Controller

Meera (“Meera”, “we”, “us”) is the data controller for personal data processed through the Service at meera.tours. Contact: [email protected].

2. Data We Collect

Data CategoryExamplesPurpose
Account identityName, email, optional time zoneAccount creation, sign-in, sending you your trip
Travel preferencesTravel style (e.g. balanced/packed/leisurely), dietary preferences, accessibility needs, interestsPersonalising the itineraries we generate for you
Trip contentDestinations, dates, day-by-day plans, places saved, notes you writeService delivery — this is the planner
ConversationsMessages exchanged with the Meera planning agentGenerating and refining your itinerary; service improvement
Trip memoriesPast trip summaries you choose to keep, sentiment about places visitedBetter recommendations on future trips
Subscription payment metadataStripe customer ID, subscription status, billing email, invoice historyProcessing Pro / per-trip / Export-to-Agent payments to Meera (card details handled entirely by Stripe — see §8)
Optional integrationsGoogle Calendar OAuth tokens (only if you connect it), passport scan (only if you upload one for visa-helper features)Pulling travel events from your calendar; visa requirements lookup. Both opt-in; revocable any time.
Analytics eventsPage views, button clicks, anonymous funnel events (e.g. “Public Trip View”)Understanding which features actually help users; not used for advertising
TechnicalBrowser type, IP address, session dataSecurity, abuse prevention, performance

3. What We Do NOT Collect

Because Meera is a planning service and you book directly with travel suppliers, we do not collect or store:

  • Credit-card numbers or any payment-instrument details (Stripe handles them on their own infrastructure)
  • Passport numbers, except in the optional opt-in “visa helper” flow where you scan a passport — those scans are processed once and not retained beyond the visa lookup
  • Date of birth or nationality, except to the extent you mention them in a planning conversation; we don’t store them as separate identity fields
  • Emergency contact information
  • Any data needed for airline / hotel / car-rental booking compliance — those exchanges happen between you and the supplier on the supplier’s site, not through Meera

4. Legal Basis for Processing

  • Contract performance: Providing the Meera planning Service you signed up for — storing your trips, generating itineraries, sending you the artifacts you asked for (PDF, share link, etc.).
  • Legitimate interest: Service improvement, fraud / abuse prevention, anonymous analytics.
  • Consent: Marketing emails, optional integrations (Google Calendar, passport scan), analytics cookies where required by law.

5. How We Use Your Data

  • Generate and refine trip itineraries based on your destination, dates, preferences, and conversation
  • Save your trips so you can come back to them, share them, or clone someone else’s
  • Send you trip artifacts (PDF travel guide, share link, calendar export) by email when you request them
  • Send pre-trip reminders (T-14, T-7, T-3, T-1 days) for trips you’ve booked dates on, if you’ve enabled them
  • Process subscription payments via Stripe (Pro $99/yr, per-trip unlock $4.99, Export-to-Agent $19, etc.) — see §8
  • Show you partner suggestions (flights via Travelpayouts, trains via Omio, hotels via Booking, etc.) with affiliate-tracked deeplinks. We do not send your personal data to those partners — only an anonymous click ID — see §7
  • Improve the planner’s accuracy by analysing aggregate trip-creation patterns, never individual users’ trips
  • Detect and prevent abuse (rate-limit excessive automated traffic, daily-spend caps on third-party APIs)

6. Data Storage & Security

Your data is stored in:

  • PostgreSQL: User profiles, trips, conversations, subscription metadata, analytics events. Encrypted at rest by the underlying disk.
  • Redis: Short-lived caches (search results, in-progress chat state) that auto-expire (TTL hours to weeks). No long-term storage of personal data here.
  • On-disk image cache: Photos shown on trip cards are cached server-side after first fetch. The cache stores image bytes only — no user identifier is ever attached to a cached file.

Sensitive opt-in data (e.g. an uploaded passport scan used for the visa-helper feature) is encrypted at the application layer using Fernet symmetric encryption and is purged once the lookup completes. Subscription card details are never stored by Meera — Stripe handles all card processing and is PCI DSS Level 1 compliant.

7. Third-Party Data Sharing

We share data with third parties only as needed to operate the Service. The list below is exhaustive — no other parties receive your personal data.

PartnerData SharedPurpose
StripeEmail (for receipts), subscription / one-time payment amount + currency, customer IDProcessing Pro / per-trip / Export-to-Agent payments to Meera. Stripe handles card data on their own infrastructure.
Google Places (Google LLC)Search query strings (e.g. “best lunch restaurants in Lisbon”) and approximate latitude/longitude for biasing results. No user identifier is included.Looking up real-world places to populate your itinerary
Affiliate partners (Travelpayouts, Omio, Booking.com, World Nomads, etc.)An anonymous click-attribution ID that includes the destination + dates of your trip. No name, email, or other identifier.Tracking that a click came from Meera so the partner can credit us with affiliate revenue if you book on their site. You enter the booking flow on the partner’s site under their privacy policy.
Plausible AnalyticsAnonymous, non-personal page-view and event data (no IP, no cookies, no fingerprinting)Privacy-respecting product analytics. Plausible’s data policy
Email service providerEmail address, content of confirmation / digest / reminder emailsSending you the things you signed up to receive (trip PDFs, reminders, sharing notifications)
CloudflareEdge request data (IP, user agent) for fraud / abuse preventionDDoS protection, bot mitigation, CDN delivery
OpenAI / Anthropic / Google (LLM providers)The contents of your planning conversation, trip preferences, and destination context, in order to generate the itineraryAI itinerary generation. We use these providers under their data-processing agreements; conversations are not used by them to train new models.

We do not sell your personal data to any third party. We do not allow our analytics to be used for ad retargeting.

8. Payment Processing

All payments to Meera (Pro subscription, per-trip travel-guide unlock, Export-to-Agent, gift purchases) are processed by Stripe, Inc. We do not store your credit-card number, CVV, or expiration date. Stripe’s privacy policy governs the handling of your card data. Refunds, where applicable, follow the Meera Refund Policy.

Travel bookings are not processed by Meera. When you click a partner link to book a flight, hotel, train, tour, or insurance plan, you transact directly with that supplier on their site under their privacy policy and terms. Your card details, passport, and other booking data go to them, not to us.

9. Public Itineraries, Sharing & Cloning

When you create a trip, it is private to your account by default. You can optionally:

  • Share with companions via an unlisted invite link. Only people with the link can view; trips are not indexed publicly.
  • Publish publicly on the Meera Trips browse page so other travellers can discover and clone the itinerary as a starting point for their own trip. Public trips show your trip’s destination, dates, day-by-day structure, photos, and the count of how many other travellers have viewed or cloned it. They do not show your name or email unless you explicitly add them to the trip description.

You can revoke a public-share status at any time from your account settings; the trip then immediately stops appearing in the browse page and on search engines (subject to normal search-engine cache delay).

When someone clones a public trip, they get a copy of the itinerary structure (destinations, places, day plan) but not your private notes, messages, or account information. Clone events are counted on the original trip (the clone-count number) but the cloner’s identity is never shared back to you.

10. Cookies & Local Storage

We use essential cookies for sign-in session management. Where required by law, you’ll see a cookie banner on first visit. We use browser localStorage for in-progress trip drafts (the “Explore Planner” saves your work as you go), saved preferences, and minor UI state. No third-party advertising or fingerprinting cookies are set.

11. Data Retention

Data TypeRetention Period
Subscription transaction records7 years (tax / legal requirement for the SKUs Meera processes)
Account profile (name, email, preferences)Until you delete your account, then permanently removed within 30 days
Trips you createdUntil you delete them or your account, then permanently removed within 30 days
Conversation history1 year, then automatically deleted unless you’ve marked specific exchanges as “memories”
Trip memories (sentiment about places visited)3 years, then anonymised and used only in aggregate
Public itinerary view / clone countersIndefinite, but only as anonymous integers — no per-viewer record
Analytics events13 months on Plausible (anonymous), then aggregated
Session data24 hours (auto-expires)
Optional passport scanPurged within 24 hours of the visa-helper lookup that requested it

12. Your Rights (GDPR & equivalents)

If you are in the EU/EEA, UK, or California (CCPA), you have the following rights — and Meera honours them globally regardless of your location:

  • Right of access: Request a copy of all your personal data
  • Right to rectification: Correct inaccurate data
  • Right to erasure: Delete your account and all associated data (subject to the 7-year tax-record retention for any subscription receipts)
  • Right to data portability: Export your data in a machine-readable format (JSON includes your trips, conversations, preferences)
  • Right to restriction: Limit how we process your data
  • Right to object: Object to processing based on legitimate interest
  • Right to withdraw consent: Withdraw consent for any optional processing at any time
  • Right to opt out of sale (CCPA): Not applicable — we don’t sell personal data

How to Exercise Your Rights

  • Data export: Available via your account settings or by contacting [email protected]
  • Account deletion: Available via your account settings. This permanently removes all your personal data from our systems within 30 days, except subscription transaction records retained for tax compliance.
  • Other requests: Email [email protected]. We respond within 30 days (or 45 days for complex requests, with notice).

13. International Data Transfers

Your data may be transferred to and processed in countries outside the EU/EEA / UK (including the United States) where our infrastructure and third-party providers operate. Where this happens, we rely on Standard Contractual Clauses (SCCs) with our processors to ensure equivalent protection.

14. Children’s Privacy

The Service is not intended for children under 16 (under 13 in the United States). We do not knowingly collect data from minors. If we learn we have collected data from a minor, we will promptly delete it. Adults planning a trip that includes minors do not need to enter the minors’ personal data — Meera plans destinations and activities, not airline manifests.

15. Security Incident Notification

In the unlikely event of a personal-data breach, we will notify affected users and the relevant supervisory authority within 72 hours of becoming aware, in accordance with GDPR Article 33-34 and equivalent obligations under other laws.

16. Changes to This Policy

We may update this Privacy Policy periodically. Material changes (new data categories, new third-party recipients, new processing purposes) will be communicated by email to your account address and via in-app notification at least 30 days before they take effect. The “Last updated” date at the top indicates the most recent revision.

17. Contact

For privacy inquiries or to exercise your rights:

  • Email: [email protected]
  • Data Protection Officer: [email protected]
  • EU/UK supervisory authority: you have the right to complain to your local data protection authority. We will cooperate with any inquiry.