Privacy Policy

Last updated: July 2026

1. Controller

Marcel Hizli
[Street and house number]
[Postal code and city]
Germany
Email: info@tripsake.app

We are not required to appoint a data protection officer. Please direct all privacy enquiries to the address above.

2. General

TripSake is an application for planning trips together and is currently in a testing phase. We process personal data only to the extent necessary to provide the app (Art. 6(1)(b) GDPR), where you have given us your consent (Art. 6(1)(a) GDPR), or where we have a legitimate interest in operating it securely and reliably (Art. 6(1)(f) GDPR). Providing your data is voluntary, but without the data marked as necessary we cannot provide the service.

3. Minimum age

TripSake is not intended for children. You may only use TripSake if you are at least 16 years old. We do not knowingly collect personal data from children under 16. If you become aware that a child has provided us with personal data, please contact us and we will delete it without delay.

4. Hosting

The app is hosted on servers operated by Hetzner Online GmbH (Gunzenhausen, Germany). When you access the app, technically necessary data (IP address, time of access, page requested, user agent) is processed in server logs on the basis of Art. 6(1)(f) GDPR and deleted after a short period.

5. Registration and sign-in

You sign in via email (magic link) or via your Google, Apple, Facebook or X account (OAuth), all handled through Supabase (Supabase Inc.). With social sign-in, we receive your email address and display name from the respective provider. Your email address and sign-in timestamps are processed in the process. Guests can join via invite links as anonymous users without providing an email address; in that case only a technical identifier is created.

Emails we send you — magic links, sign-up confirmations and notifications — are delivered through our transactional email provider, which receives your email address and the content of the message for that purpose only.

6. Content you create

Content you create in the app — trips, places, bookings, packing lists, expenses, photos, voice and text notes — is stored in our database (Supabase) and is visible only to members of the respective trip. You can delete your content yourself at any time.

7. Location data

The live feature can access your device location in order to share it with your trip members. This only happens after your explicit consent in the browser or operating system (Art. 6(1)(a) GDPR) and can be stopped at any time by withdrawing the permission in your browser or device settings.

8. Push notifications

If you use our mobile app and allow notifications, we process a device token through Firebase Cloud Messaging (Google Ireland Limited / Google LLC) in order to deliver countdown reminders and trip updates (Art. 6(1)(a) GDPR). Withdrawing the notification permission in your device settings stops this at any time.

9. Google services

We use the following services of Google Ireland Limited / Google LLC:

Results from these AI features are suggestions, not decisions about you: no automated decision-making within the meaning of Art. 22 GDPR takes place, and we do not use your content to train AI models.

10. Other services we use

11. International transfers

Some of the providers named above are based in, or have parent companies in, the USA. Transfers take place on the basis of the EU-U.S. Data Privacy Framework, to which Google and Supabase are certified, or on the basis of the EU Standard Contractual Clauses together with additional safeguards. You can request a copy of the relevant safeguards from us at the address in section 1.

12. Cookies and local storage

We use technically necessary cookies and browser storage for session management (login); these require no consent. We do not use advertising cookies, and we do not sell or share personal data for cross-context behavioural advertising.

In addition, we use PostHog (EU-hosted) for privacy-friendly product analytics — no autocapture, no cross-site tracking, and profiles only for signed-in users. This runs only with your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG), which we ask for on your first visit. You can withdraw or change your choice at any time here:

13. Storage period

Data is stored for as long as your account or the respective trip exists. Server logs and error reports are deleted after a short period. As the app is in a testing phase, data may also be reset or deleted at any time as part of testing.

14. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). Where processing is based on your consent, you can withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal.

To exercise any of these rights — including receiving a copy of your data in a portable format — write to info@tripsake.app. We respond within one month. You also have the right to lodge a complaint with a data protection supervisory authority, in particular the authority of the Member State of your habitual residence, place of work, or of the alleged infringement.

15. Deleting your account

You can delete your account, including all personal data, yourself at any time: in the app via the account menu or directly at delete TripSake account. Deletion takes effect immediately and is irreversible: your account, your expenses and your expense shares are erased. Items you added to a shared trip and that the group keeps using — bookings, packing and shopping entries — stay in that trip with your authorship removed, so the remaining members’ lists are not torn apart. Those entries no longer reference you.