Privacy & Data

Privacy Policy

How Tripistic collects, uses, shares, and protects personal data across the platform, the public website, and the customer portal.

Last updated July 1, 2026·Effective July 1, 2026·6 min read

Template notice. This document is a production-ready starting point maintained by the Tripistic team. Review it with qualified legal counsel in your operating jurisdictions before publishing it as your binding policy.

Tripistic ("Tripistic", "we", "us") provides an AI-native travel operations platform for tour operators, travel agencies, destination management companies, and enterprise travel brands. This Privacy Policy explains what personal data we process, why we process it, how long we keep it, and the rights available to you.

This policy covers the Tripistic marketing website, the authenticated application, the customer portal, public booking pages, embeddable booking widgets, and our REST API.

Who is the controller

Tripistic acts in two distinct roles:

  • Controller for data we collect about our own customers, prospects, website visitors, and applicants — account records, billing details, support conversations, and marketing analytics.
  • Processor for data our customers upload or generate inside their workspace — traveller records, bookings, participants, waivers, itineraries, and guest messages. In that context, the operator using Tripistic is the controller and our Data Processing Agreement governs the relationship.

Data we collect

Account and workspace data

Name, work email, hashed password, role, workspace name, workspace slug, locale, time zone, plan, and onboarding progress.

Traveller and operational data (processed on behalf of operators)

Customer and lead records, companies, bookings, participants, payment status, waivers, documents, itineraries, guide and driver assignments, vehicle records, incident reports, tasks, and CRM timeline activity.

Payment data

Tripistic does not store full card numbers. Payments are processed by Stripe. We retain payment intent identifiers, amounts, currency, status, and webhook event records so bookings can be reconciled and audited.

Technical data

IP address, user agent, device and browser type, referring URL, pages viewed, session duration, and error diagnostics.

Communication data

Support requests, sales enquiries, demo bookings, newsletter subscriptions, and transactional email delivery records.

AI interaction data

Prompts and context sent to configured AI providers when you use AI itinerary generation, business insights, or AI search. Workspace administrators control which provider is configured. We do not use customer content to train third-party foundation models, and we require the same of our AI subprocessors.

Why we process data

PurposeLegal basis (GDPR Art. 6)
Providing and operating the platformPerformance of a contract
Processing payments and preventing fraudContract and legitimate interests
Transactional email (confirmations, reminders, receipts)Contract
Product analytics and service improvementLegitimate interests
Marketing analytics and advertising measurementConsent
Security monitoring and audit loggingLegitimate interests and legal obligation
Responding to support and sales requestsContract and legitimate interests
Meeting tax, accounting, and legal dutiesLegal obligation

Cookies and analytics

We use strictly necessary cookies for authentication, session integrity, and workspace context. Analytics and marketing cookies load only after you consent. Details of every category, the vendors involved, and how to change your choice at any time are documented in our Cookie Policy.

Analytics and measurement tools we may operate, subject to your consent: Google Analytics 4, Google Tag Manager, Google Search Console, Microsoft Clarity, Meta Pixel, and LinkedIn Insight Tag. Product analytics events are recorded without advertising identifiers where consent has not been granted.

Sharing and subprocessors

We share personal data only with vendors that support the service. Each is bound by a data processing agreement and appropriate transfer safeguards.

SubprocessorPurposeRegion
Cloud hosting and edge networkApplication hosting, CDN, DDoS protectionUS / EU
Managed PostgreSQL providerPrimary data store and backupsUS / EU
StripePayments, subscriptions, invoicingGlobal
Transactional email providerBooking confirmations, reminders, receiptsUS / EU
AI providers (OpenAI, OpenRouter, or operator-configured)AI itineraries, insights, searchUS
Twilio / WhatsApp BusinessSMS and messaging notifications, where enabledGlobal
Google Maps PlatformGeocoding, maps, route contextGlobal
Analytics and measurement vendorsConsent-gated product and marketing analyticsUS / EU

We do not sell personal data, and we do not share personal data for cross-context behavioural advertising as those terms are defined under United States state privacy laws.

International transfers

Where data leaves the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and supplementary technical measures including encryption in transit and at rest.

Data retention

Record typeRetention
Active account and workspace recordsDuration of the subscription
Traveller, booking, and operational recordsDuration of the subscription, then 30 days for export
Invoices, payment records, and tax documents7 years, as required by financial law
Security and audit logs12 months
Backups35 days on a rolling window
Support conversations24 months
Marketing analytics14 months
Deleted workspace dataPurged within 30 days of confirmed deletion

Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or object to processing; to receive a portable copy of your data; to withdraw consent; and to lodge a complaint with a supervisory authority.

GDPR and UK GDPR

Residents of the EEA, the UK, and Switzerland can exercise the rights described in our GDPR Compliance page, including the right to object to processing based on legitimate interests and the right not to be subject to solely automated decisions with legal effect. Tripistic does not make solely automated decisions of that kind; AI outputs are advisory and always reviewable by a human operator.

CCPA and CPRA

California residents, and residents of other US states with comparable laws, can exercise the rights described in our CCPA / US State Privacy page, including the right to know, delete, correct, and opt out of sale or sharing. We honour Global Privacy Control signals.

To exercise a right, email privacy@tripistic.com from the address associated with your account, or use the in-product data export tools. We respond within 30 days and will tell you if we need an extension. If your request concerns data held inside an operator's workspace, we will route it to that operator as the controller.

Children

Tripistic is a business tool and is not directed at children. Operators running educational or youth travel programs are responsible for obtaining guardian consent for participant records they upload, and for using the participant and waiver features in line with applicable law.

Security

We apply encryption in transit and at rest, role-based access control, tenant isolation on every query path, signed webhooks, audit logging, and least-privilege internal access. Our controls and vulnerability reporting process are described in the Security Policy.

Changes

We will post material changes to this page and update the "Last updated" date. Where required, we will notify account administrators by email before the change takes effect.

Contact

Questions about this document?

Email legal@tripistic.com or use the contact form. Enterprise teams can request countersigned copies and completed security questionnaires.