MITA
Travel App
When you create a Mita account, we collect information you voluntarily provide: your display name, email address, date of birth (to verify you are 18 years of age or older), profile photograph, home country, travel style preferences (e.g., adventure, budget, luxury, cultural), and any biography you choose to write. If you register via Apple Sign-In or Google, we receive a limited profile dataset authorized by you and that provider.
We automatically collect device model, operating system version, unique device identifiers, IP address, mobile carrier, app version, crash logs, and performance diagnostics to maintain service quality and diagnose technical issues.
With your permission, Mita accesses your device location to enable travel-specific features. We also collect trip planning data, itineraries, bucket list destinations, and travel records you create within the app. See Section 3 for full details.
We record how you use the Service: destinations you browse, content you interact with, creators you follow, search queries, and session frequency and duration. This informs our recommendation systems and product improvements.
Travel photos, videos, destination reviews, journal entries, itineraries, tips, and comments you publish on Mita constitute User-Generated Content (UGC). See Section 4 for full details.
If you contact our support team, submit a report, or participate in surveys, we retain the content and metadata of those communications for resolution and service improvement.
All payments are processed exclusively by Apple App Store or Google Play. We do not store your payment card details. We receive only anonymized transaction confirmation tokens and purchase entitlement data to activate in-app features.
We use your information to authenticate your account, enable trip planning and community features, process purchases, enforce content policies, and deliver all core Service functions.
Your travel history, destination preferences, and behavioral signals power Mita's recommendation engine, surfacing destinations, itineraries, and community content tailored to your travel style. See Section 6 for full details.
We process behavioral data, user reports, and content signals to detect and prevent fraud, harassment, prohibited content, and policy violations.
Aggregated and de-identified usage data is analyzed to improve recommendation accuracy, trip planning features, and overall platform performance.
With your consent where required by law, we may send promotional communications about new features, travel inspiration, and platform offers. You may withdraw consent at any time via in-app settings or email unsubscribe.
We process personal data as necessary to comply with applicable laws, respond to valid legal process, and protect the safety of our users and the public.
Mita requests “While Using the App” location permission to power features including nearby destination discovery, location-tagged posts (at city or region level, never precise GPS), and local travel tips. We will seek separate explicit consent before requesting any background location access. You may revoke location permission at any time in device settings without losing access to non-location features.
Itineraries, bucket list destinations, travel notes, and trip records you create are stored on our servers and associated with your account to enable cross-device access. You may export or delete trip data at any time from account settings. We do not share your unpublished trip plans with travel brands or advertisers without your explicit consent.
When you publish a post or check-in, Mita displays location at the city or landmark level only — never precise GPS coordinates. EXIF geolocation data embedded in uploaded photos is automatically stripped before your content is made publicly visible.
Precise session location data is not retained beyond the session unless you explicitly create a location-tagged post or check-in. Aggregate, anonymized location analytics may be retained indefinitely for product development and cannot be used to identify individual users.
Where a user reports a safety emergency during travel, Mita may use available location data to assist in directing you to relevant emergency services or sharing information with law enforcement or rescue services, where this is legally appropriate and operationally possible.
Travel photos, videos, destination reviews, journal posts, shared itineraries, tips, and comments you publish are stored on our secure cloud infrastructure and associated with your account. You retain ownership of all original content you create.
By submitting UGC, you grant Mita a non-exclusive, worldwide, royalty-free, sublicensable license to host, store, reproduce, display, and distribute your content within the Service and in connection with promoting the Service, subject to your privacy settings. This license persists for a commercially reasonable period following deletion.
Photos and videos you upload may contain embedded geolocation EXIF metadata. Mita automatically strips all geolocation EXIF data from uploaded media before it is made publicly visible, protecting your precise location from disclosure.
UGC is reviewed using automated screening and human review for compliance with our Community Guidelines. Content that is false or misleading about travel destinations or safety conditions, that depicts illegal activity, or that otherwise violates our policies will be removed. Repeat violators may face account suspension or termination.
You may delete your content at any time. Deleted content is removed from public view within 48 hours, from production servers within 30 days, and from backup archives within 90 days.
Mita's community feed surfaces travel posts, destination photos, and itineraries from users you follow and from the broader Mita community. Public posts are visible to all Mita users and may be surfaced in discovery feeds.
Reviews and tips you submit about destinations, accommodations, restaurants, and activities are public and associated with your display name. This content informs other travelers and may be aggregated into destination ratings. Review content must reflect your genuine experience.
Where Mita offers destination-specific groups or interest-based forums, your display name and post content are visible to all group members. Membership lists may be visible to other group members depending on group settings.
If you choose to share a trip itinerary publicly, it becomes visible to all Mita users and subject to the license grant in Section 4.2. You may set itinerary visibility to Private or Followers Only at any time from your trip settings.
Mita's recommendation system analyzes your destination history, travel style preferences, saved content, followed creators, and behavioral signals to surface travel content we believe you will find inspiring. The system covers both the discovery feed and destination-search results.
We build an internal travel preference profile from your activity on Mita. This profile is used exclusively for in-app personalization and is not sold to travel brands, advertisers, or data brokers without your explicit consent.
You may disable personalized recommendations at any time in Settings > Privacy > Personalization. Mita will then serve a non-personalized, editorially curated discovery feed. Core Service functions are unaffected.
We share personal information with trusted third-party service providers supporting our operations: cloud infrastructure, mapping services, CDN providers, payment processors, analytics platforms, customer support tools, and content moderation systems. All providers are contractually bound to process your data only on our instructions and in compliance with applicable data protection law.
We do not sell your personal information. We do not share your travel preferences, itineraries, or personal data with airlines, hotels, tour operators, or advertisers for their independent commercial use.
In the event of a merger, acquisition, or asset sale, your data may transfer to the acquiring entity. We will notify you in advance before your data becomes subject to a materially different privacy policy, giving you the opportunity to request account deletion.
We may disclose your information to law enforcement or government authorities when required by applicable law, valid legal process, or where necessary to protect the safety of any person. Where legally permitted, we will notify affected users prior to disclosure.
Your display name, profile photo, public posts, destination reviews, and public itineraries are visible to all Mita users and may be indexed by search engines. You may set your account or individual content to private in account settings.
Mita integrates third-party mapping services to display destination maps, calculate distances, and surface nearby points of interest. These providers process your location data when map tiles or place data are requested, in accordance with their own privacy policies.
Mobile analytics SDKs measure app performance and feature engagement, configured with privacy-preserving settings including anonymized event collection and suppression of advertising identifiers absent your consent.
Apple Sign-In and Google authentication are governed by their own terms and privacy policies. Our use of data from these services is limited to account creation and basic profile population.
User data is hosted on cloud infrastructure with internationally recognized security certifications. Data processing agreements are in place with all infrastructure providers. Details available at service@mita.bet.
We retain your personal information for as long as your account is active. Accounts with no login activity for 24 consecutive months will receive a dormancy notice; following the notice period, inactive data may be anonymized or deleted.
Trip plans, itineraries, and travel records are retained for the life of your account. You may delete individual trips or your full travel history at any time from account settings.
Financial transaction records are retained for a minimum of seven years to comply with applicable accounting, tax, and consumer protection obligations.
Records of content moderation actions, user reports, and enforcement decisions are retained for up to 36 months after account closure to support pattern analysis, appeals, and legal defense.
Aggregate, irreversibly anonymized data may be retained indefinitely for product research and platform development.
We implement TLS 1.2+ encryption for all data in transit, AES-256 encryption for sensitive data at rest, strict role-based access controls, and automated anomaly detection to flag unusual access patterns for review.
Data access is restricted on a need-to-know basis, requires multi-factor authentication, and is subject to comprehensive audit logging. All personnel with data access receive regular data protection training and sign confidentiality agreements.
We conduct regular security assessments and third-party penetration testing. Report security vulnerabilities responsibly to service@mita.bet.
In the event of a personal data breach posing risk to your rights and freedoms, we will notify relevant supervisory authorities within 72 hours where required by law and inform affected users without undue delay.
Mita uses session tokens, local storage, and analytics SDKs (not traditional browser cookies) to maintain your session, remember preferences, and measure feature engagement.
On iOS, we request ATT consent before accessing your IDFA. On Android, we respect your opt-out via device advertising settings. Advertising identifiers are used only to measure our own user acquisition campaigns and are not shared for third-party behavioral advertising.
Our website may use standard browser cookies for session management and analytics, manageable via your browser settings.
Mita serves a global travel community and operates infrastructure across multiple regions. Your personal data may be transferred to and processed in countries other than your country of residence, which may have different data protection standards.
For transfers from the EEA, UK, or Switzerland to countries lacking an adequacy decision, we rely on EU Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum (IDTA). Equivalent safeguards apply to other cross-border transfers.
Where applicable national laws impose mandatory data localization requirements, we take reasonable steps to store and process the required data categories within the mandated territory.
Request a copy of personal data we hold about you via in-app account settings or by emailing service@mita.bet with subject “Data Access Request.”
Correct inaccurate information directly in account settings or by contacting us. We action corrections within 30 days.
Request deletion via Settings > Account > Delete Account or by emailing us. See Section 20 for full details.
Object to or request restriction of processing in certain circumstances. We pause relevant processing while assessing your objection.
Where processing is based on consent or contract and automated, request your data — including trip and itinerary data — in a structured, machine-readable format for transfer to another service.
Withdraw consent for marketing or personalization at any time via in-app settings or by contacting us, without affecting prior lawful processing.
Email service@mita.bet with “Privacy Rights Request” in the subject, your registered email, and a description of your request. We verify your identity and respond within applicable legal timeframes.
For EEA and UK users, Mita acts as the data controller of your personal information under the GDPR and UK GDPR respectively.
We process your data under: (a) contractual necessity (to provide the Service); (b) legal obligation (regulatory compliance); (c) legitimate interests (safety, fraud prevention, service improvement), where not overridden by your rights; and (d) consent (for marketing and optional personalization).
You may lodge a complaint with your national data protection supervisory authority if you believe your data has not been handled lawfully. We encourage you to contact us first.
California residents have rights under the CCPA as amended by the CPRA, including the right to know, delete, correct, and opt out of the sale or sharing of personal information. Mita does not sell personal information and does not share it for cross-context behavioral advertising.
Exercising your California privacy rights will not result in denial of services, different pricing, or reduced quality of experience.
California residents may designate an authorized agent by providing written proof of authorization. We verify both agent and resident identity before processing any request.
Brazilian users have rights under the Lei Geral de Protecao de Dados (LGPD) including confirmation, access, correction, anonymization, deletion, portability, and withdrawal of consent.
We process Brazilian users' data based on contract performance, legal obligation, and consent where applicable.
Brazilian users may lodge complaints with the Autoridade Nacional de Protecao de Dados (ANPD) where they believe data processing violates the LGPD.
Mita is designed exclusively for users who are 18 years of age or older. We implement date-of-birth verification at registration and apply additional detection measures to accounts suspected of being operated by minors. Confirmed underage accounts are immediately and permanently terminated with all associated data deleted.
If you are a parent or guardian and believe a minor has created a Mita account, contact us immediately at service@mita.bet. We will investigate and, where confirmed, permanently delete the account and all associated data without delay.
All in-app purchases are processed exclusively through Apple App Store or Google Play. Mita does not store your payment card details. We receive only anonymized transaction confirmation tokens and entitlement data.
If Mita offers virtual currency or premium features: (a) they have no cash value; (b) are non-transferable between accounts; (c) are non-refundable except as required by applicable law or app store policy; (d) may expire per terms disclosed at purchase; and (e) may be forfeited upon account termination for cause.
Transaction records are retained for a minimum of seven years to satisfy applicable accounting, tax, and consumer protection requirements.
Mita may send push notifications for: new content from followed creators, community interactions on your posts, destination alerts and travel tips, platform feature announcements, and account security alerts.
Control notification types in Settings > Notifications or via your device OS settings. Disabling all notifications may cause you to miss important security alerts.
Transactional emails (account confirmations, purchase receipts, security alerts) are essential for Service operation and cannot be unsubscribed from while your account is active. Marketing emails are optional and may be unsubscribed from at any time.
Delete your account at any time via Settings > Account > Delete Account, or by emailing service@mita.bet with subject “Account Deletion Request.”
Your profile, trip data, and public content are removed from view within 48 hours. Personal data is deleted from production servers within 30 days. Backup archives are purged within 90 days of the next scheduled rotation.
Certain data is retained where required by law: transaction records (up to 7 years); safety and moderation records (up to 3 years); data subject to a legal hold. All retained data is isolated and processed only for the purpose requiring its retention.
Mita does not transfer your personal information — including your travel plans, destination preferences, or itineraries — to airlines, hotels, tour operators, or travel insurance providers for their direct marketing purposes. Any integrations with travel booking or service platforms are performed at your explicit initiation with clear disclosure at the point of action.
The Service may contain affiliate links to travel products, accommodations, or experiences through which Mita or a content creator may earn a commission. The presence of an affiliate link does not influence how your personal data is processed, and we do not share your personal data with affiliate partners as a condition of affiliate arrangements.
Destination information, travel advisories, entry requirements, and local condition information on Mita is community-generated and for informational purposes only. Mita does not verify the real-time accuracy of this information. Always consult official government travel advisories before making travel decisions.
This Policy is governed by applicable international data protection law and the laws of the jurisdiction in which Mita is incorporated, except where mandatory local law in your country of residence imposes higher standards that cannot be contractually excluded.
If our response to a direct complaint has not resolved your concern, you retain the right to escalate to the relevant data protection supervisory authority in your country of residence.
Material changes are communicated at least 14 days before taking effect via in-app notice, push notification, and/or email to your registered address. Non-material corrections may be made without advance notice.
Continued use of Mita after any revised Policy's effective date constitutes acceptance. If you do not agree, delete your account before the changes take effect.
Prior versions are available upon request at service@mita.bet.
For questions, data rights requests, or privacy concerns:
We acknowledge inquiries within 5 business days and respond within 30 days.
Use the in-app Report function on any content or profile, or email service@mita.bet immediately with subject “CSAE Report.” These are our highest-priority safety matter, actioned without delay.