Privacy Policy
Last updated: 20 May 2026
1. Who We Are
Tripcerto is operated by TRIPCERTO LTD, a private limited company registered in England and Wales with company number 16121124 ("Tripcerto", "we", "us", or "our").
Contact details:
- Privacy and support:
hello@tripcerto.com - Registered office:
118 Jellicoe Avenue, Alverstoke, Hampshire, United Kingdom, PO12 2PX
2. Scope
This Privacy Policy explains how we collect, use, disclose, and otherwise process personal information when you use:
- the Tripcerto website and web application
- Tripcerto account features
- Tripcerto planning, research, review, social, and messaging features
- related communications, support, and invitations
3. Information We Collect
We collect the following categories of information, depending on how you use the service.
Account and authentication information
- email address
- password credentials handled through our authentication providers
- OAuth account information when you sign in with Google
- account identifiers and session information
Profile information
- full name
- avatar or profile photo
- profile tagline
- account email
Content you create or upload
- trip plans, trip titles, notes, and preferences
- trip reviews, destinations, stays, and experiences you enter
- trip moments, captions, hashtags, and related content
- messages you send in plan chats or other messaging features
- prompts, questions, and feedback you submit to AI-powered features
- uploaded photos and videos
Location and place information
- destination and place selections
- addresses and place identifiers
- latitude and longitude associated with plans or moments
- location metadata we extract from uploaded media if you choose to upload files containing it
Social and collaboration information
- follows and public profile interactions
- collaborators on plans
- invitations you send or receive, including invitee email addresses
- shared review and plan participation details
Notifications and device/browser data
- in-app notification records
- browser notification permission state
- technical data needed to maintain sessions and app state, including browser storage such as local storage and session storage
Media and technical metadata
- file name
- content type
- file size
- image or video dimensions
- duration and bitrate for videos
- storage paths and processing status for uploads
Demo and pre-release information
- name and email address you provide when accessing a demo or pre-release feature
- anonymous session identifiers used to associate your demo activity
- partner or operator context associated with the demo you are using
Website usage and analytics information
- pages and sections viewed, referring sites, and approximate location derived from your IP address
- device and browser type
- interaction events such as scroll depth, clicks, and time on page
Usage, diagnostics, and security information
- logs needed to secure and operate the service
- error, abuse-prevention, and performance information
- chat/session metadata and recommendation-feedback signals
4. How We Collect Information
We collect information:
- directly from you when you create an account, edit a profile, upload content, message, or use Tripcerto features
- automatically from your browser or device when required to run, secure, and measure the service
- from authentication providers when you sign in with Google or similar services
- from collaborators or other users when they invite you to a plan or otherwise interact with you
- from service integrations that help us resolve locations, travel content, or related media
5. How We Use Information
We use personal information to:
- create and maintain your account
- authenticate users and keep sessions active
- operate planning, review, social, chat, and collaboration features
- process uploaded media and generate derived formats
- infer or organise travel preferences and trip context
- provide AI-powered recommendations, summaries, and related outputs
- measure, personalise, and improve the service and our website
- send invitations, account emails, and service notifications
- protect the service, investigate abuse, and enforce our Terms
- comply with legal obligations
6. AI Processing
Tripcerto includes AI-powered features, including conversational travel planning and recommendation systems.
When you use those features, we may process:
- prompts and messages you submit
- trip context and preference information
- related metadata needed to generate, rank, or improve responses within the service
We may send relevant content to third-party AI providers and supporting tools that process data on our behalf in order to provide these features.
Tripcerto does not use your content to train its own proprietary models. Instead, we use third-party AI models and tools to help generate, organise, and deliver responses and workflows within the service.
Current providers reflected in the codebase reviewed on 22 April 2026 include:
- OpenAI
- Anthropic
7. When Information May Be Visible To Other Users
Some Tripcerto features are inherently social or collaborative.
Depending on the feature and your settings or actions, other users may be able to see:
- your public profile information
- content you share into collaborative plans
- trip reviews and trip moments you publish or share
- your display name and avatar alongside messages or contributions
You should not upload or share content that you do not want other users to see.
8. How We Disclose Information
We may disclose personal information to the following categories of recipients:
- service providers that host or operate authentication, storage, database, infrastructure, or messaging functions
- AI providers that help us generate or process responses
- mapping, geocoding, travel-content, and place-enrichment providers
- analytics providers that help us measure how our website is used
- other users where content is public, shared, collaborative, or message-based
- professional advisers, auditors, insurers, or counterparties in connection with legal, compliance, or transaction matters
- government authorities or other parties where required by law or necessary to protect rights, safety, and security
Processors and vendors we use or may use to provide the service
Tripcerto uses or may use service providers in categories including:
- Supabase
- Vercel
- Google OAuth
- OpenAI
- Anthropic
- Geoapify
- Tripadvisor
- object storage / media-processing infrastructure
9. Cookies, Local Storage, and Similar Technologies
Tripcerto uses browser-side storage and similar technologies to run the service, including session persistence and app-state recovery.
Tripcerto currently uses browser-side storage for functions such as:
- local storage is used for authentication persistence
- session storage is used for short-lived auth and recovery flow state
- browser notification permissions may be requested when you use notification features
Website analytics
On our public website we use Vercel Web Analytics to understand how visitors find and use the site. This processes information such as aggregate page views, referring sites, approximate location derived from your IP address, device and browser type, and interaction events such as scroll depth, section views, clicks, and time on page.
Vercel Web Analytics is privacy-focused: it does not set cookies, does not store an identifier in your browser, and does not track you across other websites. We rely on our legitimate interest in measuring and improving our website for this processing.
We do not use advertising or cross-site marketing technologies. If we later add non-essential tracking technologies, we will update this Privacy Policy and, where required, request consent before using them.
10. Legal Bases For UK / EEA Users
If UK GDPR or GDPR applies, we rely on one or more of the following legal bases:
- performance of a contract, such as creating and operating your account and providing Tripcerto features
- legitimate interests, such as improving the service, measuring website usage, preventing abuse, securing the platform, and communicating with users about service operations
- consent, where we ask for it
- compliance with legal obligations
11. Retention
We retain different categories of personal information for different periods, depending on why we need the information and whether it remains part of an active account, plan, review, or collaboration feature.
Account and profile records
We retain account credentials, profile details, and core account records while your account is active. If you delete your account, we generally delete or de-identify this information from active systems within 30 days, unless we need to retain it longer for security, fraud prevention, legal compliance, or dispute resolution. Encrypted or access-restricted backups may remain for up to 90 days before they are overwritten.
Trip plans, trip reviews, trip moments, chats, and other user content
We retain trip plans, reviews, moments, messages, prompts, and similar user-generated content while it remains in your account or in a shared plan, review, or collaboration space. If you delete this content, or if it is removed as part of account deletion, we generally remove it from active systems within 30 days. Content that is part of a shared plan, shared review, or conversation history may remain available to other participants until the shared item itself is deleted. Backups may persist for up to 90 days.
Uploaded media
We retain uploaded photos, videos, thumbnails, and related media metadata while the media remains attached to your account content. If media is deleted by you or as part of account deletion, we generally remove it from active systems within 30 days, subject to backups for up to 90 days and longer retention where reasonably necessary for abuse prevention, legal claims, or compliance.
Invitations, notifications, recommendation feedback, and operational interaction records
We generally retain invites, notification records, recommendation feedback, and similar operational interaction records for 24 months after creation or resolution, unless a longer retention period is reasonably necessary for security, fraud prevention, or legal claims.
Security, fraud-prevention, and technical logs
We generally retain security, fraud-prevention, and technical diagnostic logs for 12 months, and longer where reasonably necessary to investigate abuse, protect the service, or comply with law.
Legal, compliance, and dispute records
Where necessary, we may retain relevant information for the duration of a legal claim, investigation, audit, enforcement matter, or compliance obligation, and for any additional period required or permitted by applicable law.
12. Your Rights
If UK data protection law applies to your use of Tripcerto, you may have rights to:
- access the personal information we hold about you
- ask us to correct inaccurate or incomplete personal information
- ask us to delete personal information in some circumstances
- ask us to restrict how we use personal information in some circumstances
- object to certain processing
- receive a copy of certain personal information in a portable format
- withdraw consent where we rely on consent
To exercise rights, contact us at hello@tripcerto.com.
You may also have the right to complain to the UK Information Commissioner's Office (ICO) if you believe your personal information has been handled unlawfully.
These rights are not absolute, and they may be limited in some situations under applicable law.
13. International Transfers
Your information may be processed in countries outside the United Kingdom.
Where we transfer personal information internationally, we will take steps designed to ensure it is protected appropriately under applicable law, including by using contractual safeguards where required.
14. Children
Tripcerto is not intended for children under 16.
We do not knowingly collect personal information from children under the applicable minimum age for the service. If you believe a child has provided personal information in violation of this policy, contact us at hello@tripcerto.com.
15. Security
We use technical and organisational measures designed to protect personal information. However, no system is perfectly secure, and we cannot guarantee absolute security.
16. Changes To This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice as appropriate for the service and the law.
17. Contact
For questions or privacy requests, contact:
hello@tripcerto.com
TRIPCERTO LTD
Registered office: 118 Jellicoe Avenue, Alverstoke, Hampshire, United Kingdom, PO12 2PX