Privacy Policy
Last updated: 25 August 2026
This policy explains what personal information Executive Travel Assistant (“ETA”), a product of JJW Apps Ltd (“we”, “us”, “our”), collects, why, and what you can do about it. It applies to our website at executivetravelassistant.com, to the ETA application, and to any forms you submit to us, including LinkedIn Lead Gen Forms.
The short version
We’re a small company building a travel research tool for executive assistants. We collect personal data in two main ways: from people who fill in a form to take part in our research or join our early-access list, and from people who use the ETA app to plan travel for their executives. We use it to provide the service and to contact you about it — nothing else. We don’t sell your data, and you can ask us to delete it at any time at support@executivetravelassistant.com.
The rest of this page is the detailed version.
1. Who we are
The data controller responsible for your information is:
- JJW Apps Ltd— a limited company registered in England and Wales (company number 17259212)
- 135 Hungerhill Road, Rotherham, S61 3NW
- Contact for privacy questions and requests: support@executivetravelassistant.com
If you’re in the UK or EU, you have the right to contact us about how we handle your data using the details above.
2. What information we collect
When you submit a form (on our site or via a LinkedIn Lead Gen Form), we collect:
- Your name
- Your email address
- Your job title or sector
- Your answers to any questions on the form (for example, how often you arrange executive travel)
LinkedIn pre-fills some of these fields from your LinkedIn profile when you use a Lead Gen Form. You choose whether to submit them.
When you submit a beta trip request (the itinerary-request form on our site), we collect:
- Your email address, so we can send you the itinerary you requested
- The trip details and travel preferences you type into the form (for example dates, destinations, preferred airlines and hotels). Please only include what’s needed to research the trip.
- Your consent to be contacted for feedback about that itinerary
Trip requests are not linked to any account and are deleted automatically around 90 days after submission (see How long we keep it).
When you use the ETA app (with or without an account), we collect and store:
- Account data— if you create one: your name, email address, and the authentication identifiers created when you sign up with email/password or Google sign-in.
- Traveler profiles you build— the details you enter about the executive(s) you arrange travel for, including their name, contact details, travel preferences (airlines, cabin class, hotels, loyalty-programme numbers, home locations) and any notes.
- Trip data— the briefs you give us (origin, destination, dates, purpose, budget, constraints), the flight, hotel and ground-transport options ETA researches in response, and the options you select.
- Company travel policy— any travel rules you configure for ETA to apply.
- Conversation history— your messages to the ETA assistant during profile setup and trip planning.
If you plan a trip without creating an account, we don’t collect your name or email address — only the traveler and trip data above, tied to a persistent, anonymous identifier for your browser rather than to you personally. If you later create an account or sign in, that identifier and everything tied to it carries over, unchanged, to your account.
If you enter information about other people(such as the executive you support, or colleagues) — with or without an account — you are responsible for making sure you’re entitled to share that information with us for this purpose.
When you visit our website or use the app, we may collect, through cookies and similar technologies:
- Basic device and browser information
- How you arrived at and moved through the site
- Aggregated, non-identifying usage and performance statistics
See Cookies below.
When you contact us directly (e.g. by email), we collect whatever information you choose to include in your message.
3. Why we use your information, and our lawful basis
Under UK and EU data protection law, we must have a “lawful basis” for using your personal data. Ours are set out below.
| What we do | Lawful basis |
|---|---|
| Contact you to arrange a research interview, or about early access you requested | Consent, and/or our legitimate interest in conducting product research |
| Research and email you the itinerary you requested through our beta trip-request form, and follow up for your feedback on it | Taking steps at your request before entering a contract (building the itinerary); consent (the feedback follow-up) |
| Provide the ETA app and its travel-research features, including processing the traveler profiles and trip briefs you enter | Performance of our contract with you (our terms of service) |
| Let a visitor plan a trip without creating an account, for the ~30 days we keep it before it expires | Taking steps at your request before entering a contract (planning your trip); legitimate interest, secondary, in offering that without requiring sign-up, for that same 30-day window |
| Understand the executive-assistant market in aggregate to improve and prioritise what we build | Legitimate interest |
| Measure how you use the ETA app, with or without an account — the product analytics, session replay, and error tracking described in Cookies — attributed to a persistent Firebase uid that isn’t linked to your name, email address, or any other contact details, to understand and improve the product | Legitimate interest (improving the service) |
| Run and secure our website and app, and keep them reliable | Legitimate interest (security and reliability); consent for any non-essential cookies |
| Measure how visitors find and use our public website, and measure the effectiveness of our advertising | Consent, given via our cookie banner, for advertising and for analytics cookies; legitimate interest for anonymous, aggregate measurement that doesn’t identify you (see Cookies) |
Where we rely on consent, you can withdraw it at any time (see Your rights). Withdrawing consent doesn’t affect anything we did lawfully before you withdrew it.
ETA researches and ranks travel options to assist you, but you remain in control — a person makes the final decisions. We do not use your information for automated decision-making that produces legal or similarly significant effects on you.
4. Who we share it with
We don’t sell your personal data. We share it only with service providers who help us operate, and only as far as needed. These currently include:
- LinkedIn— where you submit a Lead Gen Form (subject to LinkedIn’s own privacy policy)
- Calendly— to book interview and demo times
- Google Workspace— to contact you
- Google Firebase / Google Cloud— to run the site and app, sign you in, store your data, and monitor performance
- Google (Gemini API)— to process your trip briefs and preferences and generate travel research
- SerpAPI— to run the flight and hotel searches behind your trip research
- Resend— to send you the confirmation and itinerary emails for beta trip requests
- Google reCAPTCHA Enterprise(via Firebase App Check) — to protect our public forms from bots and abuse; it assesses your browser interaction to distinguish people from automated traffic
- Google (Analytics/Ads via Google Tag Manager)— on our public website only. Before you consent, Google Analytics runs in a privacy-preserving mode that collects only anonymous, aggregate measurement without cookies. We only set analytics cookies, and only enable Google Ads measurement, once you consent via our cookie banner
- Reddit— the Reddit Pixel on our public marketing site, and a server-side conversion signal that can also fire from inside the app (see Cookies), both gated on your consent via our cookie banner, to measure the effectiveness of our Reddit advertising
- LinkedIn Insight Tag— on our public marketing site, not the signed-in app, and only once you’ve consented via our cookie banner, to measure the effectiveness of our LinkedIn advertising
- PostHog(PostHog EU Cloud — data hosted in the EU) — across our public website and the signed-in ETA app, for four purposes: product analytics (how the site and app are used), session replay (a recording of in-app interactions, with sensitive fields masked, after consent), error tracking (page path and error details so we can fix bugs), and AI-usage metadata(which model answered, token counts, and latency for each AI interaction — not the content of your briefs or chat messages in production analytics). See Cookies for how consent governs this.
These providers act on our behalf and are not permitted to use your data for their own purposes beyond providing their service to us. We may also disclose information if required by law, or to protect our legal rights.
5. International transfers
We’re based in the United Kingdom. Some of our service providers are located outside the UK and European Economic Area (for example, in the United States). Where your data is transferred outside the UK/EEA, we rely on appropriate safeguards — such as the relevant Standard Contractual Clauses or an adequacy decision — to protect it.
6. Your rights
If you’re in the UK or EU, you have the right to:
- Access the personal data we hold about you
- Correctdata that’s inaccurate or incomplete
- Eraseyour data (“right to be forgotten”)
- Restrict or object to how we use it
- Port your data to another provider
- Withdraw consent at any time, where we rely on it
To exercise any of these, email us at support@executivetravelassistant.com. We’ll respond within one month.
If you planned a trip without creating an account, we can’t identify you from your data alone — email us at support@executivetravelassistant.com with your trip’s link and we’ll act on your request using that. We don’t currently offer in-product deletion for anonymous trips.
You also have the right to complain to a data protection authority. As we’re established in the United Kingdom, you can contact the Information Commissioner’s Office (ICO) at ico.org.uk.
7. How long we keep it
We keep your information only as long as we need it:
- Research interview contacts: for the duration of the research project and up to 12 months afterwards, unless you ask us to delete it sooner.
- Early-access list: until you ask to be removed, or until we close the list.
- Beta trip requests: deleted automatically around 90 days after submission (the automatic clean-up can take a day or two beyond that), or sooner if you ask us at support@executivetravelassistant.com.
- Trip data from anonymous planning (no account):deleted automatically around 30 days after you start, unless you link an account first — doing so keeps it for as long as you have that account.
- Account, traveler-profile and trip data:for as long as you have an ETA account. If you close your account or ask us to delete your data, we’ll do so within 30 days, except where we’re required to keep it by law.
- Website and app performance data:in line with our provider’s retention settings.
8. Cookies
Our website and app use cookies and similar technologies. We use:
- Essential cookies— needed to sign you in and keep the app secure (for example, your authentication session cookie, the cookie that remembers your cookie-banner choice, and a cookie that remembers which country we resolved your connection to, so we show the right consent options). These don’t require consent. The country is derived from your IP address using the GeoLite2 database created by MaxMind, available from maxmind.com; the IP address is not stored.
- Limited performance and diagnostic data— collected via Firebase Performance Monitoring to help us keep the app fast and reliable.
- Analytics cookies— via Google Tag Manager and Google Analytics on our public website, and via PostHog on our public website and the signed-in ETA app, to understand how visitors and account holders use our site and app.
- Advertising cookies— on our public marketing site, via Google Ads, the Reddit Pixel, and the LinkedIn Insight Tag, to measure and improve our advertising.
- Advertising measurement we send from our servers— once you’ve consented to advertising cookies, we send Reddit a signal directly from our servers when you complete your first trip-planning turn, gated on the same consent signal and Reddit click id as the cookie above. That signal carries the identifiers Reddit needs to match it to your ad click: your IP address, your browser’s user-agent, the Reddit pixel’s own identifier for your browser, and the anonymous identifier we use for you. The IP address and that anonymous identifier are hashed before they leave our servers. Unlike the cookie-based measurement, this can fire inside the app, not just on our public marketing site.
Your cookie choice carries into the app: the consent and Reddit click-id cookies described above are read wherever you use ETA, so nothing above starts measuring just because you signed in or began planning anonymously.
The analytics and advertising cookies above are off by default. The first time you visit our public website, a cookie bannerasks you to Accept or Reject them; we only set these cookies once you Accept. Before you choose — and if you Reject — Google Analytics runs in a privacy-preserving “consent mode” that uses no cookiesand doesn’t identify you, sending only limited, aggregate measurement signals to Google; the Reddit Pixel and all advertising cookies stay switched off entirely until you Accept. You can withdraw your consent at any timeby clearing your cookies for our site and revisiting — the banner will ask again. We don’t track you across other, unrelated websites.
PostHog is cookieless until you consent.This applies both on our public website and inside the signed-in ETA app. Before you Accept — and if you Reject — PostHog runs in an in-memory mode: no cookies, no local storage, and no session replay. Once you Accept via the cookie banner, PostHog sets analytics cookies and local storage so it can recognise you across visits, and enables session replay— a recording of your in-app interactions, with sensitive fields (traveler details, chat messages) masked, and applied to a sampled subset of sessions rather than every one. If you withdraw consent, PostHog returns to cookieless, in-memory mode and stops recording new sessions. Error tracking (the page path and error details behind a crash, linked to your account when you’re signed in) and AI-usage metadata (model, token counts, latency) are captured independently of this cookie/replay consent, as part of running and improving the service under our legitimate interest — see the table in Why we use your information.
9. Security
We take reasonable technical and organisational measures to protect your information, including access controls and encryption in transit. No method of transmission or storage is completely secure, but we work to protect your data and to respond promptly if anything goes wrong.
10. Children
Our website and services are not directed at children, and we don’t knowingly collect data from anyone under 16.
11. Changes to this policy
We may update this policy from time to time. We’ll change the “last updated” date above, and for significant changes we’ll take reasonable steps to let you know.
12. Contact
Questions about this policy or your data? Email support@executivetravelassistant.com.