Privacy Policy
Effective date: 22 July 2026
goTravelas is operated by PT Silauk Smart System ("we", "us"). This policy explains what personal data we collect when you use goTravelas, why we collect it, who we share it with, and the rights you have over it.
It is written to comply with Indonesia's Personal Data Protection Law (UU No. 27 of 2022). We extend the rights described below to all our customers, wherever you are located.
1. Data we collect
We collect only what the service needs to function:
- Account data — your name, email address, and profile picture, received from Google when you sign in through our authentication provider, Clerk.
- Trip inputs — the destination, travel dates, Daily Stamina profile, Travel Radius, and preferences you enter when generating an itinerary, and the itineraries generated for you.
- Device fingerprint — an anonymized device identifier (generated with FingerprintJS) used solely to prevent abuse of free credits. It is not used for advertising or cross-site tracking.
- IP address — used at request time to estimate your country (for showing prices in your currency and detecting VPN use) and to apply rate limits.
- Purchase records — the credit packages you buy, payment status, payment channel (e.g. QRIS, card), amounts, and your credit ledger (purchases, usage, refunds, bonuses). We never see or store your card or bank details.
- Partner interactions — when a partner place is shown to you or selected by you in an itinerary, we log that event to measure partner performance.
- Cookies — a session cookie from Clerk to keep you signed in, and a locale cookie that remembers your language choice. We use no advertising or analytics trackers.
2. How we use your data
We use your data to: authenticate you and maintain your account; generate the itineraries you request; maintain your credit balance and Loyalty Tier; process payments and prevent fraud and free-credit abuse; show prices in the right currency; enforce fair-use rate limits; and improve the relevance of partner recommendations.
We do not sell your personal data, and we do not use it for third-party advertising.
3. Legal basis for processing
We process your personal data only where we have a lawful basis to do so under Indonesia's Personal Data Protection Law (UU No. 27 of 2022):
- Performance of a contract — authenticating you, generating the itineraries you request, and maintaining your credit balance and Loyalty Tier. Without this data we cannot provide the service.
- Legitimate interests — preventing fraud and free-credit abuse, enforcing fair-use rate limits, keeping the platform secure, showing prices in your local currency, and measuring partner performance.
- Legal obligation — retaining payment and ledger records for as long as Indonesian tax and financial regulations require.
- Consent — where we rely on your consent, such as remembering your language choice, you may withdraw it at any time without affecting processing already carried out.
4. Who we share data with
We share data only with the processors needed to run the service, each receiving the minimum required:
- Clerk (authentication) — your Google account name, email, and avatar.
- Google Gemini (AI generation) — your trip inputs (destination, dates, stamina, radius, preferences). Your name and email are not included in generation requests. See section 4 for how AI generation works and what it means for your data.
- Xendit (payments) — your email and the order amount, to create the payment invoice. Card and bank details are handled entirely by Xendit.
- proxycheck.io (geolocation) — your IP address, to estimate country and detect VPNs for pricing.
- OpenStreetMap (maps) — your IP address is visible to OSM tile servers when map tiles load in the trip wizard.
- Upstash (rate limiting) and Vercel (hosting) — technical request data necessary to serve and protect the site.
- Cloudinary (image hosting) — hosts images of partner places; no customer personal data is uploaded.
- Successor entities — if goTravelas is involved in a merger, acquisition, or sale of assets, your personal data may be transferred to the buyer, which will remain bound by this policy or one at least as protective. We will notify you before your data becomes subject to a different policy.
5. AI itinerary generation
Your itineraries are generated by Google Gemini (model gemini-3.6-flash). When you request a plan, we send only your trip inputs: the destination, travel dates, Daily Stamina profile, Travel Radius, preferences, and the names of any places you selected.
We never send your name, email, payment details, or device fingerprint to the AI. It receives nothing that identifies you.
We currently use Gemini's free tier. Under Google's terms for that tier, Google may use the trip inputs we send to improve and train its AI models, and those inputs may be reviewed by humans. The inputs are not linked to your identity, but if you would prefer they not be processed this way, avoid entering details you consider sensitive.
The AI only drafts a suggested travel plan. It makes no automated decision that has a legal or similarly significant effect on you.
AI output can be inaccurate or out of date. Always verify important details — opening hours, prices, safety, and locations — before relying on them.
6. Security of your data
We apply technical and organizational measures appropriate to the risk. Staff passwords are stored only as bcrypt hashes; session cookies are httpOnly and cryptographically signed; all traffic is served over HTTPS/TLS; and payment card and bank details never reach our servers — they are handled entirely by Xendit. Access to production data is limited to the people who need it.
No method of transmission over the internet or of electronic storage is ever 100% secure. While we work hard to protect your personal data, we cannot guarantee absolute security, and any transmission is at your own risk. Please access the service from a secure environment and keep your account credentials confidential.
7. How long we keep data
Account data and itineraries are kept while your account is active. Payment orders and ledger entries are kept as long as Indonesian tax and financial regulations require, even after account deletion. Device fingerprints are kept while relevant for abuse prevention. IP-based geolocation lookups are cached briefly (about one hour) and are not stored with your profile.
8. Your rights
You can request: a copy of the personal data we hold about you; correction of inaccurate data; deletion of your account and data; an export in a portable format; that we restrict or stop (object to) certain processing of your data; and, where we rely on your consent, its withdrawal at any time.
To exercise any of these, email privacy@gotravelas.com from the address linked to your account. We will respond within 30 days. On deletion requests we remove your account, itineraries, and fingerprint associations, and ask Clerk to delete your authentication record; purchase and ledger records are retained only as long as financial law requires, then deleted.
9. Children
goTravelas is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
10. Changes to this policy
If we materially change this policy, we will update the effective date above and, for significant changes, notify you by email or in-app notice before the change takes effect.
11. Contact
PT Silauk Smart System — privacy@gotravelas.com