PRIVACY POLICY | GLOBE
Last updated: September 6, 2026(1) Who We Are
Globe is a group travel planning application developed and operated by AREU BV, a company incorporated under Belgian law, with registered address at Wilgenweg 6, 2890 Puurs-Sint-Amands, Belgium, enterprise/VAT number BE1037624935 ("Globe", "we", "us", "our").
AREU BV is the data controller for personal data processed through the Globe application and associated services. For the purposes of the GDPR, AREU BV is the Data Controller.
Contact us at any time regarding this Privacy Policy or your personal data:
- Email: privacy@areu.io
- Post: Wilgenweg 6, 2890 Puurs-Sint-Amands, Belgium
(2) Scope of This Policy
This Privacy Policy applies to:
- The Globe mobile application (iOS and Android)
- The Globe web application at app.areuglobe.com
- Any related services, communications, or support interactions
It does not apply to third-party services linked from Globe (e.g. booking platforms, map providers, or links shared by other users). Those services have their own privacy policies which we encourage you to review.
(3) Personal Data We Collect
3.1 Account and Identity Data
When you create a Globe account, we collect:
- Your name and email address
- Profile photo (pulled from your Google or Apple account if you use Google or Apple Sign-In, or optionally self uploaded). If you are a Globe Pro member you may also set an animated profile photo; when you do, we store a still frame for general use and the animated file separately, and the animated version is shown only on profile screens and only while your subscription is active.
- A username (generated automatically from your email on registration, which you can change), display initials, and avatar colour
- Authentication credentials — if you sign in via Google or Apple Sign-In, we receive a verified email address and display name from the provider. We never receive or store your Google or Apple password.
- Your date of birth — collected during the new-user onboarding wizard and editable later in My Account → My Profile. We use it only to confirm you meet our minimum age and our purchasing age threshold (see §11). It is self-reported and we do not verify it against any document.
- Your analytics consent decision — whether you accepted or declined optional product analytics. This was previously held only on the device; we now also store it on your profile so that our servers can honour it (see §3.5). A consequence worth knowing: your choice now applies to your account rather than to each device separately.
- Optional profile details you choose to add: short bio, home city, travel style/interests, preferred currency, time zone, language, and week-start preference
Identity data is first collected through the onboarding wizard, which prompts every new account (including users who sign in with Google/Apple or who join from an invite link) for a language, display name, username, and date of birth before they use the app. Optional profile details — home city, profile photo, and travel interests — can be added during onboarding or later in My Account → My Profile.
3.2 Trip and Group Data
When you create or participate in a trip, we collect:
- Trip name, type, description, and dates you provide
- Your availability for the trip dates
- Your budget range per person
- Destination preferences, searches, and votes
- Itinerary items, tasks, stays, and notes you create or contribute
- Expense records you enter, including amounts, categories, dates, and who paid
- Proposal content — including title, description, price, any link, and any additional information you add (e.g. custom notes, flight numbers)
- Location coordinates (latitude and longitude) associated with proposals, stays, and destination searches — these are coordinates of places you select, not your device's real-time GPS position (see §3.3)
- Your "trip input" — optional per-trip fields you can fill in and share with your trip group: dietary preferences and a free-text dietary/allergy note, an accessibility/mobility note, and a general note. The dietary/allergy and accessibility notes may reveal health-related information; they are entirely optional, you choose what to share, and we process them only with your explicit consent (see §4.6). They are visible to the other members of that trip.
- Trip Moments — short videos with sound. During an active trip, Globe invites each member a few times a day to record a two-second video clip, with audio, from inside the app. Recording is always your choice: the invitation is a notification you can ignore or switch off, and the camera and microphone are used only while you are recording a clip. Clips are visible to the members of that trip, you can delete your own clip at any time, and the trip organiser can also remove one for moderation. Members can "like" a clip, which records that they did so. See §3.4 for how the files are stored and §8 for how long they are kept.
- Trip vlogs. At the end of a trip, and whenever a member asks for one, Globe combines that trip's clips into a single video file. The composition happens on our own servers in the EU; nothing is sent to any other company. The finished video shows each contributor's profile photo and the time of day the clip was taken, and is readable only by that trip's members. Because those details are drawn into the video itself, they stay in the finished file even if the person later changes their profile photo or deletes their account — the same way anything else you contribute to a group stays with the group.
- Your travel history — the places you have visited, stored in your personal travel history. Each record can link back to the trip(s) on which you visited the place. Visited places are partly auto-derived from your trips' schedules and can also be confirmed, corrected or added by you (see §3.5). Your travel history is visible to your mutual friends, like your bucket list.
- Trip reviews — if you rate or write a short review of a trip during its wrap-up, your rating and review text are stored on your membership record for that trip and are visible to the other members of the trip.
- Personal notes — if you are a Globe Pro member you can create private notes that are not tied to a trip; their content, title and timestamps are stored and are accessible only to you.
- Your relationship data — your friend connections and friend requests (other users are found by username or email). This includes your friend groups (named, reusable groupings of your friends used to invite people): the people in a group are visible to one another, any member of a group — not only its creator — can rename it, change its emoji, or add and remove other members (the creator can't be removed), any member can leave at any time, and being added to a group sends the added member an in-app notification. It also includes any users you have blocked — a private record visible only to you. When you block someone, Globe immediately and silently severs any existing friendship between you, cancels any pending friend requests or trip invites in either direction, and offers to remove you from any trips you share with them. We also store friend-suggestion dismissals (so a "People you may know" suggestion you dismiss does not reappear on any device), your personal wishlist ("bucket list") places, and any past trips you add manually.
- Your friend activity feed — Globe keeps a personal activity feed showing trip-related events from your mutual friends (for example when a friend creates a trip, completes one, or confirms a place they visited). Each entry includes the friend's name and the action; the feed is visible only to you.
- Shared-schedule links you create
- During a trip's wrap-up phase, whether and when you completed your wrap-up tasks (e.g. confirming your visited places, marking the "add photos" task done) is shown to your co-travellers so the group can see who has finished — the underlying visited places themselves stay private to you and your mutual friends.
Where your name appears on something you contributed earlier — a message, an activity entry, a member list — Globe shows the name currently on your profile rather than the name you had at the time. If you rename yourself, that change is reflected on your earlier contributions rather than your former name persisting in other members' views.
3.3 Device Location
Globe uses your device's GPS in the following ways. We never prompt automatically — the location permission request only appears when you explicitly take an action that needs it.
- Weather card. If you tap "Enable location" on a trip's weather card, we take a one-off position reading to show local weather; the coordinates are rounded (to roughly 1 km) when sent to the weather provider and are not stored in our database and not tracked in the background.
- Chat location sharing. From the trip chat you can share a location with your trip group in three ways:
- A place pin — a place you search for and select (resolved via Google Places; the place's coordinates, not your device's position).
- Your current location — a one-off static pin of your device's current GPS position at the moment you tap share.
- Live location — your precise GPS position, broadcast to your trip group for a time window you choose (15, 30 or 60 minutes — capped at one hour). Live sharing is opt-in each time, visible only to the members of that trip, foreground-only (it stops when you leave the chat screen or the app is backgrounded), and stoppable at any time; it also stops automatically when the time window expires. While active, your position is stored in a per-trip live-location record that trip members can read to see the moving pin; it auto-expires at the end of the window. Sharing your current or live location requires foreground-location permission (on iOS the "while using the app" location permission; on Android the fine/coarse location permission), which your device only requests when you start a share — never at app launch.
Globe's maps do not use your location: the map in a trip is centred on the places the group has proposed, not on you, and displaying it requires no location permission.
We collect device location only for these features and do not use it for advertising or background tracking.
3.4 Photos, Documents, Video and Media
When you upload photos or documents (images and PDFs) to a trip — including media shared in trip chat — we collect and store:
- The file itself (photos in the trip album; PDFs/images in trip documents)
- A compressed thumbnail generated automatically for display (for images)
- Metadata associated with the upload (upload timestamp, uploader identity within the group, file name, type and size)
- Likes and reactions other group members make on your photos
When you share an image in trip chat you can choose whether it also joins the trip album. If you choose not to, it is stored separately at a smaller size and is not added to the album; it remains visible to the trip's members in the conversation, and its file is removed when the message is deleted.
We also store, for Trip Moments (see §3.2):
- Each two-second video clip you record, together with a still frame taken from it for display
- The time of day the clip was recorded, and which member recorded it
- The finished trip vlog composed from the group's clips
Important: photos, documents, videos and other media you share with a trip are visible to all members of that trip group. Before sharing, ensure you have the right to do so and that the content does not contain sensitive personal data of others without their consent. When you record a Moments clip, be aware that it captures sound as well as picture.
3.5 Usage, Analytics and Diagnostic Data
We collect limited technical, product-analytics and diagnostic data. We want to be clear about what we do not do: we do not use advertising identifiers, we do not build advertising profiles, and we do not sell data that identifies you.
- Product analytics — opt-in. With your consent, Globe uses Google Analytics for Firebase (GA4) to understand how the app is used so we can improve it. Collection is off by default and only starts after you accept the consent banner shown on first launch (web and native); you can withdraw consent at any time in My Account → Settings → Privacy. When enabled, we record:
- Which in-app actions were performed — a fixed list of action types covering signing up and signing in, onboarding steps, creating and joining trips, sending invitations, proposals, polls, planning, expenses, tasks, documents, notes, sending a chat message, saving and sharing memories, and friend activity. We record the type of action only, never its content: no trip names, no message text, no place names, no file names, no email addresses, no coordinates. A chat message is counted; what it says is never sent.
- The name of the screen being viewed — a fixed screen name such as "trip proposals" or "account settings". These names are derived from the app's internal page structure and can never contain an identifier: the same screen viewed for two different trips produces one identical name.
- Four fixed, non-identifying attributes of your account, attached to those events so we can understand different groups of users: your subscription tier, your platform (web, iOS or Android), the language the app is set to, and the method you signed in with. These are single values from a short fixed list. They are cleared when you sign out, so a second account on a shared device does not inherit them.
- Your Firebase user ID is associated with these events so they can be tied to your account.
- Sales reporting — separate from the analytics opt-in. When a purchase, renewal or refund completes, our servers report the transaction to the same Google Analytics property: the amount charged, the currency, the payment provider, the plan bought, and the payment provider's transaction reference. This is a server-to-server message; it does not touch your device and sets no cookie or device identifier. We do this to keep accurate revenue records, which is our own financial reporting rather than analysis of how you use the app, and we rely on our legitimate interest for it (see §4.2). Your analytics choice still governs whether the sale is linked to you: if you have not granted analytics consent, the report carries no user identifier at all, so Google cannot connect it to you, to your other purchases, or to your app usage. If you have granted consent, your Firebase user ID is attached. The transaction reference is always sent so that duplicate reports can be discarded; Google cannot link it to a person, though we can, so we describe it as pseudonymous rather than anonymous.
- Crash and error diagnostics — always on, legitimate interest. Globe uses Sentry (EU data residency) on web, iOS and Android to detect and fix crashes and errors. When the app hits an uncaught error or crash, we send Sentry a stack trace, recent in-app breadcrumbs, and basic device/OS/app-version context, collected from all sessions. Separately, we sample a small fraction of sessions (about 10% by default) for performance traces — page-load and navigation timing on web, and app-start and navigation timing on native — so we can monitor latency. This is privacy-minimised: no IP address or cookies are auto-attached and the only user identifier attached is your Firebase user ID — never your email or name. Error and diagnostic monitoring is not part of the analytics opt-in; we run it under our legitimate interest in keeping Globe secure and working. On the web, these reports are routed through our Cloudflare infrastructure so that browser content-blockers do not silently drop them. We also collect content-security-policy (CSP) violation reports, which contain only technical data and no user identifiers or content, to help us tune our security policy before it is enforced.
- Anti-abuse / app integrity. To prove that requests come from a genuine Globe client and to protect our backends and proxy from abuse, we use Firebase App Check: Google reCAPTCHA v3 on the web, Google Play Integrity on Android, and Apple App Attest / DeviceCheck on iOS. These send device/browser/app-integrity signals to Google or Apple to produce a short-lived attestation token; the tokens are not stored by us. We also apply rate limits to public endpoints (see §8.6 and §12).
- Travel-history derivation. During a trip's wrap-up you are invited to confirm, correct or remove the places you visited before they are saved. For members who do not confirm, we automatically derive their visited places from the trip's schedule — after the trip is filed to the Timeline, or by a periodic automated process — and add them to that member's travel history. This is an automated step that writes inferred location history to your account; the resulting visited places are visible to your mutual friends, like the rest of your travel history.
- Operational and support data. App version, platform (iOS/Android/web), and the screen you were on are collected only when you contact support or report content, to help us respond. Your IP address is processed transiently by our infrastructure providers (Google/Firebase, Cloudflare) to deliver and secure the service and apply rate limits — not to profile you for advertising. For cost-anomaly detection, our Cloudflare infrastructure also writes a short server-side log line for upstream requests, recording your Firebase user ID, IP address and basic request metadata, retained per Cloudflare's settings. A device push-notification token and its platform are stored so we can send notifications you have allowed (see §13).
3.6 Chat and Poll Data
Globe includes a real-time group chat and polling feature within each trip. Messages you send and poll responses you submit are stored in our database and visible to all members of your trip group. Chat supports text, GIFs, photos, documents, shared locations, emoji reactions, replies, and mentions of proposals and of other members (mentioning a member notifies them). You can delete your own messages at any time.
3.7 Payment Data
Globe never collects or stores your payment card details. Payments are processed by our payment providers:
- On the web, by Stripe, which collects your billing name and address and your card details directly on its hosted checkout.
- On iOS/Android, by RevenueCat together with the Apple App Store / Google Play, which process the payment.
From these providers we store only what we need to give you access: a Stripe customer identifier, your subscription / Trip Pass status, and billing cycle. For purchases made under our guardian-assisted flow for users who are not yet 18 (see §11), Stripe requires the cardholder to authenticate via 3-D Secure (Strong Customer Authentication) with their bank; this authentication is handled by Stripe and your bank, and we store no additional data from it. Please refer to the providers' own privacy policies for how they handle payment data.
Trip Pass — your withdrawal acknowledgement. A Trip Pass unlocks immediately, so before you buy one we ask you to tick a specific acknowledgement that you are asking for immediate access and are therefore giving up your 14-day right of withdrawal. Because that acknowledgement is what allows us to decline a later withdrawal request, we keep a record of it: your user identifier and email address, the trip concerned, the exact wording you agreed to and its version, the language and platform you saw it in, whether the purchase used the guardian-assisted flow, the time you accepted, and — once payment completes — the provider and its transaction reference. We then send you a confirmation email restating the acknowledgement, which EU consumer law requires us to provide on a durable medium. These records are kept even if you later delete your account — see §8.4. Globe Pro is different: it carries no such waiver, and its 14-day right of withdrawal is unaffected.
3.8 Communications Data
If you contact us for support, or report content within the app, we collect the content of your message or report and your contact details (and limited technical context such as app version and platform) in order to respond and to keep a record. These requests are handled through our support desk provider (Atlassian Jira Service Management — see §6.2). Reportable content includes messages, photos, documents, proposals, Moments clips and profile photos; a report records what was reported and the display name of its author as you saw it.
We also send transactional emails where the law or your purchase requires it — currently the Trip Pass withdrawal confirmation described in §3.7. These are sent through our email provider (Brevo — see §6.2).
If you ask to be notified about upcoming "Max" plans, we store that interest signal on your profile. We do not send marketing emails today; any future marketing outreach would be optional and separately consented.
(4) Legal Bases for Processing (GDPR)
4.1 Performance of a Contract (Article 6(1)(b))
We process your account data, trip and group data, chat data, and payment/subscription data because it is necessary to provide the Globe service you have signed up for.
4.2 Legitimate Interests (Article 6(1)(f))
We process limited data based on our legitimate interest in:
- Keeping Globe secure and preventing abuse (e.g. rate limiting, app-integrity attestation, and fraud prevention)
- Detecting and fixing crashes and errors and monitoring performance (crash/error diagnostics — see §3.5)
- Keeping accurate records of sales, renewals and refunds, including reporting the transaction to our analytics provider without identifying you unless you consented (see §3.5)
- Monitoring operational costs and detecting billing anomalies (see §3.5)
- Operating and supporting the service, and responding to your requests
- Moderating content — we may access content (for example a chat message, photo, document, video clip or proposal) when you or another user reports it, or in order to handle your support request
You can object to processing based on legitimate interests — see Section 9.
4.3 Consent (Article 6(1)(a))
Where we rely on your consent — for example device permissions such as camera, microphone, location and notifications, and optional product analytics — we ask for it explicitly and you can withdraw it at any time (analytics consent is managed in My Account → Settings → Privacy).
4.4 Legal Obligation (Article 6(1)(c))
We may process data where required by applicable Belgian or EU law, including tax and accounting obligations, and keeping evidence of the consumer acknowledgements described in §3.7.
4.5 Vital Interests (Article 6(1)(d))
In exceptional circumstances, we may process data where it is necessary to protect the vital interests of you or another person. This basis will rarely apply in the context of Globe's services.
4.6 Explicit Consent for Special-Category Data (Article 9(2)(a))
Globe lets you optionally share dietary/allergy information and accessibility/mobility needs with your trip group (see §3.2). Because these can reveal health information, or religious beliefs (for example a halal or kosher diet) — special categories of data under Article 9 GDPR — we rely on Article 9(2)(a) explicit consent: these fields are blank by default, clearly marked optional ("only share what you're comfortable with"), and we process them only because you deliberately choose to enter and share them with your group for trip planning. You can edit or remove this information at any time — by clearing the field, leaving the trip, or deleting your account — and you are never required to provide it.
4.7 Device Permissions
Globe requests a device permission only at the moment you take an action that needs it, never at launch, and the app remains usable if you decline:
- Camera and microphone — only to record a Trip Moments clip (see §3.2). Both are used only while you are recording.
- Location — only for the weather card and for sharing a location in chat (see §3.3). Maps do not use it.
- Notifications — to deliver the notifications described in §13.
- Saving to your photo library — only when you save a photo or video from a trip to your device. This is an add-only permission: it lets Globe write the file you asked to save, and does not give Globe access to your library.
Globe does not request read access to your photo library. When you pick a photo to upload, your device's own picker hands us only the files you selected.
(5) How We Use Your Personal Data
We use personal data for the following purposes:
- Providing and maintaining the Globe service
- Creating and managing your account, including generating your profile, username, and avatar
- Enabling group trip creation, collaboration, decision-making, and real-time chat
- Displaying shared photos, documents and memories within your trip group, and composing the group's video clips into a trip vlog
- Building your personal travel history from the trips you complete
- Processing and tracking trip expenses and cost-splitting calculations
- Enabling location search and autocomplete for proposals, stays, and destinations, and displaying maps of the places your group is considering
- Managing Trip Pass and Globe Pro subscriptions, verifying you meet the minimum age to use Globe and to make purchases, and keeping records of purchases and the consumer acknowledgements attached to them
- Sending notifications you have allowed, via in-app messages and push notifications
- Improving Globe through opt-in product analytics, and keeping it stable through crash/error diagnostics
- Responding to your support requests and content reports, and moderating reported content
- Keeping the service secure and preventing abuse
- Complying with legal obligations
We do not sell data that identifies you. We may create, use, and share or sell aggregated and anonymised insights and trends (for example, the most-searched destinations or popular travel periods) that cannot be linked back to you or any individual. We do not use your data for automated decision-making that produces legal or similarly significant effects on you.
(6) How We Share Your Data
6.1 Within Your Trip Group
The following is visible to all members of your trip group by design:
- Your name, username, and profile photo
- Your availability and budget range (unless the organiser has enabled anonymous mode)
- Any trip input you choose to share (dietary, accessibility and general notes)
- Your destination votes and preferences
- Proposals you submit, including location and price
- Expenses you record
- Photos, documents and video clips you upload or record, and the trip vlog composed from the group's clips
- Messages, reactions, poll responses, and any locations you share in the group chat
- Any trip review (rating and text) you write
- During wrap-up, whether/when you have completed your wrap-up tasks
Some data is also visible to your mutual friends outside a specific trip — your travel history and bucket list, and the membership of any friend groups you share.
6.2 Service Providers (Data Processors)
We share data with trusted third-party providers. Most act as our data processors under a data processing agreement; a few — the sign-in, app-store and GIF providers — act as independent controllers under their own privacy policies (we disclose them here and minimise what we send them):
- Google Firebase / Google Cloud — core cloud infrastructure (Authentication, Firestore database, Cloud Storage, Cloud Functions, Hosting, Cloud Messaging for push notifications, and App Check). Our Cloud Functions run in the EU region, and the composition of trip vlogs described in §3.2 happens there.
- Google LLC — Google Sign-In (verifies your identity and shares your name and email on sign-in); the Google Places, Maps, Map Tiles and Weather APIs used for destination search, maps and weather; Google reCAPTCHA v3 used by App Check on the web for anti-abuse attestation; Google Play Integrity used by App Check on Android; and Google Analytics for Firebase (GA4) for opt-in product analytics and for the server-side sales reporting described in §3.5. Most Google requests are sent via our Cloudflare proxy. The exception is the interactive map on phones and tablets, where Google's own map component runs inside the app and contacts Google directly from your device, under Google's Maps Platform terms; Google therefore receives your device's IP address and the map area being displayed. No Globe account identifier is sent with it, and the map does not use your location.
- Apple Inc. — Apple Sign-In (web and iOS), which verifies your identity and shares your name and email with us on first sign-in; and Apple App Attest / DeviceCheck used by App Check on iOS for anti-abuse attestation.
- Sentry (Functional Software, Inc.) — crash/error reporting and a small sample of performance diagnostics on web, iOS and Android (EU data-residency region). Receives a stack trace, in-app breadcrumbs, device/OS/app-version context and your Firebase user ID — never your email or name. Web reports transit through our Cloudflare Worker.
- Cloudflare — proxy layer for our Places, Maps, Weather, GIF and image requests, and a transit point that forwards our web error/CSP reports to Sentry. Cloudflare may process request metadata, including IP addresses, for delivery and rate limiting, and we write a minimal operational cost log there. Privacy policy: cloudflare.com/privacypolicy/
- Brevo (Sendinblue SAS, France) — sends our transactional emails, currently the Trip Pass withdrawal confirmation described in §3.7. It receives your email address and the content of that message, and keeps its own sending logs.
- KLIPY (Kikliko, Inc.) — GIF search and trending content in chat, acting as an independent data controller under its own privacy policy (it has appointed an EU representative under GDPR Art. 27). When you use the GIF picker we send only your GIF search terms and a pseudonymised identifier (a salted one-way hash of your user ID, never the raw ID or any account data); because these requests are proxied through our Cloudflare Worker, KLIPY does not receive your real IP address.
- Stripe — payment processing for web purchases (billing name, address and card data are handled by Stripe), including 3-D Secure authentication for guardian-assisted purchases.
- RevenueCat — manages in-app purchases on iOS/Android. It receives your Globe user identifier and store receipt data.
- Apple App Store / Google Play — process in-app payments on their platforms.
- Atlassian (Jira Service Management) — our support desk. Support requests and content reports include your email, name, user identifier, the content reported, and technical context (platform, app version).
- Wikimedia Foundation — public destination images. No personal data is sent.
- Expo / Expo Application Services — delivers the app and over-the-air updates; receives device runtime version and update channel.
6.3 Legal Requirements
We may disclose data if required by law, court order, or to protect the rights and safety of Globe, our users, or others.
6.4 Business Transfers
If Globe is involved in a merger, acquisition, or asset sale, your data may be transferred. We will provide notice before your data becomes subject to a different Privacy Policy.
6.5 With Your Consent
For any sharing not described above, we will ask for your explicit consent.
(7) Cookies and Tracking Technologies
7.1 Mobile app
The Globe mobile app does not use browser cookies or advertising identifiers. It stores data locally on your device (using the device's local storage) for your login session, your preferences, and offline caching. It runs opt-in product analytics only after you accept the consent banner, and runs crash/error diagnostics for security and stability (see §3.5).
7.2 Web application
The Globe web app uses your browser's local storage and IndexedDB (not cookies) for three purposes: your authentication session (Firebase Auth), offline data caching (Firestore), and preference keys you set explicitly (such as your chosen language, theme and notification settings). It does not set advertising cookies and does not use third-party advertising trackers. It does load Google reCAPTCHA v3 (via Firebase App Check) for anti-abuse attestation, and — with your consent — Google Analytics for Firebase. On first visit, the web app shows an informational cookie/storage disclosure banner explaining the essential storage and the reCAPTCHA script, with a link to this policy; analytics remain off until you opt in, and no analytics event is recorded before your choice is applied.
7.3 Do Not Track
Globe does not track you across third-party websites and does not use advertising trackers, so there is no cross-site tracking to which a "Do Not Track" signal would apply.
(8) Data Retention
8.1 Active Accounts
Data associated with your account is retained for as long as your account remains active. Optional trip input you share — including the dietary/allergy and accessibility notes described in §3.2 — lives on your membership record for that trip; it is removed when you clear the field or leave the trip, and is anonymised with your other participant data when you delete your account.
8.2 Your Trips Are Kept for as Long as Your Account Exists
Your trips and everything in them — photos, documents, chat messages, expenses, itineraries, video clips and vlogs — remain fully accessible to that trip's members for as long as the account exists, on every plan. Globe does not archive, lock or delete a trip because it is old, and does not restrict access to a past trip because it was created on the free plan.
An organiser can move a completed trip to the Timeline to declutter the active list. This is a presentation change only: the trip stays fully readable to its members, and nothing about it is removed.
Deletion remains under your control: you can delete your own content, an organiser can delete a trip, and deleting your account removes your personal data as described in §8.4.
8.3 What the Paid Plans Change
Trip Pass and Globe Pro affect how much you can add to a trip — the number of photos and notes, the amount of document storage, and how many files you can upload at once. They do not affect how long anything is kept, and they do not gate access to content you have already added.
If a subscription ends, the trip's allowances return to the free level. Content already in the trip stays exactly where it is and remains readable; the group simply cannot add more until someone upgrades again. A subscription lasts for the period the app store or payment provider says it does, with no separate grace period beyond it.
8.4 Account Deletion
When you delete your account (which requires you to re-authenticate first):
- Your profile and personal data — profile, profile photos, bucket list, travel history (including trip-confirmation markers), friend connections, friend groups, blocked-user records, friend-suggestion dismissals, your friend activity feed, personal notes, product-interest signals (such as the Max-tier waitlist flag), and notifications — are permanently deleted, along with your uploaded files (such as your avatar) and your login credentials. This happens immediately, not after a delay.
- In trips you shared with others, your contributions — including any trip reviews, wrap-up task-completion timestamps, and the dietary/accessibility notes you shared — are anonymised to a "Deleted user" placeholder so the group's records stay coherent. Expense records you were part of are kept intact for the group's financial accuracy, and photos, documents or video clips you contributed remain in the shared trip for other members.
- Where a trip vlog was already produced, your profile photo and the clip time are part of the finished video file and cannot be removed from it without destroying the group's memory; the underlying clip is anonymised like your other contributions.
- Records of the Trip Pass withdrawal acknowledgement described in §3.7 are retained, together with the confirmation email we sent you. We keep these because they are the evidence behind a payment that was not refunded, which we are required to be able to demonstrate. They are not used for any other purpose.
- We cancel your Stripe subscription and delete your RevenueCat record on a best-effort basis. An App Store or Google Play subscription must be cancelled by you in the relevant store — we cannot cancel it for you.
- Financial records required for tax obligations may be retained for up to 7 years.
8.5 Chat Messages
Chat messages within a trip are retained for the life of the trip and remain visible to its members. For performance the app loads messages in pages, but older messages remain available as you scroll back. You can delete your own messages, and deleting your account anonymises the messages you sent. An image shared in chat but not added to the album is removed when its message is deleted.
8.6 Short-Lived and Operational Data
- Live-location shares exist only while you are actively sharing. At the end of the window you set (up to one hour) the share is deactivated and is no longer broadcast to or readable by trip members; the inactive record may remain in our database until routine cleanup removes it.
- Blocked-user records are kept until you unblock the person (or delete your account).
- Rate-limit counters are short-lived server-side records holding only a time window and a count, keyed to a salted hash of the IP address (never the raw IP) or to your user ID.
- Product-analytics events (Google Analytics for Firebase / GA4) are retained for the period set on our Firebase/GA4 property (GA4's default event-data retention is 2 months, extendable to 14 months). Withdrawing analytics consent stops further collection but does not by itself delete events already collected by Google.
- Crash/error and performance reports are retained by Sentry per its default retention (typically around 30–90 days).
- Operational logs (e.g. the Cloudflare cost log) are retained per the provider's log-retention settings.
- Transactional email records — the queued copy of a confirmation email we sent you is kept as evidence that it was delivered, as described in §8.4.
- Trip videos — a superseded or in-progress vlog render is deleted when it is replaced or finished; finished vlogs and clips are kept with the trip.
8.7 Support Communications
Records of support requests and content reports are retained for as long as necessary to handle and document the request, in line with our support-desk provider's retention.
(9) Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — request correction of inaccurate or incomplete data
- Right to erasure ("right to be forgotten") — you can delete your account from within the app (see §8.4), or request deletion. Note the limited exceptions in §8.4: content you contributed to a shared trip stays with that group in anonymised form, and records evidencing a consumer acknowledgement behind a completed purchase are retained.
- Right to restriction — request that we limit how we use your data
- Right to data portability — receive your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent — where processing is based on consent, withdraw it at any time
- Right not to be subject to automated decision-making — Globe does not use automated decision-making that produces legal or similarly significant effects
To exercise any of these rights, contact us at privacy@areu.io. We will respond within 30 days. Today, access and data-portability requests are handled manually by our team.
If you are not satisfied with our response, you have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données):
- Website: www.dataprotectionauthority.be
- Address: Rue de la Presse 35, 1000 Brussels, Belgium
(10) International Data Transfers
Globe is operated from Belgium and primarily uses infrastructure within the European Economic Area (EEA); our Firestore database, Cloud Storage and Cloud Functions all run in the EU, our error-diagnostics provider (Sentry) uses an EU region, and our email provider (Brevo) is established in France.
Some of our processors operate, or may route data, outside the EEA — including Google (Sign-In, Google APIs, Maps Platform, App Check/reCAPTCHA v3/Play Integrity, and Analytics for Firebase) and Apple (Sign-In, and App Attest/DeviceCheck), Stripe, RevenueCat, KLIPY, Cloudflare (a global network), Atlassian, and Expo. Where data is transferred outside the EEA, this is covered by Standard Contractual Clauses or another transfer mechanism approved under the GDPR.
(11) Children's Privacy and Age Requirements
Globe is intended for users aged 16 and over. During sign-up, the onboarding wizard collects your date of birth and applies a technical age check: if you indicate you are under 16, you are blocked from completing onboarding and signed out. We do not store your date of birth or create a profile for a blocked sign-up; if a technical failure ever left any partial data, we delete it promptly. This check is self-reported — we do not verify your date of birth against any document. This age threshold is set in accordance with Article 8 of the GDPR as implemented in Belgian law.
Purchases require you to be 18 or over. Buying a Trip Pass or Globe Pro is restricted to users aged 18+. This is enforced both in the app and on our servers (our checkout function refuses a purchase by an under-18 user unless it goes through a guardian-assisted flow, in which an adult cardholder completes the payment and authenticates via 3-D Secure). If your account has no date of birth on file, purchases are also blocked until you add one in My Account → My Profile. On iOS/Android, store-level parental controls also apply.
If you are a parent or guardian and believe your child under 16 has registered with Globe, please contact us at privacy@areu.io and we will delete the account promptly.
(12) Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encrypted data transmission (TLS/HTTPS) for all data in transit
- Firebase Authentication for secure access control, with re-authentication required before sensitive actions such as account deletion
- Access controls that restrict each trip's data to its members, so a trip cannot be read by non-members or discovered by outsiders, and trip joins by invite code are handled by our server rather than by direct database access. Private notes and their images are accessible only to their author. Trip video clips and vlogs are restricted to the trip's members, and can be written only by our servers.
- Rate limiting on public endpoints to deter abuse and invite-code guessing, using a salted, one-way hash of the IP address rather than the raw IP.
- App-integrity attestation (via Firebase App Check) to ensure requests originate from genuine Globe clients rather than automated tools
- Access controls limiting photo, document and video access to trip participants, with uploads restricted to permitted file types and a size limit per file
- Sensitive fields (such as subscription and Trip Pass status) can be changed only by our servers, and certain records are kept server-side and not accessible to the app
Known limitation (transparency). Photos, documents and videos in a trip are opened through secure links. Anyone who already holds such a link can keep opening that file even when our access rules would otherwise no longer allow it. In practice, a member who is later removed or blocked from a trip may still be able to open media their device had already loaded, until the link is refreshed. We do not currently refresh these links automatically when a member is removed.
In the event of a personal data breach that is likely to result in a risk to your rights, we will notify the Belgian Data Protection Authority within 72 hours, as required by the GDPR.
(13) Push Notifications
Globe uses push notifications (via Google Firebase Cloud Messaging) on iOS, Android and the web to keep you informed about trip activity, invitations, mentions, friend requests, and updates. Push notifications require your permission, which your device requests the first time it is relevant; we store a device push token so we can deliver them. On mobile, the app icon may also show the number of unread messages you have.
Separately, Trip Moments capture invitations are scheduled on your own device and are not sent from our servers.
You can fine-tune which categories of notification you receive in My Account → Settings → Notifications, and manage or disable push notifications at any time through your device settings — iOS: Settings → Notifications → Globe; Android: Settings → Apps → Globe → Notifications.
(14) Links to Other Services
Globe may contain links to third-party websites or services — for example links added by other members in proposals or chat (such as booking platforms or maps). We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
(15) Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via in-app notification — and by email where available — at least 14 days before the changes take effect. The version history of this policy will be maintained and available on request.
(16) Contact and Data Controller Details
- AREU BV — Wilgenweg 6, 2890 Puurs-Sint-Amands, Belgium
- Enterprise/VAT number: BE1037624935
- Email: privacy@areu.io
We aim to respond to all privacy requests within 30 days.
