Privacy Policy

Last updated: April 20, 2026

1. Introduction

Developer Box Inc. (“we”, “us”, or “our”) operates Caravan and is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data. By using Caravan, you agree to the practices described in this policy.

2. Information We Collect

We collect the following categories of data:

  • Account data — your display name, email address, and profile photo, provided during registration or via OAuth (Google or GitHub)
  • Trip data — itineraries, stays, flights, points of interest, expenses, tasks, and any other content you create within the Service
  • Usage data — page views and feature interactions collected via Firebase Analytics to help us understand and improve the Service

3. How We Use Your Information

We use your data to:

  • Create and manage your account and authenticate your sessions
  • Store and display your trip data to you and your trip collaborators
  • Send transactional emails such as magic sign-in links
  • Analyze aggregate usage patterns to improve the Service

We do not sell your personal data to third parties, and we do not use your data for advertising purposes.

4. Authentication

Caravan uses Firebase Authentication to manage sign-in. You may authenticate using:

  • Google OAuth — Google shares only the profile data you authorize
  • GitHub OAuth — GitHub shares only the profile data you authorize
  • Email and password
  • Magic link (passwordless email sign-in)

OAuth sign-ins are governed by the respective provider’s privacy policy in addition to this one.

5. Data Storage

Your data is stored in Google Firestore (part of Firebase), hosted on Google Cloud infrastructure. By using Caravan, you acknowledge that your data is subject to Google’s data processing terms in addition to this policy. We apply Firestore security rules to ensure users can only access data they are authorized to view.

6. Data Sharing

We share your data only in the following limited circumstances:

  • With Firebase/Google — solely to operate authentication, data storage, and analytics infrastructure
  • With trip collaborators — trip data you create is visible to other members of the same trip
  • Legal requirements — if required by law, court order, or governmental authority

7. Data Retention

We retain your personal data for as long as your account remains active. If you wish to delete your account and associated data, please contact us at legal@developerbox.com. We will process deletion requests within 30 days.

8. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data. To exercise any of these rights, please contact us at legal@developerbox.com.

9. Cookies

Caravan uses session cookies to maintain your authenticated session. We do not use third-party tracking or advertising cookies. You can disable cookies in your browser settings, but doing so will prevent you from staying signed in.

10. Children’s Privacy

Caravan is not directed at children under 13 years of age. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected data from a child, please contact us and we will promptly delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “last updated” date at the top of this page and notify users via the Service or email. Your continued use of the Service after changes are posted constitutes your acceptance of the revised policy.

12. Contact

If you have any questions or concerns about this Privacy Policy, please contact us at legal@developerbox.com.