Privacy Policy

Last updated: 2026-07-17

Operator

PYNTravel is operated by:

„KOFFWARE” S.R.L.
IDNO: 1026600015511
Republica Moldova

Privacy contact: privacy@pyntravel.com

Data we process

We process account data such as email address, password hash, display name, locale, OAuth provider identifiers, email verification status, and account timestamps.

For mobile app launch updates, we also process waitlist data such as email address, optional name, platform interest, travel interest, notes, locale, and consent timestamp.

We process trip data created by users, including trip titles, dates, currencies, itinerary days, activities, locations, notes, traveler profiles, transport legs, planned budget rows, real trip expenses, analytics derived from those records, trip members, and email invitations.

Invitation flows process invitee email addresses, invitation status, role, token metadata, inviter, and accepted account when applicable.

Why we process data

We process account, trip, invitation, and payment-access data to provide and secure the service and perform our contract with users. We process limited technical and abuse-prevention data for our legitimate interests in keeping PYNTravel reliable and safe, and where required by law to meet legal obligations. We rely on consent for the mobile-app waitlist and optional analytics where consent is required; consent can be withdrawn at any time without affecting earlier processing.

Authentication and emails

The service supports password login, email verification codes, password reset emails, Google login, Apple login, and JWT authentication for the mobile API. Transactional emails are sent from no-reply@pyntravel.com with support replies directed to support@pyntravel.com.

Analytics

The website uses Umami Cloud analytics to understand page usage. The tracker is configured to respect Do Not Track and exclude URL search parameters. We do not use Umami to intentionally identify individual visitors.

Storage and retention

Account and trip data is stored while the account is active or while needed to provide the service, protect security, handle support, or meet legal obligations. Some technical records, email logs, and abuse-prevention records may be retained for a limited period after deletion.

Your rights and deletion

You can request access, correction, export, restriction, objection, or deletion by contacting privacy@pyntravel.com, using the Privacy Centre, or using the Delete Account page. We may need to verify that the requester controls the account email before acting on a request.

Third parties and international transfers

The service uses providers needed to run its features: Paddle for checkout and billing, Umami Cloud for optional analytics, Google Places for requested location autocomplete, and Google or Apple only when a user chooses those sign-in methods. It also uses hosting and email-delivery providers. Providers may process data outside your country; where required, we use an appropriate transfer mechanism and provide further information on request.

Sources and detailed data categories

We receive data directly from you, from people who add or invite you to a shared trip, and from the service providers you choose to use. When another user creates a traveler profile or invitation for you, that user is the source of the name, email address, role, date of birth, age, home or passport country, and other trip details they provide.

Account and profile data can include contact details, password hash, display name, language, home country, time zone, sign-in provider identifiers, verification state, notification and email preferences, and timestamps showing acceptance or acknowledgement of legal documents. Traveler data can include names, date of birth, age, traveler type, home or passport country, and links to an account or managing user. Trip data can include dates, locations, place identifiers, time zones, notes, bookings, travelers, invitations, member roles, transport, budgets, expenses, currencies, and analytics derived from those records.

Billing data can include Paddle customer, subscription, transaction, invoice, entitlement, refund, and event identifiers and status. Paddle collects payment-method details; PYNTravel does not store full card details. Technical data can include session and security records, consent preferences, requested URLs without analytics query parameters, device or browser category, country-level analytics, email-delivery records, and abuse-prevention information.

Purposes and legal bases

  • Contract: creating and securing an account; saving, sharing, and synchronizing trips; processing invitations; providing support; and enabling paid features.
  • Legitimate interests: preventing fraud and abuse, protecting accounts, diagnosing failures, maintaining service reliability, and defending legal claims. We balance these interests against the rights of affected people.
  • Legal obligations: accounting, tax, consumer-protection, lawful authority requests, and compliance records where applicable.
  • Consent: optional Umami analytics and the mobile-app waitlist where consent is required. Consent can be withdrawn at any time without affecting earlier lawful processing.

Fields marked as required are needed to create an account, provide a requested trip feature, complete an invitation, or respond to a request. Without them, the relevant feature cannot be provided. Optional profile, traveler, note, analytics, and waitlist fields may be omitted without losing unrelated service access.

Recipients and shared trips

Trip information is shared with the owner, editors, viewers, and travelers who are given access to that trip. Service providers receive only the data needed for their role: Paddle for checkout and billing; Google Places for location searches requested by a user; Google or Apple for a chosen sign-in method; Umami Cloud for optional analytics; and hosting, database, security, email-delivery, and support providers for service operation. We may disclose data to professional advisers, courts, regulators, or law-enforcement authorities when legally required or necessary to establish, exercise, or defend legal claims.

Google Places use is subject to the Google Maps Platform Terms and Google Privacy Policy. Paddle processes buyer and payment data under its Buyer Terms and Privacy Policy.

International transfers

Some providers may process data outside Moldova or your country. Depending on the destination and provider, transfers rely on an adequacy decision, contractual safeguards such as standard contractual clauses, another legally recognized safeguard, or a transfer necessary to perform a requested contract. Contact privacy@pyntravel.com to request information about the safeguard used for a particular provider and, where available, a copy of it.

Retention criteria

Account and trip data is kept while the account or shared trip is active and then only as long as needed for deletion processing, security, dispute resolution, or a legal obligation. Invitation and security records are kept according to their status and the need to prevent abuse. Support and email-delivery records are kept for the time needed to resolve the request and document the response. Billing, transaction, refund, and tax records are kept for the statutory accounting and limitation periods that apply. Backups and provider logs are removed on their normal protected rotation schedules. You may ask privacy@pyntravel.com for the criterion that applies to a specific record.

Rights, complaints, and response time

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or an export, and may object to processing based on legitimate interests. You may withdraw consent through Cookie Settings or by contacting us. We normally respond without undue delay and within one month after receiving and verifying a request. Where legally permitted, a complex or repeated request may take up to two additional months; we will explain an extension within the first month.

You may complain to the National Center for Personal Data Protection of the Republic of Moldova or to another competent data-protection authority where you live or work. You may also seek a judicial remedy.

Automated decisions and children

PYNTravel does not make decisions that produce legal or similarly significant effects solely by automated means and does not use personal data for advertising profiling. An adult account holder may add a child traveler only when authorized to provide that information. Children must not create accounts below the minimum age stated in the Terms of Service.

Policy changes

We update this policy before material changes to our data practices. The current version and a route for privacy requests are available on the website.

Privacy controls

Manage a privacy request

Use the Privacy Centre to request access, correction, export, restriction, objection, or deletion. We may ask you to verify account ownership first.

Open Privacy Centre