Skip to content
N8GoTravel

Legal

Privacy policy

Last updated 24 July 2026

This policy explains what personal data we collect, why we collect it, who we share it with, and the rights you have under the UK GDPR and EU GDPR.

1. Who we are

N8Go Travel Ltd is the data controller for the personal data described here. You can contact us about data protection at privacy@n8go.travel.

2. What we collect and why

We collect the following categories of data:

  • Account data — your email address, name, and a hashed password. Needed to give you an account. Lawful basis: performance of a contract.
  • Booking data — traveller names, dates of birth where an airline requires them, contact details, and booking references. Needed to make bookings on your behalf. Lawful basis: performance of a contract.
  • Payment data — we do not store card numbers. Stripe processes payments and returns only a token and the last four digits. Lawful basis: performance of a contract, and legal obligation for transaction records.
  • Preferences and activity — your onboarding answers and which trip ideas you save or skip, used to personalise what we show you. Lawful basis: legitimate interests, and you can reset this at any time.
  • Trip planning conversations — what you tell the trip planner, used to produce your itinerary. Lawful basis: performance of a contract.

3. Automated processing

We use Anthropic’s Claude API to turn your description of a trip into search criteria, and to write short explanations of why an option was chosen. This shapes what we suggest to you; it does not make a decision with legal or similarly significant effects about you, and it never sets a price. Prices always come from the airline or accommodation provider.

Personalisation of your homepage feed is likewise a ranking of editorial content, not a decision about you.

4. Who we share data with

  • Airlines and accommodation providers — the traveller details required to make a booking you have asked us to make.
  • Duffel and RateHawk — the distribution platforms through which those bookings are made.
  • Stripe — for payment processing.
  • Anthropic — trip planning conversation content, for generating itineraries.

We do not sell personal data, and we do not share it with advertising networks.

5. International transfers

Some of our processors are located outside the UK and EEA. Where that is the case, the transfer is covered by UK International Data Transfer Agreements or EU Standard Contractual Clauses, together with additional safeguards where required.

6. How long we keep it

  • Account data: while your account is open, then 12 months.
  • Booking and payment records: 7 years, to meet tax and accounting obligations.
  • Trip planning conversations: 24 months.
  • Preference and activity data: until you reset it or close your account.

7. Your rights

You have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, and to receive it in a portable format. You can exercise these by emailing privacy@n8go.travel.

Where we rely on legitimate interests — personalisation — you can object at any time and we will stop.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office (ico.org.uk), or to your local supervisory authority if you are in the EEA.

8. Security

Passwords are hashed with Argon2id. Card data never reaches our servers. Access to production data is restricted and logged.

This document is a working draft prepared for the N8Go Travel platform build. It sets out how the service is intended to operate and must be reviewed and finalised by a qualified solicitor before the service accepts real customers.