Privacy Policy
Last updated: 8 July 2026
This Privacy Policy explains how Josh Wright, trading as VoyageLine (“VoyageLine,” “we,” “us”), the data controller, handles personal data. VoyageLine is a proposal-building tool for travel advisors (“Agents”). Agents use it to prepare cruise proposals for their own customers (“Clients”).
Our two roles
- Controller — for the Agent’s own account data (how we run the service and bill for it).
- Processor — for the Client information an Agent enters or imports into VoyageLine. The Agent is the controller of that data; we process it on their behalf under our Terms / Data Processing Agreement.
What we collect
- Account data: name, email, profile image (via Google sign-in or email magic-link), and your agency/workspace settings.
- Client data entered by Agents: typically a Client name (often just a surname), and optionally contact details and notes the Agent chooses to add.
- Import content: text or screenshots an Agent pastes or uploads from suppliers, used to extract cruise details. These may incidentally contain personal data.
- Billing data: handled by Stripe; we store subscription status and identifiers, not full card numbers.
- Usage & engagement analytics: on public proposal links we record best-effort metrics (view counts, time-on-page, scroll depth). We store a hashed (not raw) IP address and a coarse geographic region; we do not store the raw IP.
- Cookies: strictly-necessary cookies for sign-in and your active workspace, plus the analytics above which run only with your consent.
How we use AI
To save Agents time, content they paste or upload for import is sent to our AI sub-processor (Anthropic) to extract structured cruise details. AI output is assistive only — the Agent reviews and edits every field before it becomes a proposal. Do not paste data you are not authorized to process with a third-party AI service.
Sub-processors
We rely on these providers to operate the service:
- Anthropic — AI extraction
- Stripe — payments
- Resend — transactional & sign-in email
- Cloudflare R2 — file/image storage
- MaxMind — coarse IP geolocation
- Neon — database hosting
- Railway — application hosting
- Inngest — background jobs
- Google — sign-in (OAuth)
Cookies & similar technologies
We use a small number of first-party, strictly-necessary cookies to run sign-in and the app. Under the ePrivacy Directive these are exempt from consent because they are essential to a service you explicitly request (signing in and using your workspace). We set no advertising or cross-site tracking cookies, and we do not share cookie data with third parties.
Our optional engagement analytics on public proposal pages (view counts, time-on-page) run only after you click “Accept” on our consent banner; they use an in-memory per-visit identifier and do not set a tracking cookie. Choosing “Decline” leaves them off.
| Cookie | Purpose | Category | Retention |
|---|---|---|---|
__Secure-authjs.session-token | Keeps you signed in (HttpOnly, Secure). | Strictly necessary | ~30 days |
__Host-authjs.csrf-token | Protects the sign-in form against CSRF (HttpOnly, Secure). | Strictly necessary | Session |
__Secure-authjs.callback-url | Returns you to the right page after sign-in (Secure). | Strictly necessary | Session |
cqf_workspace | Remembers your active workspace (HttpOnly, Secure). | Strictly necessary | ~1 year |
cqf_consent | Stores your cookie/analytics choice. | Strictly necessary | ~1 year |
All the above are first-party cookies set by voyageline.app. You can clear or block them in your browser; blocking the strictly-necessary ones will prevent sign-in. To revisit your analytics choice, clear the cqf_consent cookie.
How long we keep data
- Quotes/proposals: kept while your account is active.
- Import screenshots/text: purged once the import is completed (promoted) or discarded.
- Engagement analytics: kept with the related proposal and deleted when the proposal or account is deleted.
- Closed accounts: deleted within 90 days of account deletion (sooner on a verified erasure request).
International transfers
VoyageLine serves Agents and Clients worldwide and hosts its infrastructure in the United States, so personal data (including data of EU/UK visitors) may be processed there and in other countries. For transfers out of the EEA/UK we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses with our processors. [Counsel to confirm transfer mechanism.]
Your rights
Depending on your location (including under the GDPR/UK GDPR and CCPA/CPRA), you may have rights to access, correct, delete, export, or object to the processing of your personal data. To make a request, contact us at privacy@voyageline.app. If you are a Client, please also contact the Agent who prepared your proposal, as they control that data.
Security
We apply access controls, encryption in transit, tenant isolation, and data-minimization (e.g. IP hashing). No system is perfectly secure, but we work to protect your data and to limit what we collect.
Children
VoyageLine is a business tool not directed to children and is not intended for use by anyone under 16.
Changes
We will update this policy as the service evolves and will revise the “last updated” date above.
Contact
Josh Wright, trading as VoyageLine (United States) — privacy@voyageline.app. [Postal address to be added.]