Privacy Policy
Last updated: 24 August 2026
This Privacy Policy explains how Comitava Ltd (“Vivaera”, “we”,
“us”) collects, uses and protects your information when you use the Vivaera mobile
app (the “App”). We are the data controller. If you have questions, contact us at
privacy@vivaera.app.
Vivaera is intended for travellers aged 40 and over. We do not
knowingly collect data from anyone under 40.
1. Information we collect
You provide
- Account & profile: email address, first name and surname,
year of birth, bio, profile photo, and ID-verification status.
- Travel preferences: lifestyle and travel-style answers used
for matching — budget, pace, sleep schedule, interests, home country.
- Trips & community content: trips you post, community
posts and comments, tips, messages and group chats.
- Trusted contacts (optional): the name, email address and
phone number of up to three people you nominate for the Safe Roam and SOS
features. Please only add people who are happy for you to share their
details with us for this purpose.
- Travel documents (optional): passport expiry and issue
dates, and the country of issue, so the App can warn you about validity
rules before a trip. We never ask for your passport number.
- Travel insurance (optional): insurer, policy number,
24-hour assistance number and cover dates.
- Health information (optional): if you complete a Medical ID
— blood type, allergies, conditions, medications. This is
special-category data and is processed only with your
explicit consent, so it can be made available in an emergency.
Collected automatically
- Location: precise device location when you use
Coffee Mode (to find nearby travellers) or trigger an
SOS (shared with your trip group and trusted contacts).
Location is used only for these features, and only while the App is open —
we do not track you in the background.
- Device & technical data: device model, operating system
version, app version, and a push-notification token.
- Usage events: a record of actions taken in the App — for
example that a trip was posted or a checklist item ticked — so we can see
which features work and where people get stuck. These records hold counts
and identifiers only, never the content of your messages, trips or medical
details, and they are deleted after 180 days.
- Diagnostics: crash and error reports, to keep the App
stable. These are configured not to attach personal identifiers.
2. How we use your information
- Create and operate your account and profile.
- Match you with compatible travel companions.
- Enable messaging, group chats, trips, voice and video calls, and community
features.
- Provide safety features — Coffee Mode, Safe Roam check-ins, SOS alerts and
the Trip Ready checklist.
- Send notifications you have enabled.
- Maintain security, prevent abuse, and improve and debug the App.
- Comply with legal obligations.
3. Legal bases (UK GDPR)
We rely on performance of a contract (to provide the App),
consent (location, health data, notifications — each of which you
can withdraw), legitimate interests (security, abuse prevention,
product improvement), and legal obligation where applicable.
4. Who we share it with
We do not sell your data. We share it with service providers
(“processors”) who help run the App, under contract and only as needed:
- Supabase — database, authentication and file storage.
- Daily.co — voice and video calls.
- Expo, Google Firebase and Apple — delivering push
notifications.
- Sentry — crash diagnostics.
- Resend — sending safety and account emails.
- Cloudflare — website hosting and bot protection on sign-up.
- Google Maps — displaying maps.
Other members see the profile information, content and — where you choose to
share it — location that you make available to them. We may disclose data if
required by law, or to protect the safety of our members.
5. International transfers
Some providers process data outside the UK and EEA. Where they do, we rely on
appropriate safeguards such as UK and EU Standard Contractual Clauses. Our
database region is the EU.
6. Data retention
We keep your data while your account is active. When you delete your account
(see section 8) we delete your personal data, except where we must keep limited
records to comply with the law or resolve a dispute. Usage events are deleted
after 180 days regardless.
7. Security
We use encryption in transit, access controls and database row-level security.
No system is perfectly secure, but we work to protect your data.
8. Your rights
Under UK GDPR you can access, correct, delete, restrict or object to the
processing of your data, request portability, and withdraw consent at any time.
- Delete your account and data in the App:
Profile → Delete account. This permanently removes your
account and associated data.
- If you cannot access the App, you can
request deletion here.
- To exercise any other right, email
privacy@vivaera.app. You may also
complain to the UK Information Commissioner’s Office at
ico.org.uk.
9. Safety features — important
Coffee Mode, Safe Roam and SOS are convenience features and are not a
substitute for the emergency services. We cannot guarantee that an SOS
or alert will be delivered or received. Always call local emergency services —
999, 112 or 911 — in a genuine emergency.
10. Changes
We may update this policy. We will post the new version in the App and update
the date above, and material changes will be notified in the App.
11. Contact
Comitava Ltd, registered in England and Wales, company number
[COMPANY NUMBER], registered office
[REGISTERED ADDRESS].
Email privacy@vivaera.app.