Skip to content
Back to home

Last updated: August 4, 2026

Privacy Policy

Version 0.1. Effective date: August 4, 2026. If translations conflict, the Portuguese version prevails, unless applicable law requires otherwise.

1. About this Policy

This Privacy Policy explains how Baggagi collects, uses, stores, shares, and protects personal data during use of its platform, applications, pages, services, and related features.

This Policy applies to the following audiences:

  • travelers;
  • free users;
  • Premium users;
  • independent travel agents;
  • agency owners and employees;
  • travel-related establishments;
  • event organizers;
  • travel and event participants;
  • people included as dependent travelers;
  • visitors to Baggagi pages.

By using Baggagi, the user declares that they have been given access to this Policy. When a given processing activity depends on consent, Baggagi will present a specific, prominent request separate from other terms.

2. Who is responsible for Baggagi

Baggagi is currently operated by:

Controller: Jonathas de Sales Fonseca Santos

Location: Eunápolis, Bahia, Brazil

Support e-mail: hi@baggagi.com

Privacy e-mail: privacy@baggagi.com

Until a legal entity is incorporated, Jonathas de Sales Fonseca Santos will be responsible for decisions related to data processing carried out directly by Baggagi.

When a legal entity is incorporated to operate the platform, this Policy will be updated with its legal name, CNPJ, address, and other applicable information.

Baggagi is initially aimed at the Brazilian market and follows Brazilian legislation. The platform, however, may be accessed by users located in other countries.

3. Roles of Baggagi and business customers

In certain operations, Baggagi acts as the controller of personal data, making decisions about processing. This occurs, for example, in account administration, billing, security, support, marketing, fraud prevention, and platform operation.

In services provided to agencies and travel agents, the agency may act as the controller of its own customers' data. In those cases, Baggagi may act as a processor, storing and processing data according to the business customer's instructions.

The agency will be responsible for:

  • having a valid legal basis for registering the data;
  • informing its customers about processing;
  • obtaining authorizations when necessary;
  • registering only necessary information;
  • proving authorization from the legal guardian when minors are involved;
  • managing its employees' permissions;
  • requesting corrections or deletions when necessary.

Baggagi will continue to act as an independent controller for processing carried out for its own purposes, such as security, billing, fraud prevention, and compliance with legal obligations.

4. Data we may collect

4.1. Registration data

To create and manage an account, we may collect:

  • full name;
  • e-mail;
  • password or authentication credentials;
  • date of birth;
  • country;
  • city;
  • nationality;
  • username;
  • phone number, when provided;
  • profile photograph, when provided.

Passwords must be stored through secure authentication mechanisms and are not made available in plain text to the Baggagi team.

4.2. Authentication data

Authentication may occur through:

  • Google account;
  • e-mail and password;
  • Magic Link;
  • other mechanisms that may be made available.

When the user uses an external provider, Baggagi may receive information necessary to identify and link the account, such as name, e-mail, provider identifier, and photograph.

4.3. Profile data

Depending on the user's privacy choices, the profile may contain:

  • full name;
  • username;
  • nationality;
  • photograph;
  • countries visited;
  • posts;
  • reviews;
  • events;
  • other information published voluntarily.

The profile may be public or private, according to available settings.

Other users may search profiles by name, username, or e-mail, subject to the privacy controls and limitations implemented by Baggagi.

4.4. Travel planning data

To generate, save, and manage a trip, we may process:

  • city or destination;
  • trip duration;
  • arrival and departure dates;
  • period or season of the year;
  • number of travelers;
  • group type;
  • approximate budget;
  • dietary preferences;
  • interests;
  • activity types;
  • event types;
  • desired number of activities;
  • hotel name, when provided;
  • accessibility information;
  • trip-related restrictions;
  • generated itinerary and changes made by the user.

It is not necessary to provide each traveler's name to generate an itinerary.

4.5. Health data and other sensitive data

In some situations, the user, guardian, or agency may register information related to:

  • allergies;
  • medical restrictions;
  • accessibility;
  • reduced mobility;
  • medications;
  • conditions relevant to trip organization;
  • health certificates required by the destination.

This information is considered higher-sensitivity data and should be registered only when necessary for safe trip organization.

Baggagi will not use health data for advertising or to create commercial profiles.

When this data is registered by an agency, the agency will be responsible for having the authorization or other legal basis required.

4.6. Data of people without an account

A user or agency may include documents and information about travelers who do not have their own Baggagi account.

The person who registers this data must:

  • have authorization to do so;
  • inform the data subject or their legal guardian;
  • use the data only for trip organization;
  • avoid registering excessive information.

4.7. Travel documents

Baggagi may store documents directly related to the organization or execution of a trip, such as:

  • passport;
  • identification document;
  • visa;
  • travel authorization;
  • ticket;
  • booking confirmation;
  • travel insurance;
  • certificate required by the destination;
  • accommodation confirmation;
  • tour confirmation;
  • other documents necessary for the trip.

The following must not be uploaded:

  • passwords;
  • credentials;
  • authentication codes;
  • bank access data;
  • full card numbers;
  • documents obtained without authorization;
  • illicit files;
  • files unrelated to the trip;
  • complete medical records without trip-related necessity.

Documents may be viewed by:

  • whoever uploaded them;
  • authorized trip participants;
  • agents responsible for the respective customer;
  • the agency owner, according to their permissions;
  • authorized Baggagi team members, when necessary for support, security, investigation, or compliance with a legal obligation.

Baggagi's administrative access to documents will be recorded in logs.

4.8. Messaging and social content data

When the user uses chat, posts, comments, reviews, or events, we may process:

  • message content;
  • sender and recipients;
  • date and time;
  • read confirmation;
  • attachments;
  • posts;
  • comments;
  • photographs;
  • videos;
  • links;
  • published location;
  • likes and other interactions;
  • reports;
  • blocks;
  • moderation history.

Public profiles may receive messages from other users. Private profiles may limit messages to previously accepted people.

4.9. Event data

To create or participate in events, we may process:

  • organizer identity;
  • description;
  • date and time;
  • location;
  • images;
  • age rating;
  • guests;
  • attendance confirmation;
  • posts and comments;
  • accessibility information;
  • event status;
  • reports and moderation measures.

Ticket sales is still a future feature. This Policy will be updated before that service is made available.

4.10. Reviews

To publish and verify reviews, we may process:

  • reviewer's profile;
  • rating;
  • review text;
  • establishment response;
  • link to booking, event, trip, or purchase;
  • evidence needed to verify the experience;
  • reports and disputes.

Reviews will not be anonymous.

When the experience can be confirmed, the review may receive the “Verified experience” badge.

4.11. Location

With the user's authorization, Baggagi may temporarily access the device's location.

In this process:

  1. the device provides latitude and longitude;
  2. the coordinates are sent to Mapbox;
  3. the result is forwarded to Baggagi's backend;
  4. the information is used to locate nearby events;
  5. exact coordinates are discarded after the query.

Baggagi does not intend to maintain a continuous movement history.

Permission may be denied or revoked in browser or device settings. Some proximity-based features may not work correctly without this permission.

4.12. Technical data and logs

We may collect:

  • IP address;
  • browser;
  • device;
  • operating system;
  • date and time of access;
  • pages and features used;
  • authentication attempts;
  • errors;
  • session identifiers;
  • security logs;
  • administrative access logs;
  • application performance.

Amazon CloudWatch is used for technical monitoring, error diagnosis, security, and infrastructure operation.

Baggagi does not currently use Google Analytics, Meta Pixel, Microsoft Clarity, Hotjar, or equivalent behavioral advertising platforms.

4.13. Payment and subscription data

Payments are processed by Stripe.

Baggagi may receive:

  • subscribed plan;
  • amount;
  • billing frequency;
  • billing status;
  • payment date;
  • renewal date;
  • transaction identifier;
  • limited information about the payment method;
  • billing attempts;
  • cancellations;
  • refunds.

Baggagi does not store full card numbers.

4.14. Communications and support

When the user contacts us, we may process:

  • name;
  • e-mail;
  • request content;
  • attachments;
  • support history;
  • technical information related to the issue;
  • measures taken to resolve the request.

5. How we obtain data

Data may be obtained:

  • directly from the user;
  • from a legal guardian;
  • from an authorized agency or agent;
  • from other trip participants;
  • through authentication providers;
  • through Stripe;
  • through Mapbox;
  • through infrastructure vendors;
  • automatically during use of the platform;
  • through integrations requested by the user.

6. How we use data

Baggagi may process data to:

  • create and manage accounts;
  • authenticate users;
  • generate itineraries;
  • save and edit trips;
  • enable collaboration;
  • store documents;
  • show nearby events;
  • offer chat and messaging;
  • enable posts, comments, and reviews;
  • manage events;
  • verify experiences;
  • process payments;
  • manage subscriptions and trials;
  • send transactional communications;
  • send marketing with authorization;
  • personalize the experience;
  • present recommendations;
  • prevent fraud and abuse;
  • enforce community rules;
  • analyze reports;
  • protect users and infrastructure;
  • provide support;
  • fix errors;
  • perform backups;
  • comply with legal obligations;
  • exercise or defend rights;
  • maintain contracting and acceptance records;
  • improve platform stability and performance.

7. Legal bases used

Depending on the operation, Baggagi may use the following legal bases:

Contract performance

For processing necessary to provide the account, travel planning, documents, payments, support, and other contracted features.

Pre-contractual steps

For registration, free trial, plan subscription, and requests made before contracting.

Consent

When necessary for:

  • marketing;
  • newsletter;
  • offers;
  • location access;
  • certain optional information;
  • advertising use of content;
  • sensitive data processing that depends on this authorization.

Consent may be withdrawn through the channels made available.

Compliance with a legal or regulatory obligation

For record keeping, response to authorities, and compliance with tax, consumer, accounting, or regulatory obligations.

Regular exercise of rights

To prevent or respond to proceedings, disputes, reports, fraud, chargebacks, and complaints.

Legitimate interest

When necessary and proportionate for:

  • security;
  • fraud prevention;
  • service improvement;
  • support;
  • user protection;
  • abuse control;
  • account-related communications;
  • performance analysis.

Legitimate interest will not be used to justify advertising based on sensitive data.

Protection of life or physical integrity

In exceptional situations involving concrete risk to a person.

When Baggagi acts as a processor for an agency, defining the main legal basis will be the responsibility of the controlling agency.

8. Artificial intelligence

Baggagi uses the Gemini API, provided by Google, to assist in creating itineraries.

The following may be sent to the API:

  • destination;
  • duration;
  • season;
  • number of travelers;
  • approximate budget;
  • generic dietary preferences;
  • interests;
  • activity types;
  • event types;
  • general information necessary for planning.

Baggagi does not intend to send to the Gemini API:

  • name;
  • e-mail;
  • phone number;
  • passport;
  • documents;
  • payment numbers;
  • credentials;
  • identifiable medical data;
  • identifiable data of children or adolescents.

When a child is on the trip, the request may mention only that the group includes a child, without name, document, contact, or other identification.

Baggagi does not keep the original prompt text as permanent history after planning is completed.

The structured AI response may be saved as part of the trip.

The project used by Baggagi has active billing. According to the terms applicable to paid Gemini API services, prompts and responses are not used by Google to improve its products, unless the project owner voluntarily opts to share logs or datasets.

Baggagi should not voluntarily enable sharing prompts with Google for training without first evaluating the purpose, legal basis, and updating this Policy when necessary.

Google may maintain limited technical logs according to its terms, settings, and security measures.

Itineraries may contain errors, incomplete information, incorrect estimates, or outdated data. Critical information must be confirmed with official sources and the respective providers.

9. Children's and adolescents' data

Baggagi does not allow people under 18 years of age to create or control their own account.

Minors may be included as dependent travelers by:

  • a parent or legal guardian;
  • an agency authorized by the guardian.

The minor must not have:

  • their own login;
  • a public profile;
  • chat;
  • direct messages;
  • posts;
  • autonomous event creation;
  • payment control.

To organize the trip, the following may be processed:

  • name;
  • age;
  • date of birth;
  • nationality;
  • relationship;
  • passport;
  • medical restrictions;
  • guardian contact.

The agency must confirm that it has valid authorization and that it informed the guardian about processing.

Baggagi will seek to limit processing to the minimum necessary and consider the best interest of the child or adolescent.

10. Public profiles and published content

When the user makes their profile or content public, other people may view the information made available.

The following may be displayed:

  • name;
  • username;
  • nationality;
  • photograph;
  • posts;
  • comments;
  • reviews;
  • events;
  • other information chosen by the user.

The user should avoid publishing:

  • documents;
  • identification numbers;
  • banking data;
  • home address;
  • private location;
  • medical information;
  • third-party information without authorization.

Baggagi may remove content that violates the rules, third-party privacy, or the law.

11. Internal data sharing

Group trips

Documents and information may be shared with authorized participants of the same trip, according to the permissions chosen.

Agencies

The agency owner may view customers linked to the company.

Other agents may only view trips and customers for which they are directly responsible.

One agency may not access another agency's data.

Support and administration

Authorized Baggagi team members may access information when necessary for:

  • support;
  • security;
  • investigation;
  • fraud prevention;
  • error correction;
  • compliance with a legal obligation.

Document access will be recorded in logs.

12. Vendors and external sharing

Baggagi may share data with providers necessary for service operation, including:

  • Amazon Web Services and AWS Amplify: hosting, processing, infrastructure, and frontend;
  • Amazon CloudWatch: monitoring and logs;
  • Amazon SES: e-mail delivery;
  • Neon: authentication and database;
  • Cloudflare R2: document and file storage;
  • Stripe: payments and subscriptions;
  • Google Gemini API: itinerary generation;
  • Mapbox: maps, geocoding, and location.

We may also share information:

  • due to legal obligation;
  • by court order or order of a competent authority;
  • to protect rights and security;
  • in fraud investigation;
  • in corporate reorganization, acquisition, or transfer of operations, preserving privacy obligations;
  • at the user's request or with authorization.

Baggagi does not authorize vendors to use data for purposes incompatible with the contracted service.

13. International transfers

Some vendors may process or store data outside Brazil.

These transfers may occur for:

  • hosting;
  • authentication;
  • processing;
  • payments;
  • storage;
  • e-mail delivery;
  • artificial intelligence;
  • maps and location;
  • support;
  • security;
  • monitoring.

Baggagi will seek to use contracts, standard clauses, technical measures, and other mechanisms permitted by Brazilian legislation.

Transfers should be limited to the data necessary for each purpose.

The data subject may request additional information at privacy@baggagi.com.

14. Marketing, offers, and newsletter

Baggagi will only send marketing, offers, and newsletter to users who have checked a specific option accepting these communications.

Consent for marketing:

  • will be separate from acceptance of the Terms;
  • will not be required to create an account;
  • may be withdrawn;
  • will not prevent normal use of the platform.

The preferences center will allow separate control of:

  • marketing and offers;
  • newsletter;
  • trip reminders;
  • message notifications;
  • event notifications.

The user may also request unsubscribe at privacy@baggagi.com.

Withdrawal of promotional consent will not stop messages necessary about:

  • authentication;
  • security;
  • payments;
  • contractual changes;
  • account operation;
  • user requests.

15. Recommendations, advertising, and affiliates

Baggagi may present:

  • recommended results;
  • affiliate links;
  • sponsored content;
  • advertising.

Ranking may consider:

  • preferences;
  • location;
  • price;
  • reviews;
  • availability;
  • popularity;
  • commercial relationships;
  • commission;
  • sponsorship.

Affiliate, sponsored, or advertising items will be identified so the user can distinguish commercial content from a recommendation based mainly on suitability.

Sensitive data will not be used to target advertising.

16. Cookies and similar technologies

Baggagi uses or may use cookies, local storage, and similar technologies necessary for:

  • authentication;
  • session maintenance;
  • security;
  • preferences;
  • language;
  • interface operation;
  • fraud prevention;
  • navigation continuity.

Services such as Stripe, Mapbox, Neon, and AWS Amplify may use their own technologies according to the feature accessed.

Baggagi does not currently use Google Analytics, Meta Pixel, Microsoft Clarity, or equivalent behavioral advertising platforms.

A separate Cookie Policy will present categories, vendors, purposes, and durations after completion of the browser technical inventory.

Strictly necessary cookies may function without consent when indispensable to the service. Non-essential cookies will be subject to applicable user choices before activation.

17. How long we retain data

Data will be kept for the period necessary to fulfill its purposes.

The following criteria will be used:

Active account

Account, trip, post, event, and message data will be kept while the account and related features remain active.

Account deletion

When the user deletes the account:

  • access will be deactivated;
  • the profile will no longer be displayed;
  • the photograph will be removed;
  • links to the profile will be deactivated.

Profile, trips, posts, and events may be kept in a restricted archive for up to one year when necessary for security, fraud prevention, compliance with an obligation, or regular exercise of rights. When there is no need for retention, they will be deleted before that period.

Messages

Shared messages may remain while the conversation exists.

The author will be identified as “Deleted user”, without photograph and without a link to the former profile.

Messages deleted by the user may be preserved separately when related to a report, fraud, security, or dispute.

Documents

Documents will be removed from normal access when the corresponding trip or account is deleted.

Residual copies may remain in backups for up to 90 days.

Backups

Backups may be kept for up to 90 days, with restricted access and without normal operational use.

Logs

CloudWatch technical logs will normally be kept for 90 days.

Application access records may be kept for at least six months when this retention is required by applicable legislation.

Payments and contracts

Records of payments, subscriptions, acceptances, cancellations, and refunds may be kept for applicable legal, tax, accounting, and defense periods.

Inactive accounts

Accounts with no activity for two years may be deleted.

When possible, Baggagi will send notices:

  • 90 days before;
  • 30 days before.

Accessing the account during the notice period may stop deletion.

Disputes and investigations

Data related to fraud, reports, disputes, proceedings, or authority orders may be kept for the period necessary to resolve the case.

18. Deletion and export

The user may delete their own account through the available features.

Baggagi is also developing an account data export tool.

While automatic export is not available for all data, the user may request a copy by e-mail:

privacy@baggagi.com

Export may be limited when necessary to protect:

  • third-party data;
  • other participants' conversations;
  • security;
  • trade secrets;
  • intellectual property rights;
  • information whose delivery is prohibited by law.

19. Data subject rights

Under applicable legislation, the data subject may request:

  • confirmation of processing;
  • access to data;
  • correction;
  • update;
  • information about sharing;
  • anonymization;
  • blocking;
  • deletion of unnecessary or unlawfully processed data;
  • portability, when applicable;
  • withdrawal of consent;
  • information about the possibility of not consenting;
  • objection to processing in certain situations;
  • review or explanation of automated decisions, when applicable;
  • filing a complaint with the National Data Protection Authority.

Requests should be sent to:

[privacy@baggagi.com](mailto:privacy@baggagi.com)

Baggagi may request information to confirm the requester's identity and prevent data from being delivered to unauthorized third parties.

Simple requests will be handled immediately when possible.

Detailed requests will be answered within the periods provided by applicable legislation, seeking a timeframe of up to 15 days when the nature of the request allows.

Some requests may be denied or partially fulfilled when retention is necessary for:

  • legal obligation;
  • third-party protection;
  • security;
  • fraud prevention;
  • regular exercise of rights;
  • contract performance;
  • other applicable legal basis.

The justification will be communicated to the requester when possible.

20. Security

Baggagi adopts technical and administrative measures intended to protect data, including:

  • encryption in transit;
  • encryption at rest for documents and compatible data;
  • access controls;
  • role-based permissions;
  • separation between agencies;
  • administrative access logs;
  • monitoring;
  • authentication;
  • backups;
  • credential management;
  • prevention of unauthorized access;
  • incident response.

The agency owner may access the company's customers. Other agents may only access trips under their responsibility.

No system is completely immune to incidents. If an incident is identified that may cause relevant risk or harm, Baggagi will take the investigation, containment, and communication measures required by legislation.

The user should also:

  • protect their password;
  • not share credentials;
  • keep their devices updated;
  • be wary of suspicious links and requests;
  • promptly report unrecognized access.

21. Automated decisions and features

Itinerary generation and ranking of certain recommendations may involve automated processing.

These systems may consider:

  • destination;
  • period;
  • budget;
  • preferences;
  • location;
  • reviews;
  • availability;
  • commercial relationships.

The user will remain responsible for deciding whether to use or purchase a suggestion.

Requests for information about automated criteria may be sent to privacy@baggagi.com, subject to trade secrets and applicable technical limits.

Baggagi may direct the user to websites of:

  • hotels;
  • airlines;
  • insurers;
  • tours;
  • events;
  • establishments;
  • affiliate partners.

Baggagi's Privacy Policy does not control processing carried out directly by these providers after the user accesses their environments.

The user should consult the respective provider's policies before completing a purchase.

23. Changes to this Policy

This Policy may be updated to reflect:

  • new features;
  • legal changes;
  • new vendors;
  • changes in corporate structure;
  • changes in security practices;
  • new forms of processing.

The version and update date will be indicated at the beginning of the document.

When a change is relevant, Baggagi may inform the user by e-mail, notice on the platform, or another appropriate means.

When a new purpose depends on consent, Baggagi will request new authorization before starting processing.

24. Contact

Questions, requests, and complaints related to privacy may be sent to:

Baggagi will seek to respond clearly and within applicable timeframes.

Prepared for the Baggagi product. This does not replace formal legal advice; review by a lawyer before final publication is recommended.