← Tripmaat
Privacy Policy
Last updated: 6 October 2026
Before public launch: the publisher must identify the data controller, add a working privacy contact, set retention/deletion procedures, and review this notice for applicable privacy law.
Who operates Tripmaat
Controller: [Add the publisher's legal name]. Contact: [Add a working privacy contact email].
Information Tripmaat handles
- On your device: trips, places, notes, bookings, expenses, settings, and locally attached small images are stored in browser storage as a working copy. Account sign-in is required to create and use trips. The signed-in account syncs its trips through Supabase.
- Account and cloud sync: Supabase Auth processes your email/account. Tripmaat stores trips, sharing memberships, invitation email addresses, and uploaded attachments in a private storage bucket. Your trip content is sent to Supabase to sync it to devices and invited tripmates.
- Transit requests: when you request a public-transport route while signed in, Tripmaat sends the start, destination, trip date and requested time to its Supabase function. It forwards the request to TfL for London, Île-de-France Mobilités for Paris-region routes, or a regional endpoint such as Entur or transport.rest where configured. Place names may also be sent to OpenStreetMap Nominatim to find coordinates. Route results are held in the active page session and are not written to trip storage or cloud sync.
- AI requests: if you ask for an itinerary, packing list, guide, or general description while signed in, relevant destination and trip details are sent through the Supabase function to OpenAI. The request asks the API not to store the response. Do not include sensitive personal information in prompts.
- Other lookups: city search, exchange rates, and destination images may contact Open-Meteo, OpenStreetMap/Nominatim, Frankfurter, and Wikipedia. Opening an external navigation link sends the selected destination to Google Maps or Apple Maps. These providers may receive the query and standard connection data such as your IP address.
Why and how long
Trip data is used to provide planning, sync, sharing, and requested provider features. Local browser data remains until you clear it or remove the trip. Cloud data remains in the Supabase project until the account operator deletes it; this version does not include an in-app cloud account deletion tool. Attachments and shared trip data are visible to authorized trip members. Configure provider retention and backup rules before launch.
Service providers
Configured cloud and API providers process information under their own terms and privacy policies: Supabase, TfL Open Data, Île-de-France Mobilités PRIM, Entur, transport.rest, OpenStreetMap Nominatim, Google Maps, and OpenAI. Review them before enabling these services.
Your choices and requests
You can browse Tripmaat without signing in, but an account is required to create and use trips. You can export or clear local trip data from your browser. To request access, correction, or deletion of cloud information, contact the publisher using the address added above. The operator must establish and follow a response process before launch.
Security and children
Cloud access is protected by Supabase authentication and database/storage access policies. No online service can guarantee absolute security. Tripmaat is not designed for children under 13.
Contact
[Add a working privacy contact email before public launch.]