Legal

Privacy Policy

This policy describes the personal information we process, why we process it, who we share it with, and the choices you have.

Last updated: 1 August 2026

1. Overview

This Privacy Policy explains how SafarWise (“we,” “us”) collects, uses, shares, stores, and protects personal information when you use our website and applications (the “Service”).

We design our practices around transparency, data minimization, and respect for your rights under applicable privacy laws, including the EU/UK General Data Protection Regulation (GDPR) where it applies, and consumer privacy laws such as the California Consumer Privacy Act (CCPA/CPRA) where relevant.

This Policy works together with our Terms of Service and the planning disclaimer shown in our footer and account onboarding.

2. Who is responsible for your data

For most processing described here, SafarWise acts as the data controller (the organization that decides why and how personal data is processed).

When we process data strictly on behalf of another organization under a written agreement, we act as a processor and follow their instructions.

3. Information we collect

  • Account data: email address, authentication identifiers, first and last name (when provided), and timestamps such as terms/privacy acceptance.
  • Guide and planning context: destination country, trip purpose (for example tourism or business), travel party size, valid visas held, and similar parameters you choose when viewing visa guides or using planning tools. Some of this may be stored only in your browser session to personalise a guide view and is not necessarily saved to your account.
  • Submissions: contact or support messages, partner applications, guide information flags (including the guide section you reference and your description of the issue), and — through the Application Portal — visa application documents (which may include identity or travel documents) and booking-assistance requests for flights, hotels, or tours.
  • Usage and product analytics: pages viewed, feature interactions (such as guide views, plan-trip actions, or partner link clicks), referral/entry source, device/browser type, IP address, and diagnostic logs needed to secure and operate the Service. We use analytics tools such as PostHog when enabled.
  • Server-side activity logs: aggregated records of guide views and certain planning events (which may be linked to your account if you are signed in, or stored without account linkage if you browse anonymously).
  • Optional donations: if you support SafarWise through a linked payment provider, that provider processes payment details—we receive confirmation and supporter display information according to that provider’s flow, not your full card number.
  • Outside the Application Portal, we do not intentionally collect passport scans, government ID numbers, or payment card numbers directly through SafarWise. Do not include sensitive identity documents in general free-text fields (such as support messages or guide flags)—use the Application Portal for visa document submissions, and verify official government submission channels separately.
  • Application Portal documents: when you use the Application Portal, we store the visa application documents you upload securely and use them only to process your document submission or booking-assistance request.

4. How we collect information

  • Directly from you when you register, complete your profile, contact us, apply to partner with us, or flag guide information.
  • Automatically through cookies, local storage, session storage, and similar technologies needed for authentication, remembering guide context in your browser session, and analytics.
  • From service providers that host authentication, databases, analytics, infrastructure, or affiliate redirect flows on our behalf.

5. Why we use your information

  • Provide and maintain the Service, including visa guides, travel alerts, currency context, and partner referral flows.
  • Authenticate users, prevent fraud and abuse, and enforce our Terms.
  • Personalise guide content to the travel profile you select (such as purpose, party size, or visas held).
  • Improve content quality, including automated enrichment of visa intelligence where enabled.
  • Measure product usage and affiliate performance so we can maintain and improve the Service.
  • Communicate with you about security, service updates, or support requests.
  • Comply with legal obligations and respond to lawful requests.
  • With your consent or as otherwise permitted by law, for optional features we clearly describe at the point of collection.

7. When we share information

  • Infrastructure and authentication providers (for example, Supabase for auth and database hosting).
  • Analytics providers (for example, PostHog) to understand how the Service is used.
  • Cloud hosting, email delivery, payment, and security vendors that process data only to provide services to us.
  • AI or data providers used to generate or refresh visa intelligence, travel itineraries, and destination context, under contractual safeguards.
  • Travel affiliate and partner programmes when you choose to follow an outbound partner link (for example, to search flights or book hotels). Those partners receive information needed to attribute the referral and operate their service, governed by their own policies.
  • Authorities, regulators, or parties involved in legal process, when required by law or to protect rights and safety.
  • Successors in a merger, acquisition, or asset sale, subject to this Policy or a successor notice.
  • We do not sell your personal information for money. If we ever use data for cross-context behavioural advertising in jurisdictions that define that as “selling” or “sharing,” we will provide required opt-out mechanisms.

8. International transfers

Your information may be processed in countries other than where you live. Where required, we use appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms for transfers from the EEA/UK.

9. How long we keep data

  • Account and profile data: while your account is active and for a reasonable period afterward to resolve disputes, enforce Terms, and meet legal obligations.
  • Contact messages, partner applications, and guide flags: for as long as needed to handle your request, operate the Service, and meet legal obligations.
  • Analytics and server activity logs: typically for a limited period unless needed for security investigation or aggregate reporting.
  • Browser session data (such as guide search context): until you close the tab or session, or until you clear site data in your browser.
  • You may request deletion as described below; some data may be retained where law requires or where anonymized aggregates are used.

10. Security

We implement administrative, technical, and organizational measures appropriate to the risk, such as access controls, encryption in transit, and monitoring. No method of transmission or storage is completely secure; you use the Service at your own risk and should protect your credentials.

11. Your privacy rights

To exercise rights, use in-app profile settings where available or contact us through the channels listed below. We may verify your identity before responding.

  • Access, correction, and deletion of personal data we hold about you, subject to exceptions.
  • Restriction or objection to certain processing, and data portability where GDPR applies.
  • Withdrawal of consent where processing is consent-based, without affecting prior lawful processing.
  • Opt-out of marketing communications at any time.
  • For California residents: rights to know, delete, and correct personal information, and to opt out of sale/sharing where applicable.
  • Lodge a complaint with your local supervisory authority if you are in the EEA/UK and believe we have not addressed your concern.

12. Children

The Service is not directed to children under 16 (or the higher age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided data, contact us so we can delete it.

13. Cookies and similar technologies

We use essential cookies and local storage for authentication, session persistence (including “Remember me” preferences), guide context in your browser session, and security.

When enabled, we use analytics technologies (such as PostHog) to understand usage of the Service. Non-essential advertising cookies, if introduced separately, will be described in a cookie notice with choices where required by law.

14. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the revised version with an updated “Last updated” date and, where required, notify you of material changes.

15. Contact

For privacy questions or requests, visit our Contact Us page at https://safarwise.app/contact or email support@safarwise.app.

For partnership-related privacy questions, email partnerships@safarwise.app.

You may also contact the founder at bilal@safarwise.app.