Last updated: 2026-05-10 · v1

Privacy Policy

Effective Date: 2026-05-11 Last Updated: 2026-05-11 Version: 1.0

This Privacy Policy explains how GRANDROUTES GLOBAL PTE. LTD. ("Gvoya", "we", "us") collects, uses, discloses, and protects your personal data when you use the Gvoya AI voyage concierge services (the "Service"). It is designed to comply with the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018 and UK GDPR, the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), the Singapore Personal Data Protection Act 2012 (PDPA), the People's Republic of China Personal Information Protection Law (PIPL), Brazil's Lei Geral de Proteção de Dados (LGPD), Canada's PIPEDA and Quebec Law 25, Japan's APPI, Australia's Privacy Act 1988, and other applicable privacy frameworks.

1. Identity of the Controller

GRANDROUTES GLOBAL PTE. LTD. (UEN: [TBD]), a company incorporated in the Republic of Singapore, is the controller of personal data processed through the Service.

2. Categories of Personal Data We Collect

CategoryExamplesSource
Identification & AccountName, email, phone, password hash, optional date of birthYou
Booking & TravelPassenger names, passport numbers (AES-256-GCM encrypted at rest), itinerary, dietary/medical needs you submitYou
PaymentLast-4 digits of card, transaction reference (full card never stored on our systems)Payment processor
AI ConversationYour messages with the AI Concierge, derived intent, recommended voyages, click-through outcomesYou + automated processing
GeolocationApproximate country derived from IP, optional precise location if you grant browser permissionInferred / you
Device & UsageIP address (truncated to /24 for IPv4 / /48 for IPv6 in retention), browser/user-agent, page views, refererAutomated
Cookies & IdentifiersFirst-party cookies (gvoya_anon_id, gvoya_geo, language, session token), analytics cookies if acceptedAutomated / your consent
ComplianceConsent records (document slug, version, hash, scope, IP truncated, UA, timestamp), DSAR submissionsAutomated / you

We do not intentionally collect special categories of personal data under Art. 9 GDPR (e.g., health, race, religion, sexual orientation) unless you voluntarily provide such information in connection with a booking (e.g., dietary or accessibility needs you choose to disclose to the operator). Where you do, we process it on the basis of your explicit consent and only to fulfill the booking.

3. Lawful Basis for Processing (GDPR / UK GDPR)

PurposeLawful basis
Account creation, authentication, account managementContract performance — Art. 6(1)(b)
Processing bookings, AI Concierge recommendations, customer supportContract performance — Art. 6(1)(b)
Marketing communications (newsletter, promotions)Consent — Art. 6(1)(a); withdrawable at any time
Fraud prevention, account security, defense logging, sanction screeningLegitimate interests — Art. 6(1)(f); we balance against your rights
Tax records, accounting, legal claimsLegal obligation — Art. 6(1)(c)
Service improvement (de-identified analytics, AI quality measurement)Legitimate interests — Art. 6(1)(f)

For PIPL (China), our legal bases include separate consent for each cross-border transfer scenario, contract performance, and legal obligation under Art. 13 PIPL. For PDPA (Singapore), our processing relies on consent, contractual necessity, and the legitimate-interests exceptions in the First Schedule. For CCPA/CPRA (California), we rely on the "business purpose" disclosures in §1798.140(e).

4. How We Use Your Data

a. To deliver the Service: process bookings, route AI Concierge requests to inference providers, return personalized recommendations. b. To communicate: confirm bookings, send pre-departure information, deliver service notices, respond to support inquiries. c. To personalize: remember preferences (destination, cabin type, budget) so the AI Concierge can return better matches in future conversations. You may clear this memory at any time via /account/settings. d. To comply: maintain Consent records (GDPR Art. 7, PIPL Art. 14 separate consent), respond to Data Subject Access Requests, satisfy tax and accounting law. e. To protect: detect and prevent fraud, abuse, scraping, brute-force attacks (DefenseEvent log with hash chain), screen counterparties against OFAC/UN/EU/UK/CN sanction lists. f. To improve: analyze de-identified usage patterns to improve the AI Concierge and Service. We do not use your raw conversation logs to train AI models without separate explicit consent.

5. Disclosures to Third Parties

We share personal data with the following categories of recipients on a need-to-know, contractually-restricted basis:

RecipientRoleLocation
Suppliers (cruise lines, yacht operators)Independent controllers for the bookingVarious
Anthropic, PBCProcessor — AI inferenceUnited States
Cloudflare, Inc.Processor — CDN, R2 storage, DDoSUnited States / Global
Neon Inc.Processor — managed PostgreSQLUnited States / EU
Resend, Inc.Processor — transactional emailUnited States
Stripe / Alipay / WeChat PayIndependent controllers — paymentVarious
Sentry / PostHogProcessor — error & analytics (de-identified where possible)United States / EU
Google / WeChatProcessor (where applicable) — OAuth identityVarious
Government, regulators, courtsWhen required by law or valid legal processVarious

We have entered into Data Processing Agreements (DPAs) and Standard Contractual Clauses (EU SCC 2021/914 Module Two and Module Three; UK International Data Transfer Addendum) where applicable. See our DPA and Sub-processor List.

We do not sell your personal information for monetary consideration, as defined under CCPA §1798.140(t). We do not "share" personal information for cross-context behavioral advertising under §1798.140(ah).

6. International Transfers

Your data may be transferred to and processed in jurisdictions outside your country of residence, including Singapore, the European Union, the United States, mainland China, and other markets where Gvoya operates. We rely on the following transfer mechanisms:

  • EU/EEA → third countries: Standard Contractual Clauses (Commission Decision 2021/914), supplementary measures (encryption in transit, encryption at rest with AES-256-GCM, contractual override of US executive-branch access where applicable), Transfer Impact Assessments per Schrems II.
  • UK → third countries: UK International Data Transfer Addendum 2022.
  • China → outside China: Separate consent under PIPL Art. 39, Standard Contract for Cross-Border Transfer of Personal Information (CAC) where applicable, and Cybersecurity Review for sensitive volumes.
  • All transfers: Encrypted in transit (TLS 1.2+) and at rest (AES-256-GCM for sensitive fields).

7. Retention

We retain personal data only as long as necessary for the purposes described:

DataRetention
Account dataUntil you delete your account (subject to legal-hold exceptions)
Booking & financial recordsSeven (7) years from completion (tax / audit requirement)
AI conversation logsTwo (2) years from creation, then anonymized
Consent recordsSeven (7) years from acceptance, then anonymized (ipAddressTrunc, userAgent, anonId cleared)
Marketing consentsUntil you withdraw, then immediately deleted from active marketing systems
Server logsNinety (90) days
DefenseEvent (security incidents)Two (2) years for evidence preservation

Anonymization is enforced automatically by the legal-retention worker cron each day at 03:00 UTC.

8. Your Rights

Depending on your jurisdiction, you have some or all of the following rights:

RightDescription
AccessRequest a copy of personal data we hold about you (GDPR Art. 15, CCPA §1798.110, PIPL Art. 45)
RectificationCorrect inaccurate or incomplete data (GDPR Art. 16, PIPL Art. 46)
Erasure / "right to be forgotten"Delete your data, subject to legal-retention exceptions (GDPR Art. 17, CCPA §1798.105, PIPL Art. 47)
RestrictionRestrict processing in specific circumstances (GDPR Art. 18, PIPL Art. 44)
PortabilityReceive your data in a structured, machine-readable format (GDPR Art. 20, CCPA §1798.130(a)(2))
ObjectObject to processing based on legitimate interests, including direct marketing (GDPR Art. 21)
Withdraw consentWithdraw consent at any time, including for cookies and AI training data (GDPR Art. 7(3), PDPA s.16, PIPL Art. 15)
Not be subject to solely automated decisionsObject to automated decision-making with legal/significant effects (GDPR Art. 22, PIPL Art. 24, LGPD Art. 20)
Non-discriminationEqual price and service if you exercise rights (CCPA §1798.125)

To exercise any right, submit a request via /account/legal-requests/new or email privacy@gvoya.com. We respond within thirty (30) days under GDPR / PIPL / PDPA / PIPEDA, forty-five (45) days under CCPA, fifteen (15) days under LGPD. We may extend by an additional thirty (30) days for complex requests with notice. You also have the right to lodge a complaint with your local supervisory authority (e.g., your EU Data Protection Authority, the UK ICO, the Singapore PDPC, the Cyberspace Administration of China).

9. Children

The Service is intended for individuals aged 18 or older. We do not knowingly collect personal data from children under 13 (or 16 in the EU/EEA). If you believe a child has provided us with personal data, contact privacy@gvoya.com and we will delete the data promptly.

10. Cookies and Similar Technologies

Our use of cookies, web beacons, and similar technologies is described in detail in the Cookie Policy. You can manage your cookie preferences via the cookie banner or your account settings.

11. Security

We implement technical and organizational measures appropriate to the risk, including:

  • TLS 1.2+ for all data in transit
  • AES-256-GCM encryption for passport numbers and other high-sensitivity fields at rest
  • Bcrypt password hashing (cost factor 12)
  • JWT session tokens with 8-hour expiry
  • Truncated IP storage (/24 IPv4, /48 IPv6) for compliance evidence
  • Two-tier rate limiting and honeypot routes (DefenseEvent system) to deter automated attacks
  • Hash-chained audit logs that detect tampering
  • Annual penetration testing and quarterly internal reviews
  • Sub-processors bound by DPAs and SCCs

In the event of a personal-data breach posing a high risk to your rights, we will notify you within seventy-two (72) hours of awareness, in compliance with GDPR Art. 33-34 and analogous obligations.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes (those affecting your rights or how we use data) will be announced at least thirty (30) days before they take effect via email and the in-app reaccept banner. Continued use after the effective date constitutes acceptance. Each version is hash-stamped and your acceptance recorded for compliance.

13. Contact

For any privacy-related inquiry, please contact:

Data Protection Officer: dpo@gvoya.com Privacy team: privacy@gvoya.com EU/EEA Representative (Art. 27): dpo@gvoya.com UK Representative: dpo@gvoya.com

GRANDROUTES GLOBAL PTE. LTD. 25 SEAH STREET, #02-01, SINGAPORE 188381