VoyZa Privacy Policy
Last updated: July 3, 2026
Effective date: July 3, 2026
This Privacy Policy explains how VoyZa ("VoyZa," "we," "us," or "our") collects, uses, shares, and protects your personal information when you use the VoyZa mobile application on iOS and Android (the "App"). VoyZa is a trip planner and multi-stop route optimizer that lets you save places, build itineraries, optimize routes, and collaborate on trips with people you invite.
Please read this policy carefully. By using the App, you agree to the practices described here. If you do not agree, please do not use the App.
1. Who We Are and How to Contact Us
VoyZa is operated by Heng Kok, an individual developer (sole trader) based in Phnom Penh, Cambodia, who is the data controller for the personal information described in this policy. "VoyZa" and "Xtremon" are brand/trading names used by the operator; there is currently no separate registered company, so the responsible legal person is the individual named here.
- Controller: Heng Kok (individual / sole trader, trading as VoyZa)
- Country of establishment: Cambodia
- App: VoyZa (iOS and Android)
- Website: https://voyza.xtremon.com
- Privacy policy: https://voyza.xtremon.com/privacy
- Contact email: hengsamkok76@gmail.com
"VoyZa" is a brand/trading name operated by the individual named above. If you wish to identify, contact, or bring a claim against the controller, the individual and address named above is the responsible legal person.
Data Protection Officer. We have assessed our processing under Article 37 GDPR / UK GDPR and have determined that we are not required to appoint a Data Protection Officer (our core activities do not consist of large-scale systematic monitoring or large-scale processing of special-category data). Privacy matters are handled directly by the controller at the contact details above.
EU and UK data subjects (Article 27). The controller is established outside the EU and the UK. We are a small independent developer and have not appointed an Article 27 representative in the EU or the UK. If you are in the EEA, the UK, or Switzerland, you can raise any privacy matter with us directly at hengsamkok76@gmail.com, and we will respond. You also retain the right to lodge a complaint with your local supervisory authority at any time (see Section 13).
If you have any questions about this policy or want to exercise your privacy rights, email us at hengsamkok76@gmail.com or write to the controller at the registered address above.
2. What Data We Collect
We collect the categories of personal information set out below. We only collect what we need to operate the App, process your subscription, keep the service secure, and improve it.
| Category | Examples | Source | Where it is stored / sent |
|---|---|---|---|
| Account & identity | Email address, password (used only to authenticate you), first and last name, phone number, your VoyZa user ID. Optional profile fields that you may choose to add: profile picture, bio, date of birth, gender, address, city, country, preferences. | You, at sign-up / in your profile | Supabase (authentication + profile database; password authentication is handled by Supabase). Your email, and — where you provide them at sign-up — your name and phone number, are shared with RevenueCat as subscriber attributes. Your email may be cached on your device if you choose "Remember me." |
| Trip & location content | Trips (name, description, dates, country, status), saved places (name, address, precise latitude/longitude, scheduled dates, stay duration, notes, opening-hours overrides, done/skipped flags), waypoints, optimized routes, place search queries, and CSV exports you create. | You, and place details returned by Google | On your device (Hive / local storage) and Supabase. Coordinates and search queries are sent to Google Maps Platform to provide search, geocoding, and routing. Content on a shared trip is visible to collaborators you invite. |
| Precise location | Your device's current GPS latitude/longitude while you use the App. | Device sensor (location permission, while-in-use only) | Used on-device to show your position on the map, bias place searches, detect your country, and calculate distances. Sent to Google Maps Platform for these features. We do not store your raw GPS history on our servers, and we do not collect background location. |
| Place photos | Photos of places shown on place cards, sourced from Google Places (photo references resolved to image URLs and cached briefly on your device). | Third party (Google Places) | Google Maps Platform; image URLs cached on-device for a short period. The App does not access your device camera or photo library. |
| Purchases & subscriptions | Subscription/product identifier, price, currency, entitlement and trial status, trial expiry, store receipts, and a RevenueCat app user ID (which may be anonymous before sign-up). | Your purchase via the App Store or Google Play | Raw store receipts stay with RevenueCat and Apple/Google; only derived subscription fields (status, product identifier, store, expiry, and renewal flags) are mirrored to Supabase. Price and currency of a purchase are sent to Firebase/Google Analytics as a conversion event (subject to the consent gate in Section 6). |
| Usage & analytics | In-app events such as sign-up, trip created, place added (and your total place count), route optimized (and number of stops), trial started, and purchase (with value and currency). | Derived from your use of the App | Firebase Analytics / Google Analytics 4 (subject to the consent gate described in Section 6). |
| Device identifiers | A Firebase installation/app-instance ID; a RevenueCat app user ID; an FCM push registration token; a locally generated anonymous UUID for pre-sign-up activity; a device ID (Android ID or iOS identifier-for-vendor) used for free-trial and referral abuse prevention; and, on Android, the Advertising ID (analytics/measurement signals only; not collected before consent for EEA/UK/CH users — see Section 6). | Device/OS APIs and SDK-generated | Firebase/Google, RevenueCat, and Supabase (push token in device_tokens; abuse-prevention device ID in trial_devices). The anonymous UUID stays on your device. |
| Diagnostics: performance & stability | Cold-start time, slow/frozen frame traces, network latency, limited crash/stability signals, and related device/app metadata (device model, OS version, app version, network/carrier, country derived from IP). | Derived (Firebase Analytics / Performance SDKs) | Firebase (Analytics and Performance Monitoring). We do not run a dedicated crash-reporting SDK (e.g., Crashlytics); only the limited stability signals captured by Firebase Analytics/Performance are collected. |
| Push token | Your device's FCM push notification token and device platform (iOS/Android). | Device (Firebase Cloud Messaging) | Supabase device_tokens, keyed to your user ID. When you sign out, a token is marked inactive so we can stop sending to it and avoid resurrecting stale tokens; see the retention period in Section 10. |
| Support & communications | The content of emails you send us and emails we send you (e.g., onboarding welcome, activation reminder, referral reward, win-back; password reset and other authentication emails are sent via Supabase Auth). | You / our email service | Our inbox; lifecycle emails are sent via Resend; authentication emails (e.g., password reset) are sent via Supabase Auth's email service. |
| Referrals & invitations | Your personal referral code; a referral record linking you (as referrer) to the person who accepts your invitation (as referee) and the resulting reward status; and, when you invite someone who is not yet a VoyZa user, the email address you entered for them together with the trip you invited them to and your referral code. | You (by inviting someone or entering a referral code) | Supabase (referral_codes, referrals, and pending_trip_invites). A pending-invitation email is stored only until that person signs up or the invitation expires (30 days), after which it is deleted. Used to operate the referral program, connect an invited person to your trip, reward eligible referrers and referees with promotional VoyZa Pro, and prevent referral fraud. |
Location fingerprints (deduplication)
When your saved places sync, we compute a one-way SHA-256 hash of each place's name plus its coordinates. This "fingerprint" is used only to detect and remove duplicate places when local data syncs to the cloud. It is a content hash of place data — it is not a device or person tracking identifier — and it is stored alongside your locations in Supabase.
Free-trial abuse prevention (device check)
To enforce one free trial per device and prevent abuse of our free tier, when you start a trial we read a device identifier (the Android ID on Android, or the identifier-for-vendor on iOS) and store it with your user ID and the product in our trial_devices registry. This is a persistent, hardware-linked identifier used to prevent abuse of our free and promotional offers — repeated free-trial sign-ups on the same device, and referral rewards claimed by referring an additional account of your own on a device you have already used. We do not use it for advertising. See Sections 4 (lawful basis and balancing test), 10 (retention), and 13 (your right to object and our automated-processing statement).
3. How We Use Your Data
We use your personal information to:
- Provide the App: create and manage your account, save your trips and places, optimize multi-stop routes, show maps, autocomplete and search for places, geocode addresses, and sync your data across devices.
- Enable collaboration: let you invite others to a trip and share trip content with the collaborators you choose; if you invite someone who does not yet have a VoyZa account, we hold a pending invitation (keyed to the email you entered) so they can join that trip when they sign up (see Section 7).
- Process subscriptions: manage purchases, trials, restores, and entitlements through RevenueCat and the app stores.
- Send notifications and transactional email: deliver push notifications about trip activity and collaboration, and transactional emails such as password reset.
- Send lifecycle / marketing email (with opt-out): send onboarding (welcome), activation-reminder, and win-back emails. These are sent on a soft opt-in / legitimate-interest basis and you can unsubscribe at any time (see Section 4).
- Operate the referral and invitation program: let you invite friends and collaborators, connect an invited person to the trip and to you when they join, grant referral rewards (promotional VoyZa Pro to eligible referrers and referees), and prevent referral fraud (see Sections 4 and 7).
- Prevent abuse and secure the service: enforce one free trial per device, prevent referral fraud, detect other fraud and misuse, and protect the integrity of the App.
- Understand and improve the App: measure how features are used through analytics and monitor performance and stability (subject to consent where required — see Section 6).
- Measure advertising: attribute installs and conversions from our marketing campaigns (see Section 6).
- Request feedback: occasionally show the native in-app rating prompt after you complete an action such as optimizing a route. This prompt is handled entirely by Apple or Google; we do not receive any personal data from it.
- Comply with law: meet our legal obligations and respond to lawful requests.
4. Legal Bases for Processing (GDPR / UK GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the legal bases mapped purpose-by-purpose in the table below.
| Processing purpose | Personal data involved | Lawful basis |
|---|---|---|
| Create and manage your account; authenticate you | Account & identity | Performance of a contract — Art. 6(1)(b) |
| Provide core features (trips, places, route optimization, collaboration, sync) | Trip & location content, precise location, place photos | Performance of a contract — Art. 6(1)(b) |
| Operate the referral and invitation program, including holding a pending invitation and its email so an invited person can join your trip and both sides can be rewarded | Referrals & invitations; account & identity | Taking steps at your request / performance of a contract — Art. 6(1)(b); and legitimate interests in running a referral program and connecting invited users — Art. 6(1)(f). For the email of a person who is not yet a user, we rely on our legitimate interest in delivering the invitation you asked us to send, balanced against their interests through data minimization and short retention (deleted on sign-up or after 30 days). |
| Process subscriptions, trials, restores, and entitlements; share email/name/phone with RevenueCat as subscriber attributes to operate billing | Purchases & subscriptions; account & identity | Performance of a contract — Art. 6(1)(b); and legitimate interests in fraud-resistant billing and account linkage — Art. 6(1)(f) |
| Send transactional email (e.g., password reset) and operational push notifications | Account & identity, push token | Performance of a contract — Art. 6(1)(b); push delivery also relies on your OS-level notification permission |
| Send lifecycle/marketing email (welcome, activation reminder, win-back) | Account & identity (email) | Consent / soft opt-in — Art. 6(1)(a) / PECR Reg. 22; you can unsubscribe by emailing us |
| Prevent free-trial and referral abuse via the device check (persistent device identifier) | Abuse-prevention device ID | Legitimate interests — Art. 6(1)(f); see the balancing-test summary below |
| Detect fraud/misuse and secure the service | Device identifiers, account & identity, diagnostics | Legitimate interests — Art. 6(1)(f) |
| Product/usage analytics and performance/stability monitoring | Usage & analytics, diagnostics, device identifiers | Consent — Art. 6(1)(a) (in the EEA/UK/CH these are off until you opt in — see Section 6) |
| Advertising attribution and conversion measurement (incl. Android Advertising ID, Google Ads conversion signals) | Usage & analytics, Advertising ID (Android), purchase events | Consent — Art. 6(1)(a) (off until opt-in for EEA/UK/CH users — see Section 6) |
| Comply with tax, accounting, and lawful requests | Purchases & subscriptions; relevant records | Legal obligation — Art. 6(1)(c) |
Device-check balancing test (legitimate-interest assessment, Art. 6(1)(f) + ePrivacy/PECR). We rely on legitimate interests to read and store a persistent, hardware-linked device identifier to prevent abuse of our free and promotional offers — enforcing one free trial per device and preventing referral-reward abuse (such as referring an additional account of your own on a device you have already used). We conducted a balancing test and concluded that: (a) the interest (preventing repeat-trial and referral-reward abuse of a paid service) is legitimate and necessary; (b) the processing is limited to a single identifier tied to your account and product, is never used for advertising or cross-app tracking, and is retained for a limited period (see Section 10); and (c) the limited impact on you does not override our interest, particularly given your right to object below. Because reading an identifier from the device can engage ePrivacy/PECR, for EEA/UK/CH users this access occurs only in connection with a trial you actively start (a service you request) and is not used for any non-essential analytics or advertising purpose. You can object to this processing at any time (see Section 13); we will assess any objection and, where it succeeds, cease the processing.
Marketing email — soft opt-in. Lifecycle/marketing emails (welcome, activation reminder, win-back) are treated as direct marketing. We send them on a soft opt-in / consent basis to people who have an account, and you can unsubscribe at any time by emailing hengsamkok76@gmail.com; we will promptly stop sending them. Transactional and authentication emails (e.g., password reset) are separate and necessary to provide the service.
Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal (see Sections 6 and 13 for how).
5. Push Notifications and Device Permissions
The App requests the following device permissions:
- Location (while-in-use): to show your position on the map, bias place searches to your area, detect your country, and calculate distances. We do not request background or "always" location.
- Notifications: to deliver push notifications about trip activity and collaboration. You can disable notifications at any time in your device settings.
- Network / Internet: required for the App to function.
- Advertising ID (Android only): used for analytics and advertising measurement, subject to the consent gate in Section 6 (for EEA/UK/CH users it is not collected before opt-in consent).
The App does not request access to your camera, photo library, microphone, contacts, calendar, or Bluetooth.
6. Advertising and Analytics
We keep advertising and analytics deliberately limited and transparent. Here is exactly what we do on each platform.
ePrivacy / PECR — consent before any non-essential access (EEA, UK, Switzerland)
For users in the EEA, the UK, and Switzerland, no non-essential SDK reads from or writes to your device, and no analytics or advertising signal fires, before you give opt-in consent. This includes Firebase Analytics / Google Analytics 4, Google Ads conversion measurement, the Android Advertising ID, and any conversion/measurement signal. In particular, for these users the Android Advertising ID is not collected for analytics or advertising before consent. Only essential, service-providing processing that you actively request runs without this consent. This reflects the prior-consent requirement under ePrivacy / PECR for storing or accessing information on your device, which applies independently of any GDPR legal basis.
On iOS
- On iOS we use the Apple Search Ads (AdServices) attribution token only, for aggregate, campaign-level measurement of whether our marketing led to an install or subscription (collected via RevenueCat).
- We do not register an SKAdNetwork ID or declare
SKAdNetworkItems, and we do not use SKAdNetwork ad-network attribution (the Google Analytics SDK bundles on-device conversion components, but they are not configured for SKAdNetwork attribution). We do not show an App Tracking Transparency (ATT) prompt, we do not access the IDFA, and we do not track you across other companies' apps and websites for advertising. Our iOS privacy declaration isNSPrivacyTracking = falsewith no tracking domains.
On Android
- We use the Advertising ID for analytics and advertising measurement (for example, to attribute app installs and subscriptions to our campaigns) — and, for EEA/UK/CH users, only after opt-in consent (see above).
- You can reset your Advertising ID or opt out of ad personalization at any time in your device's system settings (Settings → Google → Ads). When you opt out at the OS level, we respect that choice.
Analytics and advertising consent (EEA, UK, Switzerland)
For users in the EEA, the UK, and Switzerland, advertising- and analytics-related signals (including Google Consent Mode signals such as ad_storage, ad_user_data, and ad_personalization) are off by default until you give in-app consent (opt-in). You can change your choice at any time in the App at Settings → Privacy → Analytics & Ads consent, and you can withdraw consent there at any time.
We determine whether the opt-in requirement applies based on your device's locale/region setting. Where your device region indicates the EEA, the UK, or Switzerland, analytics and advertising signals remain off until you opt in. We do not currently use IP-based geolocation, so if your device region is set to a country outside the EEA/UK/CH these signals may default on. You can review and change your choice at any time in the App at Settings → Privacy → Analytics & Ads consent, and withdraw consent there at any time.
Our advertising and measurement partners
Today, we use only the following to run and measure marketing campaigns:
- Google Ads for app-install campaign delivery and conversion measurement, and the RevenueCat → Firebase → Google Analytics 4 conversion pipeline (configured).
- Apple Search Ads (AdServices) attribution token on iOS, as described above.
For ad measurement, Google (Google Ads / Google Analytics) typically acts as an independent or joint controller for the relevant device/event signals, not merely as our processor; their handling is governed by their own controller privacy terms (linked in Section 8). Any device or event data sent to them for EEA/UK/CH users is covered by the opt-in consent gate above.
We do not currently integrate Meta (Facebook/Instagram), AppsFlyer, Adjust, the Meta Audience Network, or any IDFA-based cross-app tracking SDK, and the App sends no data to Meta. No user-level cross-app tracking occurs today. If we ever introduce Meta or any user-level attribution/tracking, we will first update this policy and our iOS tracking declaration — presenting an ATT prompt, setting NSPrivacyTracking = true, and declaring tracking domains — before enabling it.
7. Trip Collaboration and Sharing Between Users
Collaboration is a core feature of VoyZa, and it is the most important sharing surface to understand.
- Inviting collaborators: You invite someone to a trip by entering their email address. If that email belongs to an existing VoyZa account, our backend (Supabase) links them to the trip. If it does not yet belong to a VoyZa account, we store a pending invitation — the email address you entered, the trip, your user ID, and your referral code — so that when that person signs up with the same email they are automatically added to the trip and both of you may receive a referral reward. A pending invitation is deleted when it is claimed or when it expires (30 days). Only invite people who are happy to be contacted and added.
- Referral program: When you share a referral link or code and someone signs up through it — or when you invite a non-user as described above — we record a referral connecting you (the referrer) to that person (the referee) so we can grant the reward. Both of you may receive promotional VoyZa Pro when the referee starts a qualifying trial or subscription. Referral rewards are subject to anti-fraud checks and the limits described in the app's Terms; see Sections 3 and 4.
- What collaborators can see: Once added, a collaborator with read or write access can see the entire trip's contents — all saved places (names, precise coordinates, addresses, photos, scheduled dates, notes, durations) and the trip name, description, and dates. Edits stream between collaborators in real time.
- Collaborator emails are visible to the group: Every member of a shared trip can see the email address of every other member, and who invited whom.
- CSV export / OS share sheet: When you export a trip to CSV or use your device's share sheet, the full itinerary (place names, addresses, scheduled dates, durations, travel times) leaves the App and is sent to whatever app or person you choose. Once you share it, that data is outside our control.
- In-app notifications: when someone invites you to a trip or collaborates with you, we store an in-app notification on our servers (including the inviter's name and the trip name) so you can see your notification history in the App. These are protected by row-level security, retained while your account is active, and deleted when you delete your account.
Only add content and invite people if you are comfortable with this visibility.
8. Sharing and Disclosure
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. We disclose data only as described below.
Most providers below act as our processors (acting only on our instructions). However, our advertising/measurement partners (Google Ads and Google Analytics for ad-conversion measurement) typically act as independent or joint controllers for the device/event signals involved; their processing is governed by their own controller privacy terms, linked below, and is subject to the consent gate in Section 6 for EEA/UK/CH users.
Service providers and partners
| Provider | Role | Purpose | What is shared | Privacy policy / terms |
|---|---|---|---|---|
| Supabase | Processor | Authentication (incl. password auth, password-reset and other authentication emails, and the email→user lookup for collaboration invites), database, realtime sync, backend functions | Account/identity, trip & place content, push tokens, subscription mirror, abuse-prevention device ID, collaborator data | supabase.com/privacy |
| RevenueCat | Processor | Subscription and in-app purchase management, paywall, restore | App user ID, email, and (where you provide them at sign-up) name and phone, purchase/receipt and entitlement data, attribution metadata (Apple Search Ads token on iOS + Firebase app-instance ID linkage) | revenuecat.com/privacy |
| Firebase / Google — Analytics (GA4) | Processor for product analytics; independent/joint controller for ad-conversion signals | Product and funnel analytics; ad conversion measurement | App-instance ID, usage events, purchase events, ad/consent signals, Advertising ID (Android) | firebase.google.com/support/privacy and policies.google.com/privacy |
| Firebase / Google — Cloud Messaging (FCM) | Processor | Push notifications | Push registration token, device platform, installation ID | firebase.google.com/support/privacy |
| Firebase / Google — Performance Monitoring | Processor | Performance and stability diagnostics | Performance/trace data, device/app metadata, instance ID | firebase.google.com/support/privacy |
| Google Maps Platform / Places | Processor | Maps, place search/autocomplete, geocoding, directions, place photos | Search queries, precise coordinates, place IDs, addresses | policies.google.com/privacy and cloud.google.com/maps-platform/terms |
| Resend | Processor | Lifecycle email (onboarding welcome, activation reminder, win-back) | Email address | resend.com/legal/privacy-policy |
| Apple App Store | Independent controller | Payment processing and subscription receipts (iOS) | Purchase/receipt data, store transaction IDs | apple.com/legal/privacy |
| Google Play | Independent controller | Payment processing and subscription receipts (Android) | Purchase/receipt data, store transaction IDs | policies.google.com/privacy |
| Google Ads | Independent/joint controller for ad measurement | App-install campaign delivery and conversion measurement | Conversion/attribution signals, Advertising ID (Android) | policies.google.com/privacy and business.safety.google/adscontrollerterms |
Other disclosures
- Other users: trip content you share with collaborators, as described in Section 7.
- Legal and safety: we may disclose information where required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of VoyZa, our users, or others.
- Business transfers: if VoyZa is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or use of your personal information.
9. International Data Transfers
VoyZa is operated with the help of service providers located in the United States and other countries. When you use the App, your personal information may be transferred to, stored, and processed in countries other than your own, including the United States, where data-protection laws may differ from those in your jurisdiction.
Where we transfer personal information out of the EEA, UK, or Switzerland, we rely on the specific safeguards below. We confirm that the EU Standard Contractual Clauses (with the UK International Data Transfer Addendum and the Swiss addendum where applicable) are in place with each US processor we engage, that we have carried out a transfer risk assessment for these transfers, and that, where a provider is certified under the EU-US Data Privacy Framework (and its UK Extension and Swiss-US framework), we additionally rely on that certification.
| Recipient / group | Country | Transfer mechanism relied on |
|---|---|---|
| Google / Firebase (Analytics, FCM, Performance, Maps/Places, Google Ads) | United States | EU-US Data Privacy Framework certification (and UK Extension / Swiss-US framework) and EU SCCs + UK IDTA |
| Apple (App Store, Apple Search Ads) | United States | EU-US Data Privacy Framework certification and/or EU SCCs + UK IDTA |
| RevenueCat | United States | EU SCCs + UK IDTA (and Swiss addendum) |
| Supabase | United States / EU regions | EU SCCs + UK IDTA where data is processed outside the EEA/UK |
| Resend | United States | EU SCCs + UK IDTA |
You have the right to obtain a copy of the relevant safeguards (e.g., the executed SCCs, with commercially confidential terms redacted). To request a copy, email hengsamkok76@gmail.com with the subject "Transfer safeguards request," and we will provide it.
10. Data Retention
We keep your personal information only for as long as we need it. Concrete periods and criteria are set out below:
- Account and profile data, trips, and saved places: retained while your account is active. When you delete your account, this data is deleted as described in Section 12.
- Subscription and purchase records: retained for the life of the subscription relationship and then for up to 7 years to meet legal, tax, and accounting obligations.
- Subscription event history (
user_subscription_history): a per-event audit log retained to support billing accuracy and reconciliation. Events recorded before you sign up are keyed only to an anonymous store identifier (no account link); a signed-up user's history is deleted when you delete your account. - Push tokens: an inactive token is retained to suppress stale deliveries; all push tokens are deleted when you delete your account.
- Referrals and invitations: your referral code and referral records (who referred whom, and reward status) are retained while your account is active and deleted when you delete your account. A pending invitation to a person who is not yet a user (their email, the trip, and your referral code) is deleted as soon as it is claimed or after it expires (30 days), whichever comes first.
- Abuse-prevention device IDs (
trial_devices): retained for as long as necessary to enforce the one-free-trial-per-device limit, and de-linked from your account (the account reference is cleared) when you delete your account, consistent with storage limitation (Art. 5(1)(e)). - Analytics and advertising data (GA4): user-level data is retained in Google Analytics 4 for the configured 14-month user-data retention window and then automatically deleted; aggregated reporting may persist longer in de-identified form.
- Performance / stability data (Firebase Performance): retained for Firebase's standard performance retention window (up to approximately 90 days for detailed traces).
- Support and email records: retained for as long as needed to handle your request and keep reasonable business records (typically up to 24 months).
When data is no longer needed, we delete or anonymize it.
11. Security
We take reasonable technical and organizational measures to protect your personal information. These include encrypted connections (HTTPS/TLS) for data in transit, authentication and access controls, database row-level security to enforce access rules, and platform-level protections that disable plaintext network traffic and exclude app data from device backups.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. You are responsible for keeping your account password confidential.
12. Account and Data Deletion
You can delete your VoyZa account at any time from within the App (Settings → Delete account). When you delete your account, we:
- delete your profile, trips, and saved locations from our servers;
- cascade-delete your trip collaborations, your referral code and referral records, any pending invitations you created, associated subscription records, and your stored push tokens (
device_tokens); and - clear VoyZa data stored locally on your device.
Retained after deletion: To enforce our one-free-trial-per-device limit and prevent referral-reward abuse, the device identifier in our abuse-prevention registry (trial_devices) is retained after account deletion — de-linked from your account — for the period stated in Section 10. See Sections 2 and 10. Some other information may be retained where we are legally required to keep it (for example, transaction records for tax purposes) or in backups for a limited period before being overwritten. Content you previously shared with collaborators or exported (for example, via CSV) may remain with those recipients.
Deleting without the App. If you cannot access the App, you can request account and data deletion via our web route at https://voyza.xtremon.com/#how-can-i-delete-my-voyza-account, or by emailing hengsamkok76@gmail.com. This web route is also referenced in our Google Play and App Store data-handling declarations.
13. Your Privacy Rights
How to exercise your rights (all regions)
You can exercise your rights by: (a) using the in-app controls described below; or (b) emailing hengsamkok76@gmail.com; or (c) writing to the controller at the registered address in Section 1; or (d) for deletion, using https://voyza.xtremon.com/#how-can-i-delete-my-voyza-account. EEA/UK users may also contact the Article 27 representatives named in Section 1.
- Withdraw analytics/advertising consent or object to analytics: in the App at Settings → Privacy → Analytics & Ads consent.
- Object to legitimate-interest processing (e.g., the free-trial abuse device check or fraud/security analytics): email hengsamkok76@gmail.com with the subject "Objection," identifying the processing; we will assess it and stop where required.
- Unsubscribe from lifecycle/marketing email: use the unsubscribe link in any such email, or email us.
- Delete your account/data: in-app (Settings → Delete account) or via https://voyza.xtremon.com/#how-can-i-delete-my-voyza-account.
We respond to rights requests free of charge and within one month of receipt (extendable by two further months for complex or numerous requests, in which case we will tell you within the first month). We may need to verify your identity before responding.
GDPR / UK GDPR (EEA, UK, Switzerland)
If you are in the EEA, the UK, or Switzerland, you have the right to:
- Access the personal information we hold about you;
- Rectify inaccurate or incomplete information;
- Erase your information ("right to be forgotten");
- Restrict processing in certain circumstances;
- Object to processing based on legitimate interests, and to direct marketing;
- Data portability — receive your data in a structured, commonly used, machine-readable format;
- Withdraw consent at any time where we rely on consent; and
- Lodge a complaint with a supervisory authority.
Automated decision-making / profiling. We do not carry out automated decision-making that produces legal or similarly significant effects about you under Article 22. The free-trial abuse device check is a simple rule-based duplicate-device check (it does not profile you or make significant automated decisions about you), and you may object to it as described above.
Supervisory authorities and complaints. You can lodge a complaint with your local supervisory authority. You can find your EEA authority via the European Data Protection Board's list at edpb.europa.eu. In the UK, you can contact the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint. In Switzerland, you can contact the Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch. We would, however, appreciate the chance to address your concerns first.
California (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, and disclose;
- Access and obtain a copy of your personal information;
- Delete your personal information;
- Correct inaccurate personal information; and
- Not be discriminated against for exercising your rights.
Categories and recipients. For the categories of personal information we collect, see Section 2; for the categories of recipients (service providers/processors and our ad-measurement controllers) and what we disclose to each for a business purpose, see Section 8. In the preceding 12 months we disclosed personal information (identifiers, account/contact data, commercial/purchase information, internet/usage activity, approximate and precise geolocation, and inferences) only to service providers for business purposes, plus device/event signals to our advertising-measurement controllers for ad attribution. We do not disclose personal information to third parties for monetary or other valuable consideration.
No sale / no sharing. We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We have not done so in the preceding 12 months. Because we do not sell or share personal information in this sense, no "Do Not Sell or Share My Personal Information" opt-out is required.
Response times. We confirm receipt of verifiable consumer requests within 10 business days and respond within 45 days (extendable by a further 45 days with notice). Requests are free of charge.
To exercise your California rights, email hengsamkok76@gmail.com or write to the controller at the address in Section 1. You may use an authorized agent, and we will verify requests as required by law.
Notice of Financial Incentive. Our free trial and any trial-recap/win-back messaging are standard product features and are not financial-incentive programs that are conditioned on, or that pay you for, your personal information; we do not currently offer any CPRA "financial incentive" or price/service difference in exchange for personal information. If we introduce one, we will add the required Notice of Financial Incentive here first.
Do Not Track / Global Privacy Control
Because VoyZa does not sell your personal information or share it for cross-context behavioral advertising, no opt-out is required. Global Privacy Control (GPC) and "Do Not Track" are browser-based signals that are not transmitted to native mobile apps; the App therefore has no mechanism to receive them, and they do not apply to the App. We manage advertising and analytics through the on-device consent controls and OS-level settings described in Section 6. If our website at voyza.xtremon.com processes GPC in the future, we will honor it there; we make no commitment to "honor GPC" in the App, which cannot receive it.
14. Children's Privacy
VoyZa is a general-audience trip-planning app and is not directed to children. The minimum age to use the App is:
- 16 in the EEA, the UK, and Switzerland, except where a Member State has set a lower age of digital consent under Article 8 GDPR (which may be 13, 14, 15, or 16), in which case that national age applies; and
- 13 in the United States and elsewhere.
We do not knowingly collect personal information from anyone below the applicable minimum age. Most processing for account holders relies on contract rather than consent; where national law sets a minimum age for entering into the relevant contract or for valid consent, that minimum-age rule applies, and a user below it should not use the App or should do so only with verifiable parental/guardian consent. Where processing relies on consent (e.g., analytics/advertising for EEA/UK/CH users), and a user is below the applicable age of digital consent, we require parental/guardian consent before that consent-based processing occurs; we use a self-declared date of birth and consent-gating as our age-assurance measure and do not knowingly proceed where the user is under age.
If we learn that we have collected personal information from a child below the applicable minimum age without the required parental/guardian consent, we will delete the account and associated personal information and remove any related abuse-prevention identifier from active use. If you believe a child has provided us personal information, contact us at hengsamkok76@gmail.com and we will act promptly.
15. Third-Party Links and Services
The App may link to or open third-party apps and services — for example, opening Google Maps or a ride-hailing app for directions, or the Apple App Store / Google Play for subscriptions. These third parties have their own privacy policies, and we are not responsible for their practices. We encourage you to review the privacy policy of any third-party service you use.
16. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page and, where appropriate, notify you in the App or by email, giving prior notice of material changes.
For any change that requires your consent (for example, new analytics or advertising processing), we will seek fresh, affirmative opt-in consent before that processing begins — continued use of the App will not be treated as consent to it. For non-consent-based informational updates, your continued use of the App after the update takes effect, following appropriate notice, indicates your awareness of the revised policy.
17. Contact Us
If you have any questions, requests, or complaints about this Privacy Policy or how we handle your personal information, contact us at:
Controller:
Heng Kok (individual, trading as VoyZa)
Email:
hengsamkok76@gmail.comWebsite:
https://voyza.xtremon.com