← Back to Yoteiko

Privacy Policy

Last updated: June 20, 2026

1. Introduction

Yoteiko("we," "us," or "our") operates the Yoteikomobile application and website (the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Service.

We are committed to protecting your privacy in accordance with applicable international data protection laws, including but not limited to the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the California Consumer Privacy Act ("CCPA"), Japan's Act on the Protection of Personal Information ("APPI"), Brazil's Lei Geral de Proteção de Dados ("LGPD"), Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA"), Australia's Privacy Act 1988, South Africa's Protection of Personal Information Act ("POPIA"), and Google Play Data Safety requirements.

By using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.

2. Data Controller

The data controller responsible for your personal information is:

Yoteiko

Email: privacy@yoteiko.com

For users in the European Economic Area (EEA), our EU representative can be contacted at eu-privacy@yoteiko.com.

3. Information We Collect

3.1 Information You Provide

  • Account information: name, email address, password (hashed), profile picture
  • Travel data: itineraries, destinations, dates, budgets, packing lists, notes
  • Payment information: processed securely through third-party payment providers (we do not store full card numbers)
  • Communications: messages sent through our support channels, feedback, and survey responses
  • Collaboration data: when you invite others to a trip, we store their email addresses and shared itinerary access

3.2 Information Collected Automatically

  • Device information: device type, operating system, unique device identifiers, browser type
  • Usage data: features used, session duration, screens visited, interaction patterns
  • Location data: approximate location derived from IP address (we do not collect precise GPS location without your explicit consent)
  • Log data: IP address, access times, referring URLs, error logs
  • Cookies and similar technologies: see Section 10 (Cookies)

3.3 Information from Third Parties

  • Authentication providers: if you sign in via Google, Apple, or other OAuth providers, we receive your name, email, and profile picture
  • Analytics providers: aggregated usage statistics and crash reports
  • Travel partners: destination information, local tips, and seasonal data (no personal data)

4. Google Play Data Safety Disclosure

In compliance with Google Play's Data Safety requirements, the table below provides a transparent summary of the data types our app collects, shares, and how each is used. This section should be read in conjunction with the full privacy policy above.

Data Collected

The following categories of data are collected when you use theYoteiko mobile application:

👤

Personal Info

  • Name: Your display name used to identify you within the app and on shared itineraries.
  • Email Address: Used for account creation, authentication, password recovery, and service-related communications.
  • User IDs: Unique identifiers assigned to your account for internal system operations and data linking.
  • Phone Number: Used for two-factor authentication, account verification, and optional SMS notifications.
  • Other Info: Additional profile details you choose to provide, such as profile picture, travel preferences, and bio.
💬

Messages

  • In-App Messages: Text messages exchanged within trip chats and collaborative planning conversations.
📷

Photos & Videos

  • Photos: Images you upload or share within the app, including trip photos and profile pictures.
🎤

Audio Files

  • Voice or Sound Recordings: Voice messages recorded and shared within trip chats for quick communication.
📊

App Info & Performance

  • Crash Logs: Diagnostic data including stack traces, device state, and app version information used to identify and resolve technical issues.
📱

Device or Other IDs

  • Device or Other IDs: Unique device identifiers used for authentication, push notifications, security, and analytics.

How Data Is Used

All collected data falls into the following usage purposes:

PurposeData Categories
App FunctionalityPersonal Info, Messages, Photos, Audio Files, Device IDs
Account ManagementPersonal Info, Device IDs
AnalyticsApp Info & Performance, Device IDs
Crash DiagnosticsApp Info & Performance
Security & Fraud PreventionPersonal Info, Device IDs
CommunicationsPersonal Info

Data Sharing

We do not sell your personal data. Data is shared only with essential service providers (cloud hosting, crash reporting, analytics) under strict data processing agreements, and only as described in Section 6 of this policy. All data sharing is limited to what is necessary to provide and maintain the Service.

Security Practices

  • Data is encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Users can request data deletion at any time via the app or by contacting privacy@yoteiko.com
  • We comply with Google Play Developer Program Policies and Data Safety requirements

6. How We Use Your Information

We use your personal information for the following purposes:

  • Providing and maintaining the Service, including itinerary creation, budget tracking, packing lists, and offline access
  • Processing transactions and managing your account
  • Enabling collaborative trip planning features you initiate
  • Sending service-related communications (trip reminders, itinerary updates, security alerts)
  • Personalizing your experience based on your travel preferences and history
  • Analyzing usage patterns to improve features, performance, and user experience
  • Detecting, preventing, and addressing technical issues and security threats
  • Complying with legal obligations and enforcing our terms of service
  • With your consent, sending promotional communications about new features and travel tips

7. Data Sharing and Disclosure

We do not sell your personal information. We may share your data only in the following circumstances:

  • Service providers: Cloud hosting (AWS/GCP), analytics (privacy-focused), payment processing, email delivery, and crash reporting. These providers are contractually bound to use your data only for the services they provide to us
  • Collaboration partners: When you use collaborative planning features, your itinerary and profile information are shared with trip members you invite
  • Legal requirements: When required by law, court order, or governmental regulation, or to protect the rights, property, or safety of Yoteiko, our users, or the public
  • Business transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred. You will be notified of any such change
  • With your consent: For any other purpose disclosed at the time of collection or with your explicit permission

8. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws.

When we transfer data internationally, we ensure:

  • EU Standard Contractual Clauses (SCCs) for transfers from the EEA
  • Adequacy decisions where applicable
  • Binding corporate rules and data processing agreements with all service providers
  • Compliance with Japan's APPI cross-border transfer requirements
  • Compliance with other applicable regional transfer mechanisms

9. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes described in this policy:

  • Account data: Retained while your account is active and for 30 days after deletion request
  • Trip data (itineraries, budgets, packing lists): Retained while your account is active, deleted within 30 days of account deletion
  • Messages and media (photos, voice recordings): Retained while your account is active or until manually deleted
  • Payment records: Retained for 7 years as required by tax and financial regulations
  • Usage logs: Retained for 12 months for analytics and security purposes
  • Crash logs: Retained for up to 90 days for diagnostic and stability improvement purposes
  • Marketing consent records: Retained until consent is withdrawn
  • Support communications: Retained for 24 months after the last interaction

After the retention period expires, data is securely deleted or anonymized so that it can no longer be associated with you.

10. Data Security

We implement industry-standard security measures to protect your personal information:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Secure password hashing using bcrypt with salt
  • JWT-based authentication with secure token management
  • Regular security audits and penetration testing
  • Access controls and principle of least privilege for employee access
  • Automated threat detection and intrusion prevention systems
  • Regular data backups with encrypted storage
  • Incident response procedures with 72-hour breach notification (GDPR compliant)

While we strive to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

11. Cookies and Tracking Technologies

We use cookies and similar technologies for the following purposes:

  • Essential cookies: Required for the Service to function (authentication, session management, security). These cannot be disabled
  • Analytics cookies: Help us understand how visitors interact with our website. We use privacy-focused analytics that do not track individual users across sites
  • Preference cookies: Remember your settings and preferences (language, theme)
  • Marketing cookies: Used only with your explicit consent to deliver relevant advertisements

You can manage cookie preferences through your browser settings. The website functions without non-essential cookies, though some features may be limited.

12. Your Rights

12.1 Rights Under GDPR (EEA Users)

  • Right of access: Obtain a copy of your personal data
  • Right to rectification: Correct inaccurate or incomplete data
  • Right to erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to restrict processing: Limit how we use your data
  • Right to data portability: Receive your data in a structured, machine-readable format
  • Right to object: Object to processing based on legitimate interests or direct marketing
  • Right to withdraw consent: Withdraw consent at any time without affecting prior processing
  • Right to lodge a complaint: File a complaint with your local supervisory authority

12.2 Rights Under CCPA/CPRA (California Residents)

  • Right to know: What personal information we collect, use, and disclose
  • Right to delete: Request deletion of your personal information
  • Right to correct: Request correction of inaccurate personal information
  • Right to opt-out: Opt out of the sale or sharing of personal information (we do not sell data)
  • Right to non-discrimination: We will not discriminate against you for exercising your rights
  • Right to limit use of sensitive personal information

12.3 Rights Under APPI (Japan Residents)

  • Right to disclosure of retained personal data
  • Right to correction, addition, or deletion
  • Right to suspension of use or erasure
  • Right to suspension of third-party provision

12.4 Rights Under Other Jurisdictions

Users in Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act), South Africa (POPIA), and other jurisdictions have similar rights under their applicable laws. We honor all legitimate data subject requests regardless of jurisdiction.

12.5 How to Exercise Your Rights

To exercise any of these rights, contact us at privacy@yoteiko.com. You may also request data deletion directly through the app settings. We will respond within 30 days (or sooner if required by applicable law). We may request identity verification before processing your request.

13. Children's Privacy

Our Service is not intended for children under 16 years of age (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. We will delete such information promptly.

For users in the United States, we comply with the Children's Online Privacy Protection Act (COPPA). For users in the EEA, we comply with GDPR Article 8 regarding child consent.

14. Third-Party Links and Services

Our Service may contain links to third-party websites, services, or applications (e.g., airline booking sites, hotel platforms, travel guides). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.

15. Automated Decision-Making

We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects you. Our AI-powered packing suggestions are recommendations only and do not constitute automated decision-making under GDPR Article 22.

16. Do Not Track Signals

Some browsers include a "Do Not Track" (DNT) feature. Our Service currently responds to DNT signals by disabling non-essential tracking. We do not use cross-site tracking technologies.

17. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the updated policy on this page with a revised "Last updated" date
  • Sending an in-app notification for significant changes
  • Sending an email to your registered address for changes that affect your rights

Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.

18. Contact Us

If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:

Yoteiko Privacy Team

Email: privacy@yoteiko.com

For GDPR-related inquiries (EU residents): eu-privacy@yoteiko.com

For APPI-related inquiries (Japan residents): jp-privacy@yoteiko.com

We aim to resolve all complaints within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.