Legal

Privacy Policy

Effective Date: September 29, 2026

Last Updated: September 29, 2026

This Privacy Policy explains what personal data tripstone.app ("Service", "Platform") collects, why we collect it, who receives it, and what rights you have.

The Service is operated by FOP Kravchuk Volodymyr Serhiiovych (Individual Entrepreneur Kravchuk Volodymyr Serhiiovych), registered address: 108g/54 Peremohy Ave., Chernihiv, Chernihiv Oblast, Ukraine ("we", "us", "our"). We are the controller of your personal data.

Our representative in the European Union under Article 27 GDPR is Kravchuk Volodymyr Serhiiovych, 108g/54 Peremohy Ave., Chernihiv, Chernihiv Oblast, Ukraine, email: [email protected]. You can contact them instead of us about any matter relating to your personal data.

We process personal data in accordance with the Law of Ukraine "On the Protection of Personal Data" and, where it applies to you, the EU General Data Protection Regulation (GDPR). Questions about your data: [email protected].

1. Information We Collect

Account information:

  • —When you sign up with email: your email address, your password (stored only in hashed form) and your name.
  • —When you sign in with Google: your name, email address and profile photo, as provided by Google.
  • —We also record when you accepted our Terms, and whether you opted in to marketing emails.

Profile information you choose to add. Date of birth, preferred currency, travel styles, dietary preferences and accessibility needs. All of these are optional. Dietary preferences and accessibility needs may reveal information about your health or beliefs, so we use them only with your explicit consent (see §2).

Trip information. What you enter to plan a trip: destination, dates, number of travellers (adults, children, infants, pets), interests, cuisine and budget preferences. Also the itineraries we generate, your edits, hotels you save (including links you paste), expenses you record, share links you create, and feedback you leave.

Payment information. Card details are entered directly into the payment window of our payment provider, WayForPay, and never reach our servers. From WayForPay we receive and store:

  • —the order reference, amount, currency and payment status;
  • —the authorisation code and a masked card number (for example, 4444 55** **** 1111);
  • —for subscriptions, a payment token that allows renewals.

Support requests. When you contact us through the website or the chat: your name, email address, subject and message, and the type of browser you used.

Technical and usage information:

  • —Your IP address. We use it to protect the Service from abuse and, for visitors who are not signed in, to apply the free daily generation limit. For IPv6 addresses we keep only the network part (the first 64 bits).
  • —Browser and device information, pages visited and actions taken in the Service. See §6.
  • —Server logs, which may include your IP address and account ID.

Please do not share sensitive information we have not asked for. Do not enter health, identity-document, financial or similar sensitive information in free-text fields, trip notes or the chat. The optional dietary and accessibility fields are the only place where we ask for such information, and only with your explicit consent.

We do not ask for identity documents. We do not knowingly collect data about children; see §10.

2. How We Use Your Information

PurposeData usedLegal basis (GDPR)
Create and run your account; generate, save and share tripsAccount, profile, trip informationPerformance of a contract (Art. 6(1)(b))
Personalise itineraries using your dietary preferences and accessibility needs, including sending them to our AI provider (§3)Dietary preferences and accessibility needsYour explicit consent, given by ticking the consent box next to these fields (Art. 9(2)(a)); withdraw it at any time by unticking the box or clearing the fields
Process payments, subscriptions and refundsPayment informationPerformance of a contract (Art. 6(1)(b))
Keep payment and accounting recordsPayment informationLegal obligation (Art. 6(1)(c))
Prevent abuse, fraud and automated misuse; enforce free-usage limits; keep the Service secureIP address, technical information, logsLegitimate interests (Art. 6(1)(f))
Answer your support requestsSupport requestsPerformance of a contract or legitimate interests (Art. 6(1)(b), (f))
Improve the quality of generated itineraries and fix errors, by reviewing feedback and a limited sample of generated tripsTrip information, feedback, account IDLegitimate interests in improving the Service (Art. 6(1)(f))
Produce aggregated statistics that do not identify you (for example, popular destinations)Trip and usage information, aggregatedLegitimate interests (Art. 6(1)(f))
Understand how the Service is used and improve itUsage information (analytics cookies)Consent (Art. 6(1)(a))
Measure advertising and partner referrals, and show relevant adsUsage information (marketing cookies)Consent (Art. 6(1)(a))
Send travel tips and offersEmail addressConsent (Art. 6(1)(a)); only if you opted in
Send service messages (account confirmation, password reset, trip reminders)Email addressPerformance of a contract (Art. 6(1)(b))
Comply with the law and protect our rightsAny data relevant to the matterLegal obligation or legitimate interests (Art. 6(1)(c), (f))

Where we rely on legitimate interests, we have balanced our interests against your rights and you can object at any time (see §11).

We do not sell your personal data. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.

3. AI Trip Generation

Itineraries are created by an artificial intelligence system. They are generated by an AI model provided by Google Cloud. To create a trip we send Google Cloud:

  • —your trip details: destination, dates, number of travellers, interests, cuisine and budget;
  • —your travel styles;
  • —your dietary preferences and accessibility needs, only if you added them and gave your consent (§2);
  • —a list of candidate places.

We do not send your name or email address. Google Cloud processes this data on our behalf, as our processor, to generate the response.

No training on your data. We do not use your personal data to train or fine-tune AI models. Under Google Cloud's terms, Google does not use the data we send to train its models.

Check before you travel. AI-generated itineraries may contain mistakes or outdated information. Please check opening hours, prices, availability and entry requirements before you rely on them.

4. Automated Protection

To protect the Service from bots and abuse we use Cloudflare, including Cloudflare Turnstile. Turnstile checks whether a visitor is human when you create a trip, sign up or contact support. It receives technical information about your browser and your IP address. Cloudflare may show a short check before a page opens.

5. Who Receives Your Data

We share personal data only with service providers that help us run the Service, and only as needed for the purposes above. They act on our behalf (processors) under data processing agreements, except where noted as independent controllers.

ProviderWhat they do for usData involved
Supabase (database hosted in the EU, Ireland)Accounts, sign-in, data storageAccount, profile, trip, payment records
RailwayHosting of our website and serversAll data passing through the Service; server logs
CloudflareNetwork security, bot protection, Turnstile, image storageIP address, technical information
Google CloudAI itinerary generationTrip details and, with your consent, dietary and accessibility preferences (§3)
Google Maps PlatformPlace search, maps, geocoding, place photosDestinations and place searches
MapboxInteractive trip mapsMap views, IP address
Open-MeteoWeather forecasts for your tripDestination coordinates and dates (no personal data)
WayForPayPayment processingOrder and payment details; card details you enter in their window
ResendDelivery of account emailsEmail address, email content
CrispLive chat on trip pagesMessages you send in the chat, technical information
Upstash / RailwayBackground task queuesAccount and trip IDs
Google Analytics, Google Tag ManagerWebsite analytics (with your consent)Usage information, cookies
AmplitudeProduct analytics (with your consent)Usage information, account ID
Meta, Google Ads, TikTok, AhrefsAdvertising measurement (with your consent)Usage information, cookies
GetYourGuidePartner tours and analytics (with your consent)Usage information, cookies

Links to partners. When you follow a link to Booking.com, GetYourGuide or another partner, the link carries the hotel or activity, dates and number of guests, and a referral code that identifies us. The partner may set its own cookies and then processes your data as an independent controller under its own privacy policy. If you book, the partner pays us a commission and may send us booking reports (for example, booking date, value and status) so that we can account for it. The same independent-controller rule applies to YouTube videos embedded in our blog.

Shared trips. When you create a share link, anyone who has the link can view the trip it points to, including any notes you added. Share links only with people you trust. You can disable a share link at any time, and the trip will no longer be accessible through it.

Google sign-in. TripStone's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use this information only to sign you in and show your name and photo in your account.

Other disclosures. We may also disclose data to our professional advisers (lawyers, accountants) under duties of confidentiality; to courts, law-enforcement or other public authorities where required by law; to protect our rights, our users or the public; or to a buyer or successor as part of a sale or reorganisation of the business, who will remain bound by this Policy.

6. Cookies and Similar Technologies

We use cookies and browser storage in three categories. You choose which you allow in the cookie banner, and you can change your choice at any time via Cookie Settings at the bottom of every page.

CategoryWhat it doesExamples
EssentialKeeps you signed in, remembers your cookie choice and interface settings, protects against bots. Always onSign-in session cookies, cookie-choice cookie, sidebar state, trip onboarding state, pending trip dates in browser storage
AnalyticsHelps us understand how the Service is used. Only with your consentGoogle Analytics, Amplitude
MarketingMeasures advertising and partner referrals. Only with your consentGoogle Ads, Meta Pixel, TikTok, GetYourGuide

Google tags start with all consent types set to "denied" and change only after you allow them.

If your browser sends a Global Privacy Control (GPC) signal, we treat it as a refusal of marketing cookies. We do not respond to "Do Not Track" signals, because there is no common standard for them; use Cookie Settings or GPC instead.

7. How Long We Keep Data

DataHow long
Account, profile and tripsUntil you delete them or your account
Consent to use dietary and accessibility preferencesUntil you withdraw it or delete your account; a record of when consent was given or withdrawn is kept for as long as we need to prove it
Unfinished trips created without an accountUp to 72 hours
IP addresses used for the free generation limitUp to 90 days
Payment recordsAs long as required by Ukrainian tax and accounting law. After account deletion they are kept without any link to you
Support requestsUp to 2 years after the last message
Server logsUp to 30 days
Analytics dataAccording to the retention settings of each provider

Deleted data may remain in encrypted backups for a short period until the backups are overwritten; it is not used during that time.

8. International Transfers

Our main database is in the European Union (Ireland). Some providers, including Google, Cloudflare, Railway and analytics services, may process data in other countries, including the United States.

  • —For users in the EU/EEA: where data leaves the European Economic Area, we rely on an adequacy decision (for example, the EU–US Data Privacy Framework, for certified providers) or the European Commission's Standard Contractual Clauses.
  • —For users in Ukraine: transfers to EEA countries are made on the basis that they provide an adequate level of protection. Transfers to other countries, including the United States, are made where necessary to perform our contract with you, on the basis of contractual safeguards with the provider, or with your consent, in accordance with Article 29 of the Law of Ukraine "On the Protection of Personal Data".

You can ask us for more information about the safeguards we use by writing to [email protected].

9. Security

  • —All traffic is encrypted (HTTPS), and our database is encrypted at rest.
  • —Passwords are stored only in hashed form.
  • —Access to your data in the database is restricted to your own account.
  • —Card details never reach our servers.
  • —Automated abuse is filtered before it reaches the Service.

No method of transmission or storage is 100% secure, but we work to protect your data and review our safeguards regularly. If a personal data breach is likely to put your rights at risk, we will notify the competent authority and, where required, you, within the time limits set by law.

10. Children

The Service is intended for people aged 16 and over. Paid plans and subscriptions are available only to people aged 18 and over. We do not knowingly collect personal data from children under 16. The number of children in a trip is used only to plan it and does not identify them.

If you believe a child under 16 has given us personal data, contact us and we will delete it.

11. Your Rights

Depending on where you live, you have the right to:

  • —access the personal data we hold about you and get a copy;
  • —correct inaccurate data — most of it you can edit in your profile;
  • —delete your data — see "Deleting your account" below;
  • —restrict processing in certain cases;
  • —object to processing based on our legitimate interests; you can always object to direct marketing, and we will then stop it;
  • —data portability — receive the data you gave us in a structured, commonly used, machine-readable format;
  • —withdraw consent at any time: via Cookie Settings for cookies, by unticking the consent box or clearing the dietary and accessibility fields in your profile, or by using the unsubscribe link in marketing emails. Withdrawal does not affect processing done before it.

To exercise these rights, email [email protected] from the address linked to your account. We may ask you to confirm your identity before we act on a request. We reply within one month; for complex or numerous requests we may extend this by up to two further months and will tell you why. Exercising your rights is free, unless a request is clearly unfounded or excessive. Some rights have legal exceptions, for example we must keep payment records for accounting.

You may also complain to a data protection authority:

  • —in Ukraine, the Ukrainian Parliament Commissioner for Human Rights;
  • —in the EU, the authority in your country of residence, place of work or where the alleged breach occurred.

Deleting your account. You can delete your account at any time in your profile settings. This permanently deletes your profile, trips, share links, feedback, notifications, subscriptions, credits and usage limits, and your sign-in account. Payment records are kept for accounting (see §7) but are no longer linked to you.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will change the "Last Updated" date above, and for material changes we will notify you on the Service or by email before they take effect.

13. Contact

FOP Kravchuk Volodymyr Serhiiovych

Address: 108g/54 Peremohy Ave., Chernihiv, Chernihiv Oblast, Ukraine

Email: [email protected]

Website: https://tripstone.app

EU representative (Article 27 GDPR)

Kravchuk Volodymyr Serhiiovych

Address: 108g/54 Peremohy Ave., Chernihiv, Chernihiv Oblast, Ukraine

Email: [email protected]