Expevida

Legal

Privacy policy

What we collect, why we collect it, who else sees it, and how to make us delete it. Written to be read rather than to be survived.

Last reviewed 15 August 2026.

What we collect

Only what a trip actually requires. Specifically:

  • Your mobile number, when you sign in. We authenticate with a one-time code sent over WhatsApp, so the number is the account.
  • Your name and email address, when you give them to us in a trip request, an enquiry, the newsletter box or a Signature Escapes interest list.
  • Traveller details you enter for a booking — names, and ages where a vendor or an activity requires them.
  • Your wishlist and comparisons, so they follow you between devices.
  • Photos and notes you upload to your Experience Vault. These are private to your account and stored in a non-public bucket.
  • Anything you choose to write to us in a message.

We do not collect card or bank details. When online payments go live they will run through a regulated payment gateway that handles those details directly — the numbers never reach our servers.

Analytics, and what we deliberately don't do

We use PostHog, hosted in the European Union, to count page views and catch errors. It tells us which pages people read and where the site breaks. We do not run session replay, we do not run advertising pixels, and we do not sell or rent your data to anyone, for any price.

Local development traffic is excluded, so the numbers reflect real visitors rather than us.

Why we hold it

  • To plan, book and run the trip you asked for — which means telling the stay how many people are coming and what they eat.
  • To reach you about your own booking, and about the specific list you joined.
  • To keep your account, wishlist and Vault working across devices.
  • To meet tax and accounting obligations on trips that actually ran.

We do not use your data to build a profile for advertising, and we do not email you about things you did not ask about.

Who else sees it

  • The stay, transport operator, guide or activity partner running your trip — and only the details they need to host you. Never your full contact list, never your Vault.
  • Supabase, which hosts our database, authentication and file storage.
  • PostHog (EU), for the analytics described above.
  • Our email provider, to deliver the messages you asked for.
  • A payment gateway, once online payments are live.
  • Anyone a valid legal order compels us to disclose to — and where we are allowed to tell you, we will.

Some of these providers process data outside India. We use them because they are the right tools, and we hold them to their published data-protection terms.

How long we keep it

  • Account, booking and Vault data: for as long as your account exists.
  • Records of trips that ran: as long as tax and accounting law requires us to keep them, even after you close your account.
  • Newsletter and interest lists: until you unsubscribe or ask us to remove you.
  • Enquiries that never became a trip: cleared out once they are plainly stale.

Your choices

You can ask us to show you what we hold about you, correct anything wrong, delete your account and its data, or stop emailing you. Email hello@expevida.com from your registered address and we will act within 30 days, usually a lot sooner.

Deleting your account removes your profile, wishlist, saved travellers and Vault uploads. Records of trips we actually ran are retained where the law requires, and we will tell you which those are.

Children

Accounts are for adults. Children travel with us all the time, but on a parent's or guardian's booking — the only details we hold about a child are the ones an adult entered for the trip, and we do not market to them.

Changes to this policy

If we change how we handle your data in a way that matters, we will update this page and change the review date at the top. Material changes get an email to anyone on a list, not a silent edit.

Questions about any of this? Ask us directly.

Who you're dealing with

Expevida

Bengaluru, India

hello@expevida.com