Legal

Privacy Policy

Last updated: July 9, 2026

1. Introduction

JourneyFuse LLC ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the JourneyFuse platform ("the Service").

2. Information We Collect

Information you provide

  • Account information: name, email address, and password when you register
  • Profile information: business name, agency details, and contact information
  • Client data: traveler profiles, trip details, itineraries, and communications you manage through the Service
  • Payment information: billing details processed securely through our payment provider (Stripe)

Information collected automatically

  • Usage data: pages visited, features used, and actions taken within the Service
  • Device information: browser type, operating system, and device identifiers
  • Log data: IP address, access times, and referring URLs
  • Cookies and similar technologies for session management, analytics, and advertising (see section 9)

3. How We Use Your Information

  • Provide, maintain, and improve the Service
  • Process transactions and send related information
  • Send you technical notices, updates, and support messages
  • Respond to your comments, questions, and customer service requests
  • Monitor and analyze trends, usage, and activities to improve the Service
  • Detect, investigate, and prevent fraudulent transactions and other illegal activities
  • Personalize and improve your experience

4. Data Sharing & Disclosure

We do not sell your personal information. We may share your information only in the following circumstances:

  • Service providers: Third-party vendors who assist us in operating the Service (e.g., hosting, payment processing, email delivery, analytics). A full list is published at /sub-processors.
  • Legal requirements: When required by law, subpoena, or other legal process
  • Protection of rights: To protect the rights, property, or safety of JourneyFuse, our users, or others
  • Business transfers: In connection with a merger, acquisition, or sale of assets, with notice to affected users

5. Client Data

The data you store about your clients (traveler profiles, trip details, communications, financial records, credit card authorizations, etc.) is Your Data. We process it solely to provide the Service to you. We do not access, use, or share your client data for our own purposes. You are responsible for ensuring you have the appropriate consent from your clients to store their information in the Service.

Your JourneyFuse subscription is billed through Stripe, a PCI-compliant payment processor. Client credit card authorizations collected through proposals or invoices are encrypted and stored in Evervault's PCI DSS Level 1 certified infrastructure — the highest level of payment security certification. In both cases, payment card data is never stored on JourneyFuse servers and client payment information is accessible only within your workspace.

When you use the passport photo OCR feature to extract fields from a passport image, the image is sent to OpenAI's API for one-time field extraction under OpenAI's no-training data processing terms. The extracted fields are written to your workspace; the image is not retained by OpenAI for model training. You can choose to enter passport details manually instead if you prefer not to use this feature.

6. Workspace Data Isolation

JourneyFuse is designed with strict data isolation between workspaces. Each agency or advisor account operates in a completely separate environment:

  • Your client data, trip information, financial records, communications, and all other workspace content is architecturally separated from every other user's data at the database level
  • No other user, agency, or advisor on the platform can view, access, search, or export your data — there are no shared directories, client lists, or cross-workspace discovery features
  • JourneyFuse employees access your data only when (a) you request technical support, (b) a security incident requires investigation, or (c) we are compelled by legal process
  • We do not use your client data to build profiles, generate leads, create marketing lists, or provide business intelligence to any third party, including other users of the Service
  • Credit card authorization data collected from your clients is isolated to your workspace and is never accessible to other agencies or advisors on the platform

7. Data Security

We implement industry-standard security measures to protect your information, including encryption in transit (TLS/SSL) and at rest, secure authentication, and regular security reviews. However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

8. Data Retention

We retain your information for as long as your account is active or as needed to provide the Service. Upon account deletion, we will delete or anonymize your data within 30 days, except where we are required to retain it for legal or legitimate business purposes.

9. Cookies & Tracking

We use cookies and similar technologies in three categories:

  • Essential: required to keep you signed in, maintain your session, and secure the Service. These are always active and cannot be turned off.
  • Analytics: help us understand aggregate traffic and how our marketing pages are used, so we can improve them. We use Google Analytics for this.
  • Advertising: used to measure the performance of our advertising and to show relevant ads. These are set by Google (Google Ads, Google Tag Manager) and Meta (the Meta Pixel), and may involve sharing limited information with those networks.

Analytics and advertising cookies are only used on our public marketing and sign-up pages — never inside the authenticated product or on the proposal, itinerary, invoice, and portal pages your clients see.

We ask for your consent before setting non-essential cookies. Visitors in the European Economic Area, the United Kingdom, and Switzerland must opt in before any advertising or analytics cookies are set. Visitors elsewhere can opt out at any time. You can change your choices whenever you like using the "Cookie preferences" link in our website footer.

We also honor the Global Privacy Control (GPC) browser signal as a request to opt out of the sale or sharing of your personal information for advertising.

10. Third-Party Services

The Service integrates with third-party services (e.g., email providers, payment processors, travel booking systems). When you connect a third-party service, that provider's privacy policy governs their handling of your data. We encourage you to review their policies.

10a. Google API Services

When you connect your Google account, JourneyFuse accesses the following data:

Gmail (when email sync is enabled):

  • Reads incoming emails to match them with your client records
  • Sends emails on your behalf through your Gmail account
  • Sets up push notifications to detect new emails in real-time

Google Calendar (when calendar sync is enabled):

  • Reads your calendar list to let you choose which calendars to sync
  • Creates, updates, and deletes events on your selected calendar for trips, tasks, and payments
  • Reads events from calendars you subscribe to and displays them in the JourneyFuse calendar view

JourneyFuse's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect Google services at any time from Settings > Email (for Gmail) or Settings > Calendar (for Google Calendar). You can also revoke access from your Google Account at myaccount.google.com/permissions.

10b. Microsoft 365 Services

When you connect your Microsoft account, JourneyFuse accesses the following data:

Outlook Mail (when email sync is enabled):

  • Reads incoming emails to match them with your client records
  • Sends emails on your behalf through your Outlook account

Outlook Calendar (when calendar sync is enabled):

  • Reads your calendar list to let you choose which calendars to sync
  • Creates, updates, and deletes events on your selected calendar for trips, tasks, and payments

JourneyFuse accesses only the data necessary to provide the features you enable. We do not sell or share your Microsoft account data with third parties, and we use it solely to operate the integration features you have turned on.

You can disconnect Microsoft services at any time from Settings > Email (for Outlook Mail) or Settings > Calendar (for Outlook Calendar). You can also revoke access from your Microsoft Account at account.microsoft.com/privacy/app-access.

11. Your Rights

Depending on your location, you may have the right to:

  • Access and receive a copy of your personal data
  • Correct inaccurate or incomplete personal data
  • Request deletion of your personal data
  • Object to or restrict processing of your personal data
  • Data portability, receive your data in a structured, machine-readable format
  • Withdraw consent at any time where processing is based on consent
  • Opt out of the sale or sharing of your personal information (we do not sell personal information)
  • Lodge a complaint with a data protection authority

To exercise any of these rights, contact us at privacy@journeyfuse.com. Self-serve data export is also available from inside the product at Settings > Data Export.

11a. GDPR (European Economic Area, United Kingdom, and Switzerland)

For users and clients whose personal data is processed under the EU General Data Protection Regulation, UK GDPR, or the Swiss Federal Act on Data Protection, JourneyFuse acts as a data processor for the client data you store on the platform, and as a data controller for account and usage data about you as the workspace user.

Our lawful bases for processing include performance of a contract (operating the Service), legitimate interests (securing and improving the Service), and consent (where required for marketing or optional features).

All rights listed in section 11 above are honored for GDPR-covered data subjects. Requests are answered within 30 days. To submit a request, email privacy@journeyfuse.com.

Customers who require a signed Data Processing Agreement (DPA), including Standard Contractual Clauses for international transfers, can request one at /dpa.

11b. CCPA / CPRA (California)

For California residents, the California Consumer Privacy Act (as amended by the CPRA) provides the following rights:

  • Right to know what personal information is collected, used, shared, or sold
  • Right to delete personal information held by us
  • Right to correct inaccurate personal information
  • Right to opt out of the sale or sharing of personal information
  • Right to limit the use of sensitive personal information
  • Right to non-discrimination for exercising these rights

JourneyFuse does not sell your personal information for money. However, our public marketing and sign-up pages use advertising cookies from Google and Meta (see section 9). Under the CPRA, this use may be considered "sharing" personal information for cross-context behavioral advertising. We do not engage in this sharing on the authenticated product or on the client-facing pages (proposals, itineraries, invoices, portals) that contain your or your clients' data.

You can opt out of this sharing at any time using the "Cookie preferences" / "Do Not Sell or Share My Personal Information" link in our website footer, or by enabling the Global Privacy Control (GPC) signal in your browser, which we honor automatically.

To exercise your other CCPA rights, email privacy@journeyfuse.com with "CCPA Request" in the subject line.

11c. International Data Transfers

JourneyFuse processes data on infrastructure located in the United States. Customers outside the United States who require formal international transfer arrangements (including Standard Contractual Clauses for transfers from the EEA, UK, or Switzerland) can request them by emailing privacy@journeyfuse.com.

A full list of sub-processors with their locations and roles is published at /sub-processors.

12. Children's Privacy

The Service is not intended for children under 16. We do not knowingly collect personal information from children under 16. If we learn that we have collected such information, we will take steps to delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Service and updating the "Last updated" date. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.

14. Contact

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at hello@journeyfuse.com.

See also our Terms of Service