Privacy Policy for Lakbayo

Last Updated: August 5, 2026

Lakbayo is a mobile travel discovery and organization app operated by Pantoygames (“Lakbayo,” “we,” “us,” or “our”).

Lakbayo helps users discover hotel offers, save hotels, create shortlists and trips, compare options, view maps, receive optional promotional notifications, and open travel providers through affiliate links.

Lakbayo is not a hotel, booking platform, travel agency, or payment processor. We do not complete reservations, accept payments, manage check-ins or check-outs, issue refunds, or control the final price and availability shown by an external provider.

This Privacy Policy explains what information Lakbayo handles, why it is used, where it is stored, and the choices available to you.

1. Summary

Lakbayo does not require you to create a user account.

Most personal travel information you create in the app is stored locally on your device. This includes bookmarks, recently viewed hotels, shortlists, personal notes, trip details, itineraries, and checklists.

Some information is processed through our Cloudflare backend to provide hotel results, curated collections, public shared-trip links, optional notification subscriptions, security protections, error monitoring, and other server-supported features.

Lakbayo also uses Firebase services for analytics, crash reporting, limited deal-popularity information, and optional push-notification delivery.

Lakbayo does not sell your personal information or precise location.

2. Information We Handle

2.1 Information stored on your device

Depending on the features you use, Lakbayo may store the following information locally:

Bookmarked or saved hotel information

Hotel names, locations, images, prices, discounts, ratings, amenities, and affiliate links

Recently viewed hotels

Cached hotel results

The time hotel results were last refreshed

Cached hotel coordinates

Named hotel shortlists

Personal notes added to shortlists

Trip names and destinations

Optional travel dates

Personal travel budgets

Trip notes

Itinerary entries

Checklist items and their completion status

Hotels attached to shortlists or trips

Temporary hotel comparison selections

App preferences, including theme settings

Notification preferences, including followed destinations, followed collections, selected alert types, alert frequency, and notification status

A notification subscription identifier and management token when notifications are enabled

Temporary click-cooldown information used to prevent repeated clicks from artificially affecting hotel popularity

This information is generally stored in the app’s local database, app preferences, secure device storage, or storage managed by integrated service software on your device.

2.2 Information processed automatically

When Lakbayo communicates with our backend or third-party services, certain technical information may be processed automatically, including:

Internet Protocol address

Approximate network location derived from an IP address

Device type

Operating system and app version

Language or regional settings

Request date and time

Requested city identifier

Random request or diagnostic identifiers

Network status

Error and crash information

App usage events

Selected deal identifiers and categories

General interactions with app features

App-installation or app-instance identifiers

A push-notification registration token when notifications are enabled

We use this information to operate the app, return hotel results, deliver requested notifications, secure our backend, diagnose errors, measure feature usage, and prevent abuse.

2.3 Information you intentionally submit

If certain server-supported features are available and you choose to use them, we may process:

Trip information included in a shared trip

Notification preferences

Followed destination identifiers

Followed collection identifiers

Selected notification categories

Selected notification frequency

Hotel or deal reports

Free-form details included in a report

An app-installation identifier or similar identifier

Platform information needed to deliver notifications

A push-notification registration token

An unsubscribe or subscription-management token

Do not include passwords, payment details, government identification numbers, medical information, or other sensitive personal information in trip notes, report details, itinerary entries, or shared-trip content.

2.4 Information we do not directly collect

Lakbayo does not directly collect or process:

Credit or debit card numbers

Bank account details

Booking account passwords

Passport information

Government identification numbers

Hotel check-in or check-out information

Reservation payment details

Refund or cancellation information handled by an external provider

Any information you provide after leaving Lakbayo is processed under the external provider’s own privacy policy and terms.

3. Location Information

Lakbayo may request permission to access your device location when you use features such as Near Me, distance calculations, map positioning, or nearby hotel discovery.

If you grant location permission, Lakbayo may use your approximate or precise location to:

Identify nearby destinations or hotels

Display your position on a map

Calculate approximate distances

Sort hotels by proximity

Center the map around your location

Location access is requested only when needed for a location-based feature. Lakbayo does not continuously track your location in the background.

Your device location is primarily processed on your device. It may also be provided to mapping, geocoding, or operating-system services when necessary to display maps or translate coordinates into place information.

You may deny or revoke location access through your device settings. Some Near Me and map features may not work correctly without location permission.

Lakbayo does not sell your precise location.

4. Local Storage, Offline Data, and Device Backups

Lakbayo uses a local database and device preferences so that bookmarks, recently viewed hotels, shortlists, trips, notes, itineraries, checklists, notification preferences, and cached results can remain available without an internet connection.

This local information normally remains on your device unless:

You delete it within the app

You clear the app’s storage

You uninstall the app

Your operating system removes the app’s data

You deliberately use a feature that uploads a copy, such as sharing a trip through a public link

You enable notifications, which sends the notification information described in this policy to our backend and notification provider

Your device backup service backs up application data

Depending on your device and account settings, Android, Google, your device manufacturer, or another backup provider may include some Lakbayo app data in a device or cloud backup. Those backups are controlled by the relevant provider and your device settings.

Uninstalling Lakbayo may remove its active local data, but copies could remain temporarily in device backups until those backups expire or are deleted.

5. Sharing Hotels, Shortlists, and Trips

5.1 Sharing a hotel

When you share a hotel, Lakbayo uses your device’s standard share sheet.

The shared text may contain:

Hotel name

Displayed price

General hotel information

An affiliate link

The app you select from the share sheet controls how the shared information is processed.

5.2 Sharing a shortlist

When you share a shortlist, Lakbayo may generate a text summary containing selected hotel information.

The text is passed to your device’s standard share sheet. Lakbayo does not control the messaging, email, social media, or other app you choose to share it through.

5.3 Sharing a trip through a link

When you deliberately choose to share a trip, Lakbayo may upload a copy of the selected trip information to our Cloudflare backend and create a public link.

The uploaded information may include:

Trip name

Destination

Optional travel dates

Personal budget

Trip notes

Itinerary entries

Checklist text and completion status

Selected hotel snapshots

Hotel names, displayed prices, amenities, and affiliate links

Anyone who receives or obtains the link may be able to view the shared trip without signing in.

Do not include private, confidential, or sensitive information in a trip that you intend to share.

Shared-trip links normally expire after 30 days. An expired link will no longer display the trip, and the associated record is removed through routine cleanup.

If Lakbayo cannot create a shared link, such as when your device is offline, the app may fall back to sharing a text-only trip summary through the device share sheet.

If you want a shared-trip link removed before it expires, contact us and include the complete shared-trip URL. Only send the link if you are comfortable providing us access to the same shared content.

6. Cloudflare Backend and D1 Database

Lakbayo uses Cloudflare Workers as its backend and Cloudflare D1 as its server database.

Cloudflare helps us:

Protect affiliate credentials from being included in the mobile app

Request hotel information from an affiliate provider

Validate incoming requests

Cache hotel responses

Apply rate limits

Return safe error responses

Provide curated hotel collections

Create expiring shared-trip links

Store limited operational price snapshots

Process hotel reports if that feature is available

Store and manage optional notification subscriptions

Store notification campaigns and limited delivery records

Run scheduled data-refresh and notification-delivery tasks

Monitor backend errors

6.1 Hotel requests

When you request hotel results, the app may send the selected city identifier and standard technical request information to the Cloudflare backend.

The backend requests the corresponding hotel information from an affiliate provider and returns only the fields needed by Lakbayo.

Hotel responses may be cached temporarily to improve performance, reduce unnecessary provider requests, and help control service usage.

6.2 Rate limiting

To protect the backend against abuse, Cloudflare provides the originating IP address to the Worker.

The Worker converts the IP address into a SHA-256 hash and stores the hash with a short time bucket and request count. Lakbayo does not intentionally store the raw IP address in the D1 rate-limit table.

These rate-limit records are temporary and are deleted through routine scheduled cleanup.

Although Lakbayo does not intentionally save raw IP addresses in its own D1 rate-limit table, Cloudflare may independently process network information as part of providing its infrastructure and security services.

6.3 Curated collections and disabled deals

D1 may contain server-managed hotel collections and operational records identifying deals that should not be displayed.

These records are used to manage the content available in Lakbayo and generally do not contain user personal information.

6.4 Price snapshots

D1 may store limited hotel price snapshots for selected destinations.

A price snapshot may contain:

Hotel identifier

City identifier

Currency

Displayed price

Original displayed price

Discount percentage

Time the price was checked

Price snapshots are used for operational monitoring and potential future price-related features. They do not intentionally include user identity, payment information, hotel descriptions, or personal trip information.

Lakbayo does not currently provide automated price-watch notifications.

Final prices and availability are always controlled and displayed by the external provider.

6.5 Notification subscriptions

If you choose to enable notifications, Lakbayo sends limited subscription information to the Cloudflare backend.

The backend may store:

A randomly generated subscription identifier

A hashed app-installation identifier

Device platform

A Firebase Cloud Messaging registration token or similar notification destination

Followed destination identifiers

Followed collection identifiers

Selected notification categories

Selected notification frequency

Subscription status

A hashed unsubscribe or management token

The time the subscription was created or updated

The time a notification was most recently sent

This information is used to match your preferences with available notification campaigns and deliver the alerts you requested.

Notification categories may include:

New-discount campaigns

Trending-hotel campaigns

Curated promotional campaigns

Creating a notification campaign is an administrative action. Cloudflare automatically delivers active campaigns to eligible subscriptions based on followed destinations, followed collections, selected alert categories, and selected frequency.

Lakbayo does not use notification subscriptions to create a named user profile or booking history.

6.6 Notification campaigns and delivery records

The Cloudflare backend may store notification campaign information, including:

Campaign type

Notification title and message

Hotel identifier

City identifier

Collection identifier

Affiliate link

Campaign status

Start and expiration times

The backend may also store limited delivery records, including:

Campaign identifier

Subscription identifier

Whether delivery succeeded or failed

A limited technical error code

Time delivery was attempted

Delivery records are used to prevent duplicate notifications, apply the selected alert frequency, troubleshoot delivery problems, and disable invalid notification destinations.

Notification credentials and registration tokens are designed not to appear in Lakbayo application logs.

6.7 Disabling notifications

You may turn off notifications from the notification-preferences screen inside Lakbayo.

Turning notifications off inside Lakbayo requests removal of the corresponding subscription from the Cloudflare backend and removes locally stored subscription-management information.

You may also block notification permission through Android Settings. Blocking permission prevents notifications from being displayed, but it may not immediately notify Lakbayo’s backend that the subscription should be removed. To request removal of the server subscription, use the Turn Off option inside Lakbayo before uninstalling the app when reasonably possible.

A registration token that Firebase reports as invalid may be automatically disabled by the backend.

6.8 Hotel reports

If Lakbayo offers a report feature and you submit a report, the backend may store:

Hotel identifier

City identifier

Report reason

Details you voluntarily enter

Report status

Creation and update times

Reports are used to investigate broken links, inaccurate hotel information, inappropriate content, or other reported problems.

Do not include unnecessary personal or sensitive information in report details.

6.9 Error and operational records

The backend may store limited technical records such as:

Random request identifier

Operation name

Error code

Response status

City identifier

Time of the error

Scheduled refresh status

Number of cities processed

Number of price snapshots created

These records help us diagnose technical problems and monitor the reliability of the service.

We design logs to avoid storing affiliate credentials, notification credentials, authorization secrets, full shared-trip content, or unnecessary personal information.

For more information about Cloudflare’s processing practices, see:

https://www.cloudflare.com/privacypolicy/

7. Maps and OpenStreetMap

Lakbayo may use OpenStreetMap data and map-related software or content-delivery services to display hotel locations.

When a map is displayed, the map provider may receive:

Your IP address

Browser or embedded web-view information

Device and network information

The map area and tiles requested

Request date and time

The map area requested may reveal the general location being viewed, but this does not necessarily mean that it represents your current physical location.

For more information, see:

https://osmfoundation.org/wiki/Privacy_Policy

8. Firebase Services

Lakbayo uses Firebase services provided by Google.

These services may include:

Firebase Analytics

Firebase Crashlytics

Cloud Firestore

Firebase Cloud Messaging

8.1 Analytics

Firebase Analytics helps us understand how users interact with the app.

Analytics events may contain information such as:

Deal identifier

Deal title

City

Deal category

App version

Device and operating-system information

General feature interactions

App-instance identifiers generated by Firebase

We use this information to understand feature usage and improve the app.

8.2 Crash reporting

Firebase Crashlytics may collect crash reports and technical diagnostic information, including:

Device model

Operating system

App version

Crash stack traces

Error conditions

Diagnostic identifiers

Technical state at the time of a crash

This information helps us identify and fix stability problems.

8.3 Deal-popularity information

Lakbayo may store limited deal-click information in Cloud Firestore to calculate popularity and trending labels.

This information may include:

Deal identifier

Deal title

City

Category

Click count

Most recent click time

Lakbayo uses an on-device cooldown to reduce repeated clicks from the same installation artificially affecting rankings.

The stored popularity record is associated with the deal, not with a named user account.

8.4 Firebase Cloud Messaging

If you enable notifications, the Firebase Cloud Messaging software on your device registers the app instance to receive notifications and provides a registration token.

Lakbayo sends this token to the Cloudflare backend so that requested notifications can be addressed to your app installation.

Firebase Cloud Messaging may process:

A Firebase app-instance or installation identifier

The notification registration token

Device platform and technical information

Notification title and message

Campaign identifier and category

Hotel, city, or collection identifiers associated with the notification

An affiliate link included with the notification

Message-delivery and technical diagnostic information

A notification may be displayed on your lock screen or notification tray depending on your device settings. You are responsible for choosing notification and lock-screen privacy settings appropriate for your device.

When you tap a hotel notification, Lakbayo may open the included affiliate link in your browser or another supported external application.

For more information, see:

Firebase Privacy and Security:

https://firebase.google.com/support/privacy/

Firebase Cloud Messaging:

https://firebase.google.com/docs/cloud-messaging

Google Privacy Policy:

https://policies.google.com/privacy

9. Affiliate Links and External Providers

Lakbayo is an affiliate travel discovery app.

When you select “View deal,” tap a promotional hotel notification, or use another external-offer button, Lakbayo opens the corresponding travel or booking provider in a browser or supported external application.

The affiliate link may contain information used to attribute the referral to Lakbayo. We may receive a commission if you complete an eligible transaction with the provider.

Opening an affiliate link may allow the provider to process:

IP address

Device and browser information

Referral or affiliate identifiers

Cookies or similar technologies

Search and booking activity

Account information you provide to the provider

Payment and reservation information you provide to the provider

Lakbayo does not control the external provider’s website, app, availability, prices, reservation process, payment processing, cancellation policies, refunds, or privacy practices.

Once you leave Lakbayo, the provider’s own privacy policy and terms apply.

Lakbayo does not receive your complete payment-card information or provider account password.

10. How We Use Information

We use information handled through Lakbayo to:

Display hotel offers and curated collections

Provide search, sorting, and filtering

Calculate approximate hotel distances

Display hotels on a map

Maintain bookmarks and recently viewed hotels

Provide offline access to saved and cached information

Create and manage shortlists and trips

Generate hotel, shortlist, and trip-sharing content

Create public shared-trip links when requested

Calculate deal popularity and trending labels

Register app installations for optional notifications

Store and apply followed destinations and collections

Apply notification-category and frequency preferences

Deliver new-discount, trending-hotel, and curated promotional campaigns

Prevent duplicate or excessive notification delivery

Open an affiliate link when a notification is selected

Investigate user-submitted reports

Protect the backend against abuse

Apply request limits

Cache hotel responses

Diagnose crashes, notification failures, and API errors

Monitor scheduled data refreshes and notification delivery

Maintain app security and reliability

Comply with legal obligations

Enforce our terms and protect users, the service, and third parties

11. How Information Is Shared

We may disclose or allow limited information to be processed by:

Cloudflare, for backend hosting, D1 storage, notification-subscription management, scheduled delivery, caching, security, and request processing

Google and Firebase, for analytics, crash reporting, deal-popularity storage, app-instance registration, and notification delivery

Map and geocoding providers, when map or location-related services are used

Affiliate travel or booking providers, when requesting offers or opening an external deal

Apps you select through your device’s standard share sheet

People who receive a public shared-trip link

Service providers that help us operate, secure, or maintain Lakbayo

Government agencies or other parties when disclosure is legally required

Successors involved in a merger, acquisition, reorganization, or transfer of the service

We do not sell your personal information.

We do not automatically upload your locally stored shortlists, notes, itineraries, or checklists unless you deliberately use a feature that requires uploading a copy, such as creating a shared-trip link.

12. Data Retention

We keep information only for as long as reasonably necessary for the purpose for which it was collected.

Current retention practices include:

Local app data: Remains on your device until you delete it, clear app storage, uninstall the app, or your operating system removes it.

Recently viewed hotels: Limited to a reasonable number of recent entries, currently up to 50.

Cached hotel results: Retained locally until replaced, refreshed, cleared, or removed by the operating system.

Shared trips: Normally expire after 30 days.

Rate-limit records: Kept temporarily and removed through routine scheduled cleanup.

Price snapshots: Normally retained for up to 30 days.

Backend API error records: Normally retained for up to 30 days.

Scheduled-refresh records: Normally retained for up to 30 days.

Notification subscriptions: Retained until turned off inside Lakbayo, unsubscribed, deleted, automatically disabled because the notification destination is invalid, or no longer needed to provide the feature.

Notification delivery records: Normally retained for up to 30 days.

Expired notification campaigns: Normally removed through routine cleanup after they are no longer active.

Hotel reports: Retained for as long as necessary to investigate, resolve, document, or prevent the reported issue.

Curated collections and disabled-deal records: Retained while operationally useful.

Firebase analytics, crash, app-installation, messaging, and delivery information: Retained according to our Firebase configuration and Google’s applicable retention practices.

Deleted information may remain temporarily in encrypted backups, recovery systems, caches, or provider infrastructure before it ages out.

We may retain certain information longer when required for security, fraud prevention, dispute resolution, legal compliance, or enforcement of our agreements.

13. Your Choices and Controls

You may control your information in the following ways:

Deny or revoke location permission through device settings

Clear your recently viewed history in the app

Remove bookmarks, shortlists, notes, trips, itinerary entries, or checklist items

Clear the app’s storage through device settings

Uninstall Lakbayo

Choose not to create or share a public trip link

Avoid including sensitive information in shared trips or reports

Choose whether to enable notifications

Choose followed destinations and collections

Choose notification categories and frequency

Turn notifications off inside Lakbayo to request removal of the server subscription

Block notification permission through Android Settings

Control lock-screen notification visibility through device settings

Control Firebase-related advertising or analytics settings through your device or Google settings, where available

Choose which app receives content from the standard share sheet

Decline to open an external affiliate link

Because Lakbayo does not require a user account, we may not be able to identify or retrieve information stored only on your device.

For a shared-trip deletion request, provide the complete shared-trip URL so we can identify the associated server record.

If you cannot access the in-app Turn Off option and want assistance removing a notification subscription, contact us. We may need limited technical information to determine whether a particular subscription can be identified.

14. Security

We use reasonable technical and organizational safeguards designed to protect information handled through Lakbayo.

These safeguards include:

HTTPS network connections

Server-side storage of affiliate credentials

Cloudflare Worker Secrets

Secure server-side storage of notification-service credentials

Hashed notification installation identifiers

Hashed notification-management tokens

Request validation

Rate limiting

Temporary response caching

Hashed rate-limit identifiers

Hashed shared-trip tokens

Expiring shared-trip links

Restricted administrative endpoints

Safe error responses

Logging practices designed to exclude credentials and notification tokens

Limited data collection

Scheduled cleanup of temporary operational data

No application, network transmission, database, or storage system can be guaranteed to be completely secure.

You are responsible for protecting any shared-trip link you create. Anyone with access to that link may be able to view its contents until it expires or is removed.

15. International Processing

Lakbayo’s service providers may process information in countries other than the country where you live.

Cloudflare, Google, Firebase, mapping providers, affiliate providers, and other service providers may operate infrastructure in multiple regions.

When information is processed internationally, it may be subject to the laws of the country where it is processed.

16. Children’s Privacy

Lakbayo is not directed to children under 13 years of age.

We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information through Lakbayo, contact us so we can investigate and take appropriate action.

17. Changes to This Privacy Policy

We may update this Privacy Policy when Lakbayo’s features, service providers, data practices, or legal obligations change.

When we make changes, we will update the “Last Updated” date at the top of this policy.

Material changes may also be communicated through the app, website, store listing, or another appropriate method.

Your continued use of Lakbayo after an updated policy becomes available means the updated policy will apply to future use of the app.

18. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or Lakbayo’s handling of information, contact:

Pantoygames

Email: pantoygames@gmail.com

When requesting deletion of a shared trip, include the complete shared-trip URL so we can identify the relevant record.

Innovation

Creating engaging games from the heart of Butuan.

© 2025. All rights reserved.