Privacy Policy

1. Introduction

Welcome to tripcode ("we", "us", or "our"). tripcode is a product of zhakura studio GmbH, a company registered in Switzerland (commercial register no. CHE-248.204.588) with its registered office at Winzerhalde 109, 8049 Zürich, Switzerland. zhakura studio GmbH is the data controller responsible for the personal data described in this policy. We operate the tripcode mobile application and website (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By accessing or using the Service, you agree to this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.

2. Information We Collect

Account Information

When you create an account, we collect your email address, name, profile photo, travel style preferences, interest tags, and biographical information you choose to provide.

During account setup we also collect your date of birth. We use your date of birth for the following purposes:

The legal bases for this processing are the performance of our contract with you (the Terms), our legitimate interest in matching travellers to suitable trips, and — for the optional profile display — your consent, which you can withdraw at any time by toggling the setting off.

Trip Information You Set as a Host

When you create a trip, you may set a preferred participant age range. This range is shown publicly on the trip page so prospective participants can self-select. The age range reflects your preference for the trip and is not derived from any individual user's date of birth.

For trips you have set to public, we display the trip's title, destination, dates, and your first-letter avatar on our public marketing pages (e.g. tripcode.io). This metadata contains no third-party personal data and is licensed to us under our Terms.

Your uploaded cover image is handled separately. We display it on our marketing pages only when you have explicitly opted in by enabling the "Feature my cover image on tripcode.io" toggle on the trip. The opt-in is off by default; when off, we may substitute a stock photograph (e.g. licensed via Unsplash) representative of the destination, so the trip can still appear on the marketing page without exposing any people identifiable in your upload. You can disable the cover-featuring opt-in at any time by editing the trip; your cover will be removed from the marketing page on the next deploy. When you opt in, you confirm that you have any necessary consents from anyone identifiable in your cover image. If anyone identifiable in your cover image objects to its display, they (or you) can request removal directly from each card or by emailing hello@tripcode.io; we action removal requests within a reasonable timeframe.

Waitlist Information

If you sign up for our waitlist via the landing page, we collect your email address and the source of your submission.

Trip & Travel Data

When you create or join trips, we collect trip destinations, dates, itineraries, trip status, participant lists, and related planning details.

Social Content

We collect content you post through the Service, including chat messages, trip reviews, ratings, and photos shared in trip albums.

Financial Data

If you use the expense tracking feature, we collect expense descriptions, amounts, and split details. tripcode does not directly process payments between users.

Purchase & Subscription Data

If you buy a subscription (tripcode Premium or Pro) or a paid tripcode, the purchase is processed as an in-app purchase by Apple (App Store) or Google (Google Play) and managed on our side through RevenueCat. We receive confirmation of the purchase and your resulting subscription or entitlement status; we do not receive or store your full card number. If you are a tripcode creator who receives payouts, those payments are processed by Stripe via Stripe Connect, and Stripe handles your payout and tax-identification data directly.

Device & Usage Data

When you enable push notifications, we store your device's push notification token and its platform (iOS or Android) so we can deliver notifications to you. We do not integrate any third-party analytics, advertising, or crash-reporting SDKs, and we do not track your activity across other apps or websites.

Authentication Data

If you sign in using Sign in with Apple or Sign in with Google, we receive the email address (or relay address, in the case of Apple's private email relay) and the name and profile information you have authorised that provider to share. We do not receive your password.

Sensitive Data

Some of the information you share through tripcode warrants particular care. We treat the following as sensitive and apply heightened safeguards (Row-Level Security, narrow access, transport encryption):

3. How We Use Your Information

We use the information we collect to:

4. How We Share Your Information

With Other Users

Your profile information, trip activity, reviews, chat messages, and shared photos are visible to other trip participants and, where applicable, the broader tripcode community. Your profile name, photo, and travel style may be visible to other users browsing trips.

With Service Providers

We share information with third-party service providers that help us operate the Service. Personal data is stored primarily in the European Union (see "International Data Transfers" below); some providers are located in, or transfer data to, other countries, for which we apply the safeguards described in that section. Our providers include:

With Connected Applications (AI Assistants)

You can connect third-party AI assistants (such as Claude, ChatGPT, or Gemini) to your tripcode account. Connecting is always initiated by you, through a secure sign-in and consent screen, and you choose what the assistant may do based on the permissions you grant:

A connected assistant acts as you, and can only access data you could already access yourself — the same Row-Level Security rules that protect your account in the app apply to it. We never share your tripcode password with the assistant. Information you send to, or that is retrieved by, a connected assistant is then handled under that assistant provider's own privacy policy and terms, which are outside tripcode's control.

You can review your connected applications and disconnect any of them at any time in Settings → Connected apps. Disconnecting immediately revokes that assistant's access.

For Legal Compliance

We may disclose your information if required to do so by law, in response to a court order or subpoena, or to protect our rights, property, or safety, or that of our users or others.

We Do Not Sell Your Data

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

5. Data Storage & Security

Your data is stored on secure cloud infrastructure provided by Supabase, in the European Union (Ireland region). We implement industry-standard security measures including:

While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

6. Breach Notification

If we become aware of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify affected users without undue delay and, where feasible, no later than 72 hours after becoming aware of it. Where required, we will also notify the competent supervisory authority within the same timeframe (revFADP Art. 24, GDPR Art. 33–34).

Notifications will be sent to the email address associated with your account and, where appropriate, surfaced inside the app. They will include the nature of the breach, the categories of data affected, the likely consequences, and the measures taken or proposed to address it.

7. Your Rights & Choices

Depending on your location, you may have the following rights under applicable data protection laws, including the Swiss Federal Act on Data Protection (revFADP, in force from 1 September 2023), the EU/EEA General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA):

For California Residents (CCPA)

If you are a California resident, you have the right to: (1) know what personal information we collect, use, and disclose; (2) request deletion of your personal information; (3) opt out of the sale of your personal information — we do not sell your personal information; and (4) not be discriminated against for exercising your privacy rights.

To exercise any of these rights, you may contact us at hello@tripcode.io. We will respond to your request within the timeframe required by applicable law.

8. Data Retention

We keep personal data only for as long as we need it for the purposes described in this policy, after which we delete or anonymise it. The main retention periods are:

We may retain limited information for longer where necessary to comply with a legal obligation, resolve a dispute, or enforce our agreements.

9. Children's Privacy

The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly.

10. International Data Transfers

tripcode is operated by zhakura studio GmbH, based in Zürich, Switzerland. Your personal data is stored and processed primarily in the European Union (Supabase, Ireland region).

Transfers of personal data between Switzerland and the European Economic Area (EEA) are covered by mutual adequacy: the EU recognises Switzerland as providing an adequate level of data protection, and Switzerland recognises the EEA.

Some of our service providers (see "How We Share Your Information") are located in, or transfer data to, countries outside Switzerland and the EEA, including the United States. Where personal data is transferred to such a country, we rely on appropriate safeguards under applicable data protection law — in particular the European Commission's Standard Contractual Clauses (together with the Swiss addendum recognised by the FDPIC) and, where the provider is certified, the EU–U.S. Data Privacy Framework and its Swiss extension. You can request more information about these safeguards using the contact details below.

11. Beta Service & Data Handling

tripcode is currently offered as a beta service while we finalise the platform. As the Service evolves we may migrate or restructure data, but we will not intentionally delete your user-generated content (trips, photos, chat history, reviews) without first notifying you by email and/or in-app message. Routine schema or infrastructure changes that do not affect your content are made without prior notice.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Effective date" above. We encourage you to review this Privacy Policy periodically for any changes.

13. Contact Us

If you have any questions about this Privacy Policy, or wish to exercise your rights, please contact the data controller:

zhakura studio GmbH
Winzerhalde 109
8049 Zürich, Switzerland
hello@tripcode.io