Draft — to be reviewed by a lawyer before launch. Not yet in force.

Privacy policy

Last updated 5 October 2026

This policy explains how [OWNING ENTITY — TBD: legal name, ABN and registered address] ("Tripvyz", "we", "us") handles personal information when you use tripvyz.com and the Tripvyz mobile app. We follow the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). If you live in the EU or UK, we also aim to meet the GDPR / UK GDPR.

1. What we collect

  • Account details: your name, email address, a hashed password (we never see the password itself) or the Google/Apple account you sign in with.
  • Trip details you add or import: trips, bookings, booking references, itineraries, places, expenses, checklists and comments.
  • Traveller profiles: names as on passports, dates of birth, nationality, seat preferences, and dietary or mobility needs. Dietary and mobility needs can be health information, which is sensitive information under the Privacy Act; we only collect it if you choose to add it, and only use it to check your trip.
  • Secrets: passport numbers, booking PINs and loyalty membership numbers. These are encrypted in the app before they are stored and are hidden until you choose to reveal them.
  • Cards: only the card product (for example "Qantas Premier Platinum") and, if you like, the last 4 digits. We never accept or store full card numbers, CVVs or PINs, and the app rejects anything that looks like one.
  • Imported emails: confirmation emails you forward or upload. The original message is stored encrypted and deleted automatically after 30 days; the bookings we read from it stay with your trip.
  • Device and security data: your IP address and browser or device type when you sign in, a log of sensitive actions (sign-ins, sharing, exports, account deletion), and, if you allow notifications, your phone's push token.

2. How we collect it

From you, from people you share a household or trip with (for example a partner adding a booking), and from the emails you forward or upload. If you connect a mailbox in future, we will only read messages that look like travel confirmations, and you can disconnect and purge them at any time.

3. Why we use it

  • To run the service: build your day-by-day itinerary, check it for problems (the "trip doctor"), and keep it on your phone offline.
  • To tell you about things that matter: deadlines, charges, booking changes and problems we find, by email, in the app and, if you allow it, by push notification.
  • To keep accounts and data secure, prevent abuse and meet our legal obligations.

We do not sell personal information, and we do not use it for advertising.

4. Artificial intelligence

When none of our built-in readers recognises a confirmation email, or when you ask for a translation, we send text to Anthropic's Claude API to extract the booking details. Before anything is sent, we remove card numbers, CVVs, PINs, passport numbers, membership numbers, personal email addresses and tracking links. Our automated tests check this on every change. [Lawyer to confirm: Anthropic's commercial terms on retention and model training.]

5. Where your data is stored, and who else handles it

Your data is stored in Sydney, Australia: our database is Neon Postgres in AWS's Sydney region, and the app runs on Vercel in Sydney (syd1). Some service providers process limited information outside Australia (APP 8):

  • Resend (Tokyo region, Japan): sends our emails, so it handles your email address and the message content.
  • Anthropic (United States): receives redacted email text for booking extraction and phrases for translation, as described above.
  • Expo (United States): delivers push notifications to your phone; it receives your device's push token and the notification's title and text.
  • Vercel (global edge network): may briefly handle requests and operational logs outside Australia while serving the site.
  • OpenFreeMap: map tiles are loaded directly by your browser or phone, which shares your IP address with the map provider.
  • Open-Meteo and OpenStreetMap Nominatim: receive place names and coordinates (not your name) to show weather and find places.
  • Google or Apple: only if you choose to sign in with them.

We choose providers with security commitments appropriate to the information they handle. [Lawyer to review: APP 8.1 reasonable steps and contractual terms with each provider.]

6. How we protect it

Encrypted connections (HTTPS) everywhere; data encrypted at rest by our database provider; an extra layer of application encryption for passport numbers, PINs, membership numbers and imported emails; database rules that stop one household seeing another's data; rate limits; and an audit log of sensitive actions. No system is perfectly secure; if a data breach is likely to cause you serious harm we will tell you and the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme.

7. How long we keep it

  • Account and trip data: until you delete it or your account.
  • Imported email originals: 30 days, then deleted automatically.
  • Security audit log: [24 months — TBD], so we can investigate misuse. It records an account identifier, not your name or email.
  • Backups: our database provider keeps point-in-time backups for a short restore window ([N] days — TBD); deleted data disappears from them when that window passes.

8. Your choices and rights

  • Access: download everything we hold about you as a file from Settings → Privacy and your data.
  • Correction: edit your details and trips in the app at any time, or ask us.
  • Deletion: delete your account from Settings → Privacy and your data. This removes your account, signs you out everywhere, and deletes households you own alone, with their trips.
  • Notifications: turn push notifications off in your phone's settings; email preferences are in the app.
  • Complaints: contact us first. If you're not satisfied with our response within 30 days, you can complain to the OAIC (oaic.gov.au). In the EU/UK you may also contact your local data protection authority.

9. Children

Parents and guardians can add children as traveller profiles. Account holders must be at least [16 — TBD]. Children's profiles are visible only to members of the household that created them.

10. Cookies

We only use cookies that are needed to keep you signed in and secure. We don't use advertising or third-party analytics cookies.

11. Changes and contact

We'll tell you about material changes by email or in the app before they take effect. Questions or requests: privacy@tripvyz.com [mailbox to be set up], or write to [OWNING ENTITY — TBD: legal name, ABN and registered address].