Privacy Policy

Last updated: June 14, 2026


Who we are

Lanyard is operated by 2315 Media, a UK-based company.

Contact us: privacy@2315media.com

What data we collect

Data Source Purpose
Email address OAuth provider (Google, Apple, or SSO) Account identification, notifications
Name OAuth provider Display name, avatar initials
Profile picture URL OAuth provider Avatar display
User ID Generated at sign-up Internal account reference
Trip data (names, dates, cards, notes) You (entered in the app) Trip planning and sharing
Tags and custom fields You Organisation of trip content
File attachments You (uploaded files) Card attachments

Lawful basis for processing

Purpose Lawful basis
Account management Legitimate interest — necessary to provide the service
Trip planning Consent — you create this content voluntarily
Sharing itineraries Legitimate interest — sharing is a core app feature
Error monitoring Legitimate interest — necessary for application stability
Invitations Consent — you initiate invitations; recipients receive by email
User support Consent — you explicitly enable support access

Who we share data with

  • AWS (London, UK) — server hosting (EC2), database (RDS PostgreSQL), and file storage (S3)
  • Sentry.io (EU — Ireland) — error monitoring and session replays
  • Google / Apple / OIDC provider — authentication only
  • Adobe TypeKit — font delivery (no personal data beyond HTTP request metadata)

We do not sell your data to third parties.

International transfers

  • AWS: London, UK (eu-west-2). All infrastructure (EC2, RDS, S3) remains in the UK.
  • Sentry.io: EU-based (Ireland). Data remains within the EU. Transfer covered by UK adequacy decision for EU transfers.
  • Adobe TypeKit: Content delivery network varies by edge node.

Data retention

Data type Retention period
Account data (profile, trips, cards, notes) Until account deletion
Server logs 12 months
Support access grants 24 hours (auto-expire)
Invitations 7 days
Error traces (Sentry) 90 days
Session replays (Sentry) 30 days

Your rights

Under the UK GDPR and Data Protection Act 2018, you have the following rights:

Cookies

Lanyard uses only essential cookies that are strictly necessary for the website to function:

Cookie Purpose Duration
sessionid Session management Session
csrftoken CSRF protection 1 year
messages Flash message storage Session
django_language Language preference 1 year

All of these cookies are essential/strictly necessary. No tracking, analytics, or marketing cookies are used.

Complaints

If you believe we have failed to comply with data protection law, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Changes to this policy

We will update this policy when our data processing activities change. Check the "Last updated" date at the top of this page for the latest version.