Privacy Policy
Voyage2 B.V. is committed to transparent, privacy-first travel planning. This policy details how we process, secure, and respect your personal data under the General Data Protection Regulation (GDPR / AVG).
1 Data Controller & Contact Details
The data controller responsible for the processing of your personal data on the Voyage² platform (accessible via web and mobile applications) is:
Voyage2 B.V. (d.b.a. Voyage / Voyage²)
Bankastraat 84
2585 ER 's-Gravenhage
The Netherlands
Chamber of Commerce (KvK): 42147029
RSIN: 869923237
Statutory Seat: 's-Gravenhage
Email: [email protected]
For any questions regarding this Privacy Policy, your rights under the GDPR, or how your personal data is handled, you may reach our privacy desk directly at [email protected].
2 Our Privacy Principles
Voyage² is engineered with Privacy by Design and Privacy by Default (Article 25 GDPR). We operate under the following core commitments:
- No Advertising Brokerage: We do not sell, rent, or trade your personal data, travel queries, or booking history to third-party data brokers or advertising networks.
- Data Minimization: We only collect the minimal personal data required to calculate transit itineraries, reserve tickets with licensed carriers, process payments, and ensure server security.
- Strong Cryptographic Protection: Highly sensitive identification data (such as passport numbers stored in account profiles) is encrypted at rest using industry-standard symmetric cryptography (Fernet AES-256).
3 Categories of Personal Data We Collect
Depending on how you use our platform, we process the following categories of personal data:
3.1. Account & Profile Data (Registered Users)
- Credentials: Username, email address, and cryptographically hashed passwords (using PBKDF2 with SHA-256).
- Single Sign-On (OAuth): Profile identifiers and verified email addresses if you register or log in using Google OAuth 2.0 or Facebook (Meta) Login.
- User Preferences: Travel priorities (e.g., eco-friendly, fast, low-transfer, low-stress) and onboarding questionnaire responses.
- Home Station & Location: Saved home address and associated geographic coordinates to streamline origin pre-filling.
3.2. Saved Passenger Information (Optional)
To speed up future ticket purchases, registered users may save traveler profiles:
- Full legal name, date of birth, and nationality.
- Passport & ID Numbers: Stored in our database strictly in encrypted ciphertext using Fernet AES-256.
3.3. Booking & Transaction Records
- Order Details: Unique order reference, origin/destination hubs, travel dates, seat/couchette categories, and ticket fares.
- Payment Status: Mollie transaction identifiers and payment state. Full payment card details are handled directly by Mollie B.V. and are never stored on Voyage² servers.
3.4. Technical Telemetry & Server Logs
- IP addresses, browser user-agents, calculation latency, and diagnostic error traces. Logged to maintain server security and prevent abuse. After 180 days, IP addresses are pruned or anonymized.
4 Purposes and Legal Bases (Article 6 GDPR)
| Purpose | Data Categories | GDPR Legal Basis (Art. 6) |
|---|---|---|
| Route Planning & Calculations | Origin, destination, preferences | Contract performance (Art. 6(1)(b)) |
| Ticket Issuance & Booking | Passenger names, dates of birth, e-tickets | Contract performance (Art. 6(1)(b)) |
| Payment Processing & Invoicing | Order totals, Mollie ID, invoice details | Contract & Legal obligation (Art. 6(1)(b)/(c)) |
| Tax Retention (7 Years) | Invoices, booking totals, order logs | Legal obligation (Art. 52 AWR / Art. 6(1)(c)) |
| Server Security & Fraud Prevention | IP logs, server telemetry, error traces | Legitimate interest (Art. 6(1)(f)) |
5 Recipients & Sub-processors
Voyage² shares personal data strictly with trusted service providers as necessary to deliver our services:
- Ticketing Gateway (All Aboard AB & Railway Undertakings): For reserving and generating official e-tickets with European transport carriers.
- Payment Service Provider (Mollie B.V.): Regulated payment institution supervised by De Nederlandsche Bank (DNB) for secure iDEAL and European payments.
- Cloud Hosting (Amazon Web Services / Lightsail): Hosted securely within the European Economic Area (Frankfurt, Germany).
6 Data Retention & Anonymization
We do not retain personal data longer than necessary for the purposes for which it was gathered:
- Tax & Accounting Records: 7 years pursuant to Dutch statutory tax law (Art. 52 AWR).
- User Accounts: Active for the lifetime of your account. Inactive accounts (>2 years) are pruned after prior notification.
- Technical IP & Routing Logs: Pruned after 180 days; aggregated statistical telemetry is retained in anonymized form under Recital 26 GDPR.
7 Your Rights Under the GDPR
Under the European General Data Protection Regulation, you enjoy comprehensive privacy rights:
- Right of Access (Art. 15 GDPR): Request a copy of your personal data.
- Right to Rectification (Art. 16 GDPR): Update inaccurate profile details directly in your account.
- Right to Erasure (Art. 17 GDPR): Delete your account and personal data with a single click in your profile settings.
- Right to Data Portability (Art. 20 GDPR): Receive your personal data in a structured, machine-readable format.
- Right to Object (Art. 21 GDPR): Object to processing based on legitimate interests.
You can exercise your rights in your account dashboard or by emailing [email protected].
8 Data Security Measures
Voyage2 B.V. employs robust technical and organizational security controls:
- TLS 1.3 Transport Encryption: Secures all traffic between your browser and our servers.
- Fernet AES-256 Symmetric Encryption: Protects stored passport details in our database.
- Content Security Policy (CSP): Prevents cross-site scripting (XSS) and injection attacks.
9 Complaints & Supervisory Authority
If you have concerns about how we handle your personal data, please contact our team. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens - AP) via autoriteitpersoonsgegevens.nl.