Privacy Policy
1. Who we are
Tripofreak ("we", "us", "our") is an AI-powered travel planning tool operated by Sahil Setia, based in Chandigarh, India. Our website is tripofreak.com. You can contact us at hello@tripofreak.com.
We are a travel planning and recommendation service. We are not a travel agency, tour operator, or booking platform. We do not handle travel bookings, ticket issuance, or accommodation reservations.
2. What data we collect and why
| What we collect | Why we collect it | Legal basis (GDPR) |
|---|---|---|
| Name and email address (via Google login) | To create and identify your account | Contract performance |
| Trip preferences (destination, dates, budget, interests, group type) | To generate your personalised itinerary | Contract performance |
| Payment status (paid or not paid) | To know if you have a premium plan | Contract performance |
| Saved itineraries | So you can access past trips from any device | Contract performance |
| Approximate country (from IP address) | To show you the right currency (INR or USD) | Legitimate interest |
We do not collect: phone numbers, physical addresses, passport details, financial account numbers, health data, biometric data, or any sensitive personal data as defined under DPDPA or GDPR.
3. How we use your data
- To generate and save your travel itineraries
- To send you your itinerary by email when you request it
- To remember your login across sessions
- To determine whether your account has premium access
- To show you prices in the correct currency based on your location
- To send you important account-related emails (payment confirmation, account deletion confirmation)
We do not use your data for advertising, profiling, or any automated decision-making that significantly affects you.
4. Who we share your data with
We share your data only with the services required to operate Tripofreak. These are:
| Service | What they receive | Why | Their privacy policy |
|---|---|---|---|
| Supabase (USA) | Your account data and itineraries | Database storage | supabase.com/privacy |
| Google (USA) | Your Google account info | Login via OAuth | policies.google.com/privacy |
| Groq (USA) | Your destination and trip preferences | AI itinerary generation | groq.com/privacy-policy |
| Razorpay (India) | Your payment transaction | Processing India payments | razorpay.com/privacy |
| Stripe (USA) | Your payment transaction | Processing global payments | stripe.com/privacy |
| Resend (USA) | Your email address | Sending you emails | resend.com/privacy |
We do not sell, rent, or trade your personal data to any third party for any commercial purpose. We never have and never will.
We also display affiliate links to third-party booking platforms (MakeMyTrip, Booking.com, Agoda, Cleartrip, Expedia, TripAdvisor). When you click these links, you leave Tripofreak and enter those platforms. Their privacy policies apply from that point. Tripofreak earns a commission on bookings made through these links at no extra cost to you.
5. International data transfers
Some of our service providers (Supabase, Groq, Stripe, Resend) are based in the United States. When your data is transferred to the US, it is protected by the providers' own compliance frameworks (Standard Contractual Clauses under GDPR, and applicable data protection agreements).
For Indian users: these transfers comply with the Digital Personal Data Protection Act 2023 (DPDPA). We only transfer data to jurisdictions and providers with adequate data protection standards.
6. Cookies and tracking
We use the minimum number of cookies necessary to operate Tripofreak:
- Session cookie โ keeps you logged in. Deleted when you log out.
- Preference cookie โ remembers your currency preference (INR/USD).
We do not use advertising cookies, tracking pixels, Facebook Pixel, Google Ads cookies, or any third-party analytics cookies. We do not track you across other websites.
You will see a cookie notice when you first visit Tripofreak. You can decline non-essential cookies and the site will still work fully.
7. Your rights
Regardless of where you are in the world, you have the following rights over your personal data:
Right to access
You can ask us what personal data we hold about you. We will respond within 30 days.
Right to correct
If any data we hold is incorrect, you can ask us to correct it.
Right to delete (Right to be forgotten)
You can delete your account at any time from your account settings. This permanently deletes your account, all saved itineraries, and all personal data from our systems within 30 days. Some data may be retained for legal or financial compliance (payment records) as required by Indian law.
Right to data portability (GDPR / EU users)
You can request a copy of all data we hold about you in a readable format. Email us at hello@tripofreak.com.
Right to withdraw consent
You can withdraw your consent to data processing at any time by deleting your account.
California users (CCPA)
California residents have the right to know what personal data we collect and share, the right to delete it, and the right to opt out of sale. We do not sell personal data, so the opt-out right does not apply. For access or deletion requests, email hello@tripofreak.com.
Indian users (DPDPA)
Under India's Digital Personal Data Protection Act 2023, you have the right to access your data, correct it, and withdraw consent. You also have the right to nominate someone to exercise these rights on your behalf. To exercise any of these rights, email hello@tripofreak.com. We will respond within 72 hours.
8. How long we keep your data
| Data type | How long we keep it |
|---|---|
| Account data (name, email) | Until you delete your account |
| Saved itineraries | Until you delete your account or delete the itinerary |
| Payment records | 7 years (required by Indian financial law) |
| Session data | 30 days after last login |
9. Children's privacy
Tripofreak is not directed at children under 18 years of age. We do not knowingly collect personal data from anyone under 18. If you are a parent or guardian and believe your child has provided us with personal data, please email hello@tripofreak.com and we will delete it promptly.
10. Security
We protect your data using industry-standard security measures: HTTPS encryption on all connections, secure database storage via Supabase with row-level security, and OAuth login (we never store passwords). Payment data is handled entirely by Razorpay and Stripe โ we never receive or store card details.
No system is 100% secure. If there is ever a data breach that affects your personal data, we will notify you by email within 72 hours as required by GDPR and DPDPA.
11. Changes to this policy
If we make significant changes to this policy, we will notify you by email and update the "Last updated" date at the top. Continued use of Tripofreak after the change means you accept the updated policy.
Questions or requests
For any privacy-related question, data access request, or deletion request:
Email: hello@tripofreak.com
We respond within 72 hours. For GDPR requests, we respond within 30 days as required by law.