Privacy Policy
1. Data controller
Walid Ben Miled, natural person (personal project, unregistered, brand Take.Me), 38, avenue du Golf Arabe, El Menzah 8, 2037 Tunis, Tunisia, contact@gotakeme.com.
2. Personal data collected
Take.Me collects the following data:
- Account: email address (for email and password login or with a Google account).
- Trip request: destination, dates of stay, budget, number and ages of travellers, nationality. No name or email is sent to the plan-generation AI agent.
- IP address (rate limiting): kept in RAM for 1 minute to prevent abuse, never recorded.
- IP address (unlock): retained with unlock record (proof of consent and payment), deleted with account.
- Payment: processed exclusively by Paddle. Take.Me only receives the email and order reference; card data never passes through our servers.
- Cookies and local storage: session cookie for authentication, localStorage for preferred theme (light/dark); with your consent, Google Analytics audience measurement cookies.
- Internal audience measurement (cookie-free): to understand how the service is used and to fix problems, Take.Me records events: page views, clicks on buttons and partner links, steps completed (form, quote, sign-in, preview, payment, unlock), scroll depth and errors encountered, together with the language, device type (mobile, tablet, desktop), the browser time zone, the referring site and campaign parameters (UTM). For a trip, the event may also contain the destination, the departure city, the length of stay, the number of travellers, the style, the pace, the budget range, the language and the price tier; when it concerns a plan, it carries that plan's technical identifier. These events are linked to a random identifier specific to your browsing session (kept in the browser's session storage, without any cookie), which disappears when you close the tab. They contain neither your email, nor your name, nor your IP address, nor the text you type. Your browser's "Do Not Track" signal is honoured.
- Language preference: your language choice (French, English or Spanish) is kept in your browser's local storage.
3. Purposes and legal basis of processing
| Purpose | Data | Legal basis |
|---|---|---|
| Authentication and account management | Consent (GDPR art. 6.1.a) / contract (French Financial Code L. 81-5) | |
| Travel plan generation | Destination, dates, budget, travellers, nationality | Contract performance (GDPR art. 6.1.b) |
| Payment processing and billing | Email, IP | Contract performance + legal obligation (VAT Directive) |
| Rate limiting (anti-abuse) | IP | Legitimate interest (service security) |
| Internal audience measurement and problem fixing | Anonymous usage events (pages, clicks, steps, language, device, time zone, source), random session identifier | Legitimate interest (GDPR art. 6.1.f): understanding how the service is used, fixing and improving it; you may object (section 7) |
| Service improvement | Anonymised / aggregated data | Legitimate interest |
4. Retention periods
- Plans (runs): unpurchased previews: 30 days after generation; purchased plans: 13 months after generation, so you can access your plan until your trip. After a plan is deleted, associated data is erased.
- Account: retained until voluntary deletion by the user (section "My trips" → "Delete my data"). Deletion results in immediate deletion of all plans and account information.
- Rate limiting IP: kept in RAM for 1 minute, never recorded.
- Unlock record IP: retained with unlock record (proof of consent and payment), deleted with account.
- Audience measurement events: kept for a maximum of 180 days, then deleted automatically.
- Server logs: Technical logs (IP address, requests, errors): retained for a maximum of 30 days, then automatically deleted.
5. Sub-processors and data transfers outside the EU
Take.Me relies on the following sub-processors to process personal data:
| Sub-processor | Role | Data | Location |
|---|---|---|---|
| OVH SAS | Hosting of website, API and database, and sending of transactional emails (password reset) | All plans, accounts, data, email address for sending | France |
| Paddle | Merchant of record, payment | Email, order reference, amount | United Kingdom |
| Google (Places API, Maps, Sign-In) | Geographic data, authentication | Place queries, photos, hours; email for Sign-In | United States |
| DeepSeek (DeepSeek V4.1 Flash model), via OpenCode | AI plan generation | Trip parameters only (destination, dates, budget, style, number and age of travellers, nationality) — never name, email or identifier | Outside EU (China / United States) |
| Ignav | Flight prices | Airports and trip dates — no personal data | Outside EU (not specified by provider) |
| Travelpayouts | Affiliate links | Airports and trip dates (affiliate link creation on server side) — no personal data | Hong Kong (Go Travel Un Limited) |
| OpenStreetMap | Map tiles | IP (visible to tile servers) | Various (Europe) |
| Unsplash | Destination photos | Search queries (anonymised) | United States |
| Google Fonts | Typefaces | IP (for each load) | United States |
| Google Ireland Limited / Google LLC | Google Tag Manager and Google Analytics (audience measurement, only with consent) | Cookie ID, pages viewed, device type, IP address truncated/pseudonymised by Google | United States |
Transfers outside the EU: Your data (account, plans, unlocks) is stored in France on an OVH server. Some providers located outside the European Union receive personal data to deliver the service: Paddle (United Kingdom, a country with an adequacy decision from the European Commission) for payment; Google (United States): place names for photos and place information (photos are then served from our server), email if you choose Google login, IP address when loading Google Fonts, and cookie ID / pages viewed / truncated IP address for Google Analytics (audience measurement, only with your consent via the cookies banner). These transfers rely on the EU–US Data Privacy Framework or standard contractual clauses proposed by these providers. AI, flight and affiliate providers (DeepSeek, Ignav, Travelpayouts) receive no personal data.
6. Cookies and trackers
- Session cookie: user authentication (essential, no prior consent required).
- localStorage (theme): user preference light/dark (not subject to GDPR, local storage only).
- Google Analytics cookies (_ga, _ga_*): audience measurement, placed only after your consent via the banner, retained for a maximum of 13 months; the choice is stored in local storage (key takeme.consent).
- Session storage (sessionStorage): random session identifier for internal audience measurement (key takeme.vid) and, where applicable, the campaign parameters of your arrival (key takeme.utm); erased when you close the tab. These are not cookies and are not read by third parties.
- localStorage (language): language preference (key takeme.lang), kept until you clear it.
Take.Me uses no advertising cookies. You can change your choice at any time via the "Manage cookies" link at the bottom of the page.
7. Data subject rights (GDPR)
Each user has the right to:
- Access (art. 15): request a copy of their personal data.
- Rectification (art. 16): correct their account information.
- Erasure (art. 17, "right to be forgotten"): request deletion of their account and all their plans directly from the "My trips" section (button "Delete my data"). The request is executed immediately.
- Restriction of processing (art. 18): request to freeze processing of certain data.
- Data portability (art. 20): export your data in a common format.
- Opposition (art. 21): object to processing for certain purposes.
To exercise these rights, contact contact@gotakeme.com.
8. Data Protection Officer (DPO)
Take.Me has not designated a data protection officer; for any questions, please write to contact@gotakeme.com.
9. Complaint to a supervisory authority
If you believe your rights are not being respected, you can lodge a complaint with a supervisory authority. In the EU, you can contact the national data protection authority of your country.
10. Changes to this policy
Take.Me may modify this policy at any time. Changes will be communicated with a new version date. Continued use of the service after modification constitutes acceptance of the new policy.