Legal
Privacy Policy
Last updated: 13 July 2026
1. Introduction
This Privacy Policy describes how Escapo collects, uses, stores, shares and protects your personal data when you use our website, app and services. We keep it in plain language on purpose — if anything is unclear, contact us.
2. Who Is the Data Controller
The controller of your personal data is:
SC TAF TECH LABS SRL
CUI: [TO BE COMPLETED]
Trade Register No.: [TO BE COMPLETED]
Registered office: [TO BE COMPLETED]
Contact email: support@escapo.io
3. Scope
This policy applies to the Escapo website and app, account features, itinerary generation, saved trips, premium access, payments, support and our communications with you.
4. What Personal Data We Collect
- Account data — email address, user ID, and your name and profile picture if provided through sign-in.
- Authentication and session data — sign-in state and session identifiers managed by our authentication provider.
- Travel-planning data — destinations, dates, budgets, interests, pace, travel companions, preferences, saved trips and generated itinerary content.
- Flight, accommodation and travel details you choose to enter.
- Payment and subscription data — payment-provider customer ID, subscription status, transaction metadata and billing status. Escapo never stores your full card details.
- Technical data — IP address, device and browser information, operating system, logs, errors, security events, and approximate location inferred from your IP where applicable (e.g. for regional pricing).
- Usage data — pages visited, actions taken, feature usage and trip-generation events (used for quotas and abuse prevention).
- Cookie identifiers — see our Cookie Policy. Escapo currently uses only strictly necessary cookies.
- Communications and support data — messages you send us and our replies.
- Waitlist / newsletter signups — if you join the waitlist, your email address, signup date and coarse anti-abuse metadata (country, hashed IP).
5. How We Collect Data
- Directly from you — when you create an account, answer the planning quiz, save trips, make purchases or contact us.
- Automatically — through your use of the service (logs, security events, usage events).
- From third-party providers — such as our authentication provider (basic profile data when you sign in) and our payment provider (payment status and metadata).
6. Why We Process Data and on What Legal Basis
- Account creation and authentication — performance of our contract with you.
- Generating and saving itineraries — performance of our contract with you.
- Premium access and subscription management — performance of our contract with you.
- Payments, invoices, accounting and tax — performance of our contract and compliance with legal obligations.
- Security, abuse prevention, fraud detection, rate limiting and logging — our legitimate interest in protecting the service and its users.
- Service improvement and debugging — our legitimate interest; analytics tools would rely on legitimate interest or consent depending on the tool and cookie type (none are currently used).
- Waitlist and launch updates — your consent, given when you join the waitlist. We use the address only to send Escapo launch updates and early-access messages. You can unsubscribe at any time — every email will include an unsubscribe option, or write to support@escapo.io. Once newsletter tooling is connected, these emails may be processed by our email service provider, which will be listed in section 8 before any email is sent.
- Legal compliance — compliance with legal obligations.
7. AI Processing
- Your travel inputs (quiz answers, preferences, trip details) are sent to an AI provider to generate itineraries and recommendations.
- Avoid submitting sensitive personal data (such as health information) unless genuinely necessary for your planning request.
- AI outputs may be inaccurate and are governed by our Terms — always verify important travel details.
- Escapo does not use your personal data to train its own public AI model. If that ever changes, we will state it explicitly and rely on an appropriate legal basis.
- The external AI provider we use is listed as a processor in section 8.
8. Processors and Service Providers
We use the following providers, each processing only the data needed for its role (based on an audit of our actual stack):
- Clerk — authentication and account management.
- Stripe — payment processing (card details go directly to Stripe).
- Anthropic — AI itinerary generation.
- Vercel — frontend hosting.
- Railway — backend hosting and PostgreSQL database.
- Mapbox — maps and place resolution.
- Google (Places) — place details and photos.
- Cloudflare (R2) — image storage and delivery.
- Duffel — flight and airport data.
- Analytics provider — none currently used. If one is added, this list and the Cookie Policy will be updated first.
- Email provider — none yet: no marketing or newsletter emails are currently sent, and authentication notifications come via our authentication provider. When newsletter tooling is connected, waitlist emails will be processed by our email service provider and this list will be updated first.
9. International Transfers
Some of our providers may process data outside Romania and the EU/EEA (for example, in the United States). Where required, such transfers rely on appropriate safeguards, such as data processing agreements, standard contractual clauses, adequacy decisions or the provider's applicable transfer mechanism.
10. Data Retention
- Account data is retained while your account is active.
- Saved trips are retained until you delete them or your account is deleted, unless we need to keep them for legal or security reasons.
- Payment and accounting data is retained for as long as the law requires.
- Security logs are retained for a limited period necessary for security monitoring and incident investigation.
- Support communications are retained as needed to handle your request and protect our legal interests.
- Cookie preferences are retained for as long as needed to honour your choices.
11. Your Rights
Under the GDPR and applicable data protection laws, you have the right to:
- access your personal data;
- rectify inaccurate data;
- erase your data (“right to be forgotten”);
- restrict processing;
- receive your data in a portable format;
- object to processing based on legitimate interests;
- withdraw consent at any time, where processing is based on consent;
- lodge a complaint with the Romanian supervisory authority (ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal) or the authority applicable to you.
12. How to Exercise Your Rights
Contact us at support@escapo.io. We may need to verify your identity before acting on a request. Some data may need to be retained where the law requires it or where we have legitimate legal or security reasons to keep it.
13. Cookies
See our Cookie Policy. Escapo currently uses only strictly necessary cookies. If non-essential cookies are ever introduced, they will be controlled by your preferences and consent where the law requires it.
14. Security
We use reasonable technical and organisational measures to protect your data — such as encrypted connections, access controls, server-side secrets and rate limiting. No system can be guaranteed 100% secure; please keep your account credentials safe.
15. Children
Escapo is not intended for children under 16, or under the applicable age of digital consent in your jurisdiction. If you are under that age, do not create an account without appropriate consent.
16. Changes to This Policy
We may update this policy from time to time. Updates will be posted on this page with a new "Last updated" date; material changes will be notified where the law requires it.
17. Contact
SC TAF TECH LABS SRL
Contact email: support@escapo.io