Privacy policy
Version 1.0 · Last updated: 2 July 2026 · GDPR · LOPDGDD
This policy relates to the Trovela app (app.trovelaapp.com). Use of the corporate website (www.trovelaapp.com) is governed by its own privacy policy.
This is a courtesy translation. In the event of any discrepancy between versions, the Spanish version of this document prevails.
Contents
1. Controller
- Owner: XIAO JINVEST TECHS, S.L.
- NIF/CIF: B66822917
- Registered office: Calle Corral 2, esc. 1, 3.º 3.ª, 08014 Barcelona (Spain)
- Registry details: registered with the Commercial Registry of Barcelona, Tomo 45497, Folio 216, Hoja B-489836, Inscripción 1.ª
- Contact and exercise of rights: [email protected]
“Trovela” is the web and mobile app that offers a map of plans and leisure places for families, together with the save, collection and contribution features.
2. Key information (summary)
| Controller | XIAO JINVEST TECHS, S.L. |
|---|---|
| Purpose | To create and manage your account, to provide you with the plan discovery service and to maintain a catalogue of plans compiled from publicly published content. |
| Legal basis | Performance of a contract (the terms of use), your consent, compliance with legal obligations and our legitimate interest. |
| Recipients | Technology providers acting as processors. We do not sell your data and we do not disclose it for advertising purposes. |
| Rights | Access, rectification, erasure, objection, restriction and portability, by writing to [email protected]. |
| Source | Data you provide to us, your sign-in provider (Google, Apple or Facebook) and, for the catalogue, publicly accessible posts. |
3. What data we process and whose
3.1. Registered users
- Account data: name, email address, profile picture and preferred language.
- Sign-in data: Trovela does not use passwords; you sign in through an identity provider (Google, Apple or Facebook) or through a “magic link” sent to your email address. We process the minimum technical data necessary to authenticate you securely.
- Usage data: plans you save, collections you create or share, and posts you contribute (contributions).
- Technical and session data: session identifiers or device token and the minimum logs necessary for security.
We do not ask for your date of birth, telephone number, postal address or any special categories of data. The Service is currently free of charge and we do not process payment data.
3.2. Creators of public content (catalogue)
Part of the catalogue is compiled from public social media posts. In that process we may process personal data of their authors: username, texts, images, mentions and location tags in the public post.
- Source: publicly accessible posts and profiles.
- Legal basis: legitimate interest (GDPR art. 6(1)(f)), following a balancing exercise limited to public content linked to places in the catalogue.
- Your rights: you may object and request the erasure of your content by writing to [email protected].
3.3. Browsing
We do not use analytics, advertising or tracking cookies. We only use the technical storage that is strictly necessary to keep you signed in.
4. Purposes of the processing
- To create, manage and authenticate your account.
- To provide you with the service: showing the map of plans, saving them, organising them into collections and sharing them.
- To manage the posts you contribute.
- To send you the operational communications that are necessary (for example, the sign-in link).
- To compile and maintain the catalogue of plans from public content.
- To ensure security and to comply with our legal obligations.
5. Legal basis
| Processing | Legal basis (GDPR art. 6) |
|---|---|
| Creating and managing your account and providing the service | Performance of a contract — art. 6(1)(b) |
| Signing in with Google, Apple or Facebook | Performance of a contract and your consent when choosing that provider — art. 6(1)(b) / 6(1)(a) |
| Security and minimum logs | Legitimate interest — art. 6(1)(f) |
| Catalogue compiled from public content | Legitimate interest — art. 6(1)(f) |
| Compliance with legal obligations | Legal obligation — art. 6(1)(c) |
6. Retention periods
| Data | Retention |
|---|---|
| User account and associated data | For as long as the account is active. Once deletion is requested, it is kept for 30 days so that it can be recovered and is then permanently erased. |
| One-time sign-in codes (magic link) | Valid for 15 minutes and single use. |
| Sessions and device tokens | Until you sign out or revoke access; inactive sessions expire automatically. |
| Public catalogue content | For as long as the associated plan remains in the catalogue; it is erased at the data subject's request or when it is no longer necessary. |
| Backups | Kept for a limited period and then overwritten. |
7. Recipients and processors
We do not sell your data and we do not disclose it to third parties for their own purposes. In order to provide the service we rely on providers acting as processors, bound by a contract in accordance with art. 28 GDPR. The categories of recipients are:
- Providers of hosting, infrastructure and file storage.
- Provider of transactional email delivery (for example, the sign-in link).
- The identity provider you choose to sign in with (Google, Apple or Facebook).
- Technology providers for compiling the catalogue (obtaining public content, AI processing and geocoding/maps).
- Provider of error monitoring (no personal data by default).
You may ask us for the up-to-date list of specific providers by writing to [email protected]. We may also disclose data to public authorities where there is a legal obligation to do so.
8. International transfers
Some providers may process data outside the European Economic Area, mainly in the United States. In those cases, the transfers are covered by appropriate safeguards in accordance with the GDPR: the European Commission's Standard Contractual Clauses and/or the provider's certification under the EU-U.S. Data Privacy Framework. You may ask us for information about those safeguards at [email protected].
10. Your rights
You may at any time exercise your rights of access, rectification, erasure, objection, restriction and portability, and your right to withdraw your consent, by writing to [email protected]. We may ask you to prove your identity. We will reply within one month, extendable by two further months in complex cases.
If you consider that we have not dealt with your request properly, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD), C/ Jorge Juan, 6, 28001 Madrid — www.aepd.es.
11. Minors
To register you must be at least 14 years old (art. 7 LOPDGDD). Children under 14 may not create an account without the consent of the holders of parental responsibility or guardianship over them. If we detect an account belonging to a child under 14 without such consent, we will delete it.
12. Data security
We apply appropriate technical and organisational measures: password-free sign-in, encryption of communications, access control for the administration panel and protected storage of sign-in codes. No system is completely infallible, but we work to protect your information.
13. Data Protection Officer
The controller has not appointed a Data Protection Officer, taking the view that its activity does not fall within the cases where appointment is mandatory under art. 37 GDPR. You may send any privacy enquiry to [email protected].
14. Changes to this policy
We may update this Privacy Policy to reflect legal or service changes. We will publish the version in force on this page together with its date. If the changes are substantial, we will let you know.
→ Trovela Terms and Conditions
Document compliant with Regulation (EU) 2016/679 (GDPR) and with Ley Orgánica 3/2018 (LOPDGDD). Version 1.0 · 2 July 2026. This does not constitute legal advice.