Privacy Policy
Last updated: 2 August 2026
Swita Global Ltd ("we", "us", "our") operates the Mandra mobile application ("the App"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our App.
By using Mandra, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
• First name and last name
• Email address
• Password (stored in encrypted/hashed form)
• Date of birth
• Gender
• Profile photo (optional)
• Language and currency preferences
If you sign in via Google or Apple, we receive your name, email address, and profile picture from those services. We do not receive or store your social login passwords.
1.2 Travel Document Information (Optional)
To facilitate travel bookings, you may choose to provide:
• Passport number and expiration date
• Nationality
You may also store travel companion profiles ("Saved Travelers") with similar information.
1.3 Device Information
• Device identifier. We collect a vendor/device ID to associate your travel plans with your device. On iOS this is the Identifier for Vendor (IDFV); on Android it is the device Build ID.
• Advertising ID. On Android, we may collect the Google Advertising ID for analytics purposes. On iOS, we request your permission through App Tracking Transparency before accessing advertising identifiers. See section 6.3.
1.4 Location Data
With your permission, we use your device's location only while you are using the App, to centre the map and to show how far places on your trip are from you.
To turn your coordinates into a place name, and to display maps and directions, your coordinates are sent to Google Maps Platform. They are not sent to or stored on Mandra's servers.
The App does not track your location in the background, and does not collect location data when it is closed or not in use. You can revoke location access at any time in your device settings; the rest of the App continues to work without it.
1.5 Payment Information
Payments are processed by Stripe. Your card details are collected directly by Stripe's secure SDK and never pass through our servers. We store only the Stripe payment reference IDs and transaction metadata (plan ID, booking reference, amount).
1.6 Chat, AI Assistant, and Communication Data
• AI travel assistant
When you use the AI trip assistant, or ask it to summarise or filter search results, we send the following to OpenAI, our AI processor, through Mandra's own servers:
• The messages you type or dictate to the assistant
• Your trip details — destinations, dates, number of travellers, and budget
• The listing you are viewing when you ask for a summary or a filter
We do not send your name, email address, phone number, passport or identity-document details, or payment details to OpenAI.
OpenAI processes this data solely to generate a response for you, under contractual terms that provide protection equal to that described in this policy, and does not use it to train its models.
We ask for your permission in the App before anything is sent to OpenAI for the first time. You can withdraw that permission at any time in Profile › AI assistant. If you decline, the rest of Mandra — search, booking, and trip planning — continues to work normally.
Your conversation history with the assistant is stored on our servers while your account is active, so the assistant has context for your trip.
• Voice dictation
If you use the microphone to dictate to the assistant, your speech is converted to text using your device's speech-recognition service. Depending on your device and its settings, this may be processed on the device itself or by Apple's or Google's speech-recognition services. Only the resulting text is sent to Mandra.
• Group trip chat
Messages, photos, files, and voice messages sent in group trip chats are stored and managed by Stream Chat, a third-party messaging provider.
• Photos and camera
With your permission, you can attach photos from your photo library or take new photos to share in trip chats and community posts. We access your camera and photo library only when you choose to attach something.
• Customer support
Conversations you have with our support team are handled by Intercom.
1.7 Booking Data
When you make travel bookings (flights, hotels, activities), we process the information required by the booking providers, including:
• Passenger names
• Dates of birth
• Nationality and passport details
• Email address and phone number
1.8 Community Content
If you use the community feed, we collect the posts, replies, photos, and trip details you choose to share, together with your likes, follows, blocks, and reports. Content you post to the community is visible to other users of the App.
1.9 Usage, Analytics, and Diagnostics Data
We collect usage data to improve the App, including:
• App events (for example, plan created, booking completed, features used)
• Device type and operating system
• App version
• Crash and error reports
We also use session-replay technology (LogRocket), which records how you interact with the App's screens, such as taps and navigation, so we can diagnose problems and improve usability.
2. How We Use Your Information
• To provide and maintain the App's core functionality (trip planning, bookings, group travel coordination)
• To process travel bookings with third-party providers
• To process payments via Stripe
• To send push notifications (trip reminders, booking updates, in-trip alerts)
• To provide AI-powered travel planning assistance
• To provide customer support via in-app chat
• To analyse usage patterns, diagnose faults, and improve the App
• To send re-engagement notifications (only with your explicit marketing consent)
3. Third-Party Services
We share data with the following service providers. We share only what each provider needs in order to perform its function, and we require each of them to provide protection for your data equal to that described in this policy.
• Payment processing — Stripe
• Travel booking providers — Duffel, HotelBeds, RateHawk, Musement
• AI travel planning — OpenAI
• Group messaging — Stream Chat
• Real-time updates — Ably
• Push notifications — Firebase Cloud Messaging
• Analytics — Firebase Analytics, Amplitude, AppsFlyer
• Advertising attribution — Meta
• Crash and error reporting — Firebase Crashlytics, Sentry
• Session replay and diagnostics — LogRocket
• Customer support — Intercom
• Maps, geocoding, and navigation — Google Maps Platform
• Authentication — Google Sign-In, Apple Sign-In
4. Data Storage and Security
Primary databases are hosted on MongoDB Atlas and Google Cloud SQL (PostgreSQL), located in the EU (europe-west3 region). Analytics data processed by Amplitude is stored in the EU server zone.
• All data in transit is encrypted via HTTPS/TLS.
• Passwords are hashed using bcrypt before storage.
• Sensitive data is scrubbed from error logs before transmission to monitoring services.
5. Push Notifications
Push notifications are sent for:
• Booking updates — confirmations, changes, cancellations, payment failures
• Trip reminders — upcoming trip alerts one day before departure
• In-trip alerts — check-in reminders, flight departures, activity start times
• Re-engagement — only when you have explicitly opted in
You can manage notification preferences within the App settings, or disable them entirely through your device's system settings.
6. Your Rights and Choices
6.1 Account Deletion
You can request deletion of your account at any time through the App. When you delete your account:
• Your personal information is permanently anonymised and cannot be recovered.
• Your community posts, replies, likes, follows, blocks, reports, and feedback are permanently deleted.
• Booking records are retained as required by law for financial and legal compliance.
6.2 Marketing Consent
Marketing and re-engagement notifications require your explicit opt-in consent. You can withdraw this consent at any time in the App's notification settings.
6.3 Tracking Transparency (iOS)
On iOS, we request your permission through Apple's App Tracking Transparency framework before enabling advertising attribution (Meta/Facebook) or accessing your device's advertising identifier. No advertising or attribution data is collected until you have responded to that request. If you decline, the App works normally without it. You can change this setting at any time in your device's privacy settings.
6.4 AI Assistant Consent
Before any of your data is sent to our AI provider, we ask for your permission in the App and show you what will be sent and who receives it. You can review or withdraw this permission at any time in Profile › AI assistant. Withdrawing it stops any further data being sent; it does not recall data that has already been processed.
6.5 Notification Preferences
You can customise which categories of notifications you receive (bookings, trips, in-trip alerts), or mute all notifications, within the App settings.
6.6 Data Access and Portability
You have the right to request access to, or a copy of, your personal data. You may also request correction or erasure of your data, or object to certain processing. Contact us at the address below to make such a request.
7. Children's Privacy
The App is not intended for use by children under the age of 16. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal data, please contact us and we will take steps to delete such information.
8. Data Retention
• Account data — retained while your account is active; anonymised upon account deletion.
• Booking records — retained as required by applicable financial and tax regulations.
• Analytics data — retained according to each analytics provider's retention policy.
• Chat messages — AI assistant history is retained while your account is active. Group chat data is managed by Stream Chat, per their retention policy.
• Session replay recordings — retained according to LogRocket's retention policy.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We use service providers located in the EU and the United States. Where data is transferred outside the EU/EEA, we ensure appropriate safeguards are in place.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy in the App and updating the "Last updated" date at the top of this page. Your continued use of the App after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have any questions about this Privacy Policy, or wish to exercise your data rights, please contact us:
Swita Global Ltd
Email: admin@switaglobal.com
Website: https://www.mandra.me