Version of 5 September 2026
This privacy policy describes which personal data we process when you use the crooom app and the website crooom.com, for what purpose, who we pass data on to, and what rights you have. It applies to both offerings together; where the app and the website differ, this is stated explicitly.
CreativeBarn, owner Lukas Egli
St. Gallen
Switzerland
Email: info@crooom.com
We have not appointed a data protection officer, as we are not required to do so. Please direct all data protection matters to the email address above. It is our sole point of contact for data protection enquiries.
This policy applies to:
/join, /wohin).It does not cover third-party websites and services we link to. Their providers are solely responsible for their own data processing. This applies in particular to the booking portals our affiliate links lead to, and to the Apple and Google app stores.
We are based in Switzerland and follow the Swiss Federal Act on Data Protection (FADP). Because our services are also open to people in the European Economic Area, we additionally comply with the General Data Protection Regulation (GDPR) and state the relevant legal bases in this policy. The Swiss terms "personal data" and "processing" correspond to "personal data" and "processing" within the meaning of the GDPR.
An account requires an email address and a display name. You can register in three ways:
We also store which method you signed in with, along with a user identifier (UID) assigned by Firebase, through which all your data is linked.
Purpose: providing the account, signing in, password recovery.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR); under Swiss law, processing for the performance of a contract (Art. 31(2)(a) FADP).
You may optionally provide: a profile picture, language, colour scheme (light or dark), preferred currency, and your travel preferences – preferred climate, budget range, favourite activities, preferred categories and your home airport. For the home airport we also store its geographic coordinates so that we can suggest flight connections from that location. We never collect your device's location.
Purpose: personalising destination suggestions, showing your profile in shared projects.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
So that shared trip projects show names rather than technical identifiers, we keep your display name and profile picture in a separate public profile. This is retrievable by everyone signed in to the app, not only by your fellow travellers, and it is not accessible without signing in. All other profile details – email address, travel preferences, home airport, favourites, visited places, subscription status – are visible only to you.
When you swipe through destinations, we store your rating for each destination ("liked" / "skipped") and your list of favourites. You add visited places yourself; you can attach a visit date and a photo to them.
Purpose: displaying your favourites list and your travel statistics, calculating suitable recommendations.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
A trip project is a shared workspace. For it we store the project name and description, the invitation code, the list of participants, the chosen project mode, the filters set, the travel dates and the confirmed destination.
What your fellow travellers see: your display name and profile picture, your ratings and your ranking of the destinations up for selection, your voting progress, and everything you create within the project. Ratings inside a project are therefore not anonymous towards the group.
Invitation links: a project can be opened by anyone signed in to the app who knows its project identifier. That identifier is an unguessable string and appears only in the invitation link or behind the invitation code. Only pass invitation links on to people who really are meant to plan with you.
Purpose: planning a trip together.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Once the destination is confirmed, further tools become available. Everything recorded there is visible to all participants of the project:
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
The document safe lets you store travel documents such as flight tickets, hotel confirmations, car rental agreements, visas, copies of identity documents and insurance policies. These files may contain sensitive personal data.
Please bear two things in mind. First, uploaded documents can be viewed and downloaded by all participants of the project – including people who join the project later. Second, you should only upload documents you actually intend to share with the group. In particular, do not upload other people's documents without their agreement.
For each document we store the file name, the chosen category, an optional description, the timestamp and the person who uploaded it. PDF, Word, text and image files up to 15 MB are permitted. A document can be deleted by the person who uploaded it and by the project owner.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR); where the files contain sensitive data, your explicit consent given by uploading them (Art. 9(2)(a) GDPR, Art. 6(7) FADP).
If you allow push notifications, we store the device identifier (token) assigned by Firebase Cloud Messaging in your user record. We notify you about new matches in the group, completed votes, confirmed destinations, and newly recorded expenses and activities. Every notification is also placed in your in-app list.
You control which types of notification you receive in the app settings; you can switch them off entirely in your device's system settings. We do not send advertising or newsletter messages – neither as push notifications nor by email.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR), as the notifications serve the shared planning; you grant the system-level permission voluntarily.
crooom Pro is a subscription concluded and billed exclusively through the Apple App Store or Google Play. We receive no payment data – neither credit card numbers nor billing addresses. These remain with Apple and Google as independent controllers.
We use RevenueCat to manage subscriptions. Your Firebase user identifier is transmitted there as a customer number, together with purchase events such as sign-up, renewal, cancellation and expiry. In your user record we then store the subscription tier, whether the subscription is active, the expiry date, whether it renews, the product identifier and the store.
If you redeem a promotional code, we note your user identifier against that code so the same code cannot be redeemed more than once.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
We use two services to keep the app stable and to develop it further:
Your device's advertising identifier is not used: we have explicitly disabled that access in the app. There is no cross-device tracking for advertising purposes and no disclosure to advertising networks.
Purpose: fixing errors, stability, understanding feature usage in order to improve the product.
Legal basis: legitimate interest in a functioning app that meets people's needs (Art. 6(1)(f) GDPR; Art. 31(1) FADP). You may object to this analysis at any time – an informal message to info@crooom.com is enough.
You can also browse and bookmark destinations without registering. Such bookmarks are stored solely on your device and are only transferred into an account once you sign in. In this mode we store no data about you on servers. Error diagnosis and usage analysis (section 4.10) do run without an account as well – then without a user identifier.
If you write to us by email, we process your address and the content of your message in order to answer it. Our mailbox is operated by our Swiss hosting provider.
Legal basis: performance of a contract or pre-contractual measure (Art. 6(1)(b) GDPR), otherwise legitimate interest in answering enquiries (Art. 6(1)(f) GDPR).
The website is operated by hosttech GmbH in Switzerland. On every request the server processes technically necessary information: IP address, date and time, the address requested, the volume of data transferred, the status message, the referring page, and browser and operating system identifiers. These logs serve operation, troubleshooting and defence against attacks, and are not combined with other data sets.
Legal basis: legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR).
We set one technically necessary cookie that records your choice in the cookie banner for one year. Cookies for analytics or advertising are only set after you have agreed in the banner. Independently of that, the Cloudflare network sets two cookies of its own as soon as a page loads a photo delivered through it (section 5.5); they serve to fend off automated access and not to recognise you for advertising purposes. You can change your decision at any time by deleting this website's cookies in your browser; the banner will then appear again.
Legal basis: legitimate interest for the necessary cookie (Art. 6(1)(f) GDPR), your consent for all others (Art. 6(1)(a) GDPR).
After you consent, we use Google Analytics 4 to evaluate how the website is used. This records the pages opened, time spent, approximate location at country or region level, device type and referring page. IP anonymisation is enabled, so your IP address is truncated before it is evaluated. We do not link this data to an account in the app.
You can withdraw your consent at any time (see section 5.2). Google additionally offers a browser add-on to opt out.
Legal basis: consent (Art. 6(1)(a) GDPR).
Our pages load typefaces from Google Fonts (Google Ireland Limited) and icons from Font Awesome via the Cloudflare network. Your IP address is transmitted to the respective provider in the process, because it is technically necessary in order to deliver the files to your browser.
Legal basis: legitimate interest in a consistent and quickly delivered presentation (Art. 6(1)(f) GDPR).
The photos in our travel guides are embedded directly from the image services Unsplash and Pexels. When these images load, the respective service receives your IP address and technical information about your browser.
Pexels is delivered through the Cloudflare network. Cloudflare sets two cookies of its own in the process, solely to fend off automated access: __cf_bm (expires after 30 minutes without activity) and _cfuvid (deleted when you close your browser). Neither contains an advertising identifier, and we do not evaluate them.
Legal basis: legitimate interest in an appealing presentation and in fending off automated access (Art. 6(1)(f) GDPR).
Through the form on the contact page we collect your name, email address, subject and message. On submission we additionally log your IP address and the timestamp in order to detect misuse. The message is delivered to info@crooom.com and handled there. To protect against automated submissions, the form contains a field invisible to you and a minimum delay before sending; both are evaluated exclusively by our own server.
Legal basis: pre-contractual measure or performance of a contract (Art. 6(1)(b) GDPR), otherwise legitimate interest in answering (Art. 6(1)(f) GDPR); for misuse detection, legitimate interest (Art. 6(1)(f) GDPR).
So that individual features can work, the app calls third-party interfaces. Those providers receive your IP address and the information required for the request. We transmit neither your name nor your email address nor your user identifier.
Affiliate links: booking links to Trip.com – via the redirect service of the Travelpayouts affiliate programme (Go Travel Un Limited, Hong Kong) – and to Viator are advertising links. If you click them you leave our service; the respective provider receives your IP address, usually sets its own cookies to attribute any booking, and is solely responsible from that point on. If a booking is made, we receive a commission. We do not learn who booked. The fact that an affiliate link was clicked is recorded only as an anonymous event in our usage analysis (section 4.10).
Legal basis: performance of a contract for the features you call up (Art. 6(1)(b) GDPR); for affiliate links, legitimate interest in funding the free service (Art. 6(1)(f) GDPR).
We do not sell personal data and do not pass it on for advertising purposes. Access is limited to:
We have concluded contracts with our processors obliging them to confidentiality and to compliance with applicable data protection law.
Internal analysis: for product development statistics – such as the number of registrations, group sizes or the most popular destinations – we evaluate our own database with an internal tool. It runs exclusively on our own devices and only reads the data. The resulting analyses are not passed on to third parties.
Our infrastructure is split between Europe and the United States. What matters is which data is stored where:
eur3 with data centres in Belgium and the Netherlands. This holds account and profile details, travel projects, expenses, ratings and notifications.us-central1 region. This holds every uploaded file: profile pictures, project photos and all documents in the document safe.us-central1 region. They handle project joins, notifications and subscription events, among other things.RevenueCat and Viator are also based in the USA. The Travelpayouts affiliate network (Go Travel Un Limited) is based in Hong Kong. Further transfers take place to countries in the EEA and to the United Kingdom.
From a Swiss and EU perspective, the USA does not generally offer an equivalent level of data protection. We therefore base these transfers on the following safeguards:
Despite these safeguards, it cannot be ruled out that US authorities may, under certain conditions, demand access to data stored there. We point this out explicitly because it primarily concerns the document safe: flight tickets, copies of identity documents, visas and insurance policies you store there are held in the United States. Please take this into account when choosing which documents to upload.
We keep personal data only for as long as it is necessary for the respective purpose. The following periods apply in detail:
| Data | Retention |
|---|---|
| Account, profile and travel preferences | Until you delete the account. We also delete accounts that have been unused for 24 months; we notify you by email 30 days beforehand. |
| Trip projects including places, itinerary, photos and expenses | 12 months after the end of the trip; for projects without a travel date, 12 months after the last change. Participants are informed 14 days beforehand. |
| Files in the document safe | 3 months after the end of the trip – independently of the rest of the project, because these documents are particularly sensitive and are no longer needed after the trip. |
| Notifications in the app | 90 days |
| Push device identifier | Until sign-out, withdrawal of the permission, or deletion of the account |
| Weather cache | 12 hours |
| Crash reports (Crashlytics) | 90 days |
| Usage events (Firebase Analytics) | At most 14 months |
| Subscription status | For the duration of the subscription and until the account is deleted |
| Enquiries by email or contact form | 12 months after the matter has been concluded |
| Website server logs | 30 days |
| Website analytics data | At most 14 months |
Where statutory retention obligations exist, or where retention is necessary to assert or defend legal claims, we keep the data concerned for correspondingly longer and otherwise block it from further use.
You can delete your account yourself at any time: Profile → Settings → "Delete account". For security reasons you may be asked to sign in again. Alternatively, a message to info@crooom.com is enough.
On deletion we remove your sign-in account, your user record with all profile details, travel preferences, favourites and visited places, your public profile, your profile picture, your notifications and notification settings, your push device identifier, and the customer number held for you at RevenueCat.
Trip projects: projects you created are deleted together with all their content – including contributions from the other participants, since only the creator can dissolve a project. You are removed from projects you merely joined; the content there remains for the other participants, and your name is replaced by a neutral placeholder. Expenses already recorded are retained so that the group's settlement remains consistent.
Photos, documents and contributions you left in other people's projects can be removed by you before you delete your account. After deletion this is no longer possible.
Deletion is final and cannot be undone. For technical reasons, deleted data may still be present in our provider's backups for a short time, until those backups are overwritten in the normal cycle.
We take appropriate technical and organisational measures to protect your data. These include:
Complete security cannot be guaranteed for transmission over the internet. Please therefore use a strong password used only for crooom, and do not share invitation links publicly.
You have the right to:
Please contact info@crooom.com for this. We respond within the statutory periods, usually within 30 days. So as not to disclose your data to unauthorised people, we must verify your identity; this is usually done via the email address held in your account.
Complaints: you can lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC, Feldeggweg 1, 3003 Bern, edoeb.admin.ch). If you are resident in the European Economic Area, you may additionally approach the supervisory authority of your country of residence.
crooom is aimed at people aged 16 and over. Anyone younger may only use the app with the consent of a parent or legal guardian. If we learn that an account is held by a younger person without the required consent, we delete it. Please send any information about this to info@crooom.com.
We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. The destination suggestions in the app are based on your details, favourites and visited places, but they are purely recommendations without legal consequences. Determining the group's favourites is likewise a plain count of the ratings submitted.
We adapt this privacy policy when our services, the providers we use, or the legal situation change. The version published on this page is always the authoritative one. We will inform you of material changes in good time, in the app or by email.
Version of 5 September 2026.