Privacy Policy
Last updated: September 23, 2026
Welcome to TravelReady, operated by Traveln Ltd, a company registered in England and Wales under company number 17397150, whose registered office is at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Traveln Ltd is the data controller for the personal data described in this policy. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our application.
1. Information We Collect
We may collect information about you in a variety of ways. The information we may collect includes:
- Personal Data: Personally identifiable information, such as your name, email address, nationality, and date of birth, that you voluntarily give to us when you register with the application.
- Google Sign-In Data: If you choose to sign in using Google, we receive your name, email address, and profile photo from your Google Account. We use this information solely to create and manage your TravelReady account. We do not access your Google contacts, calendar, files, or any other Google services data beyond basic profile information.
- Derivative Data: Information our servers automatically collect when you access the app, such as your IP address, your browser type, your operating system, your access times, and the pages you have viewed directly before and after accessing the app.
- Region: The two-letter country code of your network location, recorded when you sign in, so we can show prices for your region. We store the country code only, not the IP address it came from.
- Financial Data: Stripe processes card payments. We do not store full card numbers or security codes. We retain transaction details and a payment-provider customer reference to manage purchases, refunds, and subscriptions, as described in section 6.
- User-Uploaded Documents: Documents you upload to your private Secure Document Vault are encrypted and stored for your use. Our document tools process the files you submit to provide the requested analysis. We do not use your personal documents to train any models.
- Third-Party Fulfillment: When you request a supporting flight reservation, we transfer the details needed to arrange it (name, travel dates, route) to the fulfillment partner handling that request through our concierge service.
1a. How We Handle Your Documents
When you use TravelReady's document preparation tools, you may upload personal documents including but not limited to: passport bio pages and scans, photographs, bank statements and financial records, employment letters and payslips, travel itineraries and hotel bookings, educational certificates, and cover letters or supporting statements.
Your documents are used to provide the service you request, including:
- Validate completeness against embassy requirements and generate your Application Strength Score.
- Pre-fill application templates and Expert Cover Letters.
- Store securely in your Secure Document Vault for reuse across applications.
We do not:
- Share your documents with an embassy, consulate, or government body unless legally required, as described in section 10.
- Submit applications on your behalf.
- Sell or license your personal data. Service-provider sharing is described in section 4.
- Use your documents to train automated systems.
We restrict staff access to your documents. Authorized access may be needed to resolve a support request with your permission or to meet a legal obligation.
2. Use of Your Information
Having accurate information about you permits us to provide you with a smooth, efficient, and customized experience. Specifically, we may use information collected about you to:
- Create and manage your account.
- Authenticate your identity via email/password or Google Sign-In.
- Generate personalized visa checklists and travel itineraries.
- Provide Expert-powered analysis of your documents.
- Anonymously aggregate data for community insights, such as visa success rates.
- Process payments and subscriptions.
- Email you regarding your account or order.
3. Google API Services User Data Policy
TravelReady's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only request access to the data necessary to provide our services (email, name, and profile photo for account creation).
- We do not use Google user data for advertising purposes.
- We do not sell Google user data to third parties.
- We do not use Google user data to train automated systems.
- We limit our use of Google user data to the practices explicitly disclosed in this Privacy Policy.
4. Who We Share Data With
We use service providers to operate TravelReady. The categories below describe what they may receive and why. You can ask us for the current names of providers that receive your personal data at privacy@mytravelready.ai.
| Recipient category | Data they may receive | Purpose |
|---|---|---|
| Account and cloud hosting providers | Email, name, profile photo, application data | Sign-in, hosting, and storage |
| Document processing providers | Document images and text you submit for review | Document validation and checklist generation |
| Payment processor | Payment method and billing details | Payments and subscriptions |
| Email delivery provider | Email address, name, and message content | Account, service, and opted-in marketing email |
| Visa research provider | Search queries | Visa requirement lookups |
| Error monitoring provider | Technical diagnostics and request context | Detecting and fixing errors |
| Security and performance provider | Request metadata | Rate limiting and caching |
| Analytics providers, if you accept analytics | Usage events, device information, and masked session recordings that may be linked to your account | Understanding usage and improving the service (see section 5) |
| Travel-booking partner | Booking or click attribution data | Affiliate travel deals |
5. Cookies and Session Data
We use the following cookies and similar technologies to operate and improve the application:
Essential Cookies (Always Active)
- Session Cookie (
__session): An HTTP-only, secure cookie that maintains your authenticated session. It expires after 14 days and is deleted when you sign out. - Referral Cookie (
travelready_ref): Tracks referral attribution if you arrived via a referral link. Contains only the referrer ID. - Region Cookie (
tr-geo-country): Stores the two-letter country code of your network location so we can show prices for your region. It contains no personal identifier and is not used for tracking or advertising.
Analytics & Session Recordings
If you accept analytics, we use two kinds of service:
- Website analytics: Records pages visited, session duration, and general device information.
- Product analytics and session recordings: Records usage events and on-screen interactions such as clicks, scrolling, and navigation. When you are signed in, events may be linked to your account. Form input values are masked in session recordings.
When these run: Browser analytics and session recordings start only after you accept analytics, in every region. Advertising storage remains off. You can change your choice below at any time, or reset it by clearing this website’s stored site data, including local storage. PostHog product analytics and session recordings also respect your browser’s “Do Not Track” setting.
Current analytics choice: No choice yet
Affiliate Links
Some travel deals are powered by an affiliate travel-booking partner, whose script may set a cookie to attribute bookings you make through our links. We do not currently use advertising or remarketing pixels.
6. Data Retention
We retain your personal data only for as long as necessary to provide our services. Below are the specific retention periods for each category of data:
- Account Data: Retained while your account is active, subject to our retention schedule. The deletion button on this page closes your account immediately. A deletion request made through profile settings has a 30-day cancellation period. After that period, the scheduled process deletes or anonymizes account data, except records retained for legal reasons.
- Uploaded Documents: Stored in your encrypted vault while your account is active, subject to our retention schedule. The immediate deletion process marks vault documents for permanent deletion after 90 days. The scheduled deletion process removes them after its cancellation period. Legal holds may delay removal.
- Document Processing Data: Documents submitted for validation are processed to provide the result you request. Copies stored in your vault follow the uploaded-document retention period above.
- Payment Records: Transaction metadata (plan type, date, amount) is retained for 7 years for accounting and legal compliance as required by UK tax law. Full payment details are held by Stripe per their retention policy.
- Audit Logs: Security and compliance records may contain account identifiers, event details, and timestamps. Our retention schedule keeps these records for 7 years to support legal obligations and security review.
- Analytics Data: Usage events may be linked to your signed-in account. You can contact us about access to or deletion of this data.
7. Security of Your Information
We use encryption, access controls, audit logs, and other security measures to protect your personal information. Authorized staff and service providers may access data when needed to deliver the service or meet legal obligations, as described in this policy. No security measure can eliminate every risk.
8. Your Data Rights: Access and Export
You have the right to access the personal data we hold about you. The self-service JSON export includes your profile and selected account records. To request other personal data, contact privacy@mytravelready.ai.
Export Your Data
Download the account data available through self-service export.
9. Your Data Rights: Deletion (“Right to be Forgotten”)
You can request account deletion. The button below closes your account immediately. Some documents and records remain under the retention periods in section 6, and legal holds may prevent deletion.
Delete Your Account
Close your account and remove your profile and most app records now.
10. Lawful Disclosure and Government Requests
We restrict staff access to documents and review legal requests before disclosure.
We may disclose your personal data when required by law, specifically in response to:
- Valid court orders issued by a court of competent jurisdiction
- Lawful subpoenas
- Binding government requests under applicable law (e.g., UK Investigatory Powers Act)
When we receive such a request, we follow this procedure:
- Verify validity: We review the request to confirm it is legally valid and properly scoped.
- Minimize disclosure: We provide only the specific data legally required — nothing more.
- Log all access: Every disclosure is recorded in our internal audit system with the date, scope, and requesting authority.
- Notify you: We will notify you about the request unless we are legally prohibited from doing so (e.g., by a gag order or national security letter).
Where required by a valid legal order, we may place a temporary hold on the deletion of specific user data to preserve it for ongoing legal proceedings. Data under a legal hold is secured and access-restricted. The hold is lifted and normal retention policies resume once the legal obligation has been satisfied.
11. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms:
- We will notify the UK Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
- If the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay via the email address associated with your account.
- Our notification will describe the nature of the breach, the data affected, the measures we have taken, and the steps you can take to protect yourself.
12. Automated Decision-Making
TravelReady uses automated systems to validate your documents and generate visa checklists. These systems provide recommendations and assessments only — they do not make legally binding decisions about your visa application. You always retain full control over which documents to submit and how to proceed with your application.
Under GDPR Article 22, you have the right to request human review of any automated assessment. To exercise this right, contact us at privacy@mytravelready.ai.
13. International Data Transfers
Your data may be processed in countries outside the United Kingdom and European Economic Area, including the United States (where our cloud infrastructure providers operate). When this occurs, we ensure appropriate safeguards are in place:
- Cloud hosting and document processing: Transfers are governed by the applicable data processing terms and contractual safeguards.
- Payment processing: Transfers are subject to the payment provider's applicable data transfer safeguards.
All transfers comply with Chapter V of UK GDPR and are subject to appropriate safeguards.
14. Data Processing Agreement
For business and agency customers processing client data through TravelReady, we offer a Data Processing Agreement (DPA) that details our obligations as a data processor. To request a DPA, contact legal@mytravelready.ai.
15. Policy for Children
We do not knowingly solicit information from or market to children under the age of 13. If we learn that we have collected personal information from a child under age 13 without verification of parental consent, we will delete that information as quickly as possible.
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy here and updating the “Last updated” date. Where a change requires your consent, we will ask for it separately.
17. Contact Us
If you have questions or comments about this Privacy Policy, please contact us at: privacy@mytravelready.ai
You can also write to us by post at: Traveln Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.