Privacy Policy

Last updated 6 September 2026

This policy explains what we collect, why, who sees it, and what you can make us do about it. It covers https://www.passportpin.com and the Passport Pin mobile apps.

Privacy Policy Terms of Use Cookie Policy

Who we are

Passport Pin is operated by Imprint Media Group Pty Ltd (ABN 88 636 921 429), of Level 1, Suite 1.01/222 Pitt St, Sydney NSW 2000, Australia. In this policy "we", "us" and "our" mean that company, and "you" means anyone using the site or the apps.

We are the data controller for the personal information described here. For privacy questions, requests or complaints, write to support@passportpin.com. We answer within one business day and resolve within 30 days.

What we collect

Only what the product needs to work. There is no advertising profile, because we sell no advertising.

  • Account information — your email address, and a display name if you set one. If you sign in with a third-party provider, we receive your email address and nothing else from them.
  • Your map and your planning — the countries you stamp and pin, the trips you build, the packing lists and budgets you make, and the settings you choose.
  • Booking information — when you book a stay, the guest name, email address and phone number you type at checkout, the property, the dates, the room and the amount. We keep the booking reference and its status.
  • Payment information — we do not collect or store card numbers. Card details are entered directly into our payment partner’s own hosted form and never reach our servers.
  • Technical information — IP address, browser and device type, operating system, referring page, and the pages you view. This is ordinary web-server and analytics data.
  • Communications — the content of emails you send us, and whether you opened a newsletter you subscribed to.

How we collect it

Directly from you, when you create an account, build a trip, make a booking or email us.

Automatically, through cookies and similar technologies when you use the site — see our Cookie Policy for the detail.

From our partners, when a booking you made is confirmed, changed or cancelled on their systems.

Why we use it, and our lawful basis

Every use below is tied to a lawful basis under the GDPR and UK GDPR. Where a basis is legitimate interests, we have weighed those interests against your rights and describe the interest openly.

  • To run your account and save your map, trips and settings — performance of our contract with you.
  • To take and service a booking, including passing your details to the property and our booking partner — performance of our contract with you.
  • To manage a Passport+ subscription, including billing and renewals — performance of our contract with you.
  • To send transactional email (confirmations, receipts, password resets, service notices) — performance of our contract, or our legitimate interest in operating the service.
  • To send the newsletter — your consent, which we obtain by double opt-in and which you can withdraw with one click in any issue.
  • To measure which pages and guides earn their place, in aggregate — our legitimate interest in improving the product.
  • To keep the service secure and prevent fraud and abuse — our legitimate interest, and compliance with legal obligations.
  • To meet tax, accounting and consumer-law obligations — compliance with a legal obligation.

Who we share it with

We do not sell personal information. We have never sold personal information, and we do not share it for cross-context behavioural advertising.

We disclose personal information only to the following categories of recipient, and only as much as each needs:

  • Booking and travel partners — the supplier who fulfils a booking, and the property or operator providing it. A stay cannot be held without a guest name and contact details.
  • Payment processors — to take payment and process refunds. They receive the card details directly from you; we receive only the result.
  • Infrastructure providers — hosting, database, content delivery and error monitoring, acting on our instructions under contract.
  • Email providers — to deliver transactional email and the newsletter.
  • Analytics providers — to count page views and outbound clicks in aggregate.
  • Professional advisers, and authorities — where we are required by law, or need to establish, exercise or defend a legal claim.

Every processor is bound by contract to use the information only for the purpose we specify, to keep it secure and to delete or return it when the engagement ends.

Sending information overseas

We store personal information in Australia and the European Union. Some of our processors operate elsewhere, including the United States and the United Kingdom, so your information may be transferred to and accessed from those countries.

Where information leaves the EEA or the UK we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), together with technical measures such as encryption in transit and at rest. Where information leaves Australia, we take reasonable steps under Australian Privacy Principle 8 to ensure the recipient handles it consistently with the APPs.

You may ask us for a copy of the safeguards that apply to a specific transfer by writing to support@passportpin.com.

How long we keep it

We keep personal information only as long as we have a reason to, then delete it.

  • Account, map, trips and settings — while your account is open, and for 30 days after you delete it so the deletion can be reversed if it was a mistake.
  • Booking records — seven years from the date of the booking, because tax and consumer-law obligations require it.
  • Newsletter subscriptions — until you unsubscribe. An unconfirmed signup is deleted after 30 days.
  • Analytics — 26 months, in aggregate form.
  • Support email — 24 months from the last message in the thread.
  • Encrypted backups — 30 days, after which they are overwritten.

How we protect it

Everything travels over TLS. Data is encrypted at rest. Access to production systems is limited to the people who need it, protected by multi-factor authentication, and logged.

We do not store card numbers at any point, which removes the most valuable target from our systems entirely.

No system is perfectly secure. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme, and any other regulator we are required to tell, within the time limits that apply — 72 hours to a supervisory authority under the GDPR.

Your rights

Wherever you live, you can ask us to show you what we hold, correct it, or delete it. Write to support@passportpin.com. We do not charge for this and we do not treat you differently for asking.

You can also delete your account yourself at any time from Settings, which removes your map, pins, trips and email address within 30 days, backups included. There is no retention flow and no "are you sure" maze.

If you are in Australia

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

You may request access to, or correction of, your personal information at any time. If you are not satisfied with how we have handled a privacy matter, you may complain to us first at support@passportpin.com; if you remain unsatisfied you may complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

We do not use government identifiers, and we do not collect sensitive information as that term is defined in the Privacy Act.

If you are in the EU or the UK

Under the GDPR and UK GDPR you have the right to: access your personal data; have it corrected; have it erased; restrict how we process it; object to processing carried out on the basis of legitimate interests; receive your data in a portable, machine-readable format; and withdraw consent at any time without affecting processing already carried out.

You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We make no such decisions.

You may lodge a complaint with your local supervisory authority. In the UK that is the Information Commissioner’s Office at ico.org.uk. In the EU it is the authority for the country you live or work in.

If you are in California

Under the CCPA as amended by the CPRA, you have the right to know what personal information we collect and why, to have it deleted, to have it corrected, to opt out of its sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of these rights.

We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing for you to opt out of. We do not collect sensitive personal information as the CPRA defines it.

The categories we collect are set out under "What we collect" above; the categories of recipient under "Who we share it with"; the purposes under "Why we use it"; and the retention periods under "How long we keep it". To make a request, write to support@passportpin.com. You may use an authorised agent, and we will verify the request against the email address on your account.

If you are in Canada

We handle personal information in accordance with PIPEDA. We collect it for the purposes identified in this policy, with your knowledge and consent, and we limit both what we collect and how long we keep it to those purposes.

You may ask for access to your personal information and challenge its accuracy. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.

Children

You must be at least 16 to hold an account, and at least 18 to make a booking or hold a subscription.

We do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, write to support@passportpin.com and we will delete it.

Cookies

We set one cookie to keep you signed in and one preference for your theme. We set no advertising cookies and no cross-site trackers. The detail, including what your browser stores locally, is in our Cookie Policy.

Changes to this policy

If we change this policy we will update the date at the top. Where a change materially affects your rights, we will tell you by email or by a notice on the site before it takes effect.

Contact us

Privacy questions, access requests and complaints: support@passportpin.com.

Imprint Media Group Pty Ltd (ABN 88 636 921 429), Level 1, Suite 1.01/222 Pitt St, Sydney NSW 2000, Australia.