Skip to content

Privacy policy

Last updated: 18 August 2026

At Trips Together Limited, we value your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, and protect your information in compliance with the UK General Data Protection Regulation (GDPR).

Who We Are

Trips Together Limited is a platform that simplifies group travel planning by syncing travel preferences, suggesting trips, and providing itinerary-building tools. Our brochure website is located at https://www.tripstogether.co.uk.

If you have questions about this policy, contact us:
Email: support@tripstogether.co.uk

1. What Information We Collect

1.1 Personal Data You Provide

Account Information: Name, email address, phone number, and password.

Travel Preferences: Destinations, budgets, duration preferences, and travel history.

Calendar Data: Availability information if you sync your calendar.

Friend Connections: Contacts or group member details if you add friends.

1.2 Content You Post in the App

Trip Chat: Messages, photos and their captions, polls and poll votes, expense entries, and reactions that you post in a trip are stored on our systems so that the other members of that trip can see them, and so that they are still there when you come back to the app. They are visible to the members of that trip, and to us where we need to access them for the purposes described in this policy. Photos you send are stored in our cloud storage.

Retention: Trip content is kept for as long as the trip exists. Deleting a message removes it from the chat for everyone. When you delete your account, we delete your account information and remove you from your trips. A trip you organised that still has other members continues for them under a new organiser, and content you have already posted in a trip chat remains visible to the members of that trip. See section 6.

Reports and moderation: If you report content, or if our automated filters flag content, we create a moderation record. That record contains a copy of the reported content and of the display name and account identifiers of the person who posted it, the reason given, and the identity of the reporter. See section 6.1 for how long we keep it and who can see it.

1.3 Automatically Collected Data

Device Information: IP address, browser type, operating system, and device identifiers.

Usage Data: Interactions with our app and website (e.g., clicks, page views, and session duration).

Cookies and Tracking Technologies: For analytics and improving user experience.

1.4 Third-Party Data

Data from linked accounts (e.g., Google Calendar) when authorized by you.

1.5 Calendar Data

If you connect your device calendar to help coordinate trip dates, the app reads your calendar on your device only to work out which dates you are busy. We do not store your calendar events. Details such as event titles, descriptions, locations, attendees, and times are never sent to or stored on our servers. The only thing we save is the list of dates you are busy, so your group can find dates that suit everyone. Connecting your calendar is optional: you can skip it and enter your busy dates by hand, and you can disconnect at any time.

2. How We Use Your Data

We use your data for the following purposes:

Service Delivery: To provide app features such as trip suggestions and itinerary creation.

Customization: To tailor recommendations and itineraries based on your preferences.

Communication: To send you updates, notifications, or respond to inquiries.

Improvements: To analyse usage patterns and improve the app and website.

Compliance: To meet legal obligations or enforce our terms of service.

Safety and Moderation: To screen content automatically, to review content that is reported to us, and to take action on accounts that break our Community Guidelines.

3. Legal Basis for Processing

Under GDPR, we process your data based on:

Consent: When you sign up, link accounts, or provide preferences.

Contractual Necessity: To deliver services you request.

Legitimate Interests: To improve and secure our platform.

Legal Obligations: When required to comply with laws or regulations.

4. How We Share Your Data

We may share your data with:

Service Providers: For hosting, analytics, and customer support.

Business Partners: To process bookings or other travel services.

Legal Authorities: When required by law.

We do not sell your personal data to third parties.

4.1 Third-Party Sub-Processors

We use the following third-party service providers (“sub-processors”) to run specific features. Each one only receives the personal data it needs for the purpose listed. Where data is transferred outside the UK, we rely on Standard Contractual Clauses or equivalent safeguards, and each provider is bound by a data processing agreement.

Sub-processorPurposeData processed
Anthropic (Claude)AI trip chat, itinerary suggestions, and parsing of forwarded booking emailsTrip content you enter or forward (trip names, activity and booking details, chat messages). Not used to train Anthropic’s models.
OpenAIReceipt scanning (optical character recognition) and booking-email parsingReceipt images you scan and booking emails you forward. Receipt images are processed in memory and are not retained after extraction.
ApifyImporting trip content from shared social-media reels and linksThe public URLs or social-media links you share into the app. No account credentials are sent.
RevenueCatSubscription and in-app purchase management and entitlement verificationA pseudonymous account identifier and purchase/subscription receipts issued by the Apple App Store or Google Play. Your name, email address, and payment-card details remain with Apple or Google.
PostHogProduct analytics to understand feature usage and improve the app and websitePseudonymous usage events and device/session information. See our Cookie Policy for details of website analytics.

We also rely on core infrastructure providers, including Google (Firebase authentication, hosting, push notifications, and Maps/Places location features), to run the Service.

5. Your Rights

Under GDPR, you have the following rights:

Access: Request a copy of your personal data.

Correction: Update incomplete or incorrect data.

Deletion: Request deletion of your data, subject to legal requirements.

Restriction: Limit how we process your data in certain situations.

Data Portability: Receive your data in a structured, machine-readable format.

Objection: Opt out of processing based on legitimate interests.

Withdraw Consent: At any time, for activities based on your consent.

To exercise these rights, email us at support@tripstogether.co.uk.

6. Data Retention

We retain your data only for as long as necessary to provide our services or meet legal obligations. Deleting your account deletes your account information and removes you from your trips, as described in section 1.2.

6.1 Reported Content and Moderation Records

Moderation records are an exception to the above, and we keep them separately from your account.

Why they exist: when content is reported, we take a copy of it at that moment. Without a copy, a report becomes meaningless as soon as the content is deleted or removed, and there would be nothing for a moderator to judge or for an appeal to be decided against.

Who can see them: our moderators can access reported content, including content that has since been removed or deleted, along with the surrounding context needed to make a decision. Access is limited to the small number of people who carry out moderation, every moderation decision is logged, and we do not use this content for any purpose other than moderation, safety, and meeting our legal obligations.

How long we keep them: moderation records — the report, the copy of the reported content, and the record of the decision taken — are retained after the content itself is gone, and are retained after the account involved is deleted. We do this so that we can substantiate and review decisions, handle appeals, respond to legal and regulatory requests, and identify repeat behaviour.

If you want a moderation record concerning you erased, email safety@tripstogether.co.uk and we will assess the request. We may keep the record where we have a legal obligation to do so, or where we need it to establish, exercise or defend legal claims, or to protect other users.

7. Data Security

We use industry-standard security measures, such as encryption and access controls, to protect your data. However, no method of transmission or storage is 100% secure.

8. Cookies and Tracking

We use cookies to:

  • Enhance functionality.
  • Analyse site performance.
  • Deliver relevant content.

You can manage your cookie preferences at any time via our cookie banner. For full details of the cookies we set and how to control them, see our Cookie Policy.

9. International Data Transfers

If we transfer your data outside the UK, we ensure appropriate safeguards, such as Standard Contractual Clauses, to protect your rights.

10. Changes to This Policy

We may update this policy to reflect changes in our practices or legal obligations. Please review it periodically.

© 2026 Trips Together Limited – All Rights Reserved