1. Who We Are and Scope
TripGlide is a mobile travel organization app that helps you import booking documents and messages, structure trips, manage boarding details, use AI travel assistance, and sync account data across devices.
This policy applies to the TripGlide mobile apps, tripglide.online, support communications, and related services such as email, WhatsApp, and iMessage booking intake.
The public website provides product information, policies, support, and read-only trip pages opened through owner-created sharing links. Account creation, trip management, and subscriptions are handled through the mobile apps and supporting backend services.
For privacy questions, contact vin@tripglide.online.
2. Information We Collect
Account data, including your email address, authentication identifiers, profile name, optional profile photo, and account status.
Travel content you provide, including trip names, destinations, dates, itinerary items, booking confirmations, boarding passes, traveler names, booking references, seat details, baggage information, notes, source documents, and AI chat prompts or trip context when you use AI features.
Booking-intake data, including forwarded booking emails, PDF attachments, inbound booking addresses, WhatsApp or iMessage messages and attachments, pending trip choices, sender identifiers, and optional booking phone numbers used to match messages to your account.
App settings, including privacy choices, notification preferences, trial status, scan usage, subscription status, saved profile details, and local storage preferences.
Subscription and purchase data, including RevenueCat app user ID, product ID, entitlement status, purchase environment, renewal, cancellation, expiration, and related app-store receipt or webhook metadata.
Technical data required to run the service, including device push notification tokens, platform type, app configuration, security-related request metadata, server logs, and diagnostic information needed to secure and operate the service.
Optional usage analytics, only if you enable Share Usage Analytics in Privacy & Security settings.
Support data, including messages you send to TripGlide, contact details, screenshots or attachments you choose to provide, and information needed to respond to your request.
3. How We Use Information
To create your account, authenticate you, and sync your trips and settings across devices.
To extract itinerary and boarding-pass details from booking documents you upload, forward by email, or send through supported messaging channels.
To provide booking inboxes, WhatsApp booking intake, iMessage booking intake, trip selection flows, and replies confirming import status.
To provide premium features, enforce scan limits, start trials, restore purchases, and manage subscriptions.
To send push notifications and Live Activity updates when you enable those features.
To provide travel images and photographer attribution in the app.
To provide read-only live trip links and, when you explicitly choose them, separate time-limited links to selected trip PDFs.
To respond to support requests, prevent abuse, debug reliability issues, secure TripGlide, enforce terms, and improve the product.
To comply with legal obligations, app-store requirements, tax and accounting rules, and valid legal requests.
4. Legal Bases for Processing
For users in regions such as the European Economic Area, the United Kingdom, and Switzerland, we process personal data when needed to perform our contract with you, such as account access, trip sync, booking import, subscriptions, and support.
We process certain data based on your consent, such as optional AI document processing, optional usage analytics, push notifications, Live Activities, and optional local storage choices where consent is required.
We process some data for legitimate interests, such as securing TripGlide, preventing abuse, debugging reliability issues, understanding aggregate product performance, and responding to support requests.
We process some data to comply with legal obligations, such as tax, accounting, subscription, dispute, fraud-prevention, and valid legal-request requirements.
Where consent is the legal basis, you can withdraw consent through in-app settings or by contacting us. Withdrawal does not affect processing that happened before withdrawal.
5. Processors and Service Providers
Supabase: authentication, database storage, profile image storage, Edge Functions, account deletion, push token storage, settings sync, usage records, analytics events, and subscription status mirrors.
Google Gemini API: AI document extraction and AI chat features. Booking documents, boarding passes, and trip context may be sent to Gemini only when the relevant AI consent is enabled or when you use an AI feature.
RevenueCat, Apple App Store, and Google Play: subscription offerings, purchases, restores, entitlements, payment processing, refunds, subscription management, receipts, and subscription webhook events.
Resend, SendGrid, Twilio WhatsApp, LoopMessage, Spectrum, iMessage infrastructure, and related messaging providers: inbound booking messages, webhook delivery, media retrieval, reply messages, forwarded booking emails, and attachments.
Unsplash: travel image search, image delivery, download tracking required by Unsplash, and photographer attribution.
Apple Push Notification service and Firebase Cloud Messaging: delivery of native push notifications when enabled.
We use service providers only to operate TripGlide, provide requested features, process subscriptions, respond to support, secure the service, or comply with law.
6. AI Document Processing
AI document processing is off by default. If you enable AI Document Processing or use an AI feature, TripGlide may send booking confirmations, boarding passes, and related trip context to Google Gemini to extract travel details or answer trip-related questions.
If Store Sensitive Booking Details is off, TripGlide asks the extraction service to exclude traveler names, booking references, baggage allowance, seat numbers, and similar sensitive fields where possible.
If Keep Source Documents Offline or Keep Boarding Passes Offline is off, raw document files are not retained on your device after extraction. Server-side intake may temporarily process attachments to complete an import.
AI and extracted content may be incomplete or inaccurate, so you should review important travel details against the original booking provider.
We do not use your travel documents for advertising. We also do not sell travel documents or AI prompts to data brokers.
7. Analytics, Website, and Privacy Controls
Usage analytics in the mobile app is optional and disabled by default. If enabled, TripGlide sends limited event names, timestamps, and sanitized properties to Supabase.
Analytics events are designed not to include names, emails, phone numbers, destinations, booking references, tokens, session identifiers, or raw travel documents.
You can change AI processing, sensitive detail storage, local document storage, boarding-pass storage, analytics, push notifications, and Live Activities in the app's Privacy & Security and Notifications settings.
The public website does not provide account sign-up or trip editing. It can display a read-only live trip to anyone who has a valid owner-created share link, including selected PDFs only when the owner creates a separate document link.
Shared trip pages are marked not to be indexed and use no-referrer and no-store controls. We do not currently use advertising pixels or marketing analytics on shared trip pages.
8. Data Sharing, Sales, and Tracking
We do not sell your personal data. We do not use your travel documents for third-party advertising.
We do not use data for cross-app or cross-site tracking as Apple defines tracking, and we do not share data with third-party advertising networks.
We share information with processors only to provide TripGlide, process subscriptions, deliver notifications, import bookings, generate travel imagery, secure the service, comply with law, or respond to your requests.
When you create an itinerary link, anyone with that link can view the sanitized live trip details included on the page. Personal booking fields and uploaded documents are excluded from the itinerary-only link.
When you separately select PDFs for sharing, anyone with the document link can view or download those selected files for up to seven days unless you turn off sharing sooner. Share links are bearer links and recipients can forward them, so share only with people you trust and only when you have permission to disclose every person's information in the selected files.
Turning off or regenerating a link stops future access through the old link, but it cannot recall screenshots, downloads, printed copies, or other copies a recipient already made.
We may disclose information if required by law, to protect TripGlide and users, to investigate abuse or security incidents, or as part of a business transfer involving the service.
9. Data Retention and Deletion
Account data is kept while your account is active.
Trips, itinerary items, settings, scan usage, trial records, booking phone number, and profile images are kept until you delete them, clear local data where applicable, or delete your account.
Trip share records are retained while needed to operate active or revoked links. Document links automatically expire after seven days, and removing a document or deleting the trip prevents future file access through the share link.
Source booking documents are not retained in TripGlide storage unless you enable Keep Source Documents. When enabled, they are retained until you delete the relevant trip, turn off the setting, or delete your account.
Boarding-pass files are retained on your device only when you enable Keep Boarding Passes Offline. You can remove them by turning off that setting, clearing local data, or deleting the account in the app.
Pending booking choices from email, WhatsApp, or iMessage are temporary and are intended to expire or be deleted after the import flow is completed or abandoned.
Subscription events may be retained as long as needed for billing records, fraud prevention, accounting, tax, dispute resolution, and legal compliance.
Optional analytics events may be retained for product improvement and reliability analysis, then deleted or aggregated when no longer needed.
Server logs and security records are retained for a limited period needed to operate, debug, secure, and protect the service.
You can delete your TripGlide account in the app under Privacy & Security. You can also use the Account and Data Deletion page at https://www.tripglide.online/data-deletion to request deletion.
Account deletion removes your TripGlide account and associated app data from active systems, subject to backups, logs, legal obligations, anti-abuse records, and subscription or payment records we must keep.
Deleting your TripGlide account does not automatically cancel an active Apple App Store or Google Play subscription; you must cancel subscriptions through the applicable store account settings.
10. Your Rights and Choices
Depending on your location, you may have rights to access, correct, delete, export, restrict, object to, or withdraw consent for certain processing of your personal data.
California and other US state privacy laws may provide rights to know, access, correct, delete, port, opt out of sale or sharing, limit certain sensitive data uses, and appeal certain decisions. TripGlide does not sell personal data or share it for cross-context behavioral advertising.
Users in the EEA, UK, and Switzerland may have rights to lodge a complaint with a supervisory authority. We encourage you to contact us first so we can try to help.
You can update many settings inside TripGlide and download a structured copy of your account data from Privacy & Security. Download any retained original documents from the relevant trip before deleting your account.
Contact vin@tripglide.online to submit a request that is not available in the app.
We may need to verify your account or request before fulfilling privacy, access, export, or deletion requests.
11. Security
We use reasonable technical and organizational safeguards, including authentication, row-level access controls, server-side validation, webhook verification, storage ownership checks, and least-privilege handling where applicable.
No method of transmission or storage is completely secure, but we continuously work to protect your information.
If you believe your account or TripGlide data has been compromised, contact vin@tripglide.online.
12. Children's Privacy
TripGlide is not directed to children under 13 or the minimum age required in your country or region.
We do not knowingly collect personal information from children below the applicable minimum age. If you believe a child provided personal data to TripGlide, contact us so we can take appropriate action.
13. International Processing
TripGlide and its providers may process information in the United States and other countries where our providers operate. Data protection laws in those countries may differ from those in your location.
Where required, we rely on appropriate transfer mechanisms, provider commitments, and contractual protections for international processing.
14. Contact and Changes
For privacy questions, data requests, or deletion requests, contact vin@tripglide.online.
We may update this Privacy Policy from time to time. Material updates will be reflected by updating the effective date above and, when appropriate, by providing additional notice.