Privacy Policy
Effective date: 6 June 2026 | Last updated: 6 June 2026
Data Controller: TripVault (Vault Club) | Contact: privacy@tripvault.app
1. Who We Are
TripVault is a family and group travel budget intelligence platform operated by Vault Club, based in Finland. We help families and groups plan trips, estimate costs, avoid tourist traps, and store travel documents. Our app is available at app.tripvault.vaultclub.vip.
As a Finnish-based service operating within the European Union, we are subject to the General Data Protection Regulation (GDPR). This policy explains what personal data we collect, why we collect it, how we use it, and what rights you have.
2. What Data We Collect
2.1 Account Data
When you create an account we collect:
- Email address
- Display name (if provided)
- Authentication method (Google sign-in, email/password, or anonymous)
- Account creation date and last login
2.2 Trip & Planning Data
When you use the planning features we collect:
- Trip destinations, dates, and duration
- Traveller composition (number of adults, children, infants)
- Budget estimates and actual spend entries
- Trip type preferences (family, group, couple, solo, nomad)
- Itinerary events and planner notes
- Crisis checklist completion status
- Tourist trap avoidance records
- Packing list items
2.3 Documents (Pro tier and above)
If you use Document Vault, we store files you upload including:
- Passport scans or photos
- Travel insurance documents
- Flight and hotel confirmations
- Visa documents
- Medical documents
- Any other files you choose to upload
Documents are stored in Firebase Storage and linked to your account. Only you can access your documents.
2.4 Payment Data
Payments are processed by Stripe. We do not store your card number, CVV, or full payment details. We receive from Stripe only: payment confirmation status, subscription tier purchased, and transaction reference ID.
2.5 Technical Data
We automatically collect limited technical data when you use the app:
- IP address — used once on app load to detect your departure city via ipapi.co, then discarded
- Browser type and device type
- App usage patterns (which screens you visit, features used)
- Error logs
3. Why We Collect It — Lawful Basis
Under GDPR, we must have a lawful basis for processing your data. Here is our basis for each category:
- Account data — Contract performance: required to provide the service you signed up for
- Trip and planning data — Contract performance: this is the core service
- Documents — Contract performance: Document Vault is a paid feature you opted into
- Payment data — Legal obligation and contract performance
- Technical data — Legitimate interests: to operate, improve, and secure the service
We do not use your data for advertising. We do not sell your data to any third party. Ever.
4. Who We Share Data With
We use the following third-party services (sub-processors) to operate TripVault. Each has been selected for GDPR compliance:
- Firebase (Google LLC) — authentication, database, and document storage. Data stored in EU regions where available. Google's DPA applies.
- Stripe Inc — payment processing. Stripe is PCI-DSS certified and GDPR compliant.
- Anthropic PBC — AI cost estimation and itinerary generation. Your trip data (destination, dates, family size) is sent to Anthropic's API to generate estimates. No personal identifiers (name, email) are sent. Anthropic's data processing terms apply.
- ipapi.co — detects your approximate city from your IP address on first app load only, to pre-fill your departure city. No persistent tracking.
- Vercel Inc — app hosting and serverless functions. GDPR compliant.
We do not share your data with any other parties, including advertisers, data brokers, or analytics platforms.
5. How Long We Keep Your Data
- Active account data — kept for as long as your account is active
- Trip data — kept until you delete the trip or close your account
- Documents — kept until you delete the document or close your account
- Payment records — kept for 7 years (Finnish accounting law requirement)
- Technical logs — kept for maximum 90 days, then automatically deleted
When you delete your account, all personal data is permanently deleted within 30 days, except payment records required by law.
6. Your Rights Under GDPR
As an EU resident you have the following rights. To exercise any of them, email privacy@tripvault.app and we will respond within 30 days.
- Right of access — request a copy of all data we hold about you
- Right to rectification — ask us to correct inaccurate data
- Right to erasure ('right to be forgotten') — ask us to delete all your data
- Right to restriction — ask us to pause processing your data
- Right to data portability — receive your data in a machine-readable format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — where processing is based on consent, you can withdraw at any time
You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi) if you believe we have handled your data unlawfully.
7. Data Security
We take reasonable technical and organisational measures to protect your data:
- All data in transit is encrypted via HTTPS/TLS
- Firebase Storage documents are encrypted at rest
- Firebase Security Rules ensure only you can access your own data
- Stripe handles all payment data — we never see your card details
- Access to production systems is restricted to authorised personnel only
In the event of a data breach affecting your rights and freedoms, we will notify the Finnish Data Protection Ombudsman within 72 hours and notify affected users promptly.
8. Cookies
TripVault is a web application. We use only essential technical cookies required for authentication (Firebase Auth session tokens). We do not use advertising cookies, tracking pixels, or analytics cookies. No cookie consent banner is required for essential cookies only.
9. Children
TripVault is intended for users aged 16 and over. We do not knowingly collect personal data from children under 16. If you believe a child has created an account, contact privacy@tripvault.app and we will delete it.
10. Changes to This Policy
We will notify you by email and with an in-app notice if we make material changes to this Privacy Policy. The updated policy will show a new effective date at the top. Continued use of TripVault after notification constitutes acceptance.
11. Contact
Data Controller: TripVault / Vault Club, Finland
Privacy queries: privacy@tripvault.app
General queries: hello@tripvault.app
Response time: within 30 days as required by GDPR