Privacy Policy
Effective Date: September 29, 2026
Last Updated: September 29, 2026
This Privacy Policy explains what personal data tripstone.app ("Service", "Platform") collects, why we collect it, who receives it, and what rights you have.
The Service is operated by FOP Kravchuk Volodymyr Serhiiovych (Individual Entrepreneur Kravchuk Volodymyr Serhiiovych), registered address: 108g/54 Peremohy Ave., Chernihiv, Chernihiv Oblast, Ukraine ("we", "us", "our"). We are the controller of your personal data.
Our representative in the European Union under Article 27 GDPR is Kravchuk Volodymyr Serhiiovych, 108g/54 Peremohy Ave., Chernihiv, Chernihiv Oblast, Ukraine, email: [email protected]. You can contact them instead of us about any matter relating to your personal data.
We process personal data in accordance with the Law of Ukraine "On the Protection of Personal Data" and, where it applies to you, the EU General Data Protection Regulation (GDPR). Questions about your data: [email protected].
1. Information We Collect
Account information:
- —When you sign up with email: your email address, your password (stored only in hashed form) and your name.
- —When you sign in with Google: your name, email address and profile photo, as provided by Google.
- —We also record when you accepted our Terms, and whether you opted in to marketing emails.
Profile information you choose to add. Date of birth, preferred currency, travel styles, dietary preferences and accessibility needs. All of these are optional. Dietary preferences and accessibility needs may reveal information about your health or beliefs, so we use them only with your explicit consent (see §2).
Trip information. What you enter to plan a trip: destination, dates, number of travellers (adults, children, infants, pets), interests, cuisine and budget preferences. Also the itineraries we generate, your edits, hotels you save (including links you paste), expenses you record, share links you create, and feedback you leave.
Payment information. Card details are entered directly into the payment window of our payment provider, WayForPay, and never reach our servers. From WayForPay we receive and store:
- —the order reference, amount, currency and payment status;
- —the authorisation code and a masked card number (for example, 4444 55** **** 1111);
- —for subscriptions, a payment token that allows renewals.
Support requests. When you contact us through the website or the chat: your name, email address, subject and message, and the type of browser you used.
Technical and usage information:
- —Your IP address. We use it to protect the Service from abuse and, for visitors who are not signed in, to apply the free daily generation limit. For IPv6 addresses we keep only the network part (the first 64 bits).
- —Browser and device information, pages visited and actions taken in the Service. See §6.
- —Server logs, which may include your IP address and account ID.
Please do not share sensitive information we have not asked for. Do not enter health, identity-document, financial or similar sensitive information in free-text fields, trip notes or the chat. The optional dietary and accessibility fields are the only place where we ask for such information, and only with your explicit consent.
We do not ask for identity documents. We do not knowingly collect data about children; see §10.
2. How We Use Your Information
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Create and run your account; generate, save and share trips | Account, profile, trip information | Performance of a contract (Art. 6(1)(b)) |
| Personalise itineraries using your dietary preferences and accessibility needs, including sending them to our AI provider (§3) | Dietary preferences and accessibility needs | Your explicit consent, given by ticking the consent box next to these fields (Art. 9(2)(a)); withdraw it at any time by unticking the box or clearing the fields |
| Process payments, subscriptions and refunds | Payment information | Performance of a contract (Art. 6(1)(b)) |
| Keep payment and accounting records | Payment information | Legal obligation (Art. 6(1)(c)) |
| Prevent abuse, fraud and automated misuse; enforce free-usage limits; keep the Service secure | IP address, technical information, logs | Legitimate interests (Art. 6(1)(f)) |
| Answer your support requests | Support requests | Performance of a contract or legitimate interests (Art. 6(1)(b), (f)) |
| Improve the quality of generated itineraries and fix errors, by reviewing feedback and a limited sample of generated trips | Trip information, feedback, account ID | Legitimate interests in improving the Service (Art. 6(1)(f)) |
| Produce aggregated statistics that do not identify you (for example, popular destinations) | Trip and usage information, aggregated | Legitimate interests (Art. 6(1)(f)) |
| Understand how the Service is used and improve it | Usage information (analytics cookies) | Consent (Art. 6(1)(a)) |
| Measure advertising and partner referrals, and show relevant ads | Usage information (marketing cookies) | Consent (Art. 6(1)(a)) |
| Send travel tips and offers | Email address | Consent (Art. 6(1)(a)); only if you opted in |
| Send service messages (account confirmation, password reset, trip reminders) | Email address | Performance of a contract (Art. 6(1)(b)) |
| Comply with the law and protect our rights | Any data relevant to the matter | Legal obligation or legitimate interests (Art. 6(1)(c), (f)) |
Where we rely on legitimate interests, we have balanced our interests against your rights and you can object at any time (see §11).
We do not sell your personal data. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
3. AI Trip Generation
Itineraries are created by an artificial intelligence system. They are generated by an AI model provided by Google Cloud. To create a trip we send Google Cloud:
- —your trip details: destination, dates, number of travellers, interests, cuisine and budget;
- —your travel styles;
- —your dietary preferences and accessibility needs, only if you added them and gave your consent (§2);
- —a list of candidate places.
We do not send your name or email address. Google Cloud processes this data on our behalf, as our processor, to generate the response.
No training on your data. We do not use your personal data to train or fine-tune AI models. Under Google Cloud's terms, Google does not use the data we send to train its models.
Check before you travel. AI-generated itineraries may contain mistakes or outdated information. Please check opening hours, prices, availability and entry requirements before you rely on them.
4. Automated Protection
To protect the Service from bots and abuse we use Cloudflare, including Cloudflare Turnstile. Turnstile checks whether a visitor is human when you create a trip, sign up or contact support. It receives technical information about your browser and your IP address. Cloudflare may show a short check before a page opens.
5. Who Receives Your Data
We share personal data only with service providers that help us run the Service, and only as needed for the purposes above. They act on our behalf (processors) under data processing agreements, except where noted as independent controllers.
| Provider | What they do for us | Data involved |
|---|---|---|
| Supabase (database hosted in the EU, Ireland) | Accounts, sign-in, data storage | Account, profile, trip, payment records |
| Railway | Hosting of our website and servers | All data passing through the Service; server logs |
| Cloudflare | Network security, bot protection, Turnstile, image storage | IP address, technical information |
| Google Cloud | AI itinerary generation | Trip details and, with your consent, dietary and accessibility preferences (§3) |
| Google Maps Platform | Place search, maps, geocoding, place photos | Destinations and place searches |
| Mapbox | Interactive trip maps | Map views, IP address |
| Open-Meteo | Weather forecasts for your trip | Destination coordinates and dates (no personal data) |
| WayForPay | Payment processing | Order and payment details; card details you enter in their window |
| Resend | Delivery of account emails | Email address, email content |
| Crisp | Live chat on trip pages | Messages you send in the chat, technical information |
| Upstash / Railway | Background task queues | Account and trip IDs |
| Google Analytics, Google Tag Manager | Website analytics (with your consent) | Usage information, cookies |
| Amplitude | Product analytics (with your consent) | Usage information, account ID |
| Meta, Google Ads, TikTok, Ahrefs | Advertising measurement (with your consent) | Usage information, cookies |
| GetYourGuide | Partner tours and analytics (with your consent) | Usage information, cookies |
Links to partners. When you follow a link to Booking.com, GetYourGuide or another partner, the link carries the hotel or activity, dates and number of guests, and a referral code that identifies us. The partner may set its own cookies and then processes your data as an independent controller under its own privacy policy. If you book, the partner pays us a commission and may send us booking reports (for example, booking date, value and status) so that we can account for it. The same independent-controller rule applies to YouTube videos embedded in our blog.
Shared trips. When you create a share link, anyone who has the link can view the trip it points to, including any notes you added. Share links only with people you trust. You can disable a share link at any time, and the trip will no longer be accessible through it.
Google sign-in. TripStone's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use this information only to sign you in and show your name and photo in your account.
Other disclosures. We may also disclose data to our professional advisers (lawyers, accountants) under duties of confidentiality; to courts, law-enforcement or other public authorities where required by law; to protect our rights, our users or the public; or to a buyer or successor as part of a sale or reorganisation of the business, who will remain bound by this Policy.
6. Cookies and Similar Technologies
We use cookies and browser storage in three categories. You choose which you allow in the cookie banner, and you can change your choice at any time via Cookie Settings at the bottom of every page.
| Category | What it does | Examples |
|---|---|---|
| Essential | Keeps you signed in, remembers your cookie choice and interface settings, protects against bots. Always on | Sign-in session cookies, cookie-choice cookie, sidebar state, trip onboarding state, pending trip dates in browser storage |
| Analytics | Helps us understand how the Service is used. Only with your consent | Google Analytics, Amplitude |
| Marketing | Measures advertising and partner referrals. Only with your consent | Google Ads, Meta Pixel, TikTok, GetYourGuide |
Google tags start with all consent types set to "denied" and change only after you allow them.
If your browser sends a Global Privacy Control (GPC) signal, we treat it as a refusal of marketing cookies. We do not respond to "Do Not Track" signals, because there is no common standard for them; use Cookie Settings or GPC instead.
7. How Long We Keep Data
| Data | How long |
|---|---|
| Account, profile and trips | Until you delete them or your account |
| Consent to use dietary and accessibility preferences | Until you withdraw it or delete your account; a record of when consent was given or withdrawn is kept for as long as we need to prove it |
| Unfinished trips created without an account | Up to 72 hours |
| IP addresses used for the free generation limit | Up to 90 days |
| Payment records | As long as required by Ukrainian tax and accounting law. After account deletion they are kept without any link to you |
| Support requests | Up to 2 years after the last message |
| Server logs | Up to 30 days |
| Analytics data | According to the retention settings of each provider |
Deleted data may remain in encrypted backups for a short period until the backups are overwritten; it is not used during that time.
8. International Transfers
Our main database is in the European Union (Ireland). Some providers, including Google, Cloudflare, Railway and analytics services, may process data in other countries, including the United States.
- —For users in the EU/EEA: where data leaves the European Economic Area, we rely on an adequacy decision (for example, the EU–US Data Privacy Framework, for certified providers) or the European Commission's Standard Contractual Clauses.
- —For users in Ukraine: transfers to EEA countries are made on the basis that they provide an adequate level of protection. Transfers to other countries, including the United States, are made where necessary to perform our contract with you, on the basis of contractual safeguards with the provider, or with your consent, in accordance with Article 29 of the Law of Ukraine "On the Protection of Personal Data".
You can ask us for more information about the safeguards we use by writing to [email protected].
9. Security
- —All traffic is encrypted (HTTPS), and our database is encrypted at rest.
- —Passwords are stored only in hashed form.
- —Access to your data in the database is restricted to your own account.
- —Card details never reach our servers.
- —Automated abuse is filtered before it reaches the Service.
No method of transmission or storage is 100% secure, but we work to protect your data and review our safeguards regularly. If a personal data breach is likely to put your rights at risk, we will notify the competent authority and, where required, you, within the time limits set by law.
10. Children
The Service is intended for people aged 16 and over. Paid plans and subscriptions are available only to people aged 18 and over. We do not knowingly collect personal data from children under 16. The number of children in a trip is used only to plan it and does not identify them.
If you believe a child under 16 has given us personal data, contact us and we will delete it.
11. Your Rights
Depending on where you live, you have the right to:
- —access the personal data we hold about you and get a copy;
- —correct inaccurate data — most of it you can edit in your profile;
- —delete your data — see "Deleting your account" below;
- —restrict processing in certain cases;
- —object to processing based on our legitimate interests; you can always object to direct marketing, and we will then stop it;
- —data portability — receive the data you gave us in a structured, commonly used, machine-readable format;
- —withdraw consent at any time: via Cookie Settings for cookies, by unticking the consent box or clearing the dietary and accessibility fields in your profile, or by using the unsubscribe link in marketing emails. Withdrawal does not affect processing done before it.
To exercise these rights, email [email protected] from the address linked to your account. We may ask you to confirm your identity before we act on a request. We reply within one month; for complex or numerous requests we may extend this by up to two further months and will tell you why. Exercising your rights is free, unless a request is clearly unfounded or excessive. Some rights have legal exceptions, for example we must keep payment records for accounting.
You may also complain to a data protection authority:
- —in Ukraine, the Ukrainian Parliament Commissioner for Human Rights;
- —in the EU, the authority in your country of residence, place of work or where the alleged breach occurred.
Deleting your account. You can delete your account at any time in your profile settings. This permanently deletes your profile, trips, share links, feedback, notifications, subscriptions, credits and usage limits, and your sign-in account. Payment records are kept for accounting (see §7) but are no longer linked to you.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will change the "Last Updated" date above, and for material changes we will notify you on the Service or by email before they take effect.
13. Contact
FOP Kravchuk Volodymyr Serhiiovych
Address: 108g/54 Peremohy Ave., Chernihiv, Chernihiv Oblast, Ukraine
Email: [email protected]
Website: https://tripstone.app
EU representative (Article 27 GDPR)
Kravchuk Volodymyr Serhiiovych
Address: 108g/54 Peremohy Ave., Chernihiv, Chernihiv Oblast, Ukraine
Email: [email protected]