Privacy Policy
Effective date: October 1, 2026
Introduction
This Privacy Policy explains how the individual who operates the familyTravely website and related services ("we," "us," or "our") collects, uses, shares, and protects information when you use the Service. familyTravely is the brand name for the Service; it is not a registered company or other separate legal entity. familyTravely helps parents and caregivers plan family trips by generating day-by-day itineraries from information you provide.
This Policy describes our practices for the Service. It is not legal advice, and we do not claim that the Service satisfies every privacy law that may apply to you.
Who operates familyTravely
The familyTravely website and Service are operated by an individual based in Israel. familyTravely is the product and brand name for the Service, not a registered business entity. Our contact details appear in the "Contact us" section below.
Scope
This Policy applies to information we process when you visit our website, use the trip planning wizard, generate or view itineraries, download or share itineraries, open shared itinerary links, or send us feedback. It does not apply to third-party websites or services you reach through links in the Service (for example, booking sites, maps, or ride-hailing apps).
The Service is intended for adults planning family travel. It is not directed at children, and we do not knowingly collect personal information directly from children.
Information we collect
We collect information in the ways described below, depending on how you use the Service.
Information you provide
When you plan a trip, you may provide:
- Destination and travel dates
- Arrival and departure times on the first and last days
- Number of adults and children's ages (ages only, not children's names)
- Travel pace, budget style, and interests
- Transportation and accommodation preferences
- Accommodation address or place details when you choose to enter them
- Nap or rest windows
- Dietary preferences or restrictions you select from the quick-pick options we offer
You do not need to create an account to use the core planning features. Please do not enter unnecessary personal information about yourself or your children (for example, full names, school names, or medical records). Ages are used to tailor scheduling and activity suggestions.
If you use optional features, you may also provide:
- Email itinerary sharing: the recipient email address you enter so we can send a link to the itinerary.
- Feedback: your message and, if you choose, an email address for follow-up. If you submit feedback from the Service, we may also receive a sanitized page URL or path for context (for example, which part of the site you were using). We remove trip link identifiers from paths such as
/trip/…and capability parameters such asshare=before that context is included in feedback delivered to us. Feedback does not include your itinerary contents, trip plan fields, or other trip data merely because you sent feedback while viewing a trip page.
Automatically collected information
When you use the Service, we and our providers may automatically collect:
- Device and browser data such as browser type, operating system, and general device characteristics.
- Usage data such as pages viewed, actions taken (for example, wizard steps, itinerary generation, download, or share), and approximate interaction timing.
- Network identifiers such as IP address, which we use for rate limiting and abuse prevention on our APIs.
- Referrer and page URLs in product analytics and feedback, with trip link identifiers and share capability parameters redacted from URLs where implemented before they are sent to us or our analytics provider.
Information collected through analytics and error monitoring
PostHog (product analytics): When configured in our deployment, we load PostHog in your browser to understand how the Service is used. We send defined product events (for example, planner steps, itinerary generation outcomes, downloads, email shares, and feedback submissions) rather than relying on PostHog to infer every interaction automatically. Event properties include aggregated trip details (for example, destination, trip length, number of adults, count of children rather than children's ages, budget and transport categories, interest count, whether naps were configured, and a yes/no indicator for whether dietary restrictions were entered) but not the full text of dietary restrictions. Page URLs sent with analytics are sanitized to remove trip link identifiers and share capability parameters. PostHog may use cookies or similar browser storage. Events may be sent through a same-origin proxy path on our site. PostHog is not loaded when the analytics key is not configured (for example, some local development setups).
Vercel Analytics and Speed Insights: Our hosting provider may collect privacy-oriented web analytics and performance metrics about visits to the Service.
Sentry (error monitoring): We use Sentry on our servers and in your browser to detect and diagnose errors. Sentry may receive error messages, stack traces, performance traces, and related technical context. On the client, Sentry may include Session Replay for a subset of sessions (currently configured at a fractional sample rate, with replay more likely when an error occurs). Replay may record page interactions and DOM content according to Sentry's replay settings; we configure the Service so that replay does not capture network request or response bodies, and our server and edge runtimes do not send HTTP request or response bodies to Sentry. Error reports may be routed through a tunnel on our domain. Server logs may also record operational messages (for example, timing of itinerary generation).
We do not use PostHog session replay in our current PostHog configuration. Session replay, where enabled, is provided through Sentry as described above.
How we use information
We use information to:
- Generate, display, enrich, and validate itineraries
- Call mapping and places services to suggest venues, routes, and map images
- Store itineraries on our servers when you explicitly ask us to share an itinerary by email (so the recipient can open a durable link), when shared-itinerary storage is configured in our deployment
- Send itinerary emails and feedback messages through our email provider
- Enforce rate limits and protect the Service from abuse
- Measure product usage and improve reliability and performance
- Respond to feedback you send us
Itinerary generation is performed by our rule-based planning engine on our servers. Based on our current implementation, we do not send your trip inputs to a third-party generative AI model to build the itinerary. Place descriptions shown on itineraries may use template-based text derived from venue data, not an external AI chat service.
Legal bases (EEA, UK, and similar jurisdictions)
If you are in the European Economic Area, the United Kingdom, or another jurisdiction that requires a legal basis for processing, we rely on different bases depending on the activity, including:
- Performance of a service you request (for example, generating an itinerary, displaying maps, or emailing a share link you ask us to send).
- Legitimate interests (for example, securing the Service, understanding aggregated usage, fixing errors, and improving features), balanced against your rights.
- Consent where required for non-essential cookies or similar technologies under applicable law.
Israeli Privacy Protection Law and regulations may also apply to our processing as an operator based in Israel.
How information is shared
We do not sell your personal information. We share information only as described here.
Service providers and processors
We use service providers that process information on our behalf, including:
- Vercel (hosting and related infrastructure)
- Upstash (server-side storage for itineraries you explicitly share by email, and for rate limiting, when configured)
- Resend (transactional email for itinerary sharing and feedback delivery)
- PostHog (product analytics, when enabled)
- Sentry (error and performance monitoring)
- Google (Maps, Places, Directions, Geocoding, and Static Maps APIs used to power location features)
These providers are authorized to use information only as needed to provide services to us, subject to their terms and privacy policies.
Third-party services and links
The Service may link to third-party booking, maps, transportation, or ticket websites. Those sites are governed by their own policies. When you use Google Maps or open a third-party link, that party may collect information under its own rules.
International data transfers
We are based in Israel. Our service providers may process information in Israel, the United States, the European Union, or other countries. Where required, we rely on appropriate safeguards for cross-border transfers.
Data retention
How long information is kept depends on whether it is part of your current browser session, explicitly shared, or collected by our providers.
- Normal itinerary generation (browser session): When you generate an itinerary without sharing it, the Service returns the itinerary to your browser and keeps a copy in your browser's
sessionStorageso you can continue planning in the same session (for example, at a/trip/…address in that browser). This supports your current planning session; it is not a cross-device durable link and is not the same as server-side storage. We do not create a durable server-side trip record for you in this normal flow. The session copy may become unavailable if you clear site data, if session storage is unavailable, if you close the tab or browser (subject to browser behavior), or if you open the same address on another device or browser where that session data does not exist. - Explicitly shared itineraries (server): When you use email sharing, we store the itinerary and related trip plan on our servers so the recipient can open a durable link. When shared-itinerary storage is configured, we retain that shared copy for up to 90 days by default (or another period set in our deployment configuration). After that retention period expires, shared links are designed to stop working; we do not represent that deletion occurs at an exact moment beyond the expiration mechanism we use.
- Analytics and error data: Retained according to our providers' settings and our internal needs.
- Feedback email: Messages sent to us are retained in our email systems according to our operational practices.
We do not maintain user accounts today. If you generate an itinerary but do not share it by email or contact us, we do not keep a durable server-side copy of that itinerary for the normal planning flow described above.
Data security
We use reasonable technical and organizational measures designed to protect information, including HTTPS, access controls on infrastructure, rate limiting, and redaction of sensitive trip link identifiers from analytics and feedback page context where implemented. No method of transmission or storage is completely secure.
Children's privacy
familyTravely is designed for parents, guardians, and other adults planning family travel. We do not knowingly collect personal information directly from children under 13 (or the applicable age in your jurisdiction). Children's ages may be processed solely to tailor itineraries. Please do not submit children's names or other identifying details about children.
If you believe a child has provided personal information to us, contact us using the details below and we will take appropriate steps.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to certain processing, or to receive a portable copy of information you provided. You may also have the right to withdraw consent where processing is consent-based, and to lodge a complaint with a supervisory authority.
California and certain U.S. states: You may have rights to know what personal information is collected, to delete personal information, and to opt out of "sale" or "sharing" of personal information as defined by applicable law. Based on our current practices, we do not sell personal information. We do not respond to browser "Do Not Track" signals in a standardized way today because our site does not implement a dedicated DNT mechanism.
Global Privacy Control: We do not currently treat GPC signals as an opt-out of analytics cookies.
How to request access, correction, or deletion
To exercise privacy rights or ask questions about this Policy, contact us at hello@familytravely.com. We may need to verify your request. For itineraries you explicitly shared by email, access may end after the shared link retention period expires; you may also ask us to take reasonable steps to remove stored shared copies where feasible. Session-only itineraries in your browser are under your control through your browser settings.
Cookies and similar technologies
We and our analytics providers may use cookies, local storage, or similar technologies in your browser. For example, PostHog may store identifiers to recognize your browser across visits when analytics is enabled. We also use sessionStorage to hold generated itinerary and plan data for your current browser session (separate from durable shared copies created only when you share by email), and for short-lived analytics deduplication within a tab. Session storage stays on your device unless you clear it; it is not automatically uploaded to us as a durable server record.
You can control cookies through your browser settings. Blocking cookies may affect some features. We have not deployed a cookie consent banner in the current implementation.
Changes to this Privacy Policy
We may update this Policy from time to time. We will post the updated version on this page and update the effective date. Material changes may be communicated through the Service or by other reasonable means where appropriate.
Contact us
Email: hello@familytravely.com
You may also use the contact link on our homepage when available.
