Your client data, on your instructions.
When you put a client into your workspace, you decide why that data is used and we handle it for you. This addendum sets that out. It forms part of our Terms of Service for every advisor workspace, with nothing to sign.
Last updated: 21 September 2026
Who is who
You are the controller of the personal data you enter about your clients and their travelling party: names, email addresses, ages of children, trip dates, destinations, documents you upload, messages, invoices. Endless Travel Plans LLC is your processor: we use that data only to run your workspace and the pages you share, on your instructions, which are the things you do in the product.
For your own account details (your name, email, business profile, billing) we are a controller, and our Privacy Policy applies.
What we do with it, and what we never do
We store it, display it to you and to the people you share a link with, send the transactional emails your work triggers, generate itineraries, budgets and packing lists from the trip details, take invoice payments, and produce your exports.
We do not sell it, do not use it for advertising, do not add your clients to our marketing lists, and do not contact your clients except through something you sent. Pages you share with clients carry no analytics or advertising trackers. The rules on this are on the client ownership page.
Companies that process it for us
We use these sub-processors for advisor workspaces. Each receives only what its job needs.
- • DigitalOcean (United States): servers, database and encrypted backups.
- • Stripe: card payments on your invoices and your payouts. Receives the payer's name, email and the amount.
- • Postmark: delivery of transactional email. Receives the recipient address and the message.
- • Anthropic, with OpenAI as a fallback: drafting itineraries, packing lists and research briefs. Receives trip details such as destination, dates, party size and children's ages, not client names or contact details. One exception, and only when you choose it: if you ask us to read a booking confirmation with AI in Bookings, the file or text you give us goes to Anthropic, and a confirmation usually names the travellers. The screen says so before you send it, and card numbers are removed from pasted text first. By default neither provider uses data sent through its API to train its models, and we have not opted in.
- • Google Maps Platform, SerpApi and OpenWeather: places, live flight and hotel prices, and forecasts. Receive destinations, dates and party size only.
- • Sentry and PostHog: error reports and product analytics about how you use the workspace. They run on your workspace pages, not on pages your clients open.
We will list a new sub-processor here at least 14 days before it starts handling workspace data. If you object, you can export your data and close your workspace, and we refund any unused prepaid period.
Security
Traffic is encrypted in transit. The database is reachable only from the application server, behind a firewall, and backed up daily and before every deployment. Access to production is limited to the people who operate the service and protected by key-based login. Advisor accounts support two-factor sign-in. Share links are long random tokens that you can revoke, and uploaded client documents are stored outside the public web root and served only through a permission check.
If we learn of a breach affecting your client data we tell you without undue delay, and no later than 72 hours after we confirm it, with what happened, what data, and what we have done, so that you can meet your own notification duties.
International transfers
The service is hosted in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, the European Commission's Standard Contractual Clauses (Module Two, controller to processor), with the UK International Data Transfer Addendum where UK law applies, are incorporated into this addendum by reference and govern the transfer of your client data to us. Ask us for a countersigned copy at any time.
Helping you with your clients' rights
You can correct, export and delete a client's data yourself at any time from your workspace. If a client writes to us directly about data you control, we pass the request to you and do not answer it for you. We will help, on request, with a data protection impact assessment or a regulator's question about our part of the processing.
Deletion and return
Your full workspace exports on demand as a ZIP in open formats. When you remove a client, their record leaves your workspace immediately. When you close your workspace, its data is kept for 90 days in case you change your mind, then deleted, and it ages out of backups within a further 90 days. Invoices and payout records may be kept longer where tax or financial law requires it.
Audits and questions
Once a year, on reasonable notice, we will answer a written security questionnaire about the processing described here. We are a small company and do not yet hold an independent certification such as SOC 2 or ISO 27001; we would rather say so than imply otherwise.
Questions, a countersigned copy, or a sub-processor objection: support@endlesstravelplans.com. Endless Travel Plans LLC, 30 N Gould St Ste N, Sheridan, WY 82801, USA.