Andanza

Privacy

What Andanza keeps about you, who can see it, and what happens when you tap a partner link.

Last updated September 2, 2026

What Andanza stores about you

There is no signup. You join a group with an invite code and a name you pick, and that name is the only thing we ask for. No email, no phone number, no legal name, no password of your own.

Two cookies keep you in. The session cookie says which group you are in and which member you are, signed so it can't be altered. It lasts 30 days and dies early if a lead rotates the group's invite code. The device cookie is a random credential that tells the app which phone or browser this is, so your list of groups survives and you can get back in when the session runs out. It lasts 400 days. The server keeps only a hash of it, never the credential itself.

Everything else is what you add on purpose: where you're staying (a pin, the address or Maps link you pasted, the dates), flights, your I'm here check-in, time off windows, spots, events, RSVPs, comments, invites, itinerary entries and an optional photo. Plus two settings: your language and the blur switch described below.

If you join through someone's personal invite link, we record that their code brought you in. If you turn notifications on, your browser hands us a push address so we can send them; we keep that address and nothing else about the device.

Like any website, the servers that run Andanza (Railway) and the network in front of them (Cloudflare) see your connection. Andanza itself uses your IP address only to rate limit requests, in memory, and does not write it to the database.

What the group sees

People in your group see your name, your photo if you added one, and what you chose to share: your stay on the map with its dates, your spots, the events you post, your RSVPs and comments, and your I'm here pin while it lasts. Leads carry a lead badge.

Blur is a switch in your settings ("Show my location as an approximate area"). With it on, your stay and check-in pins are snapped to a grid of roughly 500 metres and the address is replaced with a generic label before anything leaves the server. The exact spot never reaches any phone, not even yours; the database keeps it so the map can put you back when you turn blur off.

A check-in is one point and one expiry, never a trail. You pick how long it shows (1 hour, 3 hours, the rest of the day, or a custom time up to 24 hours). After that it is shown to nobody, and sharing again replaces it rather than adding to a history.

Photos are served only to members of the same group. Nobody outside it, and no other group, can load them.

What never leaves the app

Booking.com, GetYourGuide and Airalo links

Three links in the app take you out of Andanza: "Places to stay near the group" (Booking.com), "Tours near here" (GetYourGuide) and "Data in …" on your flights card (Airalo, an eSIM shop). They open in a new tab, and they are how Andanza may earn money: each carries a partner id, and if you book or buy after tapping one, the partner pays Andanza a commission. Nothing in the app changes whether you tap them or not.

What the link carries. The Booking.com link goes through CJ Affiliate, the network Booking.com uses for its partners: it holds Andanza's CJ publisher id, a fixed label naming the placement, and a Booking.com search for the group's city over the trip's dates for one adult, one room. The GetYourGuide link holds Andanza's partner id and a search for the spot's name and the group's city. The Airalo link goes through impact.com, the network Airalo uses for its partners: it holds Andanza's Impact partner id and the address of Airalo's page for the country the group is travelling to, worked out from the group's timezone. That is all. No member name, no member id, no group id, no coordinates, nothing from your session. An automated test checks every built link for exactly those things.

What we count. Tapping one adds one to a counter of partner clicks for your group. The counter stores the group and which link, never who tapped, and never whether you booked. Bookings are visible only in the partner's own reporting.

What happens on their side. Once you arrive, CJ, Booking.com, GetYourGuide, impact.com and Airalo set their own cookies on their own sites, under their own policies, and your browser sends them the usual referrer (that you came from andanza.app). CJ's Services Privacy Notice says it collects click data through cookies and similar technologies, keeps that pseudonymous data for 6 years, and may share it with advertisers such as Booking.com for attribution and analytics. impact.com does the same job for Airalo. Read CJ's Services Privacy Notice, Booking.com's Privacy Notice, GetYourGuide's privacy policy, impact.com's privacy policy and Airalo's privacy policy before you rely on any of them.

Error and usage reports

The app records its own errors. When a screen crashes or a request fails, a row is written with the error message, the route, your language, the app version, your screen size and your browser's user agent string. While you are signed in, that row is stamped with your group and your member id so we can reproduce what you hit.

When you tap "Report a problem", we send what you wrote plus a technical snapshot of the screen: which sheets are open and in what state, whether taps are blocked, which of the app's own error messages are visible (matched word for word against the app's copy, so a message that contains someone's name is left out), and the last three error messages this page saw. No screenshot, no photos, nothing anyone typed into a field, no names, no addresses, no coordinates, not even the page title.

A few moments are counted, not tracked: opening the map without a stay of your own, opening a spot, and tapping a partner link. Each count is stamped with the group, never with a member, and one person adds at most one count per half hour. Refused requests (a wrong invite code, a name already taken) are counted with no group and no member at all.

Photo prefill. If you fill in a flight or a stay from a photo, the image is sent to Anthropic's Claude API to read the text, held in memory for that one request, and never stored or logged by Andanza. The option only appears when the owner has switched it on.

Other services the app talks to: the map tiles come from OpenFreeMap, so your browser loads them directly and OpenFreeMap sees which areas you look at; place search goes through our server to Photon (komoot), which receives the text you type; a pasted Google Maps short link is expanded by asking Google and, when needed, geocoded with OpenStreetMap's Nominatim. They receive the text or the link, not who you are or which group you are in.

Deleting your data

You can delete your own things from the app as you go: your photo, your check-in, each stay, flight, time off window, spot or event you created, your itinerary entries, your staying with requests, and the notification address (turn notifications off).

A lead can remove you from a group. That deletes, in one go, your stays and any staying with requests on them, your flights, your check-in, your photo, your RSVPs, ticket notes, comments, invites, itinerary, the invite codes you minted, and your profile with your name. Two things are handed on instead of deleted, because other people are using them: spots you added pass to the lead, and events you created stay in the group with no author.

What remains after that: the aggregate counts above (they never had your id), any error or problem report you filed, now with your member id removed, and your account row, which is only an opaque id plus, if you joined through someone's link, a pointer to their account. If you were still in other groups, your notification address moves to one of them; if not, it is deleted. The device cookie stays on your phone until it expires or you clear it.

There is no leave this group button yet. Ask a lead to remove you.

Contact

The quickest way to reach us about anything on this page is "Report a problem" in your settings, or the "Something's not working?" button on any screen. It lands in the queue the owner reads.

Back to the app