Privacy Policy
Last updated 3 August 2026
Draft — pending legal review. This policy describes what the product actually does with your data, written from the system itself. It has not yet been through legal review and should not be relied on as legal advice.
What we collect, and why
Your account
When you sign up we create an account in Amazon Cognito. It holds your email address and, if you choose to provide them, your phone number, your given and family name, and your locale (the language and region your device reports). Email and phone can both be used to sign in and to recover the account, so they are also used to send you verification codes. You can turn on multi-factor authentication, in which case we also send codes to your phone.
You can use parts of the app before you sign up. In that case you are given an anonymous guest identity rather than an account, and anything you create is held against that identity until you sign up.
What you put in a trip
Your itineraries and everything in them: destinations, flights, accommodation, car hire, activities, dates and times, place names and map coordinates, costs and budgets, your own notes, and checklists. If you invite someone to a trip, we record that you and they are on that trip together.
Documents you upload
Files you attach to a trip — tickets, booking confirmations, passports and visas if you choose to store them there — are held in Amazon S3. We do not ask you to upload identity documents, and you should only store what you are comfortable storing.
Booking emails you forward
Each trip has its own inbound email address. If you forward a booking email to it, we receive the whole message — sender, subject, body and every attachment — and read it to fill in your trip. Booking emails routinely contain your full name, booking references, seat and room numbers and payment summaries, so please forward only what you want stored. See how forwarded email is processed below.
Your device
If you allow notifications, we store a push notification token for your device so we can send trip alerts. If you allow location access, the app reads your approximate location on the device to put nearby places first when you search for a destination; we use it for that search and do not keep a history of where you have been.
How forwarded emails and documents are processed
This is the part of the product most worth reading carefully, because it involves automated systems reading your travel documents.
- You forward a booking email to your trip’s address. Amazon SES receives it and writes the raw message, attachments included, to a private Amazon S3 bucket.
- Attachments are sent to Amazon Textract, which converts the document into text.
- That text is sent to Amazon Bedrock, running the Amazon Nova Lite model, which picks out the flight, stay, car hire or activity details and returns them as structured data.
- The extracted details are added to your trip for you to review and correct. Nothing is booked, paid for or sent on your behalf.
Both Textract and Bedrock are Amazon Web Services products and are used here as processors on our behalf. The raw forwarded messages in that S3 bucket are automatically deleted 30 days after they arrive; the details extracted from them stay in your trip until you delete them or your account.
Who we disclose your information to
We use the following providers to run the service. We disclose to them only what each one needs.
- Amazon Web Services (AWS) — hosts the entire service: your account (Amazon Cognito), your trips, your uploaded documents and forwarded emails (Amazon S3), and the document processing described above (Amazon Textract and Amazon Bedrock). Amazon SES sends and receives our email.
- Stripe — processes payments when you buy an itinerary from the marketplace. You enter your card details with Stripe, not with us; we never see or store your card number. We receive your email address, the amount, the currency, any tax calculated and enough of a reference to match the payment to your purchase.
- RevenueCat, together with the Apple App Store and Google Play — manage subscriptions and one-off purchases made in the app. The store takes the payment and tells RevenueCat whether your subscription is active; RevenueCat identifies you by your account identifier, or by an anonymous identifier if you have not signed up yet.
- Google — provides the maps and the place search. When you search for a place or view a map, your query and the map request go to Google Maps and Google Places.
- Mixpanel — receives product analytics: which screens are opened and which actions are taken in the app, tied to your account identifier. We use it to understand what is used and what is broken.
- Expo — delivers push notifications to your device, which requires sending your push token and the message to Expo and on to Apple or Google.
- Google Analytics — used on this website only, and only when it is switched on for the deployment you are viewing. It is never used inside the app. IP addresses are anonymised.
We may also disclose information where the law requires it, or to establish or defend a legal claim. We do not sell your personal information, and we do not disclose it to third parties for their own advertising.
Some booking links in the app are affiliate links. If you follow one, the provider knows you arrived from us and we may earn a commission on a booking you make. We do not send them your personal information, and what you do on their site is covered by their privacy policy, not this one.
Your information is held overseas
We are based in Australia, but the service runs in Amazon Web Services’ us-east-1 region in the United States. Your account, your trips, your uploaded documents and the emails you forward are all stored and processed there, not in Australia.
Several of the other providers named above — Stripe, RevenueCat, Google, Mixpanel and Expo — also operate outside Australia and may hold or process your information in the United States or elsewhere.
This is an overseas disclosure under Australian Privacy Principle 8. By using the service you are giving your information to a system that holds it overseas. Overseas providers are not bound by the Australian Privacy Principles, and you may not be able to seek redress under the Privacy Act 1988 against a provider for something it does with your information overseas.
When you publish a trip to the web
Publishing is entirely your choice, it is off until you turn it on, and only the trip’s owner can turn it on — a collaborator who can edit the trip cannot publish it. Publishing produces a page at a long, unguessable web address that anyone holding the link can open without signing in.
A published page includes:
- the trip title, its dates and how many days it runs;
- each stop in order, with its place name, map coordinates, type and times;
- the cost of each stop and the trip total — but only if you left costs switched on. Choose to hide the costs and they are left out of the published page altogether, along with the trip currency, rather than merely hidden from view.
A published page never includes:
- any document you uploaded;
- any note you wrote, on the trip or on a stop;
- your email address, phone number or account details;
- who else is on the trip with you;
- your budget, your checklists, cost titles, or flight and booking reference details.
The published page is built by a single piece of code that names every field it is allowed to copy, so a field added to your trip later cannot leak onto the page by default. You can also tell search engines not to index the page, and you can unpublish it or reset its link at any time. Unpublishing deletes the published copy, and the page stops working within about a minute. It cannot, however, undo a copy someone already made or a screenshot they already took.
When you sell or buy a trip
If you sell a trip, the buyer receives a private copy that contains more than the public page does. As well as the stops, dates and times, that copy carries your notes on the trip and on each stop, the titles and amounts of your costs, and flight details including airline, flight number and stopovers. Read your notes before you list a trip: anything personal you left in them goes to every buyer.
What the copy does not carry is your identity or your files. Buyers do not receive your email address, your phone number, your uploaded documents, your budget, or the names of anyone else on the trip.
If you buy a trip, we create an account for you from the email address you give at checkout, and email you a receipt and a sign-in link there. We are told your email address, what you paid and in what currency; we are not given your card number. The seller is not told who bought their trip.
Accessing, correcting and deleting your information
Correcting it yourself
Most of what we hold is editable in the app. Your name, email, phone and locale are in your profile; every trip, stop, cost, note, checklist and document can be edited or deleted from the trip it belongs to.
Deleting your account
In the app, open your profile, go to Settings and choose Delete Account. If you cannot reach the app, email us at support@mapmyitinerary.com from the address on the account and we will do it for you.
Deleting your account removes your account and your trips. Some things necessarily outlive it: records of payments, which we have to keep for tax and accounting purposes; a copy of any trip you sold that a buyer already owns, which is now their own itinerary; and routine backups, which age out on their own schedule. Analytics events already sent to Mixpanel are deleted on request rather than automatically — ask us and we will make the request.
Asking for a copy of your information
You can ask us for access to the personal information we hold about you, or to correct it, by emailing support@mapmyitinerary.com. We will ask you to verify that the account is yours, and we aim to respond within 30 days. If we refuse access or a correction, we will tell you why in writing.
Complaints
If you think we have mishandled your personal information, email support@mapmyitinerary.com and tell us what happened. We will acknowledge your complaint and respond within 30 days.
If you are not satisfied with our response, you can take the complaint to the Office of the Australian Information Commissioner (OAIC), the regulator for the Privacy Act 1988.
How long we keep things
Your account and your trips are kept until you delete them or delete your account — we do not expire trips you have finished travelling.
The raw booking emails you forward are the exception: they are deleted automatically 30 days after they arrive. Only the details extracted into your trip remain after that.
Payment records are kept as long as tax and accounting law requires.
How your information is protected
Traffic between the app and our servers travels over HTTPS, and the AWS storage behind it encrypts data at rest. Signing in is handled by Amazon Cognito, and you can turn on multi-factor authentication in the app.
Documents you upload are stored under a folder tied to your own identity, which only your account can read. They are not attached to a published page and are not included in a trip you sell.
This is not end-to-end encryption. We hold the keys, and our own systems read your content in order to work — reading a forwarded booking email is the whole point of that feature. No online service can promise perfect security, and we do not.
Children
The app is built for adults planning travel and is not directed at children. We do not knowingly collect personal information from a child under 13. If you believe a child has given us information, email us and we will delete it.
Changes to this policy
When we change what we do with your information, we update this page and move the date at the top. If a change materially affects you, we will tell you in the app or by email rather than relying on you to re-read this page.
Contact us
For anything in this policy — access, correction, deletion or a complaint — email support@mapmyitinerary.com.