TravelSpace

Privacy Policy

This Privacy Policy explains how personal data is collected, used, disclosed and retained in connection with the TravelSpace mobile application and the associated website at www.travelspaceapp.com (together, the “Service”). It also describes the legal bases relied on for that processing and the rights available to you in respect of your personal data.

Effective date

9 September 2026


1. Scope of this Policy

This Policy applies to personal data processed through the Service. It does not apply to the practices of third parties that we do not own or control, including the operators of the platforms through which the application is distributed and the third-party services identified in section 6, each of which processes personal data under its own privacy policy.

In this Policy, “personal data” means information relating to an identified or identifiable natural person. “Processing” means any operation performed on personal data, including collection, storage, use, disclosure and erasure. “You” means the individual to whom the personal data relates.

By creating an account you confirm that you have read this Policy. Where processing is stated below to rest on consent, that consent is requested separately and may be withdrawn as described in section 11.


2. Data controller

The controller responsible for the processing described in this Policy is the operator of TravelSpace. The controller's legal name, registered address and privacy contact details are set out in section 15. Where this Policy refers to “we”, “us” or “our”, it refers to that controller.

We have not appointed a Data Protection Officer, and are not required to do so on the basis of our current processing activities. Enquiries should be directed to the contact given in section 15.


3. Categories of personal data we collect

3.1 Account and profile data. When you create an account we collect your email address, your name, your username, your date of birth, and the home location you select together with its geographic coordinates. Each account is assigned an internal identifier to which all other records are associated. The following are optional and are collected only if you choose to provide them: a telephone number, a short biography, a profile photograph, and stated travel interests.

3.2 Photograph metadata and precise geolocation. With your permission, the application reads your device photograph library. The application only reads that library; it does not modify, move or delete any item within it. The processing operates on the metadata already embedded in each photograph, namely the capture timestamp and the recorded geographic coordinates. Those coordinates constitute precise geolocation data. Where a photograph is associated with a trip, its coordinates and timestamp are transmitted to and stored on our servers for two purposes: to restore the structure of that trip following a reset of local storage or a reinstallation of the application on the same device, and to make the contents of a shared trip available to the other participants of that trip. Those records identify each photograph by an identifier assigned by the operating system which has meaning only within the library it came from, and they do not constitute a transfer of your trips to a different device. Where you participate in a shared trip, the other participants of that trip may read the coordinates and capture times you contribute to it.

3.3 Photographic content. The image content of a photograph is transmitted to us only in the following circumstances, each of which requires an affirmative act by you: where you publish the photograph to a location; where you designate it as your profile photograph; and where you attach a screenshot to a support report under section 3.6. Publication is to a location only. There is no facility by which a photograph may be published to a trip, and the participants of a shared trip exchange metadata rather than image content. In all other cases the image content remains on your device, save that the application provides a facility by which you may share a summary image of a trip, which may include a cover photograph, through the sharing functions of your operating system; where you do so the recipient is determined by you and the image is not transmitted to us. Where you exclude a photograph from processing, the identifier assigned to that item by the operating system is retained so that the exclusion persists.

3.4 User-generated content. We process the content you create through the Service, including your trips and the stops within them, journal entries, published photographs, saved and visited locations, and your connections to and blocks of other users.

3.5 Contact data (hashed). Where you elect to use the contact-matching feature, telephone numbers in your device address book are converted on your device into SHA-256 hash values before any transmission occurs. Neither the telephone numbers themselves nor the associated names are transmitted to us. The hash values are compared against values derived from telephone numbers that other users have added to their own accounts, and are then discarded; no record of the submitted values is created. We do not maintain a copy of your address book. We draw your attention to the fact that hashing a telephone number does not render it anonymous: the range of possible telephone numbers is small enough that a determined party in possession of the application could derive the original number from its hash. This is the reason the submitted values are discarded rather than stored.

3.6 Diagnostic and support data. Where you submit a support report, that report may contain a screenshot of the screen then displayed, a log of the session, a description of the application state, an enumeration of the interface elements then on screen, the stage of processing that had been reached, your device model, your operating system version and the application version. Where the application has terminated unexpectedly, become unresponsive, or exceeded a processing-time or disk-writing threshold set by the operating system, the diagnostic report generated by that system is transmitted. Two mitigations apply. First, the session log, the description of application state, the enumeration of interface elements and the operating system diagnostic report are each filtered to remove email addresses, authentication tokens and application programming interface keys; that filter is not applied to free text you type into a report yourself, which is transmitted as you wrote it. Second, the enumeration of interface elements records the label of an element only where that label matches a fixed list of application chrome, so that content you have authored, such as the title of a trip or the name of a location, is not carried within it. Screenshots are not subject to that filtering, as it cannot be applied to image data; accordingly, a screenshot is included only in a report you have submitted yourself, and a report generated automatically following an unexpected termination contains no screenshot.

3.7 Device and technical data. Where you enable notifications, the operating system issues a device token which is stored in association with your account for the purpose of delivering those notifications. That token is the only device identifier we store. The application contains no advertising identifier.

We do not knowingly collect special categories of personal data within the meaning of Article 9 of the General Data Protection Regulation, and we do not request such data.


4. Sources of personal data

Personal data is obtained from the following sources: directly from you, where you provide it in the course of registration or use; from your device, where you have granted the relevant operating system permission; and from other users, where they publish content to a shared trip on which you are a participant or otherwise interact with your account.


5. Purposes of processing and legal bases

Where the General Data Protection Regulation or the United Kingdom General Data Protection Regulation applies, we rely on the following legal bases.

We do not process personal data for advertising purposes, and we do not carry out advertising profiling. Trip detection involves the automated analysis of photograph metadata, which is performed on your device; it does not constitute a decision producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22.


6. Disclosure of personal data

We do not sell personal data and we do not disclose personal data to data brokers. Personal data is disclosed only as set out below.

6.1 To other users. A photograph you publish to a location is displayed to other users viewing that location; no other element of the associated trip is published with it, and withdrawing publication removes both the stored file and the corresponding record. A trip you share is accessible to the participants of that trip, whose own photographs and journal entries are stored within the same trip. The extent to which your remaining activity is visible to your connections is determined by settings within the application, which are enforced on our servers rather than by the requesting client.

6.2 To processors and service providers. We engage the following third parties, each of which processes personal data on our behalf or, where indicated, as an independent controller:

6.3 Legal and corporate disclosures. We may disclose personal data where required to do so by law, where necessary to respond to a valid request from a public authority, or where necessary to establish, exercise or defend legal claims. In the event of a merger, acquisition or transfer of assets, personal data may be transferred as part of that transaction, subject to the continued application of this Policy or a successor policy affording equivalent protection.


7. International transfers

The third parties identified in section 6 operate infrastructure in multiple jurisdictions, and personal data may accordingly be transferred to and processed in countries other than your country of residence, including the United States. Where personal data is transferred out of the European Economic Area or the United Kingdom, that transfer is made on the basis of an adequacy decision of the European Commission or, in its absence, standard contractual clauses adopted by the European Commission, together with such supplementary measures as are appropriate.

You may request further information about the transfer mechanisms applicable to a particular recipient by contacting us as set out in section 15.


8. Deletion of your account

You may delete your account at any time from within the application, under Settings in the You tab. Deletion removes your profile, your journal entries, the photographs you have published, your profile photograph, your saved locations, your connections, your blocks, your invitations, your notification token, your support reports and your authentication credentials. A trip of which no other participant remains an active member is deleted with the account. A trip of which one or more other participants remain active members is not deleted: control of that trip passes to the remaining participant who joined it earliest, who may keep it or delete it. The dates recorded for a trip are not altered by that transfer of control, and whether the trip is treated as past or forthcoming continues to be determined solely by those dates. Journal entries and photographs contributed by other participants are not erased on your instruction. Server-side records are removed first, followed by the copy held on your device. Deletion cannot be reversed.

The application attempts, at the time of deletion, to remove the files underlying your published photographs and your profile photograph. That attempt is not a condition of deletion completing. Where the attempt does not succeed, or where the account is deleted by us rather than from the application, those files are identified as having no remaining owner and are designed to be removed by a scheduled server-side process. Photographs held in your device library are unaffected, as they are not transmitted to or held by us.


9. Retention periods

Account, profile and user-generated content is retained for as long as your account remains open, and is erased on deletion of that account in accordance with section 8.

Support and diagnostic reports described in section 3.6 are subject to two retention periods. Each is enforced by a scheduled process within the database itself, which runs nightly, rather than by the application or by any act of ours. Erasure accordingly takes effect on the first scheduled run following the expiry of the relevant period rather than at the instant of expiry, and each run is bounded, such that any accumulated backlog is worked through over successive runs.

The evidence attached to a report is erased once ninety days have elapsed since the report was submitted. That comprises any screenshot you attached, the session log, the diagnostic report generated by the operating system, the enumeration of interface elements, the record of a photograph scan and the description of application state.

The report record itself is deleted once three hundred and sixty-five days have elapsed since submission. That comprises the text you wrote, the severity, the screen the report was filed against and the values by which recurrences of the same defect are grouped together.

Deletion of your account erases any report of yours that neither period has yet reached, as provided in section 8.

Hash values submitted for contact matching are not retained, as described in section 3.5. Records necessary for the establishment, exercise or defence of legal claims, or for compliance with a legal obligation, may be retained for the period required for that purpose.


10. Security of processing

We implement technical and organisational measures appropriate to the risk presented by the processing. Every database table containing user data is subject to row-level security, such that the database, rather than the requesting client, determines which records a given request may reach.

Your email address, your telephone number, the hash values derived from that number and your date of birth are not readable by other accounts. That restriction is imposed at the database level through column-level privileges, and does not depend on the correct behaviour of the application requesting the data.

The storage location holding published photographs is private, and each read from it is subject to an authorisation check which fails where the request carries no authenticated session. The storage location holding profile photographs is, by contrast, a public one: an object within it may be retrieved by any party able to construct its address, which is derived from the account identifier, without an authenticated session. That is a deliberate decision, taken because time-limited addresses expire and cannot be cached durably on the device, and it means that a profile photograph should be regarded as accessible to any person who obtains or derives its address. Data in transit is encrypted using transport layer security.

No method of transmission or storage is entirely secure, and we do not warrant absolute security. Where a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, you, within the periods prescribed by applicable law.


11. Your rights

Subject to the conditions and exceptions provided by applicable law, you have the following rights in respect of your personal data:

Rights other than erasure and rectification are exercised by written request to the contact given in section 15. We do not presently provide an automated facility for access or portability requests; such requests are fulfilled manually. We will respond without undue delay and within the period required by applicable law. We may request information reasonably necessary to verify your identity before acting on a request, and may decline a request to the extent permitted by law, in which case we will state our reasons.


12. Notice to residents of California

This section supplements the foregoing and is provided under the California Consumer Privacy Act as amended by the California Privacy Rights Act.

Categories collected. In the twelve months preceding the effective date of this Policy, we have collected the following categories of personal information: identifiers, including name, electronic mail address, telephone number and account identifier; internet or other electronic network activity information, in the form of the diagnostic and support data described in section 3.6; geolocation data, including precise geolocation derived from photograph metadata; audio, electronic, visual or similar information, in the form of photographs you publish; and other information you provide, including date of birth and stated travel interests. The categories of sources, the purposes of collection and the categories of recipients are as described in sections 4, 5 and 6 respectively.

Sensitive personal information. Precise geolocation constitutes sensitive personal information. We process it solely for the purpose of providing the Service, namely the identification and presentation of your trips. We do not use or disclose it for the purpose of inferring characteristics about you.

No sale or sharing. We do not sell personal information, and we do not share personal information for the purposes of cross-context behavioural advertising. We have not done so in the twelve months preceding the effective date of this Policy. We do not knowingly sell or share the personal information of consumers under sixteen years of age.

Rights. You have the right to know, to delete, and to correct personal information; the right to limit the use and disclosure of sensitive personal information; and the right not to receive discriminatory treatment for exercising any of these rights. These rights may be exercised as described in section 11. An authorised agent may submit a request on your behalf on provision of evidence of authority.


13. Advertising and tracking

The Service contains no advertising and no advertising network. We operate no analytics of our own. We do not track you across applications or websites owned by other companies, and the privacy manifest accompanying the application declares no tracking and lists no tracking domains. The collection carried out by Google described in section 6.2 is not conducted for our purposes and is not received by us.


14. Children

The Service is not directed to children and is not intended for them. Registration requires a date of birth, and an account cannot be completed where the date given indicates an age below seventeen years. That threshold is applied uniformly in every territory in which the Service is offered.

Seventeen years is not a figure required by data protection law. Article 8(1) of the General Data Protection Regulation permits each Member State to set, at between thirteen and sixteen years, the age below which the consent of the holder of parental responsibility is required for an information society service. The threshold applied here is above the highest of those figures, with the consequence that the parental consent condition in Article 8 does not arise in any Member State. The figure corresponds to the age rating under which the application is distributed.

Until the effective date of this Policy the threshold was thirteen years. An account registered under that rule may therefore belong to a person aged between thirteen and sixteen who registered legitimately at the time. Such accounts continue in existence, are not suspended and are not closed by reason of the change, and no age condition is applied to an account once it has been created. The higher threshold governs registrations made on and after the effective date.

No account has been registered on a date of birth indicating an age below thirteen years. We do not knowingly collect personal data from a person below the threshold in force at the time of registration, and where we become aware that such data has been collected we will erase it. A parent or guardian who believes that a child has provided personal data to us should contact us as set out in section 15.


15. Contact

Requests concerning your personal data, and enquiries concerning this Policy, should be addressed to info@doublethr33s.com. Requests under sections 7, 11 and 12 should be directed to that address.

Placeholder. The controller's registered legal name and registered address have not yet been established. Replace this paragraph with those particulars.


16. Amendments to this Policy

We may amend this Policy from time to time. The effective date at the head of this document records the date of the current version. Where an amendment materially affects the processing of your personal data, we will provide notice by a means appropriate to the circumstances, which may include notice within the application or by electronic mail to the address associated with your account, before the amendment takes effect. Continued use of the Service following the effective date of an amendment constitutes acknowledgement of the amended Policy.