Back to home

Privacy Policy

Effective Date: August 26, 2026 Scope: United States Users Only

Euclid Travel is operated by LumoTravel LLC, a New York limited liability company ("Euclid Travel," "we," "us," or "our"), which provides a platform that monitors and manages the travel you have already booked. Because we handle your travel itineraries and act on your behalf to secure airline credits and lower hotel rates, security and transparency are our foundational principles.

This Privacy Policy explains how we collect, use, retain, and protect your information when you use our website, application, and related services (collectively, the "Services").

1. Information We Collect

We collect information necessary to monitor your travel portfolio, negotiate with airlines and hotels on your behalf, and ensure the security of your account.

  • Account Information: When you create an account, we collect your name and email address.
  • Identity & Verification Data: To successfully execute rebookings and claim e-credits with airlines, and to cancel and rebook hotel reservations on your behalf, we collect your Date of Birth and Phone Number. Your name and Date of Birth must exactly match your official travel documents. If you opt in, we also use your Phone Number to text you about your trips (see "To Communicate With You" below); texting is optional and you can turn it off at any time.
  • Travel Itinerary Data: When you forward a booking confirmation to us, or sync your inbox (see "Google Account Data" below for how Gmail inbox sync is handled — we use it only to find your travel confirmations, and we do not use the rest of your mail for any purpose), we extract your travel data. For flights this includes your Passenger Name Record (PNR), origin, destination, dates, airline, flight numbers, cabin class, fare brand, seat assignments, and original price paid; for hotels this includes your reservation/confirmation number, property name, city, check-in and check-out dates, room type, rate, and original price paid. For a flight booked with points or miles (an award ticket), we additionally extract the loyalty program you redeemed with, the number of miles redeemed, and any cash taxes or co-pay.
  • Financial Information: To process our success fee, we require a valid payment method. All payment data is vaulted and processed directly by our payment provider, Stripe. Euclid Travel does not view, collect, or store your raw credit card numbers.
  • Device & Usage Data: We collect standard technical information when you interact with our Services, including your IP address, browser type, and interaction logs.

2. How We Use Your Information

We use your information to operate Euclid Travel and to provide the travel services you ask us to provide. We do not sell your personal data, and we do not use it for advertising.

  • To Find and Organize Your Trips: We detect travel confirmations — flights and hotels today, and, as we add support for them, rental cars, rail, cruises, and short-term rentals — from confirmations you forward to us or that we find in a Connected Inbox you have linked, and we assemble them into your trip dashboard.
  • To Monitor Prices and Reprice Your Bookings: We continuously check the current price of your enrolled bookings and, when a qualifying drop occurs, act as your agent to secure the lower price, a credit, or a refund.
  • To Execute Rebookings: We use your PNR or hotel reservation number, name, Date of Birth, and Phone Number to interface with airlines and hotels and secure your e-credits or rebooked lower rates.
  • To Provide the Travel Features You Turn On: Where you enable an additional Euclid Travel feature, we use your trip and account information to deliver it. Depending on what we offer and what you enable, these may include itinerary and document management, online check-in, help when a trip is delayed, cancelled, or otherwise disrupted, and searching for and booking travel at your direction. Each such feature is described to you in the product before you turn it on, and any feature that would spend your money requires your separate authorization (see our Terms of Service, Section 1).
  • To Personalize What We Show You: We use your own trip history and stated preferences to make the results, suggestions, and alerts we show you more relevant. We do this only for you, using your own data.
  • To Communicate With You: We send transactional emails, including price drop alerts, claim tokens, and success fee receipts. If you separately opt in, we also send text messages about your trips — for example, that a price dropped or that we repriced a booking. Text messaging is optional, is never required to use Euclid Travel, and you can stop it at any time by replying STOP or by turning it off in your settings. Message and data rates may apply. We also send promotional updates by email, which you may opt out of at any time.
  • To Operate, Secure, and Improve the Services: We use technical and usage data to keep your account secure, prevent fraud and abuse, debug errors, and understand which features work so we can improve them.
  • To Comply With Law and to establish, exercise, or defend legal claims.

We will not use your information for a materially new purpose that is not described above without first telling you and obtaining your agreement. If we introduce a new purpose, we will apply it only to data going forward, and only for users who agree to it. See Section 11 (Changes to this Policy).

3. Information Sharing & Sub-processors

We do not sell your personal data. We only share information with trusted infrastructure partners, airlines, and hotels to the extent necessary to provide the Services.

  • Airlines, Hotels & Travel Providers: To secure your e-credit or rebook a lower hotel rate, we must transmit your booking details back to the respective airline or hotel (e.g., Delta, United, Marriott, Hilton). Disclaimer: Once this data is transmitted to the travel provider, it is governed exclusively by that provider's privacy policy. Euclid Travel is not liable for how airlines or hotels handle or retain your data.

  • Infrastructure Sub-processors: We use a small set of vendors to host and operate the platform. Each receives only the data it needs, under contracts requiring them to protect it and to use it only to provide their service to us. Our current sub-processors are:

    • Supabase — database and authentication. Receives account and booking data, with sensitive fields encrypted.
    • Railway — application and worker hosting. Processes the above in transit.
    • Vercel — website and app hosting. Stores no personal data.
    • Google (Gmail API) — reads booking confirmations, with your consent. Email content is read transiently and never written to durable storage.
    • Google (Gemini API, paid tier) — extracts trip details from confirmation text. Receives confirmation email content in memory only.
    • SerpApi — flight and hotel price lookups. Receives itinerary details only: no names, record locators, or payment data.
    • AwardWallet — award-flight price lookups. Receives itinerary details only.
    • Stripe — payment processing. Receives payment credentials, vaulted by Stripe.
    • Resend — transactional email. Receives your email address and the message content.
    • Crisp — in-app support chat. Receives what you type into chat, plus your account email and device data.

    We will update this list before a new sub-processor begins processing your personal data. For advance notice of changes, email legal@euclidtravel.ai.

  • Data Parsing & AI Models: We use Google's Gemini API (paid tier) to parse your confirmation emails into structured trip details. We use this provider under terms that prohibit it from using your data to train or improve its AI models, or from having its personnel review your content, so your personal data and itineraries are never used to develop, improve, or train generalized (non-personalized) artificial-intelligence or machine-learning models.

  • Human Operations: Some of what we do requires a person. Where an airline or hotel does not permit us to automate a change, where a repricing must be verified before we act, where you contact support, or where we are investigating a suspected error, fraud, or abuse, an authorized, US-based member of the Euclid Travel team may view the specific booking details needed for that task — typically the traveler name and the record locator or hotel confirmation number, the itinerary, and the prices involved. Access is scoped to the specific trip and task, and is recorded in an audit log. Our staff do not browse your inbox. Where a feature you enable would require a person to review more than this, we will tell you before you turn it on.

  • Business Transfers: If Euclid Travel is involved in a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred as part of that transaction, and we will notify you before your personal information becomes subject to a different privacy policy. Data obtained from your Google account is treated more strictly: we will not transfer it as part of such a transaction without first obtaining your explicit prior consent, as required by the Google API Services User Data Policy. Any successor remains bound by the commitments in this policy with respect to information collected before the transfer, unless you agree otherwise.

  • Customer Support Chat: Our in-app support chat is operated by Crisp (Crisp IM SAS, France). When you open the chat, Crisp processes your account email, name, IP address, the in-app pages you view, your device and browser information, and the content of the messages you send, stored on servers within the European Union (Netherlands and Germany). We never share data obtained from your Google account — including email content or itineraries synced from Gmail — with Crisp.

4. Data Security

We protect the travel data and account credentials you entrust to us with layered, industry-standard safeguards, designed to keep your information secure both in transit and at rest:

  • Encryption in Transit: All data exchanged between you, Euclid Travel, and our infrastructure providers is protected with TLS encryption (HTTPS), so it is never transmitted in the clear.
  • Encryption at Rest: The databases that store your information are encrypted at rest by our hosting providers. As an additional layer, we apply field-level encryption to the most sensitive identifiers we hold, including your flight Passenger Name Records (PNRs), hotel confirmation numbers, traveler names, and the access credential for a connected Gmail account. These fields are encrypted with a key held separately from the database, so they remain protected even against direct database access.
  • Payment Data: We never store your raw card numbers. Payment credentials are vaulted and processed entirely by our PCI-DSS-compliant payment provider, Stripe.
  • Access Controls & Isolation: Your data is isolated at the database level so that each account can access only its own records. Internal access is limited to a small number of authorized, US-based personnel, is restricted to the specific booking identifiers needed to perform a task, and is never used to browse your inbox.
  • Minimized Handling of Email Content: When you connect Gmail, raw message content is used only transiently to extract your trip details and is never written to durable storage (see "Google Account Data" below). We do not retain the bodies of synced emails.
  • Operational Safeguards: We monitor our systems for unauthorized access and abuse, keep sensitive values out of our application logs, and maintain a published security contact for responsible disclosure at euclidtravel.ai/.well-known/security.txt.

No method of electronic transmission or storage is completely secure, so we cannot guarantee absolute security. We do, however, work continuously to protect your information and to address any vulnerability promptly.

5. Google Account Data (Gmail Inbox Sync)

If you choose to connect your Gmail account, Euclid Travel requests read-only access (the Google gmail.readonly scope) to your mailbox. We use that access to identify travel confirmations and extract the trip details we need to provide the Euclid Travel features you use. Today that means flight and hotel booking confirmations, and the related cancellation and change notices for those bookings, so we can build your trip dashboard and monitor and reprice your trips. As we add support for additional travel types (such as rental cars, rail, cruises, and short-term rentals) and additional trip features (such as itinerary management, check-in, and disruption handling), we use the same access for those travel confirmations and for those features, each of which is visible and prominent in the Euclid Travel application.

These confirmations come both directly from airlines and hotels and from travel agencies that book on your behalf — including online travel agencies and bank or credit-card travel portals (for example, Expedia, Booking.com, Chase Travel, American Express Travel, or Capital One Travel). Detecting a booking requires reading the body of these confirmation emails (which contain the flight or reservation numbers, the record locator, and the price, and — for an award ticket — the loyalty program, miles redeemed, and any cash co-pay); email headers alone are not sufficient. We identify candidate confirmations using the sender and the message content. We do not use the rest of your mail for any purpose, we never send, modify, label, or delete your email, and we will not use Gmail data for a purpose not described in this policy.

Before we request access to your Gmail account, we show an in-app disclosure that names exactly what we access (your Gmail messages, read-only) and why, which you must affirmatively approve before you are sent to Google's consent screen. Connecting Gmail is optional; forwarding a confirmation and manual entry remain available without it.

The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Specifically:

  • We do not transfer or sell information obtained through Google APIs to third parties, except: to provide or improve user-facing features that are prominent in the Euclid Travel application and only with your consent; for security purposes (such as investigating abuse); to comply with applicable law; or as part of a merger, acquisition, or sale of assets, after obtaining your explicit prior consent.
  • We do not use this information for advertising, including personalized, interest-based, or retargeted advertising.
  • We do not retain Google user data to develop, improve, or train generalized (non-personalized) artificial-intelligence or machine-learning models.
  • We do not allow humans to read this data, except where you have given explicit consent to view specific messages, where necessary for security purposes (such as investigating abuse), or where required to comply with applicable law. Where an operator must use your booking identifiers (such as your name and PNR, or hotel confirmation number) to execute a rebooking an airline or hotel does not permit us to automate, that operator uses only the identifiers from the trip you enrolled us to act on; operators do not browse your Gmail.

Raw Gmail message bodies (the HTML and text) are never written to durable storage and are discarded immediately after parsing. The structured trip details we extract are retained while your account is active so we can monitor and reprice your trips; the message subject line is retained as routing metadata and purged on the same 30-day schedule as forwarded email. You can disconnect Gmail or delete your account at any time. Disconnecting Gmail stops all future inbox sync and revokes Google's access to your mailbox; trips already enrolled remain under monitoring so we can continue to reprice them. Deleting your account additionally removes the trip data derived from your inbox — except that where a trip resulted in a repricing or a charge, the associated transaction record and operator audit log are retained for up to seven (7) years for tax and accounting compliance, as described in our Data Retention & Deletion section below. If a self-service disconnect or deletion control is not yet available to you, email support@euclidtravel.ai and we will disconnect Gmail or delete your data for you.

6. Data Retention & Deletion

We adhere to a strict data minimization protocol:

  • Raw Emails: If you forward an email to us, the raw HTML and text of that message are permanently purged from our systems after 30 days. (For Gmail inbox sync, the message body is never stored at all — it is discarded immediately after parsing; only the subject line is retained as routing metadata, under the same 30-day purge, as described in the "Google Account Data" section.)
  • Active Travel Data: Parsed flight and hotel booking data, your Date of Birth, and your Phone Number are retained while your account is active so we can continuously monitor and reprice future bookings.
  • Records of Repricings, Charges & Audit Ledgers: If you choose to delete your account, we will immediately purge your travel dashboard and active monitoring data. However, to comply with federal tax and accounting laws, we retain records of repricings and charges, anonymized operator audit logs, and Stripe transaction records for up to seven (7) years.

7. Cookies & Tracking Technologies

We use cookies to maintain the security and functionality of the platform:

  • Essential Cookies: Required to keep your session authenticated and secure while using the dashboard.
  • Analytics Cookies: Used to understand how users interact with our marketing pages so we can improve the platform. You may adjust your browser settings to decline non-essential cookies.
  • Support Chat Cookies: When you use our in-app support chat, our support provider (Crisp) sets a functional first-party cookie to maintain your conversation.

8. Your Privacy Choices

You retain full control over your travel portfolio and personal data:

  • Account Deletion: You may request the deletion of your account and travel data at any time via your account settings.
  • Inbox Sync Controls: You may turn off automatic enrollment and disconnect a connected inbox at any time from your dashboard settings (see our Terms of Service).
  • Tracking Controls: You may pause or stop monitoring for any specific trip — flight or hotel — directly from your dashboard.
  • Marketing Opt-Out: You may unsubscribe from promotional emails at any time using the link provided at the bottom of the emails. Transactional notices regarding charges and security will still be delivered.

9. Children's Privacy

Euclid Travel acts as an authorized agent for financial optimization. Therefore, you must be at least 18 years old to use our Services. We do not knowingly collect personal information from individuals under 18. If we become aware that we have collected such data, we will immediately delete it.

10. US State Privacy Rights (CCPA/CPRA)

If you are a resident of California, Virginia, Colorado, or other states with applicable privacy laws, you possess specific rights regarding your personal information:

  • Right to Know: You may request a copy of the specific pieces of personal data we hold about you by emailing support@euclidtravel.ai, and we will provide it within the period required by applicable law.
  • Right to Delete: You may request the deletion of your personal data, subject to the financial compliance exceptions noted in our Data Retention & Deletion section.
  • Do Not Sell My Personal Information: Euclid Travel categorically does not sell your personal data, nor do we share it for cross-context behavioral advertising.

11. Changes to this Policy

We may update this Privacy Policy as our services change or as legal requirements change. How we notify you, and whether we need your agreement, depends on the kind of change:

  • Routine changes (clarifications, a new sub-processor, or a new feature that uses your data for a purpose already described in Section 2): we will update the "Effective Date" at the top of this policy and, for changes that affect you materially, send a notice to your account email.
  • Materially new uses of your data: if we want to use personal information we have already collected for a purpose materially different from the purposes described in Section 2 at the time we collected it, we will obtain your affirmative agreement before applying that new use to that information. If you do not agree, we will continue to handle your existing information under the policy in effect when we collected it, and you may keep using the Services you already have.
  • Google account data: we will not use data obtained from your Google account for any purpose not disclosed in this policy, and we will not apply a new purpose to previously collected Google data without your affirmative agreement.

We keep a record of which version of this policy applied to you and what you agreed to, and we will provide prior versions on request.

12. Contact Us

If you have any questions regarding this Privacy Policy, our data practices, or if you wish to exercise your data rights, please contact us at:

LumoTravel LLC Email: support@euclidtravel.ai