Legal

Privacy Policy

Last updated: July 15, 2026

Maintained by Tripa. This page explains what personal data Tripa collects, why we process it, and the choices you have. It applies to individual accounts and to company workspaces where an employer operates Tripa on your behalf.

This document uses bracketed placeholders such as [Company legal name] where the operator must supply specifics. Have qualified counsel review before relying on this text in production.

1. Who we are

Tripa (“we”, “us”) is operated by [Company legal name], registered in [Jurisdiction], contact privacy@ontripa.com. For company workspaces, your employer is the controller of employee travel data and Tripa acts as a processor.

2. Data we collect

  • Account: name, email, password hash, avatar, workspace membership, role.
  • Trip data: destinations, dates, itinerary items, notes, travel preferences.
  • Calendar & location: events you sync, places you select, coordinates used for map routing.
  • Payment metadata: wallet balances, receipt images, expense line items. We do not store full card numbers.
  • Usage & device: IP, browser, session events, error logs used to secure and improve the service.

3. How we use data

  • Provide the service: plan, book, and manage trips within your policy.
  • Autopilot: generate itineraries, recommendations, and disruption recovery.
  • Security: authenticate you, detect abuse, enforce rate limits and audit logs.
  • Communication: transactional emails (trip updates, receipts, approvals).
  • Improvement: aggregated analytics to improve reliability and quality.
  • Contract: to deliver the features you request.
  • Legitimate interests: service security, fraud prevention, product improvement.
  • Consent: optional integrations (e.g., calendar sync) — withdrawable at any time.
  • Legal obligation: tax, accounting, and regulatory requirements.

5. Sharing & subprocessors

We share data with vetted providers only to run the service:

  • Lovable Cloud — application hosting, database, authentication, storage.
  • Google Maps Platform — places, photos, routing.
  • Lovable AI Gateway — model inference for the autopilot agent.
  • Email delivery — transactional messages from notify.ontripa.com.

Your employer receives trip and expense data you create in a company workspace.

6. Retention

Account data is kept while your account is active. Trip and expense records are retained for the period your workspace configures or as required by tax law. Security logs are retained for up to [X] months. Deleted accounts are purged within [X] days, subject to legal holds.

7. Your rights

Depending on your location, you may request access, correction, export, deletion, restriction, or objection. Email privacy@ontripa.com. You may also lodge a complaint with your local supervisory authority.

8. International transfers

Data may be processed outside your country by our providers. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.

9. Security

Tripa uses encryption in transit, encryption at rest for the managed database, role-based access control, per-request auth checks (RLS), rate limiting, CAPTCHA challenges on authentication, and audit logs. No system is perfectly secure — we continuously review and improve controls.

10. Contact

Questions or requests: privacy@ontripa.com.

Questions? Contact legal@ontripa.com.