Tripvio

Legal

Privacy Policy

Last updated 29 September 2026

Trang này chỉ có bản tiếng Anh. Đây là văn bản pháp lý, và một bản dịch chưa được rà soát có thể diễn đạt điều chúng tôi không cam kết — vì vậy chúng tôi hiển thị bản gốc có hiệu lực thay vì một bản dịch gần đúng.

The short version: you can plan trips without telling us who you are, we do not sell your data or run advertising trackers, and you can have everything we hold deleted by asking.

1. Who we are

Tripvio is an AI trip-planning service operated by Tripvio, established in Singapore ("we", "us"). This policy explains what personal data we collect when you use tripvio.ai, why we collect it, who we share it with, and what you can ask us to do with it.

For any question about this policy, or to exercise the rights described in section 9, write to support@tripvio.ai.

2. Using Tripvio without an account

You can generate, view, and share trips without signing up. When you do, we do not know who you are.

We do set one small identifier in your browser so that we can apply a limit on how many trips a single visitor can create at once. It is a random value with no name, email, or profile attached, and it is not used for advertising, analytics, or tracking you across other websites.

3. Data we collect

Depending on how you use the service, we hold:

  • Account data — your email address, a securely hashed version of your password (never the password itself), your display name if you provide one, whether your email has been verified, and the time you last signed in.
  • Social sign-in data — if you sign in with Google or Facebook, we receive and store your provider account identifier, your email address, and your name. We do not receive or store your password for that provider, and we deliberately do not keep the access tokens those providers issue: we never call Google or Facebook again on your behalf after you sign in.
  • Trip data — the destinations you enter, the number of days per destination, your travel dates and party size, the travel preferences and budget you select, an approximate departure city, and the itineraries generated for you. Trips you create while signed in are linked to your account; trips created while signed out are linked only to the browser identifier described in section 2.
  • Collaboration data — if you plan a trip with other people, we hold the messages you send to the trip planner, any comments and reactions you leave on individual stops, and the email addresses you enter when inviting someone. An invitation email address is used to send that invitation and to let the invited person join.
  • Flight booking data — if you reserve a flight through us, we pass the passenger details you enter (name, date of birth, gender, email address, and phone number) to our flight partner, who issues and holds the reservation. We keep only the passenger names and the booking reference so that we can show you the booking; we do not keep the date of birth, gender, or contact details you entered for it.
  • Weekly email list — if you sign up for “Where this weekend” (“Cuối tuần đi đâu”), we hold your email address, the language you chose, which page you signed up on, the short link you arrived through if any, and when you confirmed or unsubscribed. We send nothing but a confirmation link until you press it.
  • Correspondence — anything you send us by email, kept so we can answer you and keep a record of the request.
  • Technical data — our servers keep ordinary access logs, which include IP addresses, timestamps, and the pages requested. These are used to operate and secure the service and are not combined into a profile of you.
  • Public profile and published trips — if you choose to publish a trip, it appears in the public feed credited to the handle you pick, with the display name and one-line bio you add, if any. People see the month you travel, not your exact dates; the city you start from still appears in the trip's first and last travel stops. Publishing is optional and you can remove a trip from the feed at any time. When you like a published trip we store that you liked it, and show only the total.
  • Weekly challenges — a trip you publish to the feed takes part automatically in that week's challenge if it includes the challenge's destination. It is ranked by how many signed-in people copied it; the ranking shows your handle and the trip, as the feed does. If you win, we use your account email once, to arrange the prize.
  • Sharing counts — when you open the share panel, tap a sharing option, or save or share a trip's story image, and when someone opens a trip from a shared link, we count it: what happened, which app it went through (for example Zalo) and which trip. Nothing about who you are is stored with these counts.
  • Usage data — how pages are used: which pages you visit, what you click, how far you scroll, and how your pointer moves across the page, collected by the analytics tool described in section 4. It carries no name or email address, and we do not link it to your account.

4. Cookies and analytics

We do not use advertising cookies and we do not show advertising. Apart from the analytics described below, cookies are used only for things the service cannot work without.

  • Authentication cookies — set when you sign in, so that you stay signed in. They are marked httpOnly, which means scripts running in your browser cannot read them.
  • A sign-in handshake cookie — short-lived, used to protect the Google and Facebook sign-in flow against cross-site request forgery.
  • A visitor identifier — described in section 2, used to apply the trip limit for people who are not signed in.
  • A link source cookie — when you arrive through one of our short links (tripvio.ai/r/…), we remember that link's code for 30 days, so that if you then plan or copy a trip we can count it toward the link. It holds only the code, nothing about you, and is marked httpOnly.
  • Microsoft Clarity — an analytics tool that helps us see how the site is actually used, so we can find pages that confuse people. It runs in your browser and records your interactions with the page, including clicks, scrolls, and pointer movement, which lets us replay an anonymised session and build heatmaps. It sets its own cookies to recognise a returning visit. We do not use it to identify you, and we do not combine it with your account. Microsoft processes this data as our provider under its own privacy terms.
  • Clarity currently loads for every visitor, and we do not yet ask for your consent before it does. If you would rather it did not run, most browsers can block it, and you can email us to ask us to delete the recordings associated with your visit.
  • Map tiles are served by Mapbox, which may set its own cookies when a map loads. Their use of those cookies is governed by Mapbox's privacy policy.

5. Why we use it, and on what basis

  • To provide the service you asked for — generating itineraries, saving and reloading your trips, and keeping you signed in. Where a law such as the GDPR applies, our basis is performance of a contract with you.
  • To send you a verification email when you sign up, and to answer messages you send us. Basis: performance of a contract, and our legitimate interest in responding to you.
  • To send the weekly email list, if you signed up and confirmed. Basis: your consent, which you can withdraw at any time with the unsubscribe link in every issue.
  • To keep the service working and secure — applying usage limits, preventing abuse, and investigating faults. Basis: our legitimate interest in a functioning, secure service.
  • To understand how the site is used, so we can improve pages that are confusing or broken. Basis: our legitimate interest in improving the service. You can object to this — see section 9.
  • To comply with legal obligations where they apply to us.

6. Who we share it with

We do not sell personal data and we do not share it for advertising. We do rely on a small number of service providers to run Tripvio, and the relevant data reaches them only for the purpose described:

  • AI model providers (Anthropic and, where selected, OpenAI) — receive the trip parameters you enter, in order to generate an itinerary. They do not receive your email address, your name, or your account identifier.
  • Voyage AI — receives trip parameters as search text, used to match your request against our catalog of places.
  • Mapbox, and OpenStreetMap's Nominatim service as a fallback — receive place names and coordinates for geocoding, routing, and map display.
  • Google — Places data and the Gemini model are used to describe and enrich places in our catalog. These calls are about places, not about you.
  • Google and Meta (Facebook) — only if you choose to sign in with them, and only as part of that sign-in.
  • Resend — our email provider, receives your email address in order to deliver verification and service emails, and the weekly list if you signed up for it.
  • Render — our hosting provider, which operates the servers and managed database the service runs on.
  • Microsoft — receives the usage data described in section 4 through Clarity, in order to give us analytics about how the site is used. It receives no account data from us.
  • Booking partners (Agoda, Booking.com, Viator, and Travelpayouts/Aviasales for flight prices) — we send no personal data to them. Booking links are ordinary outbound links; if you follow one, that partner's own privacy policy governs what happens next.
  • Duffel — our flight booking partner. If, and only if, you reserve a flight through us, Duffel receives the passenger details described in section 3 in order to make that reservation with the airline. Duffel holds the reservation and is the system of record for it; deleting a trip here does not cancel a reservation made with them.
  • We may also disclose data where we are legally required to, or to establish or defend legal claims.

7. International transfers

The providers listed above operate internationally, so your data may be processed outside the country where you live. Where the law requires a transfer safeguard — such as the European Commission's standard contractual clauses — we rely on the mechanism offered by the provider concerned.

8. How long we keep it

  • Account data — for as long as your account exists, and deleted when you ask us to delete the account.
  • Trips — until you delete the trip, or until your account is deleted.
  • Sign-in tokens — refresh tokens are stored only as an irreversible hash, are replaced each time they are used, and are removed when you sign out.
  • Collaboration data — messages, comments, and reactions are kept for as long as the trip they belong to, and are deleted with it. An invitation is kept until it is accepted or expires.
  • Flight bookings — the passenger names and booking reference are kept for as long as the trip. The reservation itself is held by our flight partner under their own retention terms, and is not cancelled by deleting the trip here.
  • Weekly email list — while you are subscribed. When you unsubscribe we keep your address marked as unsubscribed, so that it is never added back without you signing up again; email us to have it removed entirely.
  • Access logs — retained for a short period for security and troubleshooting, then discarded.
  • Usage data — kept by our analytics provider under its own retention schedule, which is currently a rolling period measured in months rather than years.

9. Your rights

Depending on where you live, you may have the right to ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. You can also withdraw consent where we relied on it, and complain to your local data protection authority.

To exercise any of these, email support@tripvio.ai from the address on your account. We will not charge you for a reasonable request and we will respond within the period the applicable law allows — one month under the GDPR.

10. Deleting your data

You can delete any individual trip yourself from the trip's own page, whether or not you have an account.

To delete your whole account, including your email address, your social sign-in link, and every trip attached to it, follow the instructions on our data deletion page. If you signed in with Facebook or Google, note that removing Tripvio from that provider's own app settings stops future sign-ins but does not by itself delete the data we already hold — send us the request as well.

How to delete your data

11. Children

Tripvio is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

12. Security

Passwords are stored using a one-way hash, never in a form we could read. Sign-in cookies are marked httpOnly and are sent only over HTTPS. Refresh tokens are stored hashed and rotated on every use, so an old one cannot be reused.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority where the law requires it.

13. Changes to this policy

We may update this policy. When we do, we will revise the date at the top of this page, and we will tell you about material changes where it is reasonably practicable to do so.

14. Contact

Questions, requests, or complaints about privacy can be sent to support@tripvio.ai.

See also our Terms of Use , or get in touch.