Privacy policy
Effective 28 September 2026
Travel STV is published by System Think Van LLC (“we”). This policy says what the app and our servers collect, why, where it is kept, for how long, who else handles it, and how to delete it.
In short
- You can plan without an account. Until you sign in, your trips stay on your device and our servers learn nothing about you.
- When you sign in, your trips are stored on our servers so that they reach your other devices and the people you share them with.
- We don’t sell your data, show ads or track you across other apps and websites. The app has no analytics, advertising or crash-reporting code.
- You can delete your account, and your data with it, from inside the app at any time.
Without an account
The app keeps your trips in its own storage on your device. It asks our servers only whether your version of the app is still supported; that request carries the app’s platform and version and nothing about you, and it is logged like every request (see “Other diagnostic data”). Place search and maps go from your device to Apple (see “Other companies”).
What we collect when you have an account
Each kind of data below is also named the way the App Store’s privacy details name it. None of it is used to track you, and all of it is used only to make the app work.
Email address
In the App Store’s privacy details: Contact Info → Email Address
- What
- The address you sign up or sign in with — with Sign in with Apple or Google, the one they give us (with Apple’s Hide My Email, a relay address). When you invite someone by email address, we keep a fingerprint of that address (a SHA-256 hash) and a masked form such as b•••@example.com, never the address itself. A fingerprint of your own address lets people who know it invite you, unless you turn off “Let people find me”.
- Why
- To sign you in and send your confirmation and password-reset codes; so that people who know your address can invite you; and to show a trip’s owner who has been invited.
- Where
- Your address: our sign-in service (Amazon Cognito). Fingerprints and masked forms: our database (Amazon DynamoDB).
- How long
- Until you delete your account. An invitation expires after 30 days.
- Who handles it
- Amazon Web Services (AWS), and Apple or Google if you sign in with them
Phone number
In the App Store’s privacy details: Contact Info → Phone Number
We don’t ask for your own phone number: you can’t sign in or be invited by one yet, so it is declared ahead of use. A phone number you type into a booking or a place (a hotel’s or a restaurant’s, say) is part of that trip, under “Other user content”. If a later version lets you sign in or be invited by phone number, your number will be handled as an email address is, and this policy will say so before that version is released.
Name
In the App Store’s privacy details: Contact Info → Name
- What
- The name you set in Settings → “You” → “Your name”, which the people on your shared trips see, and which appears on invitations you send. If you sign in with Apple or Google, the name they share (Apple shares it only the first time) is also kept with your sign-in record; the app does not show that one to anyone.
- Why
- So that the people you travel with know who you are.
- Where
- The name you set: our database. The name from Apple or Google: our sign-in service (Amazon Cognito).
- How long
- Until you change it or delete your account. A report someone made about you keeps the name they were shown, for 90 days (see “Other user content”).
- Who handles it
- Amazon Web Services (AWS), and Apple or Google if you sign in with them
User ID
In the App Store’s privacy details: Identifiers → User ID
- What
- The random id that identifies your account to our servers; the username you choose, if you choose one (anyone who knows it can invite you); the ids Apple or Google use for you, if you sign in with them; and the account ids of the people you block.
- Why
- To tie your trips, invitations and settings to your account, and to recognise you when you sign in.
- Where
- Our sign-in service (Amazon Cognito) and our database.
- How long
- Until you delete your account. Afterwards your old id remains only on the records listed under “When you delete your account”, where it leads to nobody.
- Who handles it
- Amazon Web Services (AWS), and Apple or Google if you sign in with them
Other user content
In the App Store’s privacy details: User Content → Other User Content
- What
- Once you are signed in, your trips and everything in them: names, destinations and dates; plans; bookings, with any confirmation numbers, phone numbers, links and notes you add; places, with the names, addresses and map positions you choose and any phone numbers, links and notes you add; packing lists; budgets and expenses, with amounts, categories, who paid and how costs are split; your private “My space” budget, notes and personal expenses; and your settings (home currency, time zone and “Let people find me”). A share link’s random token, which lets anyone who has the link see the trip’s name, destination and dates and nothing else. When you report someone: your account id and theirs, the reason you picked, and what you were shown of them — for an invitation, the trip’s name, place and dates, the sender’s name and when it was sent, and the fingerprint of the address or username it was sent to; for a co-traveller, the trip’s name, their name and their role on the trip. A report never holds text you type.
- Why
- To store your trips and keep them in step between your devices and with the people you share them with; and to act on reports.
- Where
- Our database. While you are signed in, the app also keeps a live connection (AWS AppSync) that tells it a shared trip has changed; those messages carry only ids and are not stored.
- How long
- Until you delete it or your account. Something deleted from a trip is kept 90 days, so every member’s device learns that it was deleted. A report: 90 days.
- Who handles it
- Amazon Web Services (AWS)
Other diagnostic data
In the App Store’s privacy details: Diagnostics → Other Diagnostic Data
- What
- A log line for each request the app makes to our servers: a request id, the method and path (a path holds the ids of trips and items, never their contents), the result and how long it took, your account id when you are signed in, and the app’s platform and version; when something fails on our side, the error. This request log holds no IP address, nothing you write in a trip and no sign-in token, and a share link’s token is removed before a line is written. The first time you sign in with Apple or Google, a line naming that sign-in’s id and the account it was linked to. When the live connection refuses a request (for a trip you are no longer on, say), AWS AppSync logs the refusal: your account id and the trip’s id, and it can also hold the network (IP) address the request came from and, for a trip you were once on, the trip’s name, place and dates.
- Why
- To keep the service working, find and fix faults, and see which versions of the app are still in use before an old one stops being supported.
- Where
- Amazon CloudWatch Logs.
- How long
- 30 days.
- Who handles it
- Amazon Web Services (AWS)
On your device
Your trips live in the app’s own storage on your device, your sign-in in the system keychain, and your app settings with the app. Signing out asks what to do with changes that are not backed up yet. Deleting your account removes that account’s data from the device. Removing the app removes the trips it kept on the device.
What we don’t collect
Your location (the app never asks for it), your contacts, photos, camera, microphone, health or fitness data, payment or card details, browsing or search history, or advertising identifiers. The app has no analytics, advertising or crash-reporting tools.
Other companies
- Amazon Web Services (AWS) runs our servers, our database, our sign-in service (Amazon Cognito), our logs, the live connection and the emails that carry your codes, in the United States. AWS handles this data only to provide those services to us, under terms that require it to protect the data at least as well as this policy does.
- Our email provider hosts the mailbox of the address below, so it holds the messages you send us (see “When you write to us”). It handles them only to provide that service to us, under terms that require it to protect them at least as well as this policy does.
- Apple. If you choose Sign in with Apple, Apple confirms who you are and gives us your email address (or a relay address) and, the first time, your name. Place search and maps: what you type into place search, and the parts of the map the app shows, are requested from Apple by your device. We never receive your searches, only the place you choose, which becomes part of your trip. If you open a place in Apple Maps, the app hands Apple Maps the place’s name and position. Apple’s privacy policy covers what Apple does with them.
- Google. If you choose Sign in with Google, Google confirms who you are, and we keep your name, your email address and whether Google has verified it. We use them only as this policy describes. If you open a place in Google Maps, the app hands its position to Google, in the Google Maps app or on maps.google.com in your browser, and Google’s privacy policy covers what Google does with it.
We share personal data with no one else, never sell it, and never use it for advertising. We disclose it only if the law requires us to. At System Think Van LLC, only the people who run the service can reach it, and only to run it, to answer you and to act on reports.
When you write to us
If you email us, we receive your message, your email address and whatever you include, such as your device’s model or your account’s username. We use them only to answer you, to fix what you tell us about, and to keep a record of what we did. We keep them for as long as that takes, and delete them sooner if you ask. They are kept in our mailbox, with our email provider (see “Other companies”), and never in the app’s database.
Where your data is kept
In the United States. If you use Travel STV from elsewhere, your data is transferred to and stored in the United States. It is encrypted in transit (HTTPS) and encrypted at rest by AWS.
When you delete your account
You can delete your account in the app: Settings → “Account” → “Delete account” (how, step by step). It needs a connection.
Removed from our servers: your sign-in record (your email address, name, username and password, and any linked Apple or Google sign-in); your profile and settings; every trip only you are in; your “My space” and personal expenses; the blocks and reports you made; the invitations you sent and received; and the fingerprints that let people find you. A trip you share passes to whoever joined it first, and they keep everything in it; you leave trips other people own.
What stays, and why:
- A deletion record: your old account id, when it was deleted, and a counter, so that a device still signed in learns the account is gone. Nothing else about you is on it, and it is kept.
- In trips that now belong to other people, what you added or changed stays with the people you shared it with — it is their trip too — marked with your old account id, which leads to nobody. Something you deleted there is kept 90 days so that their devices catch up.
- For a trip you deleted while other people were on it, the record that tells their devices it is gone, which carries the trip’s name, place and dates, for 90 days after you deleted it.
- If you removed someone from a trip you owned, their own record of it, which names you only by your old account id: it tells their device the trip is no longer theirs, and it is kept.
- Rarely, an invitation to an address or username we could no longer match to you: it shows only a masked address or username, nobody can accept it, and it expires within 30 days.
- Rarely, if the last steps of a deletion fail, your sign-in record (your email address, username, a name from Apple or Google, and any linked Apple or Google sign-in) and whatever the deletion had not reached yet stay until the app tries again, which it does by itself whenever it is open with a connection. Every request that sign-in makes is refused meanwhile. If you removed the app before that finished, write to us and we will help.
- A report someone made about you, for 90 days: your old account id and what they were shown of you — for an invitation you sent, the trip’s name, place and dates, your name on it and when you sent it; on a shared trip, the trip’s name, the name you showed then and your role. It is their complaint and our record of it.
- If someone blocked you, their block: your old account id only, in their own records, and no name. It goes when they unblock you, delete their own account, or next open their list of blocked people.
- Our request logs (see “Other diagnostic data”), for 30 days. A line can name another person’s id when you removed, blocked or unblocked them.
- AWS AppSync’s log of the requests the live connection refused, which holds your account id and a trip’s id and can hold more (see “Other diagnostic data”), for 30 days.
- The log line written the first time you signed in with Apple or Google, naming that sign-in’s id and the account it was linked to, for 30 days.
- Our database’s continuous backups, which keep a deleted record restorable for up to 35 days. Nothing reads a backup, and only we can restore one.
Every expiry in this policy happens a few days after its date: that is how the database removes expired records.
Removing Travel STV from your Apple or Google account
Deleting your account doesn’t tell Apple or Google. To stop using Sign in with Apple for Travel STV: on iPhone, open Settings, tap your name, tap Sign in with Apple, choose Travel STV, then tap Delete; or sign in at account.apple.com and go to Sign-In & Security, then Sign in with Apple. For Google: go to myaccount.google.com/linkedapps, choose Sign in with Google, then Travel STV, then See details, then Stop using Sign in with Google.
Doing this alone doesn’t delete your Travel STV account or its data; delete the account in the app for that.
Your choices and rights
- Use the app without an account.
- Turn off “Let people find me” (Settings → “Sharing”), so only your username can be used to invite you.
- Change or remove your name (Settings → “You” → “Your name”), and give up your username (Settings → “Sharing” → “Username”).
- Block or report people.
- Delete your account.
To ask for a copy of your data or to correct it, or to use any right the law where you live gives you (such as access, correction, deletion, portability or objection, or complaining to a data protection authority), write to us; we will answer as that law requires.
Where the law of the European Economic Area or the United Kingdom applies, we rely on performing our agreement with you (your account, sync and sharing), on our legitimate interests in keeping the service secure and working and in acting on reports (logs, reports and blocks), and on our legal obligations.
Children
Travel STV is for a general audience and isn’t directed at children under 13. We don’t knowingly collect personal data from children under 13, or under the age of digital consent where they live. If you believe a child has given us personal data, write to us and we will act on it.
Changes
When this policy changes, the new version is posted here with a new effective date. We won’t use data you have already given us for a purpose this policy doesn’t describe unless you agree to it.
Contact
System Think Van LLC · support@systemthinkvan.com