Privacy Policy

Last updated: 11 August 2026

A Grand Tour is operated by Hanso Pte. Ltd., Singapore. This policy describes what the service collects, who else sees it, and what you can do about it. It describes the service as it is built today — not as a category of product generally works.

1. What We Collect

  • Your account: email address, username, and a name if you give one. If you use Sign in with Apple, Apple sends us an identifier and, once only, the name and email you choose to share — including a relay address if you hide your real one.
  • What you plan: tours, trips, routes, itineraries, documents and images. This is the substance of the service. It describes places you have been or intend to go, which is sensitive in a way an ordinary document is not, and we treat it that way.
  • Operational records: server logs of requests, and records of purchases. Logs include IP addresses.

We do not collect your device's location. The iOS app never asks for location permission. Coordinates in the app are the ones in your own tours.

There is no analytics or advertising in either app. No third-party analytics SDK, no crash-reporting SDK, no advertising identifier, and no tracking across other companies' apps or sites.

2. How We Use It

To run the service: to keep your account, store and sync your tours, show you maps, take payment, and send the few emails the service needs to work. We do not sell personal data, and we do not use your tours to advertise to you.

3. Who Else Sees It

Three companies necessarily receive some of your data, and each is named here with what it gets. Two things a service like this often hands to a vendor, we host ourselves.

  • Mapbox — supplies the maps. When you look at a map, Mapbox receives the requests for that area, which reveals which places you are looking at. This is unavoidable while the maps are theirs.
  • Stripe — processes card payments on the web. Your card details go directly to Stripe; we never see or store them.
  • Apple — handles in-app purchases and Sign in with Apple. Apple tells us that a purchase happened, never how you paid.
  • Images are not sent to a third party. They are stored on our own servers.
  • Email is not sent through a mail provider. It leaves our own mail server, so your address is not handed to a third party to deliver it.
  • Hosting is our own. The service runs on infrastructure we operate, not a managed platform with access to the database.

We will also disclose data where the law requires it. If that ever happens we will tell you, unless we are forbidden from doing so.

4. What You Choose to Publish

A tour is private until you make it public. A public tour is readable by anyone with the link, including search engines, and it shows your username and the tour's contents — including the places in it. Making a tour private again stops us serving it, but cannot retrieve copies already made by others.

5. Keeping and Deleting

We keep your data while your account exists. You can delete your account from the web app or from the iOS app, under Profile. This removes your account and everything attached to it: your tours and trips, your entitlements, your sessions, your sign-in credentials including any passkeys and two-factor secrets, and the image files you uploaded — your avatar, tour covers, and pictures attached to itinerary and dataset items.

Two things outlive it, and we would rather say so than let you discover it. Records that a payment happened are kept where tax law requires, and Stripe and Apple keep their own records of transactions regardless of what we do. Server logs age out on their own schedule and may briefly contain your IP address after the account is gone.

6. Your Rights

You can ask what we hold about you, correct it, or have it deleted. Two of those do not require asking us at all:

  • Download your data. Both apps can export your account details, tours, trips and itineraries as a machine-readable file, whenever you like.
  • Delete your account from the web app or the iOS app, under Profile. Section 5 says what goes and what does not.

For anything else, write to us and we will answer.

7. Cookies

The website sets a session cookie to keep you signed in, and one to protect forms against cross-site request forgery. That is all — there are no advertising or analytics cookies, so there is no consent banner to dismiss.

8. Children

The service is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has created an account, tell us and we will remove it.

9. Security

Traffic is encrypted in transit. Passwords are stored hashed, never in a form we could read. Access to production data is limited to the people who operate the service. No system is perfect, and we would rather state that than imply otherwise.

10. Changes

If this policy changes we will update the date above. If a change materially affects what we collect or who receives it, we will tell you rather than rely on you re-reading this page.

11. Contact

For privacy questions, write to team@a-grand-tour.com