Legal
Privacy Policy
Last updated: April 25, 2026
What we collect
When you use Vamoz, we collect the minimum data needed to run the app:
- Account: email, name, profile photo (from Google OAuth or magic link).
- Trip data: trip names, destinations, dates, member lists, votes, expenses, payments, bookings, and activity. Visible only to people invited to the specific trip.
- Payment data: handled by Stripe. We store payment intent IDs and amounts, never card numbers.
- Diagnostic data: anonymous error reports via Sentry. No personal data attached.
- Cookieless analytics: aggregate page views via Cloudflare Web Analytics. No tracking cookies, no fingerprinting.
What we don't do
- We don't sell your data. Ever.
- We don't run ad targeting.
- We don't track you across the web.
- We don't share trip data outside your trip members.
Where data lives
All data is stored on Cloudflare infrastructure (D1 SQLite for trip data, KV for sessions, R2 for files). Servers run in multiple US regions. Stripe handles payment processing per their own privacy policy.
Your rights
You can export, modify, or delete your data anytime from your account settings. To delete your account entirely, email privacy@vamoz.app. We respond within 7 days. CCPA and GDPR rights honored.
Contact
Questions? privacy@vamoz.app.