SavaliTrip

Privacy Policy

Effective from: 2026-05-29 · Version 1.0

This document describes how personal data is processed in the SavaliTrip service (trip.savaligear.com) in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Polish Act on Provision of Electronic Services. The Polish version at /prywatnosc is the binding version; this English translation is provided for convenience.

1. Data controller

Sławomir Śnieguła, doing business as Sniegula Expeditions, ul. Czarnieckiego 5, 88-400 Żnin, Poland, Polish tax ID (NIP) 5213392848.

Data protection contact: mail@savaligear.com.

The Controller has not appointed a Data Protection Officer — the scope of processing does not require one under GDPR Art. 37.

2. What data we process and why

Category Purpose Legal basis (GDPR) Retention
Email, username, password (bcrypt) Account creation and login Art. 6(1)(b) — contract performance Until Account deletion + 30 days backup
Content (trips, bags, items, notes) Providing the planning service Art. 6(1)(b) — contract performance Until Account deletion + 30 days backup
Vault documents (tickets, boarding passes, confirmations — encrypted) + metadata (file name, MIME type, size, kind) Storing travel documents chosen by the User Art. 6(1)(b) — contract performance Until document or Account deletion + 30 days backup
IP address (SHA-256 hashed), user agent Security, abuse detection Art. 6(1)(f) — legitimate interest 90 days
Affiliate clicks (hashed IP + product ID) Conversion statistics, partner reconciliation Art. 6(1)(f) — legitimate interest 24 months (aggregates indefinitely)
Public bags (content + slug) Display under public link Art. 6(1)(a) — consent Until consent withdrawn

3. Cookies

The Service uses only cookies essential for operation (session, CSRF token, language preference). No third-party marketing, advertising or analytics cookies are used (no Google Analytics, no Google Ads, no Facebook Pixel, no Hotjar, etc.).

4. Data recipients

We transfer data to the following categories of recipients:

We do not sell personal data. We do not share it with data brokers.

5. International transfers

Personal data is processed solely within the EEA (Hetzner — Germany). We do not transfer personal data outside the EEA.

6. What we do NOT do

7. Your rights

Under GDPR you have:

We respond to all requests within 30 days of receipt; in complex cases this may be extended by an additional 60 days with notice.

8. Security

We apply the following technical and organisational measures: password hashing with bcrypt and per-user salt, transmission only over HTTPS (TLS 1.3, Let's Encrypt certificate), session tokens in HttpOnly cookies with SameSite=Lax, SQLite database with file permissions restricted to the application process, encrypted backups with 30-day retention, security updates of dependencies at least monthly.

9. Travel document vault

The app offers an optional vault for travel documents. Files you upload to it (e.g. tickets, boarding passes, booking confirmations) are encrypted in your browser (AES-GCM) with a key derived from your password (PBKDF2). The encryption key is never sent to our server — we do not know it and cannot reconstruct it. This means we have no access to the contents of your documents (zero-knowledge architecture).

On our servers we store only: the encrypted file content (which we cannot read), the encryption initialisation vector and a cryptographic salt tied to your Account, and — in unencrypted form — the file name, type (MIME), size, chosen document kind and the date added. Please do not put sensitive data in the file name itself.

Important — a consequence of end-to-end encryption: because the key depends on your password and we do not store it, losing or changing your password in a way that prevents deriving the key means permanent loss of access to the encrypted documents. We are unable to recover or decrypt them.

Travel documents may contain special-category data or passport data (GDPR Art. 9). You alone decide whether and which documents to upload; we process them only technically, in encrypted form, without access to their contents, in order to provide the service to you (Art. 6(1)(b) GDPR). You, as the User, decide the vault's contents; we provide only encrypted storage.

10. Children's data

The Service is not directed at children under 16. Persons under 16 may use the Service only with the consent and under the supervision of a legal guardian (GDPR Art. 8). If we discover that an Account belongs to a child without guardian consent, we delete it without delay.

11. Mobile application

SavaliTrip is also planned as a mobile app (Android / iOS). Once published, it will use the same data as the web version and the rules below will apply to it.

The mobile app does not collect: location, contacts, calendar, microphone, camera (unless you manually pick a photo — then only the selected file reaches us), advertising identifiers (Advertising ID).

The app may store a session token in local device storage (Android Keystore / iOS Keychain) to keep you logged in.

SavaliTrip is free and contains no in-app payments or subscriptions.

12. Partner shops

When you click an affiliate link from the packing catalog you are taken to an external shop. The shop's privacy policy applies from that point. The Operator transfers to the shop only the product identifier in the UTM parameter, no User personal data.

13. Changes to this policy

Material changes are announced 14 days in advance by email and in-app notice. The current version is always available at trip.savaligear.com/en/privacy (PL: /prywatnosc).

14. Contact

Privacy questions and data subject requests: mail@savaligear.com. We respond within 7 business days (GDPR requests: within 30 days).