Legal
Privacy
Your travel plans are personal. Here's exactly what Orma holds, why, where it lives, and the controls you keep.
Last updated · 29 August 2026
We've tried to write this so you can actually read it. If anything's unclear, ask — section 10 explains how, and you'll get a real reply.
1 · Who's responsible for your information
Orma is made and cared for by a detail-obsessed traveller and data enthusiast in Auckland, New Zealand, operating as a sole operator — not a company.
That maker is the "agency" responsible for your information under the New Zealand Privacy Act 2020, and the "controller" under the UK and EU GDPR. In plain terms: the same hands that build Orma answer for everything this policy says.
2 · What we collect
Account basics
Your email address and sign-in identity, handled by our authentication provider. We never see your password. We also keep a record of which version of the Terms of Use you accepted, and when — that's how we know not to ask you again.
What you create
Trips, events, scenarios, wishlist entries, packing lists, budgets, notes, and the links you add. This is the substance of Orma, and it's the information we're most careful with.
If someone shared a trip with you
This one's for you if you haven't signed up — someone invited you to a trip.
Orma doesn't send email, but sharing works by invitation to a specific email address, which the person types into Orma. So if you were invited, we do hold the email address they entered — in an invitation record — because they gave it to us. That's the only thing we hold about you.
You'll only see the trip if you sign in to Orma with that same address and accept the invitation. Until then, nothing about the trip reaches you. An invitation you don't accept expires after 14 days and can no longer be used; the person who invited you can also revoke it. We keep the record either way, but you can ask us to delete the email address entered for you at any time, no account required — see section 10.
If you do sign up, we collect your email from you, the same as anyone else, and everything in this policy applies to you exactly as it does to them.
Operational logs
Request and error logs, so we can tell when Orma is broken and fix it. Sensitive fields are redacted. Kept 30 days, then gone.
What we don't collect
No advertising trackers. No cross-site tracking. No profiling. No location tracking. We don't buy data about you from anyone, and we don't sell or rent yours to anyone. There is no data broker in this picture.
3 · Why we use it, and our legal basis
Under the GDPR we have to tell you our lawful basis for each thing we do. Under the NZ Privacy Act we have to tell you the purpose. Same table does both.
| What we do | Information used | Why | Legal basis (UK/EU GDPR) |
|---|---|---|---|
| Create and secure your account | Email, sign-in identity | You asked for an account | Contract — Art 6(1)(b) |
| Store and show your trips | What you create | It's the entire product | Contract — Art 6(1)(b) |
| Keep shared trips in sync | What you create, membership | You chose to share | Contract — Art 6(1)(b) |
| Invite someone to a trip | The email address you enter, plus the trip and your identity as its owner | You chose to invite them | Contract — Art 6(1)(b) |
| Show maps and resolve places | The place text you type | You typed it into a place field | Contract — Art 6(1)(b) |
| Show weather | Coordinates of a place you added | You added the place | Contract — Art 6(1)(b) |
| Convert currencies | Currency codes only — nothing about you | Budgets in your currency | Contract — Art 6(1)(b) |
| Connect an AI assistant | Whatever scope you approve | You switched it on | Contract — Art 6(1)(b) |
| Keep Orma running and secure | Operational logs | Diagnosing faults, preventing abuse | Legitimate interests — Art 6(1)(f) |
| Understand overall usage (when our cookieless analytics are enabled) | Aggregate, de-identified counts | Knowing what's used and what's broken | Legitimate interests — Art 6(1)(f) |
| Know if affiliate links pay the bills | Aggregate click and booking counts — never tied to you | Orma is free; this is how it stays that way | Legitimate interests — Art 6(1)(f) |
| Meet legal obligations | Whatever the law requires | We don't get a choice | Legal obligation — Art 6(1)(c) |
Where we rely on legitimate interests, we've weighed our interest against your privacy and kept the data minimal and the purpose narrow. You can object — section 10 — and we'll stop unless we have compelling grounds not to.
We don't do any automated decision-making or profiling that produces legal or similarly significant effects. Orma doesn't score you, rank you, or decide anything about you.
We don't train AI models on your trips. Not ours, not anyone else's. One honest caveat, in section 7.
4 · Services we rely on
A small set of providers, each getting the minimum they need. Where the law calls them processors, they act on our instructions under a written agreement and can't use your information for their own purposes.
This list is current as at 20 July 2026. If we swap a provider for another doing the same job with equivalent protections, we'll update this table — that's not a material change, so it won't come with 30 days' notice under section 13. If we add a new kind of recipient, or send your information somewhere new, that is material and section 13 applies.
| Provider | What it does | What it receives | Where it's processed |
|---|---|---|---|
| Railway | Hosting | Everything the app processes | Singapore |
| Neon | Postgres database | Everything you create — encrypted in transit and at rest | Singapore |
| Auth0 (Okta) | Sign-in and account security | Email, sign-in identity | Australia |
| Google Maps & Places | Place search, maps | The place text you type, to return suggestions and resolve an address, coordinates and timezone | Global |
| Open-Meteo | Weather | Coordinates and the dates you're checking — no identifier, nothing that ties it to you | Germany |
| Frankfurter (ECB data) | Exchange rates | Currency codes only — nothing personal | EU |
| Cloudflare Web Analytics (when enabled) | Page-view counts on public pages | Cookieless aggregate counts. No cross-site tracking, nothing tied to your account | Global edge |
| Meta oEmbed | Previews of Instagram/Facebook links | The link only. We fetch previews server-side, so your browser never talks to Meta and your IP address never reaches them | US |
| Travelpayouts (Go Travel Un Limited, a Hong Kong company) | Affiliate link routing | Your IP address and browser details when you click an outbound booking link, plus a code identifying Orma. See section 6 | Netherlands, per their cookie policy. The company itself is in Hong Kong. |
Orma doesn't send email. There's no mailing list, no newsletter, no marketing, and no email provider in the stack at all. The only messages you'll get are the ones your sign-in provider sends to verify your address or reset your access.
Two things worth pointing out, because we built them deliberately:
Link previews are fetched server-side. When you paste an Instagram or Facebook link into a trip, Orma's server fetches the preview. Your browser never contacts Meta, so Meta never sees your IP address, and never learns you're planning a trip. Most apps don't do it this way.
Our analytics are cookieless. Cloudflare Web Analytics counts page views without setting a cookie or tracking you across sites. It's why we don't have a cookie banner.
Our typefaces are served from our own servers, not from Google Fonts. Your browser doesn't tell Google anything when an Orma page loads.
5 · Where your data lives
Orma is a New Zealand service, but your data isn't stored in New Zealand. You should know that, so here it is plainly.
| What | Where |
|---|---|
| Your trips — everything you create | Singapore |
| The app that serves them | Singapore |
| Your sign-in details — email and identity only | Australia |
| Weather and exchange-rate lookups | Germany and the EU — and neither receives anything about you |
Two things worth saying about that:
None of your data is stored in the United States. That wasn't an accident.
Your trips live in one place. Everything you create sits in a single Singapore region alongside the app that serves it. Fewer places your data goes is better for you and simpler for us.
How we protect it when it moves:
- Every provider is bound by a written data processing agreement requiring safeguards comparable to those under the NZ Privacy Act (IPP12).
- For people in the EEA or UK: Singapore and Australia aren't on the EU's adequacy list, so we rely on Standard Contractual Clauses (with the UK Addendum where UK law applies), and we've assessed the laws of both as part of that.
- Everything is encrypted in transit and at rest.
If you connect an AI assistant (section 7), your data goes wherever that provider operates — under their terms, not ours. That's your transfer, not ours, and it's your call.
6 · Sharing you control
Trips are private by default. Nobody sees them but you until you decide otherwise.
When you share: you enter the email address of the person you want, and choose their role — viewer or editor. There's no public join link; a trip is only ever shared with an address you type in. You control membership and can remove access at any time.
It's an in-app invitation, not an email. Orma doesn't send email. The invitation waits inside Orma and appears only when that person signs in with the same address and accepts it. Until they accept, nothing about the trip reaches them.
We do hold their email in the meantime. Because you typed it in to invite them, we hold that address in an invitation record until it's accepted, revoked, or expires (after 14 days unaccepted). The person it names can ask us to delete it — see section 10. Please don't use invitations to reach people who haven't agreed to hear from you.
Changes are attributed. Trip members can see who changed what, and when. If you edit a shared trip, the others can see it was you.
Affiliate links. Where affiliate links are enabled, some outbound links to booking and eSIM sites (Booking.com, Expedia, Airalo and similar) are routed through our affiliate network, Travelpayouts.
Being precise about this, because it's easy to overclaim: the link carries a code saying the visit came from Orma, and that code identifies Orma, not you. But routing means your browser passes through Travelpayouts on the way, so they receive your IP address and browser details — the same as any redirect. They're a Hong Kong company storing data in the Netherlands.
We never see your individual bookings. What we get is an aggregate total. Terms of Use section 10 explains the money side, including the part that matters: commission doesn't influence what Orma shows you.
If you'd rather not go through them, don't click the link — every booking site in Orma is one you can reach directly, and you'll pay the same price.
Otherwise, we share your information only: with the processors in section 4, with an AI assistant you connect, or where the law requires it. That's the complete list. We don't sell it, we don't rent it, and there's no data broker anywhere near this.
7 · AI assistants
Orma contains no AI. No chatbot, no model of ours, nothing of ours reading your trips.
But you can connect your own assistant — ChatGPT (OpenAI), Claude (Anthropic), or similar — if you already use one. It's off by default and connecting is a deliberate act by you. If you never touch it, skip this section.
If you do connect one, in privacy terms:
Where your data goes. Connect ChatGPT and your trip data goes to OpenAI. Connect Claude and it goes to Anthropic. Only within the scope you approve — read-only, or per-trip, if you choose.
They're not our processors. This is a real distinction, not a technicality. OpenAI and Anthropic aren't working on our instructions — they're working on yours, under your account and your agreement with them. They decide how they handle what you send. Their privacy policy governs it, not this one. We can't reach into their systems and get it back.
⚠️ They may train on it. Some assistant providers train their models on what you send them unless you turn that off in their settings. We can't control that and we won't pretend otherwise. If that matters to you — and it might, these are your travel plans — check your settings with them before you connect.
Nothing changes without you. An assistant can only propose changes to a trip's contents — proposals sit there until you open Orma, read them, and approve them. Deleting anything is held the same way: an event, a scenario and its events, or the whole trip. Because a scenario or trip deletion cannot be undone, approving one asks you to confirm a second time, and only a trip's owner can approve deleting it.
Some things do apply directly under read-and-write access: creating a trip, creating a scenario (which can copy an existing one's events into it), switching which scenario is active, leaving advisory notes on a trip alongside Orma's own checks, and any wishlist change — including deleting a wishlist entry, which we do not yet hold for review (though it goes to Recently deleted and can be restored for 30 days). A connection set to read-only writes nothing at all, not even a note.
Assistants get times, dates and timezones wrong, so read every proposal properly.
Shared trips: this affects other people. If you connect an assistant to a trip you share, their information in that trip goes to your assistant's provider too. They didn't agree to that and may not want it. Talk to them first. Any changes your assistant proposes are visible to the trip's members, attributed to the assistant by name.
Disconnect any time. One switch in settings, effective immediately, nothing further sent.
8 · Cookies & local storage
We use them for one thing: keeping you signed in and remembering your preferences — currency, date format, view settings.
That's it. No advertising cookies, no analytics cookies, no cross-site tracking, no consent banner — because there's nothing to consent to. Our analytics are cookieless and our fonts are self-hosted.
Sites you click through set their own cookies. If you follow an affiliate link from Orma, our affiliate network and the destination site do whatever they do under their own policies — see section 6. We can't control that and we're not claiming to.
9 · Retention & deletion
While your account is open, your data stays. It's your trip history — that's rather the point.
When you delete your account:
| What | What happens |
|---|---|
| Your personal information | Deleted or de-identified within 30 days |
| Your trips (not shared) | Deleted |
| Trips you shared | Survive for the remaining members. Your entries stay so the trip still makes sense — but your name and email are removed and you appear as "Deleted user" |
| Backups | Purged on a rolling 90-day cycle. Your content may persist in encrypted backups for up to that long. We don't restore deleted accounts from backups |
| Operational logs | 30 days |
| Aggregate, de-identified statistics | Kept — they're not about you and can't be traced back |
| Records we're legally required to keep | Kept as long as required, and no longer |
Export first if you want a copy. One click, any time, free, permanently — that's a Terms of Use commitment too.
Deleting your account is permanent. We can't undo it and we can't get it back from backups.
10 · Your rights
| Right | What it means | How |
|---|---|---|
| Access | Get a copy of what we hold | Export in-app, or ask |
| Correction | Fix anything wrong | Edit in-app, or ask |
| Portability | Take it elsewhere in a usable format | Export in-app |
| Erasure | Have it deleted | Delete your account, or ask |
| Object | Tell us to stop where we rely on legitimate interests | Ask |
| Restrict | Tell us to hold off while something's disputed | Ask |
| Withdraw consent | Where we've relied on consent | Ask, or flip the setting |
Most of these are self-serve, right now, in the app: export, correction, and deletion all live in your Account settings. For anything the in-app controls don't cover, ask Orma and its owner through the app. We'll respond within 20 working days (NZ Privacy Act) or one month (GDPR) — whichever applies to you, and we aim for faster.
It's free, and you don't need to explain why.
If you were invited to a trip and never signed up, you have these rights too — no account required. The practical route: ask the person who invited you to revoke the invitation (that stops the address being usable immediately), or to pass your request to us through the app on your behalf.
Not happy with how we've handled it? Tell us first — but you don't have to:
| Where you are | Who to complain to |
|---|---|
| New Zealand | Office of the Privacy Commissioner — privacy.org.nz |
| EEA | Your national data protection authority |
| UK | Information Commissioner's Office — ico.org.uk |
| Australia | Office of the Australian Information Commissioner — oaic.gov.au |
| Elsewhere | Your local regulator, and please tell us too |
11 · Children
Orma is for people aged 16 and over. We don't knowingly collect information from anyone younger.
If you're a parent or guardian and think we've got your child's information, contact us through the app — from your own account, or via the account holder who entered it — and we'll delete it.
Children's names may appear in your trips — a family holiday has children in it. That's your content under your control, and we treat it as we treat everything else you enter.
12 · Security & breaches
Encrypted in transit and at rest. Access limited to what's needed to run the service. Authentication handled by a specialist provider so we never touch your password.
We're honest about scale: Orma is one person. We use reputable infrastructure providers precisely because their security is better than anything a solo operation could build. But no service is perfectly secure, and anyone telling you otherwise is selling something.
If there's a breach that could cause you serious harm, we'll tell you and the relevant regulator — within 72 hours where the GDPR applies, and as soon as practicable under the NZ Privacy Act. We'll tell you what happened, what it means for you, and what we're doing.
13 · Changes to this policy
If we change this policy materially, we'll tell you in the app at least 30 days before it takes effect, and say what changed.
Not bury it.