TRIPSTECA

Privacy Policy

← Back to Home
Last updated

July 2026

This policy explains what information Tripsteca collects, how it's used, and which outside services help power certain features.

Who we are

Tripsteca is a personal trip-organizing application. If you have questions about this policy or your data, contact us at admin@tripsteca.com.

Information we collect

Account information: name, email address, and password (stored as a one-way hash, never in plain text) for your own login. Optionally, phone number.

Companion traveler information: if you add travelers to your account, we store whatever you enter for them — name, date of birth, nationality, passport number and expiry, and emergency contact details. Companion travelers do not have their own login and cannot access the app directly.

Trip and itinerary information: trip names, dates, destinations, budgets, and details of flights, hotels, car rentals, rail bookings, and other itinerary items you add — including confirmation numbers, costs, and any notes or links you enter.

Forwarded confirmation emails (only if you enable this optional feature): the content of emails you forward to your trip's import address, used solely to extract booking details automatically.

Technical information: IP address, collected for login attempts (to detect and block repeated password-guessing) and logged with email-import attempts (for troubleshooting).

Third-party services we use

Certain features rely on outside services, which process a limited, specific slice of your data as described below. We don't sell your data to anyone, and these services only receive what's necessary for the specific feature to work.

Anthropic (Claude AI) — if you use the optional email-import feature, the text content of emails you forward is sent to Anthropic's API to extract structured booking details (dates, confirmation numbers, etc.). This feature is off by default and must be explicitly enabled.

Mailgun — handles receiving forwarded confirmation emails and sending account-related emails (such as password resets).

Google Maps Platform — if you view a trip's map, the location text you've entered (e.g. an airport code or address) is sent to Google's Geocoding API to determine map coordinates, and the map itself is rendered using Google's Maps JavaScript API.

How we use your information

To operate the core functionality of the app: managing your account, trips, and itinerary items; showing you your own data; and enabling the optional features described above only when you turn them on.

Data security

Passwords are never stored in plain text. The site is served over HTTPS. Administrative access to view or manage user accounts is restricted to a designated superadmin role, which can only be granted via direct database access, not through the app itself.

Data retention & your choices

You can edit or delete your own trips, itinerary items, and companion traveler profiles at any time from within the app. If you'd like your entire account and all associated data deleted, contact admin@tripsteca.com and we'll process the request.

Children's privacy

Tripsteca is not directed at children and is not intended for use by anyone under 16.

Changes to this policy

If this policy changes, we'll update the date at the top of this page.