Effective date: 6 June 2026 | Data Controller: TripVault (Vault Club), Finland | Contact: privacy@tripvault.app
1. Who We Are
TripVault is a travel budget intelligence platform operated by Vault Club, based in Finland. As a Finnish-based service operating within the EU, we are subject to GDPR. This policy explains what personal data we collect, why we collect it, and what rights you have.
2. What Data We Collect
Account data: email address, display name, authentication method, account creation date. Trip & planning data: destinations, dates, traveller composition, budget entries, itinerary notes, checklist status, packing lists. Documents (Pro tier+): files you upload to Document Vault including passports, insurance, confirmations, visas, medical documents. Payment data: processed by Stripe. We receive only payment confirmation status and tier purchased — never your card details. Technical data: IP address (used once on load to detect departure city, then discarded), browser type, usage patterns, error logs.
3. Why We Collect It — Lawful Basis
Account and trip data: contract performance — required to provide the service. Documents: contract performance — Document Vault is a feature you opted into. Payment data: legal obligation and contract performance. Technical data: legitimate interests to operate and secure the service. We do not use your data for advertising. We do not sell your data to any third party. Ever.
4. Who We Share Data With
Firebase (Google LLC) — authentication, database, document storage. GDPR compliant. Stripe Inc — payment processing. PCI-DSS certified and GDPR compliant. Anthropic PBC — estimation and itinerary generation. Trip data only (destination, dates, group size). No personal identifiers sent. ipapi.co — detects your city from IP on first load only. No persistent tracking. Vercel Inc — app hosting. GDPR compliant. We share data with no other parties.
5. How Long We Keep Your Data
Active account data: kept while your account is active. Trip data and documents: kept until you delete them or close your account. Payment records: 7 years (Finnish accounting law). Technical logs: maximum 90 days, then automatically deleted. Account deletion: all personal data permanently deleted within 30 days.
6. Your Rights Under GDPR
You have the right to: access your data, correct inaccurate data, delete your data, restrict processing, data portability, object to processing, and withdraw consent at any time. To exercise any right: email privacy@tripvault.app. We will respond within 30 days. You may also lodge a complaint with the Finnish Data Protection Ombudsman at tietosuoja.fi.
7. Data Security
All data in transit encrypted via HTTPS/TLS. Firebase Storage documents encrypted at rest. Firebase Security Rules ensure only you access your own data. Stripe handles all payment data — we never see your card details.
8. Cookies
We use only essential authentication cookies (Firebase Auth session tokens). No advertising cookies, tracking pixels, or analytics cookies.
9. Children
TripVault is for users aged 16 and over. Contact privacy@tripvault.app if you believe a child has created an account.
10. Contact
Privacy queries: privacy@tripvault.app | General: hello@tripvault.app