Legal
Privacy Policy
Last updated: July 3, 2026
1. Scope
This policy explains what personal data TripOS collects, why, who processes it for us, and the controls you have. It covers the TripOS website, app, and APIs. For client records that travel businesses store in their workspaces, TripOS acts as a processor on the workspace’s instructions — see the Data Processing Addendum.
2. What we collect
- Account data. Name, email, and avatar from Google sign-in; your preference settings.
- Trip data. Briefs (destination, dates, vibes, budget, pace, dietary notes), generated itineraries, edits, comments, votes, photos and documents you upload, and — if you use Live Mode location features — the location you explicitly share.
- Workspace data. Workspace name and branding, member roles, invitations, audit-log entries, and client records your workspace creates (names, contact details, preferences, and notes about your clients).
- Billing data. Plan, seat count, and subscription state. Card details go directly to Stripe; they never touch our servers.
- Usage data. Product analytics events, logs, and metered actions (for example, one record per itinerary generation for quota enforcement).
3. Why we use it
- To provide the Service: generate, store, and deliver itineraries.
- To operate workspaces: membership, roles, tenancy isolation, audit.
- To bill plans and enforce quotas.
- To secure the Service: rate limiting, abuse prevention, error monitoring.
- To improve the product using aggregate usage analytics.
- To send transactional email (invites, deliverables, booking reminders).
We do not sell personal data, and we do not send marketing email without consent.
4. AI processing — and what we don’t do
Itinerary generation sends your trip brief (destination, dates, preference signals) to a model provider (OpenAI) via API, alongside venue, weather, and event data. Per that provider’s API terms, data sent through the API is not used to train their models. We do not train models — ours or anyone else’s — on your content, and we do not sell it. A deterministic planning pipeline handles generation when the model path is unavailable, in which case your brief stays within our infrastructure and data providers.
5. Processors we use
Current subprocessors, and what they process:
- Vercel — application hosting and logs
- PostgreSQL (managed database hosting) — primary data store
- Stripe — payments and subscription management
- Google — sign-in (OAuth) and, when configured, venue data (Places)
- OpenAI — itinerary generation (trip briefs, no card data)
- SendGrid — transactional email delivery
- Sentry — error monitoring (may capture request context)
- PostHog — product analytics
- Upstash — rate limiting (keys are user/workspace identifiers)
- Mapbox, OpenWeatherMap, Ticketmaster, Eventbrite, Amadeus — travel data lookups (queries include destinations and dates, not your identity)
We list material changes to this list here before they take effect.
6. Sharing you control
Share links, group planning invites, community publishing, and client deliverables expose exactly the content you choose to share, to the people you give the link to. Deliverable links can be revoked or set to expire. Published community trips are public until you unpublish them.
7. Retention and deletion
- Account data is kept while your account is active. Deleting your account from Settings deletes your personal data and owned content; residual copies leave backups on their rotation schedule (up to 30 days).
- Workspace data is controlled by workspace owners; deleting a workspace deletes its trips, clients, deliverables, keys, and audit log.
- Billing records are retained as required by tax and accounting law.
8. Security
Data is encrypted in transit (TLS) and at rest by our managed database provider. Access is scoped by tenancy checks enforced in the data layer, API keys are stored as hashes, and administrative actions in workspaces are audit-logged. See Trust & security for the fuller picture, including honest notes on certifications.
9. Your rights
Depending on where you live (including under GDPR), you may have rights to access, correct, export, restrict, or delete your personal data, and to object to processing. You can exercise most of these directly in the product (Settings, workspace console). For anything else, email privacy@tripos.dev — we respond within 30 days.
10. International transfers
Our processors operate globally; where data leaves your region we rely on the processors’ standard contractual clauses and equivalent safeguards.
11. Changes and contact
We will notify you of material changes to this policy by email or in-product. Contact: privacy@tripos.dev.