Privacy & Data
Privacy Policy
How Tripistic collects, uses, shares, and protects personal data across the platform, the public website, and the customer portal.
Template notice. This document is a production-ready starting point maintained by the Tripistic team. Review it with qualified legal counsel in your operating jurisdictions before publishing it as your binding policy.
Tripistic ("Tripistic", "we", "us") provides an AI-native travel operations platform for tour operators, travel agencies, destination management companies, and enterprise travel brands. This Privacy Policy explains what personal data we process, why we process it, how long we keep it, and the rights available to you.
This policy covers the Tripistic marketing website, the authenticated application, the customer portal, public booking pages, embeddable booking widgets, and our REST API.
Who is the controller
Tripistic acts in two distinct roles:
- Controller for data we collect about our own customers, prospects, website visitors, and applicants — account records, billing details, support conversations, and marketing analytics.
- Processor for data our customers upload or generate inside their workspace — traveller records, bookings, participants, waivers, itineraries, and guest messages. In that context, the operator using Tripistic is the controller and our Data Processing Agreement governs the relationship.
Data we collect
Account and workspace data
Name, work email, hashed password, role, workspace name, workspace slug, locale, time zone, plan, and onboarding progress.
Traveller and operational data (processed on behalf of operators)
Customer and lead records, companies, bookings, participants, payment status, waivers, documents, itineraries, guide and driver assignments, vehicle records, incident reports, tasks, and CRM timeline activity.
Payment data
Tripistic does not store full card numbers. Payments are processed by Stripe. We retain payment intent identifiers, amounts, currency, status, and webhook event records so bookings can be reconciled and audited.
Technical data
IP address, user agent, device and browser type, referring URL, pages viewed, session duration, and error diagnostics.
Communication data
Support requests, sales enquiries, demo bookings, newsletter subscriptions, and transactional email delivery records.
AI interaction data
Prompts and context sent to configured AI providers when you use AI itinerary generation, business insights, or AI search. Workspace administrators control which provider is configured. We do not use customer content to train third-party foundation models, and we require the same of our AI subprocessors.
Why we process data
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing and operating the platform | Performance of a contract |
| Processing payments and preventing fraud | Contract and legitimate interests |
| Transactional email (confirmations, reminders, receipts) | Contract |
| Product analytics and service improvement | Legitimate interests |
| Marketing analytics and advertising measurement | Consent |
| Security monitoring and audit logging | Legitimate interests and legal obligation |
| Responding to support and sales requests | Contract and legitimate interests |
| Meeting tax, accounting, and legal duties | Legal obligation |
Cookies and analytics
We use strictly necessary cookies for authentication, session integrity, and workspace context. Analytics and marketing cookies load only after you consent. Details of every category, the vendors involved, and how to change your choice at any time are documented in our Cookie Policy.
Analytics and measurement tools we may operate, subject to your consent: Google Analytics 4, Google Tag Manager, Google Search Console, Microsoft Clarity, Meta Pixel, and LinkedIn Insight Tag. Product analytics events are recorded without advertising identifiers where consent has not been granted.
Sharing and subprocessors
We share personal data only with vendors that support the service. Each is bound by a data processing agreement and appropriate transfer safeguards.
| Subprocessor | Purpose | Region |
|---|---|---|
| Cloud hosting and edge network | Application hosting, CDN, DDoS protection | US / EU |
| Managed PostgreSQL provider | Primary data store and backups | US / EU |
| Stripe | Payments, subscriptions, invoicing | Global |
| Transactional email provider | Booking confirmations, reminders, receipts | US / EU |
| AI providers (OpenAI, OpenRouter, or operator-configured) | AI itineraries, insights, search | US |
| Twilio / WhatsApp Business | SMS and messaging notifications, where enabled | Global |
| Google Maps Platform | Geocoding, maps, route context | Global |
| Analytics and measurement vendors | Consent-gated product and marketing analytics | US / EU |
We do not sell personal data, and we do not share personal data for cross-context behavioural advertising as those terms are defined under United States state privacy laws.
International transfers
Where data leaves the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and supplementary technical measures including encryption in transit and at rest.
Data retention
| Record type | Retention |
|---|---|
| Active account and workspace records | Duration of the subscription |
| Traveller, booking, and operational records | Duration of the subscription, then 30 days for export |
| Invoices, payment records, and tax documents | 7 years, as required by financial law |
| Security and audit logs | 12 months |
| Backups | 35 days on a rolling window |
| Support conversations | 24 months |
| Marketing analytics | 14 months |
| Deleted workspace data | Purged within 30 days of confirmed deletion |
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to processing; to receive a portable copy of your data; to withdraw consent; and to lodge a complaint with a supervisory authority.
GDPR and UK GDPR
Residents of the EEA, the UK, and Switzerland can exercise the rights described in our GDPR Compliance page, including the right to object to processing based on legitimate interests and the right not to be subject to solely automated decisions with legal effect. Tripistic does not make solely automated decisions of that kind; AI outputs are advisory and always reviewable by a human operator.
CCPA and CPRA
California residents, and residents of other US states with comparable laws, can exercise the rights described in our CCPA / US State Privacy page, including the right to know, delete, correct, and opt out of sale or sharing. We honour Global Privacy Control signals.
To exercise a right, email privacy@tripistic.com from the address associated with your account, or use the in-product data export tools. We respond within 30 days and will tell you if we need an extension. If your request concerns data held inside an operator's workspace, we will route it to that operator as the controller.
Children
Tripistic is a business tool and is not directed at children. Operators running educational or youth travel programs are responsible for obtaining guardian consent for participant records they upload, and for using the participant and waiver features in line with applicable law.
Security
We apply encryption in transit and at rest, role-based access control, tenant isolation on every query path, signed webhooks, audit logging, and least-privilege internal access. Our controls and vulnerability reporting process are described in the Security Policy.
Changes
We will post material changes to this page and update the "Last updated" date. Where required, we will notify account administrators by email before the change takes effect.
Contact
- Privacy requests: privacy@tripistic.com
- Security reports: security@tripistic.com
- General legal: legal@tripistic.com
- Postal address and the name of our EU/UK representative are available on request via the contact form.
Questions about this document?
Email legal@tripistic.com or use the contact form. Enterprise teams can request countersigned copies and completed security questionnaires.