Legal
Privacy policy
Your travel history says where you were and when. We treat it that way: this page is the full account of what we hold, who else touches it, how long it stays and how to get it back.
In short
We hold your travel history because you asked us to count it. Your email address, the people in your household, your trips, your permits and your travel documents. The document forms take the last four characters of a document number at most, never the whole number.
Your data is stored in the EU and we don't sell it. There are no advertising trackers, no third-party analytics service and no tracking cookies. The only cookie we set is the one that keeps you signed in.
Three companies are involved in running the service: Cloudflare (hosting, database, files, email) and Anthropic (Claude reads forwarded booking emails and document photos) work on our instructions. Link (Stripe) is the seller of record for payments and handles your card details itself. No one else receives your data to use for their own purposes, apart from a calendar app you connect yourself and anyone the law requires us to tell. We serve our own fonts and use no third-party analytics. If you use the tracker inside the Relo2France portal, section 13 says what moves between us.
You can take it all with you, or delete it, at any time. Export is a spreadsheet from Settings, one tab per kind of record, or the same data as a JSON file. Deleting your account cancels your billing, deletes your files and removes your data from our systems. The few exceptions, and how long each lasts, are in section 9.
1. Who is responsible for your data
MyTravelStatus is run by The Burrowbridge Group, LLC (doing business as MyTravelStatus.com), a South Dakota limited liability company, of 519 W 22nd St Ste 300 #251343, Sioux Falls, South Dakota 57105-1745, United States. We are the data controller for everything on this page, including for members who use the tracker inside the Relo2France portal. The same company also runs Relo2France and Caveau.wine (section 13).
For anything about your data, write to support@mytravelstatus.com. We read every message ourselves. We have not appointed a data protection officer; that address reaches the people who run the service.
2. What we collect and where it comes from
Almost everything we hold is something you typed in or uploaded. We do not buy data about you and we do not track you across other websites. The website never uses your device's location. Our phone and tablet apps use it only if you turn on automatic tracking, and even then only the country you were in each day reaches us, never where you were (section 2A). Our website statistics record only the country Cloudflare works out from your connection (section 6).
Your account
- Your email address, which is how you sign in and how we reach you.
- Sign-in codes and sign-in links. We store only a one-way code made from each, never the code or the link itself. Each is valid for ten minutes and can be used once.
- Sessions. We store only a one-way hash of the session token, never the token itself, with when it was created, when it expires and when it was last used. We do not record your IP address or your browser against a session.
- Which version of our terms you accepted, and when. We record it when you create your account, when a purchase completes and when you start an upgrade from Plus to Pro.
- The day you last used your account, so that a free account left unused can be deleted (section 9).
- Your display name, language and time zone, if you set them.
- Your alert settings: at what point you want to be warned, and whether you want alerts by email.
The people and travel you record
- The people in your household: their name, their role (partner, child, other), an optional year of birth, an optional nationality and an optional home country.
- Your trips: start and end dates, country, whether it was business or personal, your notes, the entry and exit points, how you traveled, and the flight, train or booking reference. Please leave document numbers out of your notes.
- Your long-stay visas and residence permits: country, kind, validity dates and notes.
- Your travel documents: kind, issuing country, a label you choose, validity dates and notes. The form takes at most the last four characters of the document number, and the database refuses anything longer. The notes turn away anything that looks like a document number.
- Your EES checks: the date you checked, what the EU tool said, a note, what our own count said at that moment, and a screenshot of the EU tool's answer if you attach one.
- Your calendar feed, if you turn it on: a one-way hash of its secret link, whether it shows names, and when it was last fetched. The calendar app you subscribe with (Google, Apple, Microsoft or another) fetches the feed and keeps its own copy of what is in it, under its own privacy policy.
Things you add on the paid plans
- Evidence files (Pro): the boarding passes, receipts and other PDFs and photos you upload. We keep each file exactly as you sent it, with its fingerprint (SHA-256), size, type, the name you gave it, a description and a document date.
- Forwarded booking emails (Plus and Pro): who sent it, the subject, a fingerprint of the original, a one-line summary of what we found, and the trip suggestions we drew from it. We keep the original email itself for 30 days, or for as long as you like if you choose to keep it as evidence.
- Your private forwarding address (Plus and Pro): a random address only you know, which you can replace at any time from the forwarded-bookings page.
- UK Statutory Residence Test answers (Pro): your answers to the questionnaire, per person and per tax year, including any short note about exceptional circumstances.
Support, notifications and billing
- Support conversations: your messages, our replies, the topic you chose, your email address, whether you agreed to let us see your plan and usage while we help you, and when you last read each one. Our staff may add internal notes to a conversation; only staff see them.
- In-app notifications: the alerts and reminders we created for you, and whether you read them.
- Billing: your Stripe customer id, the subscription id and its status, which plan you bought, when the period ends and whether you hold the lifetime purchase. We never see or store your card number, expiry date or billing address. Those go straight to Link (Stripe).
The change history
Every create, change and delete of a trip, person, permit, document, evidence file, EES check, UK residence answer or setting is written to a hash-chained history, so an altered or missing entry can be spotted later. That history keeps a snapshot of what changed, which means it also keeps the details of trips you have since deleted. It is deleted when your account is.
Abuse prevention
To stop someone flooding the sign-in form, the public calculator, the support address, the website statistics or the calendar feed, we keep short-lived counters. A counter is a number next to a key. Where the key would be an IP address or an email address, we store a one-way keyed code made from it instead, never the address itself. Counters for a signed-in account are keyed on the account id, and the website statistics also keep one keyed on the day's visitor code described in section 6. They hold nothing else (no name, no page) and are deleted automatically within two days. When you delete your account, the counters keyed on your account id and on your sign-in address go at once; any other expires within those two days.
One record works differently. If wrong sign-in codes are entered for your email address, we keep a count against that address and pause sign-in codes after ten wrong codes in a day. That row is deleted seven days after the last wrong code, or when any pause ends if that is later, and with your account.
2A. Our phone and tablet apps
The MyTravelStatus apps for iPhone, iPad and Android hold the same account and the same data as the website. They are being tested and are not yet in the App Store or Google Play. This section says what they add.
Automatic tracking (Plus, off unless you turn it on)
If you turn it on, the app notes which country your phone or tablet is in, including when the app is closed: about every four hours on Android, and on an iPhone or iPad when you have moved or arrived somewhere. It asks your device for an approximate location only. It works out the country on your device, using a map of country borders built into the app (on Android it also looks at the country of the mobile network you are connected to), and throws the location away straight after. For each day it sends us only: the country, the first and last hour it saw you there, how many times it checked, and whether the reading was clear, near a border, or from the mobile network alone. It never sends us your location, an address, a place name or times to the minute, and no map service is asked where you are.
We use these records only to add trips to your count and to warn you before a limit. Days your device records count straight away and are marked for you to review: you can confirm, change or delete each one. Near a border, a day is recorded with every country it could be, and counts in each until you confirm it. A day with no record is never filled in.
You choose which traveler in your household the device belongs to, and only one device records a person's days at a time. You can turn tracking off at any time in the app or in your device's settings; when you do, the app offers to delete what it recorded (trips you have confirmed or changed are kept). The records are kept until you delete them or delete your account.
Signing in on a phone or tablet
The app signs you in with the same emailed code. It creates a key on your device that never leaves it; we keep only the public part, to recognize your device, and store only one-way codes made from the app's session tokens. For each device we record: whether it is an iPhone or iPad or an Android device, whether it is a phone or a tablet, the app version, when it was linked and last used, whose device you said it is, and whether tracking is on. We never record its name, its model or a phone number. You can see and remove your devices in Settings, on the website and in the app.
Things the app reads on your device and never sends
- Finding trips in your calendar (only if you ask): the app reads the last and next 12 months of the calendars you choose, on your device, to suggest trips (a country and dates). Your calendar is never sent to us or anyone else. Only the trips you choose to add are sent, exactly as if you had typed them, with a note naming the calendar items each came from (such as “Flight TP 433 CDG → LIS”), which you can edit or delete.
- Finding trips in your photos (only if you ask): the app reads where and on which day your photos of the last 12 months were taken, on your device, to suggest trips. On an iPhone or iPad it looks at the photos you allow it to see; on Android, at the photos you pick. Your photos and their locations are never sent to us or anyone else. Only the trips you choose to add are sent, with a note saying how many photos on how many days each came from, which you can edit or delete.
- Finding trips in a calendar file (the website too, only if you choose one): your browser, or the app, reads the calendar file (.ics) you choose to suggest trips. The file is never uploaded to us or anyone else. Only the trips you choose to add are sent, with a note naming the calendar items each came from.
- App lock (only if you turn it on): the app asks for Face ID, Touch ID, your fingerprint or your passcode through your device. We never receive them.
Reminders, widgets and Siri
Reminders (only if you turn them on) are scheduled on your device from dates we send it, such as days left, leave-by dates and document expiry; no notification service carries your data, and they may show on your lock screen like any app's notifications. Widgets and Siri answers show the summary already on your device (days left, the next day you get back). When you ask Siri, Apple processes the spoken request under its own terms.
What the app keeps on your device
So that it opens at once and still shows something with no connection, the app keeps on your device the last answers it showed you (your status, trips and account) and the last PDF report you fetched. They stay inside the app, behind the app lock if you use it, and are removed when you sign out.
What the apps don't do
The apps contain no analytics, no advertising and no tracking code, and use no advertising identifiers. Scanning a travel document works in the apps as it does on the website, and sends the photo you choose to Anthropic (section 5); the app says so before you choose one. Once the apps are in the App Store and Google Play, downloading them is covered by Apple's or Google's own terms and privacy policies, and Apple or Google may show us anonymous crash reports if you allow that in your device's settings.
3. Why we use it, and our legal basis
Under the GDPR we need a lawful basis for each use. Ours are these.
| What we do | Why | Legal basis |
|---|---|---|
| Automatic tracking in the apps, only if you turn it on (section 2A) | Add the days you spent in each country to your count and warn you before a limit. | Performing our contract with you (Art. 6(1)(b)), for the feature you chose; and your consent to the app reading your device's location, which you give through our explanation and your device's own permission prompt and can withdraw at any time |
| Run your account and count your days | Sign you in, store your trips, permits and documents, and calculate what the rules say about them. | Performing our contract with you (Art. 6(1)(b)) |
| Hold the details of the people you add | Count their days, as you asked. | Our legitimate interest, and yours, in keeping a household's travel record together (Art. 6(1)(f)) |
| Send alerts and reminders | Warn you before you run short of days, before a document expires, before a UK visit runs past its limit or before a yearly plan renews. | Performing our contract with you (Art. 6(1)(b)); you can turn email alerts off in Settings |
| Read your forwarded booking emails and your document photos | Turn a booking confirmation or a photo of a permit into a suggestion you then confirm. | Performing our contract with you (Art. 6(1)(b)) — you choose to forward the email or take the photo |
| Keep the tamper-evident change history | So the record you may one day need to show an authority can be checked for alteration. | Performing our contract with you (Art. 6(1)(b)), and our legitimate interest in an honest record (Art. 6(1)(f)) |
| Take payment and manage your plan | Sell you Plus, Pro or Founders, and know which plan you are on. | Performing our contract with you (Art. 6(1)(b)) |
| Record which terms you accepted | So we can show what you agreed to, and when. | Our legitimate interest in being able to prove our agreement with you (Art. 6(1)(f)) |
| Answer your support messages | Help you when something is wrong. | Performing our contract with you (Art. 6(1)(b)) |
| Let support see your plan and usage | Only when you tick the box on a support message. | Your consent (Art. 6(1)(a)); tell us in the conversation to withdraw it |
| Keep the service secure and stop abuse | Rate limits, bot filtering and the admin action log. | Our legitimate interest in a service that isn't abused (Art. 6(1)(f)) |
| Count visits to the website | Know which pages and guides are worth writing, without tracking anyone. | Our legitimate interest in understanding our own website (Art. 6(1)(f)) — see section 6 |
| Keep records we must keep | Tax and accounting records, and answering a lawful request from an authority. | Legal obligation (Art. 6(1)(c)) |
Your email address is needed to run an account, and your trips are needed to count days. Everything else is optional; without it, only that feature won't work.
We make no decision about you that has a legal or similar effect by automated means. The counts are arithmetic you can check, and people make the decisions that matter.
We send only emails about your account: sign-in codes, the alerts you set, receipts and renewal reminders, a warning before we delete an unused free account, replies to your questions, and messages and announcements from us about the service. You can switch off messages and announcements in Settings, and every one of them carries a link that stops them in one click; replies to a question you asked us always come by email. We send no marketing email. If that ever changes, we will ask first, and every such email will let you stop them.
Health, religion and disability
Some things you give us can reveal health, religion or disability. Examples: a note about an exceptional stay in the UK, a hospital letter you upload as evidence, or a meal or wheelchair request in a booking email you forward. We use them only to keep your record and count your days, as you asked, and never for anything else. You can delete them at any time.
The UK Statutory Residence Test lets you leave out days you spent in the UK because of exceptional circumstances, and asks for a short note saying what happened. The form asks you not to write medical details (“Flights grounded” is enough), and the note is shown only to you.
4. Who else touches your data
We do not sell your data and we do not share it for anyone else's marketing. These are the only other companies that handle it, and only to run the service.
| Company | What it does for us | What it sees |
|---|---|---|
| Cloudflare | Hosting (Workers), the database (D1), file storage (R2), sending and receiving email, and rendering your PDF report (Browser Rendering). | Everything we store. The database and the file storage are held in Cloudflare's EU jurisdiction (section 8). |
| Anthropic | Claude reads forwarded booking emails and photos of travel documents, and turns them into a suggestion you confirm. | Only what you forward or photograph: see section 5. Never your trip database, your change history or your evidence files. |
| Stripe (including Link) | Checkout, subscriptions, receipts and the billing portal. Link (Stripe) is the seller of record: it sells you the subscription and is responsible in its own right, under its own privacy policy, for the payment details it collects. | Your email address and our internal account id from us, plus the card and billing details you give Stripe directly, which never reach us. |
| Proton (our staff mailbox, in Switzerland) | Receives the notices the service sends to the people who run it. | A support conversation's reference and a link, never its text. A daily health summary made of counts. Occasionally an alert that names an account id or a Stripe subscription id. Never your travel data. |
| Apple and Google (the apps only) | Once the apps are in their stores: deliver the apps, and show us anonymous crash reports if you allow it. | Nothing from us: not your trips and not your location records. |
| Relo2France (run by the same company) | Only for members who use the tracker inside the Relo2France portal: see section 13. | A short day-count summary for that member's household. |
We may disclose data when the law requires it, such as a valid court order. We may also disclose it to protect someone's safety, or to stop fraud or abuse of the service. We ask for a lawful basis, disclose only what is needed, and tell you unless the law forbids it or telling you would put someone at risk.
If our business is merged, sold or reorganized, your data may pass to the new owner, under confidentiality while a deal is examined. The new owner must honor this policy. We will tell you before your data is used under a different one.
5. When Claude (Anthropic) sees your data
Two features send your data to an AI model. Both are optional, both only run when you start them, and neither replaces your judgment: the model proposes, you confirm.
Forwarding a booking email (Plus and Pro)
If you forward a booking confirmation to your private forwarding address, we send the sender's address, the subject, the text of the email (up to 60,000 characters) and up to five PDF attachments to Anthropic's API, so Claude can pull out the dates and countries. What comes back is checked as untrusted input and becomes a suggestion, which you confirm or discard. We keep the original email for 30 days, and for longer only if you choose to keep it as evidence.
Scanning a travel document (all plans)
If you photograph a passport, visa or permit to fill in the form, your browser first redraws the photo, which strips the metadata including any GPS location. The photo is then sent to Anthropic's API. It is held in memory for that one request and dropped. It is never written to our database, never written to file storage and never written to a log. Claude is told to return at most the last four characters of the document number, and anything longer is thrown away rather than trimmed. Nothing is saved until you check the values and save them yourself.
A photo shows the whole document, so for that one request the model sees everything printed on it, including the full number, the date of birth and the portrait. Claude also reads the holder's name, only so we can warn you if the document seems to belong to someone other than the person you picked; we do not save it from the scan.
Under its commercial terms, Anthropic does not use what we send through its API to train its models. Anthropic says it deletes what is sent through its API within 30 days. It keeps content longer only if its safety systems flag it (up to two years) or if the law requires it. Those periods are Anthropic's, not ours. We do not send your trips, your household, your change history or your evidence files to any AI model.
6. Website statistics
We count visits to the public pages so we know which guides are worth writing. We built this ourselves rather than adding Google Analytics or a similar service. There is no third-party script, no cookie and no profile.
- We respect Global Privacy Control and Do Not Track. If your browser sends either, your visit is not counted at all: nothing is sent from the page.
- We never store your IP address, and we never store your user agent. We store a device class (mobile, tablet or desktop) and a browser family (for example “Chrome”). The abuse counter described in section 2 keeps a one-way code made from the IP address for up to two days; it is not linked to these statistics.
- To tell one visitor from another within a single day, we compute a one-way code from a random salt that changes every day, your IP address, your browser string and our host name. The salt is deleted after two days, so after that nobody, including us, can work the code back to an IP address. It also means the same person gets a completely different code tomorrow: our “unique visitors” figure is per day, and we say so on our own dashboard.
- We store the page path with any ids replaced, no query string, the host name of the site that referred you (never the full URL), any utm_source, utm_medium and utm_campaign in the link you followed, the country Cloudflare reports, and how long the page was visible, capped at 30 minutes.
- To leave out robots, the page checks three things about the browser (whether it is automated, whether it lists any plugins, and whether its window has a size) and sends only a yes or no for each.
- We never count the pages inside your account, the Relo2France embed or our own admin sessions. Once you are signed in and using the tracker, nothing is sent for these statistics.
- We also count how many accounts are created and how many checkouts are started each day. These are totals with no visitor code and no page, recorded on our servers whatever your browser settings.
- Raw rows are deleted after 90 days. Daily totals, which contain no visitor codes at all, are kept for 25 months so we can compare a year with the year before.
You can also switch this off yourself, without changing any browser setting. The choice is kept in this browser only (one entry in its local storage), so it needs no account and tells us nothing. You will find the same switch at the bottom of every page.
Off: visits from this browser are counted as described above.
7. Cookies and what your browser stores
We set exactly one cookie, and only after you sign in.
| Cookie | What it is for | How long |
|---|---|---|
| __Host-mts_session | Keeps you signed in. It holds a random token and nothing else; we store only a hash of it. Strictly necessary, so no consent is needed for it. | 30 days, or until you sign out |
There are no advertising cookies, no analytics cookies and no third-party cookies. Inside the Relo2France portal we use no cookie at all: the tracker holds a one-hour token in memory. If Cloudflare's protection ever challenges your browser during an attack, Cloudflare may set its own short-lived security cookie.
The app also keeps a few preferences in your browser's own storage, which never reach us: whether you dismissed the “install the app” banner, whether the sidebar is collapsed, whether you have finished the walkthrough and, only if you switch it on, your “Don't count my visits” choice. None of them identifies you or your account. To load quickly and show an offline page, your browser also keeps a copy of the site's own program files and icons. This never includes your data, and it happens on your first visit, whether or not you install the app.
8. Where your data is, and international transfers
We are a US company using Cloudflare's EU jurisdiction for storage. The database, your evidence files and your forwarded emails are all held there, so your records are stored in the EU. Cloudflare runs our code at the location nearest to you, so a request is handled in memory wherever you happen to be, and Cloudflare keeps our operational logs and its backups (section 9).
Some processing happens in the United States. Anthropic, a US company, reads the forwarded emails and document photos you send it. Cloudflare, also a US company, runs the service. We are a US company. The people who run it can see support conversations and account-level details.
Where the law treats any of this as a transfer of personal data out of the EU or the UK, it must rest on a recognized safeguard: the EU-US Data Privacy Framework and its UK extension, for a company certified under it, or the Standard Contractual Clauses approved for that purpose. We are confirming which one applies to each company, and will name it here. Link (Stripe) handles your payment as a separate business, under its own privacy policy, and is responsible for its own transfers.
9. How long we keep things
Most of what we hold is your travel record, and the point of a travel record is that it lasts. So we keep it until you delete it, or until you delete your account. We do not keep data we no longer need: a free account nobody has signed in to or used for three years is deleted, after warning emails 60 and 14 days before. These are the things that go automatically.
| What | How long |
|---|---|
| Your trips, people, permits, documents, EES checks, UK residence answers and change history | Until you delete them or delete your account |
| Evidence files you upload | Until you delete the file or your account |
| Days your phone or tablet recorded (automatic tracking, section 2A) | Until you delete them or delete your account |
| Phones and tablets linked to the app | Until you remove the device or delete your account. An app sign-in that isn't used for a year ends by itself |
| A free account nobody has signed in to or used | Deleted, with everything in it, after three years unused. We email you 60 and 14 days before; signing in keeps it. Never an account with a paid plan or a plan we gave you, a Relo2France link, or an admin account |
| Forwarded booking emails: the original message | 30 days, unless you choose to keep it as evidence |
| Forwarded booking emails: the record that one arrived (sender, subject, fingerprint, summary) | Until you delete it or your account. One that led to nothing (no trip suggestion left, not kept as evidence) goes after 90 days |
| Trip suggestions you dismissed | 90 days |
| The working state of the job that reads a forwarded email, including its summary and the trip suggestions drawn from it (held by Cloudflare Workflows) | A period Cloudflare sets: up to 30 days at the time of writing |
| What Anthropic receives (section 5) | Anthropic's period: 30 days, or up to two years for content its safety systems flag |
| Your calendar feed record | Until you turn the feed off or delete your account. Copies your calendar app made are its own |
| Sign-in codes and links | 10 minutes to use; the row is cleared about a day later |
| Sessions | 30 days on the website, one hour in the Relo2France embed; cleared when they expire |
| In-app notifications | 120 days |
| Website statistics: raw rows | 90 days |
| Website statistics: the daily salt | 2 days |
| Website statistics: daily totals, which contain no visitor codes | 25 months |
| Abuse-prevention counters (a one-way code or an account id, never an IP or email address) | Within two days |
| The wrong-code count against your email address | 7 days after the last wrong code, or the end of a pause if later |
| Relo2France sign-in token ids, kept so a token can't be used twice | Cleared within about a day of the token expiring |
| Payment webhook records (event id, type, fingerprint, outcome) | 400 days |
| What Link (Stripe) keeps as the seller | Its own records, under its own privacy policy. Deleting your account here also asks Stripe to delete the customer record we created |
| Relo2France members whose membership ended | 90 days, then deleted automatically — but only for a member who never set up their own sign-in with us. A member who did keeps their account and it is no longer governed by the partner agreement |
| Support conversations | A resolved conversation goes 24 months after its last message; all of them go when you delete your account. A conversation with someone who has no account goes 12 months after its last message. Removing a conversation from your list only hides it from you; we keep it for these same periods |
| Our admin logs | Six years: see the note below |
| Cloudflare's point-in-time database backups | Up to 30 days, so deleted data can persist in a backup for that long before it is gone for good |
| Our operational logs, kept by Cloudflare (a request id, the path with any calendar-feed secret removed, and sometimes an account id; never your travel data) | A period Cloudflare sets: up to 7 days at the time of writing |
10. Your rights
If you are in the EU, the UK or another place with similar law, you have the rights below. They apply to everyone: we do not think it is worth running two standards.
- See and take a copy of your data. Settings has an export button that gives you a spreadsheet straight away (an Excel file that also opens in Numbers and Google Sheets), or the same data as a JSON file for other software, with everything listed under “What the export includes” below.
- Correct anything wrong. You can edit your trips, people, permits and documents yourself. Write to us for anything you can't reach.
- Delete everything. Settings has a delete account button. It cancels any subscription, deletes your files and removes your data from our systems, apart from the few records section 9 lists. It cannot be undone, so export first.
- Ask us to restrict what we do. For example while we check a correction you asked for.
- Ask for your data in a portable form. That is what the export is for.
- Withdraw your consent where we asked for it, without affecting what we did before. Today that is only the tick that lets support see your plan and usage: tell us in the conversation and we will stop.
- Complain to a supervisory authority. In the EU that is the data protection authority where you live or work; in the UK it is the Information Commissioner's Office. We would rather you told us first, but you don't have to.
To exercise any of these, email support@mytravelstatus.com from the address on your account. If you have no sign-in address with us (someone in another person's household, or a Relo2France member), write from any address and we will ask you to confirm who you are. We reply within one month, and tell you if we need longer, which the law allows for complicated requests. We do not charge for this.
If you live in the United States
We don't sell your personal information, and we don't share it for cross-context advertising. We never have. The kinds of data we hold are in section 2, and why we use them is in section 3. The rights above are yours wherever you live. If we turn down a request, you can ask us to look again by replying “appeal”, and we will answer within 45 days. You may use an authorized agent; we will ask them for your signed permission. We honor Global Privacy Control and Do Not Track as section 6 describes. Your browser's Do Not Track signal changes nothing else, because nothing else here tracks you.
11. How we protect it
- There are no passwords to steal: you sign in with a code or a link emailed to you, and we store only a one-way code made from it.
- We store only hashes of session tokens and of the calendar feed's secret link, never the values themselves.
- Once a day, a single fingerprint of the change histories that grew that day (a hash, from which nothing can be read back) is stamped by DigiCert's public timestamp service, so you can prove when your records existed. No data about you is sent.
- Every request you make can reach only your own account. A request for someone else's record gets “not found”, and our automated tests check this.
- Every input is validated against a strict schema before it reaches the database, and every database query uses bound parameters.
- The change history is signed with a key held outside the database, so access to the database alone is not enough to forge it.
- Evidence files are stored exactly as received, verified by fingerprint, and can never be edited in place. They are only ever sent back to you as a download, never rendered in the page.
- Your PDF report is rendered with JavaScript switched off and all network access blocked.
- In the apps, your sign-in is tied to a key that can't leave your device, the session is kept in the device's secure storage and can't be copied to another device, and you can lock the app with Face ID, Touch ID or your fingerprint.
No system is perfect, and we don't claim ours is. We keep a written record of every control we rely on, and we test the ones that matter automatically on every change.
12. Children
MyTravelStatus is not for children. You must be at least 16 to have an account, and at least 18 (or the age of majority where you live, if that is higher) to buy a paid plan. We do not knowingly collect data directly from anyone under 16. If we learn an account belongs to someone under 16, we will close it and delete its data. A parent may record a child's trips and documents as part of their household; that data is the parent's to see, correct and delete, like everything else in their account. If you link a phone or tablet used by a child in your household to the app, you are responsible for that choice; the app shows on that device when automatic tracking is on.
13. If you came from Relo2France
Some people use MyTravelStatus inside the Relo2France member portal rather than on this site. If that is you, here is who is responsible for your data and exactly what moves between the two.
Relo2France and MyTravelStatus are both run by The Burrowbridge Group, LLC, so the same company is responsible for your data (the controller) whichever way you came in. The tracker uses what Relo2France sends only to count your days and keep your records, as this page describes, and every promise on this page applies to your data.
What Relo2France sends us
- A signed token identifying you as a member. We key your account on that identifier, never on your email address, so an email match can never take over an account.
- Your display name, and your email address as a contact address only. It is used for display and receipts. It can never be used to sign in here, and we never use it for marketing.
- The people in your household: their id, name, role and optional year of birth.
- Whether you hold a French long-stay visa or residence permit, and from when. That is what makes your days in France stop counting.
- Your language and time zone.
What we send back
- A short status summary for your household: days used, days left, when your window ends and whether you are safe, near the limit or over it. Nothing else — no trips, no notes, no documents.
- Inside the portal page, the same summary so the portal can show it in its own style.
The rest
- The people and the French residence dates that come from Relo2France are read-only here. Change them in Relo2France.
- We never send you marketing email, and partner-only accounts are never emailed alerts: you get them in the app.
- If your membership ends, we keep your data for 90 days and then delete it automatically. If Relo2France tells us your membership was deleted, we delete it straight away, unless you also hold a paid plan with us under your own sign-in. Then we remove only the Relo2France link, and your own account stays.
- Your Relo2France membership itself is governed by Relo2France's own terms and privacy notice.
14. Changes to this policy
The date at the top says when this page last changed. If we change something that matters — a new processor, a new use of your data, a shorter or longer retention — we will email account holders at least 30 days before it takes effect, and ask Relo2France to tell members who have no email address with us. Smaller corrections, like fixing a wrong number, we just make.
15. How to reach us
Email support@mytravelstatus.com, or use the support page when you are signed in. The terms of service cover the rest of the agreement between us.
Also on this site
The rest of the small print
- Terms of service — what we promise, what we don’t, and how the plans work.
- Settings — export everything we hold as a spreadsheet or a JSON file, or delete your account. You need to be signed in.
- Pricing and the guides.
- Questions: support@mytravelstatus.com.