Privacy policy
This policy explains which personal data Voyageur processes, why, and what your rights are. It is based on the Swiss Federal Act on Data Protection (FADP) and, where it applies, the EU General Data Protection Regulation (GDPR).
Last updated: October 6, 2026
Who is responsible
The controller responsible for the processing described here is Realistic, a company based in Switzerland, which operates Voyageur as a non-commercial project. For any question or request about your data, write to privacy@voyageur.travel.
What data we process
We only process the data needed to run the service:
- Account data: your name, email address, account creation date and, if you set them, your language and theme preferences. For email sign-in, a salted hash of your password (never the password itself). For sign-in with Google, GitHub, Facebook or Microsoft, the name of the provider, your account identifier there and the address of your profile picture.
- Sessions: a hash of each session token with its creation and expiry dates, so you stay signed in and can sign out your other devices.
- Trip content: everything you enter in your itineraries, such as destinations, dates, number of travellers, notes, bookings and confirmation codes, activities, tasks and uploaded photos.
- Sharing: who has access to which trip and whether they can edit it.
- Technical logs: for each request to our API, your IP address, the time, the method, the path (without query parameters), the response status and a request identifier.
If you enter information about other people, such as travel companions, please make sure you are allowed to do so.
Why we process it
- To provide your account and to store, display, share and export your trips (performance of our agreement with you; GDPR Art. 6(1)(b)).
- To send service emails, such as a notice when someone shares a trip with you (performance of our agreement).
- To keep the service secure and available: preventing abuse, limiting repeated sign-in attempts, fixing errors and keeping backups (our legitimate interest in a safe and reliable service; GDPR Art. 6(1)(f)).
- To comply with legal obligations where they apply (GDPR Art. 6(1)(c)).
We do not use your data for advertising, analytics, profiling or automated decision-making, and we never sell it.
Cookies and local storage
Voyageur only stores what is strictly necessary for the service to work and uses no tracking or advertising cookies:
- “voyageur_session”: a cookie that keeps you signed in, valid for 30 days or until you sign out.
- “voyageur_oauth_state”: a temporary cookie that protects sign-in with an external provider, valid for 10 minutes.
- Your browser’s local storage remembers your language, your theme and the width of the planner columns. This information stays on your device.
Who else receives data
We only disclose personal data as far as necessary:
- Other users: the people you share a trip with see its content as well as your name, email address and profile picture. A signed-in user who enters your exact email address to share a trip with you sees your name and profile picture.
- Everyone: a trip you publish to the community is public on the web, for visitors without an account too, and search engines may index it. It shows only what the publishing window lists, with your name and profile picture only if you choose to show them. When you unpublish it, Voyageur stops showing it at once; search engines drop it on their next visit.
- Administrators of Voyageur can access accounts and trips when necessary for support, maintenance or dealing with abuse.
- Hosting: Infomaniak Network SA, Geneva, Switzerland, runs the servers, the database storage and the backups on our behalf.
- Email delivery: the provider that sends our service emails receives the recipient’s address and the content of the message.
- Sign-in providers: if you choose to sign in with Google, GitHub, Facebook or Microsoft, that provider learns that you use Voyageur and shares your basic profile with us under its own privacy policy.
- Authorities, when we are legally required to disclose data.
To convert prices in other currencies, our server downloads public exchange rates from ExchangeRate-API (open.er-api.com); these requests contain no personal data.
Services your browser contacts directly
To display fonts, maps, weather and destination information, your browser loads content directly from the following services. They receive your IP address, standard browser information and the content of the request (for example a destination name or coordinates and dates) and process it under their own privacy policies:
- OpenFreeMap: map tiles and map styles.
- Open-Meteo: weather forecasts and destination search.
- Nominatim (OpenStreetMap Foundation): airport search.
- Wikidata and Wikimedia Commons (Wikimedia Foundation): popular destinations and destination photos.
- Your sign-in provider: your profile picture is loaded from its servers.
Some of these services are located outside Switzerland and the EU/EEA, including in the United States, where the level of data protection may be lower. These requests do not contain your account data, only what is needed to answer them.
Where your data is stored
All the data you store in Voyageur, including your account, your trips, your photos and every backup, is stored exclusively in Switzerland, in Infomaniak data centres, and is subject to Swiss data protection law. The European Commission recognises Switzerland as providing an adequate level of data protection, so data from the EU/EEA enjoys equivalent protection here. Personal data only leaves Switzerland in the cases described above.
How long we keep it
- Account data and trips: until you delete them or your account. Deleting your account deletes the trips you own and removes your access to trips shared with you.
- If an administrator deletes an account, for example because of abuse, the trips it owned are deleted with it, including for the people they were shared with.
- Sessions: until you sign out or they expire after 30 days.
- Backups: continuous backups are kept for 30 days. A full copy of the database is also taken before each software release, and only the ten most recent copies are kept. Deleted data disappears from the backups as these are replaced.
- Technical logs: kept only temporarily for operation and security, and not archived.
Security
Connections are encrypted with HTTPS, passwords and session tokens are only stored as hashes, sign-in attempts are rate-limited and access to each trip is checked on the server for every request. No system is perfectly secure, but we take appropriate technical and organisational measures to protect your data.
Your rights
Depending on the applicable law, you have the right to access your personal data, to have it corrected or deleted, to restrict or object to its processing and to receive it in a portable format. You can update your profile and delete your account yourself in Settings; for anything else, write to privacy@voyageur.travel. We may ask you to confirm your identity.
You can also lodge a complaint with a data protection authority: in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU/EEA, the supervisory authority of your country of residence.
Children
Voyageur is intended for people aged 13 and over. Where the law of your country requires it, users under 16 need the consent of a parent or guardian.
Changes to this policy
We may update this policy when the service or the law changes. The date at the top shows the current version, and we will inform you of significant changes in the application or by email.