Beta · Last updated August 12, 2026
Tribe Trips ("we", "us") is a group-trip planning product currently in private beta. This page explains, in plain language, what we collect, why we are allowed to collect it, who we share it with, how long we keep it, and what you can demand of us.
Tribe Trips is the data controller for the personal data described here. Contact us about anything on this page at privacy@jointribetrips.com.
Account creation, sign-in, and running your trips
Contract — GDPR Art. 6(1)(b)
We cannot provide Tribe Trips without this.
Payments for trip unlocks
Contract — Art. 6(1)(b), plus legal obligation for tax records — Art. 6(1)(c)
Card details go to Paddle; we never see or store them.
Beta recordings, voice notes and written feedback review
Consent — Art. 6(1)(a)
Optional. Decline and the app works exactly the same. Withdrawable at any time.
First-party product analytics
Consent — Art. 6(1)(a) and the ePrivacy Directive
Off until you opt in. Nothing is recorded before you say yes.
Receipts and tax invoices attached to shared trip costs
Contract — Art. 6(1)(b), plus legitimate interests — Art. 6(1)(f)
Needed so a group can settle who paid for what. We also keep a short activity log of who uploaded, viewed, downloaded or removed a receipt, so trip members can hold each other accountable for shared money.
Security, abuse prevention, rate limiting, error diagnostics
Legitimate interests — Art. 6(1)(f)
You can object; email us and we will assess and respond.
Consent is never bundled. Declining beta recordings or analytics does not reduce your access to Tribe Trips in any way.
| Data | Retention |
|---|---|
| Account and profile data | Life of your account, then 30 days |
| Trip content (destinations, costs, chat, polls, flights, stays) | Life of your account, then 30 days. Content in shared trips stays with the trip for other members, with your name removed. |
| Beta recordings, voice notes, written feedback | 6 months, then deleted |
| Receipts and tax invoices you upload to a cost | Life of the trip. Deleted when the cost, the trip, or your account is deleted, and you can remove any file you uploaded at any time. |
| Prepared receipt archives (the ZIP files a download creates) | Deleted within 1 hour of being generated |
| Receipt activity log (who uploaded, viewed, downloaded or removed a receipt) | 24 months, then deleted |
| Product analytics events | 12 months, then deleted |
| Email delivery logs | 90 days, then deleted |
| Payment and webhook records | 7 years, as required for tax and accounting; personal fields stripped on erasure |
| Security and rate-limit records | Up to 30 days |
We do not keep anything indefinitely. Where a longer period applies, it is because tax or accounting law requires it, and we strip personal fields from those records on erasure.
Sharing recordings, voice narration or written notes is entirely voluntary and requires your separate, explicit consent, which you can withdraw at any time in Settings → Privacy. We use this material only to improve Tribe Trips. We do not share it with advertisers and we do not use it to train third-party models. It is visible to the founder and a small group directly helping analyse beta feedback, stored in a restricted-access folder, and deleted within 6 months.
Please don't include sensitive information in recordings or screenshots — payment card numbers, passport or ID details, real confirmation numbers, private addresses, health information, or anything else you wouldn't want a small product team to review. Use fake or scrambled data where you can.
Trip data is visible to members of that trip. Your display name and avatar are visible to people you share a trip with. Beyond that, we share data only with the service providers below, each of which processes it on our instructions for the stated purpose. We do not sell personal data.
| Provider | Purpose | Data sent | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage | All account and trip data, uploaded images | United States |
| Cloudflare | Hosting, edge delivery, DDoS protection | IP address, request metadata | Global / United States |
| Paddle | Payments and merchant of record; retains webhook metadata | Email, billing country, transaction and subscription identifiers | United Kingdom / United States |
| Optional sign-in (OAuth) | Email, name, avatar URL | United States | |
| Microsoft | Transactional and authentication email delivery | Email address, message content of the email itself | United States / Ireland |
| GoDaddy | Domain registration for jointribetrips.com. Where our Microsoft 365 mailbox is resold or hosted through GoDaddy, they also sit in the email delivery chain. | Domain registration records (no user data). If in the email chain: email address and message content of the email itself | United States |
| Lovable AI gateway (Google Gemini) | Flight lookup and smart-add enrichment | The text or link you submit for enrichment; flight number and date | United States |
| Lovable error reporting | Crash and error diagnostics | Error message, stack trace, route, browser type | United States / EU |
| Nominatim / OpenStreetMap | Geocoding and map tiles | Trip city, region and country; your location search text | European Union |
| AviationStack | Flight lookup | IATA flight code and date | United States |
| Serpstack | Flight-search fallback when AviationStack has no result | Flight number and date | United States |
| Link enrichment fetch | Reading page titles and images from links you paste | The URL you paste, fetched server-side from our infrastructure | Wherever the linked site is hosted |
We use Standard Contractual Clauses approved by the European Commission for transfers of personal data to Supabase (US), Paddle (UK/US), Google (US), Microsoft (US), and our other non-EU vendors, together with supplementary technical measures such as encryption in transit and at rest. You can request a copy of the relevant transfer mechanism by emailing privacy@jointribetrips.com.
We do not carry out automated decision-making that produces legal or similarly significant effects, and we do not build behavioural profiles of you or use your data for advertising or credit, insurance, or employment-related scoring.
If you are in the EU, EEA or UK, you have the following rights. We respond within one month.
You can find your national supervisory authority on the EDPB list of members. In the UK, that is the Information Commissioner's Office. In Australia, the Office of the Australian Information Commissioner.
We disclose personal information to overseas recipients in the United States, the United Kingdom, and Ireland. You consent to this disclosure. If you do not consent, do not sign up. This means Australian Privacy Principle 8.1 accountability for those overseas recipients does not apply to that disclosure, and those recipients may not be subject to the Privacy Act 1988. You may complain to the OAIC using the link above.
We use browser storage that is strictly necessary to keep you signed in and remember your privacy choices — this does not require consent. Product analytics uses no third-party trackers and is only active after you opt in.
You can delete your account at any time from Settings → Profile & account. That removes your profile, the trips you organised (with their itinerary, polls, costs and chat), your votes, comments, and consent records. On trips you only joined, your membership is removed and the trip stays for the other members with your name detached from shared records such as cost entries. Backups are purged on a rolling 30-day cycle.
Data is encrypted in transit and at rest. Access to trip data is enforced at the database level by row-level security, so one trip's members cannot read another's. Administrative access is limited to the founder.
Questions, requests, or complaints — email privacy@jointribetrips.com.
This is a beta policy and may change before general availability. We will notify signed-in users by email of material changes.