Privacy Policy for Lakbayo
Last Updated: August 5, 2026
Lakbayo is a mobile travel discovery and organization app operated by Pantoygames (“Lakbayo,” “we,” “us,” or “our”).
Lakbayo helps users discover hotel offers, save hotels, create shortlists and trips, compare options, view maps, receive optional promotional notifications, and open travel providers through affiliate links.
Lakbayo is not a hotel, booking platform, travel agency, or payment processor. We do not complete reservations, accept payments, manage check-ins or check-outs, issue refunds, or control the final price and availability shown by an external provider.
This Privacy Policy explains what information Lakbayo handles, why it is used, where it is stored, and the choices available to you.
1. Summary
Lakbayo does not require you to create a user account.
Most personal travel information you create in the app is stored locally on your device. This includes bookmarks, recently viewed hotels, shortlists, personal notes, trip details, itineraries, and checklists.
Some information is processed through our Cloudflare backend to provide hotel results, curated collections, public shared-trip links, optional notification subscriptions, security protections, error monitoring, and other server-supported features.
Lakbayo also uses Firebase services for analytics, crash reporting, limited deal-popularity information, and optional push-notification delivery.
Lakbayo does not sell your personal information or precise location.
2. Information We Handle
2.1 Information stored on your device
Depending on the features you use, Lakbayo may store the following information locally:
Bookmarked or saved hotel information
Hotel names, locations, images, prices, discounts, ratings, amenities, and affiliate links
Recently viewed hotels
Cached hotel results
The time hotel results were last refreshed
Cached hotel coordinates
Named hotel shortlists
Personal notes added to shortlists
Trip names and destinations
Optional travel dates
Personal travel budgets
Trip notes
Itinerary entries
Checklist items and their completion status
Hotels attached to shortlists or trips
Temporary hotel comparison selections
App preferences, including theme settings
Notification preferences, including followed destinations, followed collections, selected alert types, alert frequency, and notification status
A notification subscription identifier and management token when notifications are enabled
Temporary click-cooldown information used to prevent repeated clicks from artificially affecting hotel popularity
This information is generally stored in the app’s local database, app preferences, secure device storage, or storage managed by integrated service software on your device.
2.2 Information processed automatically
When Lakbayo communicates with our backend or third-party services, certain technical information may be processed automatically, including:
Internet Protocol address
Approximate network location derived from an IP address
Device type
Operating system and app version
Language or regional settings
Request date and time
Requested city identifier
Random request or diagnostic identifiers
Network status
Error and crash information
App usage events
Selected deal identifiers and categories
General interactions with app features
App-installation or app-instance identifiers
A push-notification registration token when notifications are enabled
We use this information to operate the app, return hotel results, deliver requested notifications, secure our backend, diagnose errors, measure feature usage, and prevent abuse.
2.3 Information you intentionally submit
If certain server-supported features are available and you choose to use them, we may process:
Trip information included in a shared trip
Notification preferences
Followed destination identifiers
Followed collection identifiers
Selected notification categories
Selected notification frequency
Hotel or deal reports
Free-form details included in a report
An app-installation identifier or similar identifier
Platform information needed to deliver notifications
A push-notification registration token
An unsubscribe or subscription-management token
Do not include passwords, payment details, government identification numbers, medical information, or other sensitive personal information in trip notes, report details, itinerary entries, or shared-trip content.
2.4 Information we do not directly collect
Lakbayo does not directly collect or process:
Credit or debit card numbers
Bank account details
Booking account passwords
Passport information
Government identification numbers
Hotel check-in or check-out information
Reservation payment details
Refund or cancellation information handled by an external provider
Any information you provide after leaving Lakbayo is processed under the external provider’s own privacy policy and terms.
3. Location Information
Lakbayo may request permission to access your device location when you use features such as Near Me, distance calculations, map positioning, or nearby hotel discovery.
If you grant location permission, Lakbayo may use your approximate or precise location to:
Identify nearby destinations or hotels
Display your position on a map
Calculate approximate distances
Sort hotels by proximity
Center the map around your location
Location access is requested only when needed for a location-based feature. Lakbayo does not continuously track your location in the background.
Your device location is primarily processed on your device. It may also be provided to mapping, geocoding, or operating-system services when necessary to display maps or translate coordinates into place information.
You may deny or revoke location access through your device settings. Some Near Me and map features may not work correctly without location permission.
Lakbayo does not sell your precise location.
4. Local Storage, Offline Data, and Device Backups
Lakbayo uses a local database and device preferences so that bookmarks, recently viewed hotels, shortlists, trips, notes, itineraries, checklists, notification preferences, and cached results can remain available without an internet connection.
This local information normally remains on your device unless:
You delete it within the app
You clear the app’s storage
You uninstall the app
Your operating system removes the app’s data
You deliberately use a feature that uploads a copy, such as sharing a trip through a public link
You enable notifications, which sends the notification information described in this policy to our backend and notification provider
Your device backup service backs up application data
Depending on your device and account settings, Android, Google, your device manufacturer, or another backup provider may include some Lakbayo app data in a device or cloud backup. Those backups are controlled by the relevant provider and your device settings.
Uninstalling Lakbayo may remove its active local data, but copies could remain temporarily in device backups until those backups expire or are deleted.
5. Sharing Hotels, Shortlists, and Trips
5.1 Sharing a hotel
When you share a hotel, Lakbayo uses your device’s standard share sheet.
The shared text may contain:
Hotel name
Displayed price
General hotel information
An affiliate link
The app you select from the share sheet controls how the shared information is processed.
5.2 Sharing a shortlist
When you share a shortlist, Lakbayo may generate a text summary containing selected hotel information.
The text is passed to your device’s standard share sheet. Lakbayo does not control the messaging, email, social media, or other app you choose to share it through.
5.3 Sharing a trip through a link
When you deliberately choose to share a trip, Lakbayo may upload a copy of the selected trip information to our Cloudflare backend and create a public link.
The uploaded information may include:
Trip name
Destination
Optional travel dates
Personal budget
Trip notes
Itinerary entries
Checklist text and completion status
Selected hotel snapshots
Hotel names, displayed prices, amenities, and affiliate links
Anyone who receives or obtains the link may be able to view the shared trip without signing in.
Do not include private, confidential, or sensitive information in a trip that you intend to share.
Shared-trip links normally expire after 30 days. An expired link will no longer display the trip, and the associated record is removed through routine cleanup.
If Lakbayo cannot create a shared link, such as when your device is offline, the app may fall back to sharing a text-only trip summary through the device share sheet.
If you want a shared-trip link removed before it expires, contact us and include the complete shared-trip URL. Only send the link if you are comfortable providing us access to the same shared content.
6. Cloudflare Backend and D1 Database
Lakbayo uses Cloudflare Workers as its backend and Cloudflare D1 as its server database.
Cloudflare helps us:
Protect affiliate credentials from being included in the mobile app
Request hotel information from an affiliate provider
Validate incoming requests
Cache hotel responses
Apply rate limits
Return safe error responses
Provide curated hotel collections
Create expiring shared-trip links
Store limited operational price snapshots
Process hotel reports if that feature is available
Store and manage optional notification subscriptions
Store notification campaigns and limited delivery records
Run scheduled data-refresh and notification-delivery tasks
Monitor backend errors
6.1 Hotel requests
When you request hotel results, the app may send the selected city identifier and standard technical request information to the Cloudflare backend.
The backend requests the corresponding hotel information from an affiliate provider and returns only the fields needed by Lakbayo.
Hotel responses may be cached temporarily to improve performance, reduce unnecessary provider requests, and help control service usage.
6.2 Rate limiting
To protect the backend against abuse, Cloudflare provides the originating IP address to the Worker.
The Worker converts the IP address into a SHA-256 hash and stores the hash with a short time bucket and request count. Lakbayo does not intentionally store the raw IP address in the D1 rate-limit table.
These rate-limit records are temporary and are deleted through routine scheduled cleanup.
Although Lakbayo does not intentionally save raw IP addresses in its own D1 rate-limit table, Cloudflare may independently process network information as part of providing its infrastructure and security services.
6.3 Curated collections and disabled deals
D1 may contain server-managed hotel collections and operational records identifying deals that should not be displayed.
These records are used to manage the content available in Lakbayo and generally do not contain user personal information.
6.4 Price snapshots
D1 may store limited hotel price snapshots for selected destinations.
A price snapshot may contain:
Hotel identifier
City identifier
Currency
Displayed price
Original displayed price
Discount percentage
Time the price was checked
Price snapshots are used for operational monitoring and potential future price-related features. They do not intentionally include user identity, payment information, hotel descriptions, or personal trip information.
Lakbayo does not currently provide automated price-watch notifications.
Final prices and availability are always controlled and displayed by the external provider.
6.5 Notification subscriptions
If you choose to enable notifications, Lakbayo sends limited subscription information to the Cloudflare backend.
The backend may store:
A randomly generated subscription identifier
A hashed app-installation identifier
Device platform
A Firebase Cloud Messaging registration token or similar notification destination
Followed destination identifiers
Followed collection identifiers
Selected notification categories
Selected notification frequency
Subscription status
A hashed unsubscribe or management token
The time the subscription was created or updated
The time a notification was most recently sent
This information is used to match your preferences with available notification campaigns and deliver the alerts you requested.
Notification categories may include:
New-discount campaigns
Trending-hotel campaigns
Curated promotional campaigns
Creating a notification campaign is an administrative action. Cloudflare automatically delivers active campaigns to eligible subscriptions based on followed destinations, followed collections, selected alert categories, and selected frequency.
Lakbayo does not use notification subscriptions to create a named user profile or booking history.
6.6 Notification campaigns and delivery records
The Cloudflare backend may store notification campaign information, including:
Campaign type
Notification title and message
Hotel identifier
City identifier
Collection identifier
Affiliate link
Campaign status
Start and expiration times
The backend may also store limited delivery records, including:
Campaign identifier
Subscription identifier
Whether delivery succeeded or failed
A limited technical error code
Time delivery was attempted
Delivery records are used to prevent duplicate notifications, apply the selected alert frequency, troubleshoot delivery problems, and disable invalid notification destinations.
Notification credentials and registration tokens are designed not to appear in Lakbayo application logs.
6.7 Disabling notifications
You may turn off notifications from the notification-preferences screen inside Lakbayo.
Turning notifications off inside Lakbayo requests removal of the corresponding subscription from the Cloudflare backend and removes locally stored subscription-management information.
You may also block notification permission through Android Settings. Blocking permission prevents notifications from being displayed, but it may not immediately notify Lakbayo’s backend that the subscription should be removed. To request removal of the server subscription, use the Turn Off option inside Lakbayo before uninstalling the app when reasonably possible.
A registration token that Firebase reports as invalid may be automatically disabled by the backend.
6.8 Hotel reports
If Lakbayo offers a report feature and you submit a report, the backend may store:
Hotel identifier
City identifier
Report reason
Details you voluntarily enter
Report status
Creation and update times
Reports are used to investigate broken links, inaccurate hotel information, inappropriate content, or other reported problems.
Do not include unnecessary personal or sensitive information in report details.
6.9 Error and operational records
The backend may store limited technical records such as:
Random request identifier
Operation name
Error code
Response status
City identifier
Time of the error
Scheduled refresh status
Number of cities processed
Number of price snapshots created
These records help us diagnose technical problems and monitor the reliability of the service.
We design logs to avoid storing affiliate credentials, notification credentials, authorization secrets, full shared-trip content, or unnecessary personal information.
For more information about Cloudflare’s processing practices, see:
https://www.cloudflare.com/privacypolicy/
7. Maps and OpenStreetMap
Lakbayo may use OpenStreetMap data and map-related software or content-delivery services to display hotel locations.
When a map is displayed, the map provider may receive:
Your IP address
Browser or embedded web-view information
Device and network information
The map area and tiles requested
Request date and time
The map area requested may reveal the general location being viewed, but this does not necessarily mean that it represents your current physical location.
For more information, see:
https://osmfoundation.org/wiki/Privacy_Policy
8. Firebase Services
Lakbayo uses Firebase services provided by Google.
These services may include:
Firebase Analytics
Firebase Crashlytics
Cloud Firestore
Firebase Cloud Messaging
8.1 Analytics
Firebase Analytics helps us understand how users interact with the app.
Analytics events may contain information such as:
Deal identifier
Deal title
City
Deal category
App version
Device and operating-system information
General feature interactions
App-instance identifiers generated by Firebase
We use this information to understand feature usage and improve the app.
8.2 Crash reporting
Firebase Crashlytics may collect crash reports and technical diagnostic information, including:
Device model
Operating system
App version
Crash stack traces
Error conditions
Diagnostic identifiers
Technical state at the time of a crash
This information helps us identify and fix stability problems.
8.3 Deal-popularity information
Lakbayo may store limited deal-click information in Cloud Firestore to calculate popularity and trending labels.
This information may include:
Deal identifier
Deal title
City
Category
Click count
Most recent click time
Lakbayo uses an on-device cooldown to reduce repeated clicks from the same installation artificially affecting rankings.
The stored popularity record is associated with the deal, not with a named user account.
8.4 Firebase Cloud Messaging
If you enable notifications, the Firebase Cloud Messaging software on your device registers the app instance to receive notifications and provides a registration token.
Lakbayo sends this token to the Cloudflare backend so that requested notifications can be addressed to your app installation.
Firebase Cloud Messaging may process:
A Firebase app-instance or installation identifier
The notification registration token
Device platform and technical information
Notification title and message
Campaign identifier and category
Hotel, city, or collection identifiers associated with the notification
An affiliate link included with the notification
Message-delivery and technical diagnostic information
A notification may be displayed on your lock screen or notification tray depending on your device settings. You are responsible for choosing notification and lock-screen privacy settings appropriate for your device.
When you tap a hotel notification, Lakbayo may open the included affiliate link in your browser or another supported external application.
For more information, see:
Firebase Privacy and Security:
https://firebase.google.com/support/privacy/
Firebase Cloud Messaging:
https://firebase.google.com/docs/cloud-messaging
Google Privacy Policy:
https://policies.google.com/privacy
9. Affiliate Links and External Providers
Lakbayo is an affiliate travel discovery app.
When you select “View deal,” tap a promotional hotel notification, or use another external-offer button, Lakbayo opens the corresponding travel or booking provider in a browser or supported external application.
The affiliate link may contain information used to attribute the referral to Lakbayo. We may receive a commission if you complete an eligible transaction with the provider.
Opening an affiliate link may allow the provider to process:
IP address
Device and browser information
Referral or affiliate identifiers
Cookies or similar technologies
Search and booking activity
Account information you provide to the provider
Payment and reservation information you provide to the provider
Lakbayo does not control the external provider’s website, app, availability, prices, reservation process, payment processing, cancellation policies, refunds, or privacy practices.
Once you leave Lakbayo, the provider’s own privacy policy and terms apply.
Lakbayo does not receive your complete payment-card information or provider account password.
10. How We Use Information
We use information handled through Lakbayo to:
Display hotel offers and curated collections
Provide search, sorting, and filtering
Calculate approximate hotel distances
Display hotels on a map
Maintain bookmarks and recently viewed hotels
Provide offline access to saved and cached information
Create and manage shortlists and trips
Generate hotel, shortlist, and trip-sharing content
Create public shared-trip links when requested
Calculate deal popularity and trending labels
Register app installations for optional notifications
Store and apply followed destinations and collections
Apply notification-category and frequency preferences
Deliver new-discount, trending-hotel, and curated promotional campaigns
Prevent duplicate or excessive notification delivery
Open an affiliate link when a notification is selected
Investigate user-submitted reports
Protect the backend against abuse
Apply request limits
Cache hotel responses
Diagnose crashes, notification failures, and API errors
Monitor scheduled data refreshes and notification delivery
Maintain app security and reliability
Comply with legal obligations
Enforce our terms and protect users, the service, and third parties
11. How Information Is Shared
We may disclose or allow limited information to be processed by:
Cloudflare, for backend hosting, D1 storage, notification-subscription management, scheduled delivery, caching, security, and request processing
Google and Firebase, for analytics, crash reporting, deal-popularity storage, app-instance registration, and notification delivery
Map and geocoding providers, when map or location-related services are used
Affiliate travel or booking providers, when requesting offers or opening an external deal
Apps you select through your device’s standard share sheet
People who receive a public shared-trip link
Service providers that help us operate, secure, or maintain Lakbayo
Government agencies or other parties when disclosure is legally required
Successors involved in a merger, acquisition, reorganization, or transfer of the service
We do not sell your personal information.
We do not automatically upload your locally stored shortlists, notes, itineraries, or checklists unless you deliberately use a feature that requires uploading a copy, such as creating a shared-trip link.
12. Data Retention
We keep information only for as long as reasonably necessary for the purpose for which it was collected.
Current retention practices include:
Local app data: Remains on your device until you delete it, clear app storage, uninstall the app, or your operating system removes it.
Recently viewed hotels: Limited to a reasonable number of recent entries, currently up to 50.
Cached hotel results: Retained locally until replaced, refreshed, cleared, or removed by the operating system.
Shared trips: Normally expire after 30 days.
Rate-limit records: Kept temporarily and removed through routine scheduled cleanup.
Price snapshots: Normally retained for up to 30 days.
Backend API error records: Normally retained for up to 30 days.
Scheduled-refresh records: Normally retained for up to 30 days.
Notification subscriptions: Retained until turned off inside Lakbayo, unsubscribed, deleted, automatically disabled because the notification destination is invalid, or no longer needed to provide the feature.
Notification delivery records: Normally retained for up to 30 days.
Expired notification campaigns: Normally removed through routine cleanup after they are no longer active.
Hotel reports: Retained for as long as necessary to investigate, resolve, document, or prevent the reported issue.
Curated collections and disabled-deal records: Retained while operationally useful.
Firebase analytics, crash, app-installation, messaging, and delivery information: Retained according to our Firebase configuration and Google’s applicable retention practices.
Deleted information may remain temporarily in encrypted backups, recovery systems, caches, or provider infrastructure before it ages out.
We may retain certain information longer when required for security, fraud prevention, dispute resolution, legal compliance, or enforcement of our agreements.
13. Your Choices and Controls
You may control your information in the following ways:
Deny or revoke location permission through device settings
Clear your recently viewed history in the app
Remove bookmarks, shortlists, notes, trips, itinerary entries, or checklist items
Clear the app’s storage through device settings
Uninstall Lakbayo
Choose not to create or share a public trip link
Avoid including sensitive information in shared trips or reports
Choose whether to enable notifications
Choose followed destinations and collections
Choose notification categories and frequency
Turn notifications off inside Lakbayo to request removal of the server subscription
Block notification permission through Android Settings
Control lock-screen notification visibility through device settings
Control Firebase-related advertising or analytics settings through your device or Google settings, where available
Choose which app receives content from the standard share sheet
Decline to open an external affiliate link
Because Lakbayo does not require a user account, we may not be able to identify or retrieve information stored only on your device.
For a shared-trip deletion request, provide the complete shared-trip URL so we can identify the associated server record.
If you cannot access the in-app Turn Off option and want assistance removing a notification subscription, contact us. We may need limited technical information to determine whether a particular subscription can be identified.
14. Security
We use reasonable technical and organizational safeguards designed to protect information handled through Lakbayo.
These safeguards include:
HTTPS network connections
Server-side storage of affiliate credentials
Cloudflare Worker Secrets
Secure server-side storage of notification-service credentials
Hashed notification installation identifiers
Hashed notification-management tokens
Request validation
Rate limiting
Temporary response caching
Hashed rate-limit identifiers
Hashed shared-trip tokens
Expiring shared-trip links
Restricted administrative endpoints
Safe error responses
Logging practices designed to exclude credentials and notification tokens
Limited data collection
Scheduled cleanup of temporary operational data
No application, network transmission, database, or storage system can be guaranteed to be completely secure.
You are responsible for protecting any shared-trip link you create. Anyone with access to that link may be able to view its contents until it expires or is removed.
15. International Processing
Lakbayo’s service providers may process information in countries other than the country where you live.
Cloudflare, Google, Firebase, mapping providers, affiliate providers, and other service providers may operate infrastructure in multiple regions.
When information is processed internationally, it may be subject to the laws of the country where it is processed.
16. Children’s Privacy
Lakbayo is not directed to children under 13 years of age.
We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information through Lakbayo, contact us so we can investigate and take appropriate action.
17. Changes to This Privacy Policy
We may update this Privacy Policy when Lakbayo’s features, service providers, data practices, or legal obligations change.
When we make changes, we will update the “Last Updated” date at the top of this policy.
Material changes may also be communicated through the app, website, store listing, or another appropriate method.
Your continued use of Lakbayo after an updated policy becomes available means the updated policy will apply to future use of the app.
18. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or Lakbayo’s handling of information, contact:
Pantoygames
Email: pantoygames@gmail.com
When requesting deletion of a shared trip, include the complete shared-trip URL so we can identify the relevant record.
Innovation
Creating engaging games from the heart of Butuan.
© 2025. All rights reserved.
