Privacy Policy
This is tripcode's platform privacy policy, which applies to operators using tripcode. An operator Data Processing Agreement covering data you process as an operator is being finalized and will be linked here.
Effective date: August 23, 2026
1. Introduction
Welcome to tripcode ("we", "us", or "our"). tripcode is a product of zhakura studio GmbH, a company registered in Switzerland (commercial register no. CHE-248.204.588) with its registered office at Winzerhalde 109, 8049 Zürich, Switzerland. zhakura studio GmbH is the data controller responsible for the personal data described in this policy, except where this policy states otherwise (see "Guest & Web Booker Data", where the operator is the controller and tripcode acts as processor). We operate the tripcode mobile application and website (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
By accessing or using the Service, you agree to this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
2. Information We Collect
Account Information
When you create an account, we collect your email address, name, profile photo, travel style preferences, interest tags, and biographical information you choose to provide.
During account setup we also collect your date of birth. We use your date of birth for the following purposes:
- Age verification. To confirm you meet the 18+ requirement set out in our Terms.
- Trip matching. When a trip host sets a participant age range on their trip, we may use your computed age (whole years) to determine whether and how prominently the trip is shown to you. We do not share your date of birth with the host.
- Optional profile display. Your age is hidden from other users by default. You may opt in from Settings to display your age (in whole years) on your public profile. Your full date of birth is never displayed to other users — only the computed age, and only with your explicit opt-in.
The legal bases for this processing are the performance of our contract with you (the Terms), our legitimate interest in matching travellers to suitable trips, and — for the optional profile display — your consent, which you can withdraw at any time by toggling the setting off.
Trip Information You Set as a Host
When you create a trip, you may set a preferred participant age range. This range is shown publicly on the trip page so prospective participants can self-select. The age range reflects your preference for the trip and is not derived from any individual user's date of birth.
For trips you have set to public, we display the trip's title, destination, dates, and your first-letter avatar on our public marketing pages (e.g. tripcode.io). This metadata contains no third-party personal data and is licensed to us under our Terms.
Your uploaded cover image is handled separately. We display it on our marketing pages only when you have explicitly opted in by enabling the "Feature my cover image on tripcode.io" toggle on the trip. The opt-in is off by default; when off, we may substitute a stock photograph (e.g. licensed via Unsplash) representative of the destination, so the trip can still appear on the marketing page without exposing any people identifiable in your upload. You can disable the cover-featuring opt-in at any time by editing the trip; your cover will be removed from the marketing page on the next deploy. When you opt in, you confirm that you have any necessary consents from anyone identifiable in your cover image. If anyone identifiable in your cover image objects to its display, they (or you) can request removal directly from each card or by emailing hello@tripcode.io; we action removal requests within a reasonable timeframe.
Waitlist Information
If you sign up for our waitlist via the landing page, we collect your email address and the source of your submission.
Trip & Travel Data
When you create or join trips, we collect trip destinations, dates, itineraries, trip status, participant lists, and related planning details.
Social Content
We collect content you post through the Service, including chat messages, trip reviews, ratings, and photos shared in trip albums.
Financial Data
If you use the expense tracking feature, we collect expense descriptions, amounts, and split details. tripcode does not directly process payments between users.
For bookings taken through your web storefront, payments are processed by Stripe via Stripe Connect. tripcode does not collect, store, or have access to card numbers or other payment credentials — these are handled entirely by Stripe. We receive only non-sensitive transaction metadata (such as amount, currency, and booking status) needed to record the booking. Stripe's processing of payment data is governed by Stripe's Privacy Policy.
When you pay for an operator plan or per-trip platform fee, that charge is billed by tripcode to your own payment method and processed by Stripe. We keep the resulting invoice and transaction records as described in "Data Retention".
Guest & Web Booker Data
Operators can sell trips through a web storefront. A visitor can book without creating a tripcode account — we call them a guest. This subsection explains how guest data is handled.
- What we collect. At checkout we collect only the guest's name and email. No account, password, or profile is created, and no date of birth, travel preferences, or other profile data is collected.
- Controller and processor. For guest personal data collected through an operator's storefront, the operator is the data controller and tripcode is the processor, handling the data on the operator's behalf to fulfil the booking. The operator must have a lawful basis for the processing — typically performance of the booking contract.
- Roster visibility. A guest's name (not their email) is shown to co-travellers on the trip roster, with the same visibility as any other participant. Email addresses are never shown to co-travellers.
- No enrichment or marketing. Guest data is not added to any tripcode person-graph, used for marketing, or enriched with additional attributes. It is used only to service the booking, unless the guest chooses to create a full tripcode account.
- Account reconciliation. If a guest later creates a tripcode account using the same email address, the booking is reconciled into that account, and from that point the standard tripcode privacy terms apply to them as an account holder.
- Retention. Guest name and email are retained for the duration of the trip plus a reasonable post-trip period (up to 12 months) to support tax, accounting, and chargeback obligations, after which they are deleted — unless the guest has created an account or a longer period is legally required.
- Guest rights. Guests can request access, correction, or deletion of their data by emailing hello@tripcode.io. As controller, the operator is responsible for honouring these requests; where tripcode receives a request as processor, we will act on the operator's instructions and inform the operator so records can be updated.
Device & Usage Data
When you enable push notifications, we store your device's push notification token and its platform (iOS or Android) so we can deliver notifications to you. We do not integrate any third-party analytics, advertising, or crash-reporting SDKs, and we do not track your activity across other apps or websites.
Authentication Data
If you sign in using Sign in with Apple or Sign in with Google, we receive the email address (or relay address, in the case of Apple's private email relay) and the name and profile information you have authorised that provider to share. We do not receive your password.
Sensitive Data
Some of the information you share through tripcode warrants particular care. We treat the following as sensitive and apply heightened safeguards (Row-Level Security, narrow access, transport encryption):
- Location data — trip destinations, geographic coordinates of trips you create or join, and any place names you add to itineraries. tripcode does not collect background or live device location.
- Photos — images you upload to trip albums. Photos are visible only to participants of the trip in which they are posted.
- Chat messages — direct and group messages exchanged with other trip participants. Messages are stored on our infrastructure to enable delivery and history; they are not end-to-end encrypted.
3. How We Use Your Information
We use the information we collect to:
- Create and manage your account
- Provide, maintain, and improve the Service
- Facilitate trip discovery, creation, and collaborative planning
- Enable communication between trip participants via in-app chat
- Send push notifications about trip updates, applications, and messages
- Send waitlist and service-related email communications
- Track and display trip expenses among participants
- Display user profiles, reviews, and reputation within the community
- Monitor and analyse usage trends to improve the Service
- Detect, prevent, and address fraud or security issues
4. How We Share Your Information
With Other Users
Your profile information, trip activity, reviews, chat messages, and shared photos are visible to other trip participants and, where applicable, the broader tripcode community. Your profile name, photo, and travel style may be visible to other users browsing trips.
With Service Providers
We share information with third-party service providers that help us operate the Service. Personal data is stored primarily in the European Union (see "International Data Transfers" below); some providers are located in, or transfer data to, other countries, for which we apply the safeguards described in that section. Our providers include:
- Supabase — database hosting, authentication, and real-time infrastructure. Your data is stored in the EU (Ireland) region.
- Expo (USA) — push notification delivery (relayed to Apple and Google push services)
- Resend (USA / EU) — transactional email delivery (waitlist welcome messages, feedback acknowledgements, and booking/inquiry emails)
- Stripe (USA / EU) — payment processing and Stripe Connect account management for web-storefront bookings and operator billing
- Mapbox (USA) — geocoding of destinations and itinerary place names you enter (converting the location text you type into map coordinates)
- Unsplash (USA) — stock destination imagery; we send only the destination or place name as a search query
- Anthropic (USA) — AI-assisted features such as itinerary generation; receives the trip details or prompt text you submit to those features
- RevenueCat (USA) — management of in-app subscriptions and purchases; receives your tripcode account identifier and purchase/receipt data
- Cloudflare (USA) — content delivery and hosting for our website, storefronts, and public pages
- Apple Inc. — Sign in with Apple authentication and, for subscriptions and in-app purchases, App Store purchase processing
- Google LLC — Sign in with Google authentication, Google Play in-app purchase processing, and map rendering on Android devices
For Legal Compliance
We may disclose your information if required to do so by law, in response to a court order or subpoena, or to protect our rights, property, or safety, or that of our users or others.
We Do Not Sell Your Data
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
5. Data Storage & Security
Your data is stored on secure cloud infrastructure provided by Supabase, in the European Union (Ireland region). We implement industry-standard security measures including:
- Row-Level Security (RLS) policies on all database tables, ensuring users can only access data they are authorised to see
- Encrypted authentication using JSON Web Tokens (JWT)
- Secure HTTPS connections for all data transmission
- Server-side JWT verification for all authenticated requests
While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
6. Breach Notification
If we become aware of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify affected users without undue delay and, where feasible, no later than 72 hours after becoming aware of it. Where required, we will also notify the competent supervisory authority within the same timeframe (revFADP Art. 24, GDPR Art. 33–34).
Notifications will be sent to the email address associated with your account and, where appropriate, surfaced inside the app. They will include the nature of the breach, the categories of data affected, the likely consequences, and the measures taken or proposed to address it.
7. Your Rights & Choices
Depending on your location, you may have the following rights under applicable data protection laws, including the Swiss Federal Act on Data Protection (revFADP, in force from 1 September 2023), the EU/EEA General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA):
- Access: You have the right to request a copy of the personal data we hold about you.
- Correction: You have the right to request correction of inaccurate or incomplete personal data.
- Deletion: You have the right to request deletion of your personal data. You can delete your account through the app settings, or contact us to request deletion.
- Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
- Restriction of Processing: You have the right to request that we restrict the processing of your personal data under certain circumstances.
- Objection: You have the right to object to the processing of your personal data where we rely on legitimate interests as the legal basis.
- Withdraw Consent: Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of prior processing.
- Lodge a Complaint: You have the right to lodge a complaint with a data protection supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch). If you are in the EU/EEA, you may complain to the supervisory authority in your country of residence or place of work.
- Notifications: You can manage your push notification preferences in your device settings and within the app.
- Waitlist: You can unsubscribe from waitlist communications at any time by contacting us.
For California Residents (CCPA)
If you are a California resident, you have the right to: (1) know what personal information we collect, use, and disclose; (2) request deletion of your personal information; (3) opt out of the sale of your personal information — we do not sell your personal information; and (4) not be discriminated against for exercising your privacy rights.
To exercise any of these rights, you may contact us at hello@tripcode.io. We will respond to your request within the timeframe required by applicable law.
8. Data Retention
We keep personal data only for as long as we need it for the purposes described in this policy, after which we delete or anonymise it. The main retention periods are:
- Account & profile data (including email, name, profile photo, date of birth, and preferences) — kept while your account is active. When you delete your account, your data is hard-deleted within 30 days, following a short grace period during which the deletion can be reversed.
- Content you create (chat and direct messages, trip albums, trips, itineraries, and reviews) — deleted together with your account within the same 30-day window.
- Push notification tokens — kept until you sign out, uninstall the app, or the token expires.
- Waitlist email addresses — kept until you unsubscribe or we notify you that the Service has launched, and in any event no longer than 24 months.
- Guest & web-booker data (name and email captured through an operator storefront) — kept for the duration of the trip plus up to 12 months for tax, accounting, and chargeback purposes, as set out in "Guest & Web Booker Data" above, unless the guest creates an account or a longer period is legally required.
- Billing and transaction records — where we are legally required to keep accounting records (for example, under Swiss commercial law), we retain the necessary invoice and transaction data for up to 10 years, even after account deletion. These records are limited to what the law requires.
We may retain limited information for longer where necessary to comply with a legal obligation, resolve a dispute, or enforce our agreements.
9. Children's Privacy
The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly.
10. International Data Transfers
tripcode is operated by zhakura studio GmbH, based in Zürich, Switzerland. Your personal data is stored and processed primarily in the European Union (Supabase, Ireland region).
Transfers of personal data between Switzerland and the European Economic Area (EEA) are covered by mutual adequacy: the EU recognises Switzerland as providing an adequate level of data protection, and Switzerland recognises the EEA.
Some of our service providers (see "How We Share Your Information") are located in, or transfer data to, countries outside Switzerland and the EEA, including the United States. Where personal data is transferred to such a country, we rely on appropriate safeguards under applicable data protection law — in particular the European Commission's Standard Contractual Clauses (together with the Swiss addendum recognised by the FDPIC) and, where the provider is certified, the EU–U.S. Data Privacy Framework and its Swiss extension. You can request more information about these safeguards using the contact details below.
11. Beta Service & Data Handling
tripcode is currently offered as a beta service while we finalise the platform. As the Service evolves we may migrate or restructure data, but we will not intentionally delete your user-generated content (trips, photos, chat history, reviews) without first notifying you by email and/or in-app message. Routine schema or infrastructure changes that do not affect your content are made without prior notice.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Effective date" above. We encourage you to review this Privacy Policy periodically for any changes.
13. Contact Us
If you have any questions about this Privacy Policy, or wish to exercise your rights, please contact the data controller:
zhakura studio GmbH
Winzerhalde 109
8049 Zürich, Switzerland
hello@tripcode.io