1. Who we are
Tripa (“we”, “us”) is operated by [Company legal name], registered in [Jurisdiction], contact privacy@ontripa.com. For company workspaces, your employer is the controller of employee travel data and Tripa acts as a processor.
2. Data we collect
- Account: name, email, password hash, avatar, workspace membership, role.
- Trip data: destinations, dates, itinerary items, notes, travel preferences.
- Calendar & location: events you sync, places you select, coordinates used for map routing.
- Payment metadata: wallet balances, receipt images, expense line items. We do not store full card numbers.
- Usage & device: IP, browser, session events, error logs used to secure and improve the service.
3. How we use data
- Provide the service: plan, book, and manage trips within your policy.
- Autopilot: generate itineraries, recommendations, and disruption recovery.
- Security: authenticate you, detect abuse, enforce rate limits and audit logs.
- Communication: transactional emails (trip updates, receipts, approvals).
- Improvement: aggregated analytics to improve reliability and quality.
4. Legal bases (EEA/UK)
- Contract: to deliver the features you request.
- Legitimate interests: service security, fraud prevention, product improvement.
- Consent: optional integrations (e.g., calendar sync) — withdrawable at any time.
- Legal obligation: tax, accounting, and regulatory requirements.
5. Sharing & subprocessors
We share data with vetted providers only to run the service:
- Lovable Cloud — application hosting, database, authentication, storage.
- Google Maps Platform — places, photos, routing.
- Lovable AI Gateway — model inference for the autopilot agent.
- Email delivery — transactional messages from
notify.ontripa.com.
Your employer receives trip and expense data you create in a company workspace.
6. Retention
Account data is kept while your account is active. Trip and expense records are retained for the period your workspace configures or as required by tax law. Security logs are retained for up to [X] months. Deleted accounts are purged within [X] days, subject to legal holds.
7. Your rights
Depending on your location, you may request access, correction, export, deletion, restriction, or objection. Email privacy@ontripa.com. You may also lodge a complaint with your local supervisory authority.
8. International transfers
Data may be processed outside your country by our providers. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.
9. Security
Tripa uses encryption in transit, encryption at rest for the managed database, role-based access control, per-request auth checks (RLS), rate limiting, CAPTCHA challenges on authentication, and audit logs. No system is perfectly secure — we continuously review and improve controls.
10. Contact
Questions or requests: privacy@ontripa.com.
