Privacy policy
Last updated 12 August 2026
Holidr is a tool for professional travel advisors. It connects to your work email, reads it to assemble your trips, and drafts replies and follow-ups that you approve before anything is sent. This policy explains what data Holidr touches, why, where it is kept, and how you remove it. If a lawyer's version ever disagrees with this page, the lawyer wins; this is written to be honest and readable, not to bury anything.
Who this covers
The advisor who signs in and connects their mailbox is our user. Their travellers and suppliers do not have Holidr accounts, but their details appear in the mail Holidr reads, so this policy covers them too.
Google account data we access
Signing in with Google is both your login and how you connect your inbox. We request only the scopes the product needs:
- Your name, email address and profile (openid, email, profile) to create and identify your account.
- Reading your Gmail (gmail.readonly) to assemble your trips, file each message on the right one, read attachments, and draft replies.
- Sending mail as you (gmail.send) only when you approve a draft. Holidr never sends on its own.
We ask for nothing beyond these. We do not request access to your contacts, calendar, drive, or any other Google service.
How we use it
Gmail content is used solely to provide Holidr's features to you: sorting mail onto trips, reading invoices and documents, drafting replies and supplier chases for your approval, tracking commissions, and searching your own trips. Everything Holidr sends goes from your own address, under your name, and only after you approve it.
The Google Limited Use disclosure
Holidr's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: we use your Gmail data only to provide and improve the user-facing features above, we do not sell it, we do not use it for advertising, and we do not use it to train generalised or foundation AI models. Humans at Holidr do not read your mail except where you ask us to for support, where it is necessary for security, or where the law requires it.
Where it is stored, and who else sees it
Holidr runs on Cloudflare. Your mail, trips, documents and settings are stored in Cloudflare's database, object storage and key-value store. Your Google refresh token is encrypted at rest and is only ever used to sync and send your mail.
To draft replies and understand documents, the relevant text is sent to our AI model provider (currently Anthropic, reached via OpenRouter) for that single purpose. That provider processes the text to generate a draft and does not use it to train its models. Property searches may query the travel sites you have chosen as your sources. We do not otherwise share your data, and we never sell it.
Keeping it, and deleting it
Holidr keeps your data for as long as your account is open, because the product is your working record of live trips. You can erase everything yourself at any time: Settings has a "Danger zone" that disconnects Gmail, revokes Holidr's access to your Google account, and permanently deletes every trip, message, document, booking and setting we hold. This cannot be undone. You can also revoke Holidr's access directly from your Google account permissions.
Changes and contact
If this policy changes in a way that affects how we handle your data, we will say so on this page and update the date above. Questions about your data, or a request to delete it on your behalf, go to privacy@holidr.com.