Your data
Privacy Policy
TrippyMaker helps you plan and visualise your trips. This policy explains what personal data we process, why we process it and what choices you have.
Last updated on August 25, 2026
1. Who is responsible?
TrippyMaker is responsible for processing personal data within this website and app. For questions or privacy requests, email support@trippymaker.com.
2. What data do we process?
Account information
When you create an account, we process your name, email address, a secure hash of your password, the account creation date and information required for email verification and password recovery. We do not store your password as readable text.
Trip and map data
We process the trips you create and save, including trip names, dates, destinations, locations, routes, notes and other information you add to a trip. We may record the number of map and route requests per trip to monitor the service's operation and costs.
Google favourites
If you activate the Google import, we process the selected saved collections and places. This may include collection names, place names, notes, Google Maps links, place references and coordinates. During the import, we temporarily store encrypted authorisation data and technical job information.
Technical and communication data
When you use the service, technical data may be processed, such as your IP address, browser type, session data, timestamps, error messages and security events. If you contact us, we process your contact details and the contents of your message.
3. Why do we process data?
We process personal data for the following purposes and on the following legal bases:
- Performance of a contract: creating accounts, signing you in, saving trips, displaying routes and carrying out requested imports.
- Consent: activating optional connections or external map features when you choose to do so. You can withdraw your consent.
- Legitimate interests: securing the service, preventing abuse, resolving errors and monitoring technical use and costs.
- Legal obligations: retaining information when required for purposes such as financial records or legal claims.
TrippyMaker does not use your data for advertising profiles and does not make solely automated decisions that have legal or similarly significant effects on you.
4. Cookies and local storage
We use an essential session cookie to keep you signed in and secure requests. The app also uses local browser storage. This may contain your cookie preference, the last opened trip ID, map and route settings and — only if you choose this option — your email address for “Remember email”.
This local data remains on your device until the app replaces it or you clear your browser data. TrippyMaker currently does not use advertising or analytics cookies. External map services are activated only after you choose to enable them.
5. Which external services do we use?
We may use the following services for specific features:
- Google: for maps, routes, place information and the optional import of Google favourites. Read Google's Privacy Policy.
- OpenAI: for optional AI-powered place suggestions. Map boundaries and existing place names may be sent for this purpose; account passwords are not shared. Read OpenAI's Privacy Policy.
- Stripe: if you purchase a paid service, Stripe processes the payment. TrippyMaker does not receive your full card details. Read Stripe's Privacy Policy.
- Hosting and email providers: to keep the service available and send service messages.
Some providers may process data outside the European Economic Area. Where required by law, we use appropriate transfer safeguards, such as Standard Contractual Clauses approved by the European Commission. You can request more information about these safeguards via our support address.
6. How long do we retain and secure data?
We retain account and trip data for as long as your account remains active or as long as needed to provide the service. Following a valid deletion request, we delete or anonymise the data unless certain information must be retained for a legal obligation, security incident or legal dispute. Technical logs and backups are not retained longer than reasonably necessary for security and recovery.
Authorisation data for a Google import is stored in encrypted form and removed from the import job when the import is completed, fails or is cancelled. Email verification links are valid for 24 hours and password recovery links for one hour.
We take appropriate technical and organisational measures, including HTTPS, password hashing, session security, access restrictions and encryption of sensitive import tokens. However, no online service can guarantee absolute security.
7. Your privacy rights
Depending on your circumstances, you may request access to, correction, deletion, restriction or transfer of your personal data. You may also object to processing or withdraw previously given consent.
Send your request to support@trippymaker.com. We may ask you to verify your identity in an appropriate manner and will generally respond within one month. If you are dissatisfied with our response, you can lodge a complaint with the Dutch Data Protection Authority.
8. Changes
We may update this policy when the app, our practices or applicable laws change. The most recent version will always be available on this page, with the latest revision date shown above.