Last updated: July 3, 2026
This Privacy Policy describes how we process your personal data when you visit our website (notanothertravelapp.com and related domains), join our waitlist, or use the waltru mobile application (the "App"; together with the website, the "Service"). It is drafted in accordance with Regulation (EU) 2016/679 (the "GDPR"), the Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights ("LOPDGDD"), and Directive 2002/58/EC ("ePrivacy Directive") as implemented in Spain by Law 34/2002 (LSSI-CE).
1. Data Controller
The controller of your personal data is:
- Natanael Fiorilla (autónomo)
- NIF: 60345786L
- Registered address: Carrer Llorenç de Villalonga 24, 43007 Tarragona, Spain
- Contact email: waltru@notanothertravelapp.com
We have not appointed a Data Protection Officer because we are not required to do so under Article 37 GDPR. You may nevertheless raise any privacy matter at the address above.
2. Personal Data We Process
We process the following categories of personal data, depending on how you interact with the Service:
- Identity and contact data: first name, last name, email address, language preference, time zone, date of birth (optional), profile picture (optional), and the unique identifier issued by our authentication provider (Auth0 sub).
- Waitlist and partner enquiries: email address and, for partner enquiries only, name, LinkedIn URL, interest category and the free-text message you submit.
- Travel preferences ("Travel DNA"): interests (e.g. architecture, food, nature), travel pace, budget band, crowd tolerance and similar answers you provide in the onboarding quiz.
- Itinerary and usage data: itineraries generated for you, points of interest (POIs) you view, audio guides you play, routes you follow, and in-App interactions.
- Location data — foreground: when you start a tour and grant "while using the app" permission, the App continuously reads your precise GPS position (high accuracy, approximately every 3 seconds, 10-metre movement filter) and transmits it to our servers to detect proximity to POIs, adapt the route and trigger audio guides.
- Location data — background: if you additionally grant "Always" (iOS) or "Allow all the time" (Android) permission, the App continues to collect approximate GPS positions (balanced accuracy, approximately every 30 seconds, 50-metre movement filter) while the App is not in the foreground, solely to keep proximity-triggered features working while your phone is in your pocket. You can withdraw this consent at any time from your device's system settings; the foreground features continue to work without it.
- Payment and purchase data: purchase and entitlement status, product identifier, purchase timestamps and anonymised transaction identifiers received from RevenueCat and, only where the Stripe payment fallback is used, from Stripe. Purchases are one-off; we do not operate recurring subscriptions. Where the Stripe fallback is used, your card number and full payment credentials are collected and processed directly by Stripe and are never stored on our servers.
- Device and technical data: device model, operating system and version, App version, IP address, push-notification token (when you enable notifications), log and error data, and approximate location derived from the IP address.
- Website analytics data: pages viewed, referrer, approximate location (country/city), language, device and browser information, and events such as waitlist sign-up submissions, collected by Google Analytics 4 and, for session recordings and heatmaps, by Microsoft Clarity, when you consent to analytics cookies. Keyboard input in form fields is masked by default in the session-recording tool.
We do not knowingly collect special categories of personal data (Article 9 GDPR). Please do not submit health, religious, political or similar data through free-text fields.
3. Purposes and Legal Bases
We process your personal data for the following purposes, each supported by the legal basis set out below:
- Creating and managing your account and delivering the App (authentication, profile, itinerary generation, foreground GPS, audio guides, customer support) — performance of a contract (Article 6(1)(b) GDPR).
- Background location tracking during a tour — your explicit consent (Article 6(1)(a) GDPR), given through the operating-system permission dialog and confirmed through our in-App rationale screen. You can withdraw it at any time in your device settings without affecting the lawfulness of processing carried out before withdrawal.
- Personalising your itinerary using artificial intelligence (see Section 6) — performance of a contract (Article 6(1)(b) GDPR); personalisation is an essential element of the Service.
- Payments, subscriptions and invoicing — performance of a contract (Article 6(1)(b) GDPR) and compliance with tax and accounting obligations (Article 6(1)(c) GDPR, in connection with Spanish tax law).
- Push notifications with operational or tour information — your consent (Article 6(1)(a) GDPR), given through the system prompt.
- Waitlist, partner enquiries and service-related communications — your consent (Article 6(1)(a) GDPR) when you submit your email, and our legitimate interest in responding to your enquiry (Article 6(1)(f) GDPR).
- Commercial communications about products similar to those you requested — Article 21.2 LSSI-CE and your consent where required. You can opt out in every message at no cost.
- Website analytics, performance monitoring and functional cookies — your consent through our cookie banner (Article 22 LSSI-CE and Article 6(1)(a) GDPR).
- Security, fraud prevention, abuse detection and enforcement of our Terms — our legitimate interest in keeping the Service safe and available (Article 6(1)(f) GDPR).
- Compliance with legal obligations and responding to lawful requests — Article 6(1)(c) GDPR.
- Defending legal claims — our legitimate interest (Article 6(1)(f) GDPR) and Article 9(2)(f) GDPR where applicable.
4. Recipients and Processors
We share your personal data only with the recipients necessary to run the Service, under written data-processing agreements (Article 28 GDPR) that include the EU Standard Contractual Clauses where required. Our current sub-processors are:
- Okta, Inc. (Auth0) — identity and authentication. EU tenant (dev-waltru.eu.auth0.com).
- Amazon Web Services, Inc. — application hosting, database and object storage (Amazon S3) for generated audio narration.
- Anthropic, PBC — large-language-model processing (Claude) used to generate your personalised itinerary from your Travel DNA and the POI catalogue. Inputs are not used by Anthropic to train its general models.
- Google LLC / Google Ireland Ltd. — Google Maps Platform (routing, map tiles), Google Cloud Text-to-Speech (audio narration), Firebase Hosting for the website, and, on the website only, Google Analytics 4 (when you consent).
- Stripe Payments Europe, Ltd. — payment processing (independent controller for payment data).
- RevenueCat, Inc. — subscription management and entitlement verification.
- Expo (650 Industries, Inc.) — build services and Expo Push Notifications (routing of push tokens to Apple APNs and Google FCM).
- PostHog, Inc. — in-App product analytics and session replay.
- Microsoft Corporation (Clarity) — website session-recording and heatmap analytics (loaded only with your consent; keyboard input in forms masked by default).
- Apple Inc. and Google LLC — distribution of the App through the App Store and Google Play, and delivery of push notifications.
- EmailJS — transactional delivery of waitlist and partner-enquiry emails submitted through the website.
- Prospect One Sp. z o.o. (jsDelivr) and Unsplash, Inc. — content-delivery network for website scripts and hosting of city images shown on the website; these may process your IP address and request headers in standard server logs.
We do not sell your personal data, do not share it for cross-context behavioural advertising, and do not use it to train third-party AI models.
We may also disclose data to competent public authorities (police, courts, tax authorities) when legally required, and to professional advisers (lawyers, auditors) under duties of confidentiality, or to an acquirer in the context of a corporate transaction, in which case you will be informed in advance.
5. International Data Transfers
Some of the processors listed above are located in, or may access data from, countries outside the European Economic Area, principally the United States. Where no European Commission adequacy decision applies, transfers are protected by the EU Standard Contractual Clauses (2021/914) together with supplementary technical and organisational measures (encryption in transit and at rest, access controls, contractual limitations on government-access requests). Several US providers we rely on (including Google, Stripe, AWS and Anthropic) are also certified under the EU-US Data Privacy Framework where applicable. You can request a copy of the relevant transfer mechanism by writing to waltru@notanothertravelapp.com.
6. Automated Processing and Profiling
To build your itinerary we combine your Travel DNA, your coarse location and our POI catalogue, and submit them to a large-language-model service (Anthropic Claude). The output is a suggested route that you can edit, reject or ignore. This processing involves profiling within the meaning of Article 4(4) GDPR, but it does not produce legal effects or similarly significant effects on you within the meaning of Article 22(1) GDPR: the App is a travel companion and you remain free to follow, change or abandon the suggestions at any time. You can request human review of a suggestion or challenge it by writing to us.
7. Retention
We keep personal data only as long as necessary for the purposes described in this Policy:
- Account and profile data: for as long as your account is active, and up to 30 days after deletion to complete wind-down, plus any period required by law.
- Travel DNA and itineraries: while your account exists, so you can revisit past trips. You can delete individual itineraries at any time from the App.
- Foreground and background GPS logs: up to 90 days in identifiable form, after which we aggregate or delete them. Logs linked to a saved itinerary are retained with that itinerary until you delete it.
- Generated audio narration cache: up to 12 months from last playback.
- Payment and invoicing records: 6 years (Article 30 of the Spanish Commercial Code) and up to 10 years where anti-money-laundering rules apply.
- Waitlist email: until the product launches in your city, you unsubscribe, or 24 months of inactivity, whichever comes first.
- Partner enquiry data: up to 12 months after the enquiry is resolved, unless a longer period is legally required.
- Support correspondence: up to 3 years after the case is closed.
- Website analytics: up to 14 months (GA4 default) from last interaction.
- Security, fraud and access logs: up to 12 months.
After these periods expire we delete or irreversibly anonymise the data. We may retain data for longer where necessary to establish, exercise or defend legal claims, or where an applicable law requires a longer period.
8. Your Rights
Under the GDPR and the LOPDGDD you have the right to:
- Access the personal data we hold about you (Article 15 GDPR);
- Rectify inaccurate or incomplete data (Article 16 GDPR);
- Erase your data ("right to be forgotten") (Article 17 GDPR);
- Restrict processing in the cases listed in Article 18 GDPR;
- Data portability — receive your data in a structured, commonly used, machine-readable format or have it transmitted to another controller (Article 20 GDPR);
- Object to processing based on our legitimate interests and to direct marketing at any time (Article 21 GDPR);
- Withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Article 7(3) GDPR);
- Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects on you (Article 22 GDPR);
- Issue instructions regarding your personal data after your death, in accordance with Article 96 LOPDGDD.
To exercise any of these rights, write to us at waltru@notanothertravelapp.com with enough information to identify you. We will reply within one month (Article 12(3) GDPR), extendable by two further months for complex requests. The exercise of these rights is free of charge, save for manifestly unfounded or excessive requests.
You also have the right to lodge a complaint with a supervisory authority, in particular the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es, C/ Jorge Juan 6, 28001 Madrid), or with the supervisory authority of your EU/EEA country of residence or work.
9. Cookies and Similar Technologies
Our website uses strictly-necessary storage and, subject to your consent, analytics cookies from Google Analytics 4 (e.g. _ga, _ga_*) and Microsoft Clarity (e.g. _clck, _clsk, MUID, CLID), plus functional storage (such as remembering your language preference in localStorage). Analytics services load only after you accept through our cookie consent banner, and you can withdraw consent at any time from the "Cookie preferences" link at the bottom of every page. Full details are set out in our Cookie Policy. The mobile App does not use browser cookies but relies on equivalent local-storage mechanisms to keep you signed in and to store your preferences on the device.
10. Security
We apply technical and organisational measures appropriate to the risk (Article 32 GDPR), including HTTPS/TLS in transit, encryption at rest for audio and database storage, role-based access controls, least-privilege credentials, logging and monitoring, periodic backups, and contractual confidentiality obligations for our staff and processors. No system is perfectly secure; if a personal-data breach is likely to result in a risk to your rights, we will notify the AEPD within 72 hours and, where required, inform you directly (Articles 33–34 GDPR).
11. Children
The Service is not directed at children under the age of 14 (the age of digital consent in Spain under Article 7 LOPDGDD) and we do not knowingly collect their data. If you believe a child has provided us with personal data, please contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, new features, or legal requirements. When changes are material we will inform you by email or through an in-App notice at least 30 days before they take effect, and we will update the "Last updated" date above. Continued use of the Service after the effective date of the updated Policy means you have read it; where the change relies on consent we will ask for it again.
13. Contact
For any question or request related to this Policy or your personal data, contact us at waltru@notanothertravelapp.com.