GoTango · Legal
Privacy Policy
Effective Date: 25 August 2026
This Privacy Policy explains how GoTango collects, uses, stores, and shares personal information when you use gotango.co, the GoTango Score, Tia, collaboration features, and related services (together, the “Service”).
1. Who we are
GoTango, LLC is the operator and controller of personal information processed through the Service. Its registered office is:
GoTango, LLC
4615 Mount Vernon
Houston, Texas 77006
United States
Privacy and legal requests may be sent to GoTango, LLC, care of Suerken Law, PLLC, which is the legal-notice and contact recipient only and is not the operator of GoTango:
GoTango, LLC
c/o Suerken Law, PLLC
4615 Mount Vernon
Houston, Texas 77006
United States
Email: info@suerkenlaw.com
GoTango has not appointed a data protection officer, EU representative, or UK representative.
2. Information we collect
We collect the categories below when you use the Service. We do not collect every category from every visitor. Signed-out visitors can browse public Score and destination content with less identifying information than account holders.
Account and contact information. If you create an account, we collect your name, email address, mobile phone number, chosen GoTango Tail Number, account identifier (UUID), account role, account creation and update times, and a record that you accepted the Terms & Conditions (including the Terms version and the time of acceptance). We store a timestamp when your phone number is verified.
Phone verification. To create an account or sign in, we send a one-time SMS code. We temporarily store pending verification details (including phone number and, for new accounts, name, email, and Tail Number) for about 10 minutes. Twilio receives the phone number to deliver and check the code. We also store short-lived hashed rate-limit records for the requesting network address and phone number to reduce abuse.
Tia content. If you use Tia, we process the questions and prompts you submit, Tia’s answers, destination or trip context you provide, optional voice transcripts produced by your browser, saved conversations, and saved plans or Watch items. Authenticated copies may be stored on our servers (including Redis/KV and Postgres) and, for some features, in your browser.
Collaboration and invitations. If you use collaboration, we process workspace membership, invitation and join records, Tail Number snapshots shown to collaborators, chat and collaboration messages, shared Tia questions and answers, and shared plan items. Collaboration is identified to other participants primarily by Tail Number, not by your phone number or email.
Subscription and billing-related information. If you start GoTango Pro checkout, we store subscription status and Stripe customer and subscription identifiers, including period-end and cancellation flags returned by Stripe. Stripe processes payment details. GoTango does not receive or store full payment-card numbers.
Complimentary and access records. We store entitlement records needed to operate complimentary Tia access, tester or preview access, generation reservations, and related timestamps. These records are tied to your account or to an anonymous Tia session.
Communications and newsletter information. If you join the newsletter or a waitlist, we store your email address, source (if provided), and subscription timestamps. We do not currently send those messages through a separate email-delivery vendor in the Service. If you email us, we receive whatever you include in that correspondence.
Technical, security, and log information. Our hosting provider and application logs may record IP address, user-agent, request URLs, timestamps, and error diagnostics. We use this to operate, secure, and debug the Service. Rate-limiting may store a truncated or hashed form of IP address.
Cookies and browser storage. See Cookies and similar technologies.
We do not intentionally collect government identification, financial-account credentials, precise device geolocation, biometric templates, consumer health data, or information about children. Tia and collaboration are free-text features: you might type sensitive information that we did not ask for. Please do not do that unless it is necessary.
3. How we use information
We use personal information to:
- provide, operate, and display the Service;
- create and authenticate accounts, including SMS verification and session cookies;
- assign and administer Tail Numbers;
- operate Tia, including sending prompts and relevant context to AI providers;
- save and sync plans, Watch items, and Tia conversations you choose to keep;
- enable collaboration, messaging, and shared plans among participants you invite or join;
- administer complimentary Tia access, usage limits, and subscriptions;
- start Stripe Checkout or the Stripe customer portal when you request billing;
- provide customer and legal support when you contact us;
- store newsletter or waitlist signups you request;
- maintain security, prevent fraud and abuse, and enforce the Terms;
- comply with law and respond to lawful requests; and
- understand whether core features work, using first-party product analytics only after you allow analytics.
We do not use personal information to build third-party advertising profiles or to run cross-context behavioural advertising.
4. Legal bases for EEA and UK users
If the GDPR or UK GDPR applies, we process personal information on these bases as applicable:
- Performance of a contract: to create your account, verify your phone, operate Tia and collaboration, save content you request, and provide paid or complimentary access you asked for.
- Legitimate interests: to secure the Service, prevent abuse, keep necessary logs, and improve reliability, where those interests are not overridden by your rights.
- Legal obligation: to keep records or disclose information where the law requires it.
- Consent: where we rely on consent (for example, optional newsletter signup, optional voice input you start, or Vercel Web Analytics after you choose Allow Analytics). You may withdraw consent for the future without affecting prior processing that was lawful.
We do not treat account creation, authentication, Tia answers you request, or payments as optional “consent” processing. Those are needed to provide the Service you ask for.
5. Tia and artificial intelligence
Tia is AI-powered. To answer you, GoTango may send your prompt, recent conversation context, destination or trip details, and relevant collaboration context to OpenAI (or another AI provider we disclose if we add one).
Most Tia answer requests are sent with OpenAI’s API store setting off. Some Tia research steps that use web search keep a short-lived stored response on OpenAI so a follow-up research call can complete. OpenAI’s current API terms provide that API inputs and outputs are not used to train OpenAI’s models unless a customer opts in. GoTango has not enabled API-data training. OpenAI’s web-search tool may send search queries derived from your prompt to search providers so Tia can retrieve current public information.
We also use OpenAI for some destination-news, weekly-brief, and editorial-generation jobs. Those jobs process destination and public-source material, not your account profile, unless a user prompt is part of a Tia request.
GoTango does not ask you to submit health, medical, biometric, government-ID, password, full payment-card, or other highly confidential information in Tia. Please do not enter that information unless it is necessary for the question you are asking. Tia is not a confidential medical, legal, or professional channel.
If you use optional voice input, your browser’s speech-recognition interface transcribes audio. On some browsers that interface is provided by the browser vendor (for example, Google on some Chromium browsers). GoTango receives the resulting text if transcription succeeds; we do not operate a separate voice-processing vendor.
6. Collaboration and messages
Collaboration participants can view messages, Tia questions and answers, and plan items shared in that workspace. Other users may copy, screenshot, or forward shared content. GoTango processes collaboration content to provide the feature, keep membership accurate, and maintain security.
Do not share information in collaboration that you are not willing for other participants—and GoTango’s processors—to see. Treat collaboration as shared, not private to you alone.
7. Service providers
We use companies that process personal information on our behalf to provide the Service. This is not a sale of personal information. Material processors include:
- Vercel — website hosting, serverless APIs, logs, and first-party Web Analytics;
- Supabase / PostgreSQL — durable account, Tail Number, Tia, collaboration, and entitlement data (the application uses a direct database connection; it does not use Supabase Auth or browser database keys);
- Upstash / Vercel KV (Redis) — accounts, sessions-related records, newsletter and waitlist signups, Tia entitlements, share documents, and synced plans/history;
- OpenAI — Tia generation and related AI features described above;
- Twilio — SMS one-time passcodes for phone verification;
- Stripe — checkout, subscriptions, and billing portal;
- Google Fonts / Google — web fonts loaded from Google (your browser requests may include IP address). Optional voice input may also use the browser vendor’s speech service;
- jsDelivr — public map and chart libraries used to render destination maps.
FlightAware supplies aviation/arrival data used to operate the GoTango Score and related displays. The application does not send GoTango account names, emails, phone numbers, or Tia prompts to FlightAware.
We do not currently use Resend, SendGrid, or another transactional-email vendor in the Service. Legal and privacy correspondence sent to the contact email is received by our legal-notice recipient.
8. Payments
Paid GoTango Pro access is processed by Stripe. When you start checkout, we create a Stripe Checkout session (including your email if we already have it and no Stripe customer ID exists yet) and redirect you to Stripe. Stripe collects and processes payment-card and billing details under Stripe’s terms and privacy notice.
GoTango stores Stripe customer ID, subscription ID, subscription status, and related billing flags. GoTango does not receive or store full payment-card numbers. You can manage a Stripe-billed subscription through Stripe’s customer portal when that feature is available.
9. International data transfers
GoTango is based in the United States. Personal information is processed in the United States and may be processed in other countries where our providers operate. Those countries may not provide the same legal protections as your home country.
Where required by applicable law, we use legally recognised safeguards for international transfers. We have not published a specific list of standard-contractual-clause or DPA filings in this Policy.
10. Retention
We retain personal information for as long as needed to provide the Service, maintain your account, operate Tail Numbers, comply with legal obligations, resolve disputes, enforce our agreements, and maintain security. Exact periods vary by record type:
- pending phone-verification records expire after about 10 minutes;
- account session cookies last up to 30 days;
- anonymous Tia session cookies and related free-use markers may last up to 12 months;
- owner-dashboard sessions last up to 12 hours;
- some share-link records in Redis are stored with about a 30-day time-to-live; collaboration records in Postgres are kept while the workspace exists;
- saved plans support in-product removal that marks items deleted; underlying copies may remain in backups, logs, or related collaboration records;
- OpenAI-stored research responses, when used, follow OpenAI’s stored-response retention for that API feature.
We do not currently offer a self-service account-deletion portal. You may request deletion or other privacy actions as described below. We may retain limited information where we must (for example, to complete a transaction, detect abuse, or meet a legal duty), and we do not promise deletion faster than our systems and backups actually allow.
11. Your rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information; to restrict or object to certain processing; to withdraw consent where processing is based on consent; to opt out of targeted advertising, “sale,” or “sharing” where those concepts apply; and to complain to a supervisory authority.
Privacy requests may be submitted to info@suerkenlaw.com. We may need to verify your request. We do not currently operate a separate privacy-request portal.
In the product, you can remove some saved Tia conversations and Watch/plan items. That in-product removal is not a complete erasure of every copy across collaboration, logs, or backups.
12. California and other U.S. state privacy laws
If you are a resident of California or another U.S. state with a consumer privacy law, you may have some of the rights described above, subject to those statutes and their exceptions. This Policy does not claim that GoTango meets any particular statutory threshold (for example, a revenue or volume threshold that would make a specific law apply).
Where such a law applies, you may request to know, access, correct, or delete personal information, and to exercise opt-out rights that the law provides. Submit requests to info@suerkenlaw.com. Authorised agents may submit requests as the applicable law allows, subject to verification.
We do not use or disclose sensitive personal information for purposes that would require a right to limit under the CPRA, because we do not intentionally collect that information. If a law gives you a right to appeal our response, we will honour that process when it applies.
13. Texas
If Texas data-protection law applies to you, you may have rights to access, correct, delete, or obtain a copy of personal information, and to opt out of certain processing where that law provides an opt-out. Submit requests to info@suerkenlaw.com. This Policy does not claim that any particular Texas statutory threshold is met.
14. Children
GoTango is intended for users who are at least 18 years old. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact info@suerkenlaw.com and we will take appropriate steps.
15. Security
We use reasonable administrative, technical, and organisational safeguards, including HTTPS, HttpOnly session cookies, hashed lookup keys for some identifiers, and restricted database access. No method of transmission or storage is perfectly secure. We cannot guarantee that unauthorised access, disclosure, or loss will never occur.
16. Cookies and similar technologies
GoTango uses strictly necessary technologies for authentication, security, Tia usage limits, saved content, and other requested functionality. Those necessary cookies and browser-storage items operate regardless of your analytics choice. Blocking them can break sign-in, Tia limits, payments return flows, or saved content.
Strictly necessary cookies (first-party, set by GoTango):
gotango_account— signed-in account session. HttpOnly, SameSite=Lax, up to 30 days.gotango_tia_session— anonymous or linked Tia entitlement session. HttpOnly, SameSite=Lax, up to 12 months.gotango_tia_free_exhausted— records that complimentary/free Tia use for that browser is exhausted. HttpOnly, SameSite=Lax, up to 12 months.gotango_owner— owner-dashboard session only. HttpOnly, SameSite=Strict, up to 12 hours.
First-party localStorage and sessionStorage (no expiration other than you clearing site data, except sessionStorage which ends when the browser tab ends): Watch lists, Tia Watch/plan items, deleted-item markers, Tia conversation history, conversation-watch flags, and short-lived signup or collaboration return paths. These store travel-planning content you create in that browser. They are used to provide those features, not for advertising.
Analytics choice cookie. If you make a choice in the privacy bar, GoTango stores gotango_privacy_v1 with the value analytics_allowed or essential_only. It contains no name, email, account ID, Tail Number, or analytics identifier. It is first-party, SameSite=Lax, Secure on HTTPS, and lasts about 180 days so we can remember your choice.
We do not use Google Analytics, Google Tag Manager, Meta/Facebook Pixel, Instagram advertising pixels, heatmaps, session replay, advertising cookies, or cross-site behavioural advertising.
Vercel Web Analytics. GoTango uses Vercel Web Analytics only after you choose Allow Analytics. Until then, the insights script does not load and we do not send pageviews or named product events. After you allow analytics, Vercel’s first-party insights script (/_vercel/insights/script.js) may measure aggregate website and app usage so we can improve GoTango. Vercel describes this product as cookieless audience measurement. Product events use generic names (for example, that Tia opened or a newsletter signup action occurred) and do not include your prompts, messages, or account identifiers. This is not required to sign in, run Tia, or pay. You can change your choice at any time through Privacy Choices in the footer. Stripe Checkout runs on Stripe’s pages after you choose to subscribe; GoTango does not load Stripe.js on gotango.co.
Third-party content needed to display the site: Google Fonts and jsDelivr map/chart libraries. Those requests can disclose your IP address to the content network. They are not advertising pixels.
A privacy notice appears on the GoTango app until you choose Essential Only or Allow Analytics. You need to make one of those choices before continuing in the app. Either choice lets you use GoTango. Analytics stays off unless you choose Allow Analytics.
17. No sale or targeted advertising
GoTango does not sell personal information, and does not share personal information for cross-context behavioural advertising, as those terms are commonly used in U.S. state privacy laws. We do not use personal information for targeted advertising networks. Sharing with processors listed above is to operate the Service, not to advertise GoTango products to you across unrelated sites.
18. Changes
We may update this Privacy Policy from time to time. The Effective Date at the top of this page will change when we do. For material changes, we may also provide additional notice, such as an in-product message or email where we have a contact address.
19. Contact
GoTango, LLC
c/o Suerken Law, PLLC
4615 Mount Vernon
Houston, Texas 77006
United States
Email: info@suerkenlaw.com
See also the Terms & Conditions.