Privacy Policy
Effective date: August 16, 2026
MyTripDude ("MyTripDude", "we", "us", or "our") provides a trip-planning service through our website and mobile application (together, the "Service"). This Privacy Policy explains what personal information we collect, how we use and share it, and the choices and rights you have. By using the Service, you agree to the collection and use of information as described here.
1. Information We Collect
a. Account information you provide directly
- Name and username
- Email address
- Phone number
- Password (stored only in hashed form - we never store or can view your plaintext password)
- Profile photo
b. Information from Google Sign-In
If you register or log in using Google, we receive your name, email address, email verification status, and profile picture from Google, and a token used to verify your identity. We do not receive your Google password.
c. Trip and travel content you create
- Trips, itineraries, and places you search for or add (via Google Places)
- Expenses and budget information, including amounts, categories, and currency
- Uploaded documents and the data they may contain - for example passports, visas, flight tickets, hotel bookings, or insurance documents
- Trip notes and packing/preparation checklists
- Home currency, timezone, and date/number/time format preferences
Identity-document numbers and uploaded travel documents are sensitive personal information. We collect these only because you choose to store them for your own trip planning - we do not require them to use core features of the Service, and they are never shared with collaborators unless you explicitly enable document sharing for that trip.
d. Information collected automatically
- IP address and user-agent, recorded against login sessions for security purposes
- Basic device and app-error information (via our error-monitoring provider)
- Product-usage analytics (pages viewed, features used) via our analytics providers, described in Section 3
- On the website only, masked session replay - a visual reconstruction of on-screen activity used to diagnose usability issues. Text content (including expense amounts, names, and trip details) and form inputs are masked before capture
- On mobile, a device push-notification token, if you allow notifications (Android only)
We do not access your device's GPS/location, camera, or contacts. Photo-gallery access is used only when you choose to upload a document or profile photo.
2. How We Use Your Information
- To create and maintain your account and authenticate you
- To provide the Service - storing and displaying your trips, expenses, documents, and notes
- To enable collaboration features you choose to use, such as inviting other users to a trip
- To send transactional email - verification codes, collaboration invites, and account notices
- To monitor, debug, and improve the reliability and performance of the Service
- To detect, prevent, and investigate fraud, abuse, or security incidents
- To comply with legal obligations
We do not use your personal information for advertising, and we do not build advertising profiles from it.
3. Third Parties We Share Information With
We share information with the following categories of service providers who help us operate MyTripDude. Each processes only the information necessary to perform its function on our behalf, under its own security and privacy commitments.
- Google - Sign-In authentication and Maps/Places location search
- Google Analytics (GA4) and PostHog - product analytics, used to understand feature usage and improve the Service. On the website, PostHog also provides masked session replay (see Section 1.d). Analytics are not linked to your account identity
- Sentry - error monitoring, to diagnose crashes and bugs
- Firebase Cloud Messaging (via the Expo push service) - delivering push notifications on Android
- Cloud hosting and database providers - running the Service and storing your account and trip data
- Cloud storage providers - holding your uploaded documents and photos privately
- An email delivery provider - sending transactional email such as verification codes and collaboration invites
- A currency exchange-rate provider - supplying conversion rates (this data is not specific to you)
We do not sell or share your personal information for monetary or other valuable consideration, and we do not use it for cross-context behavioral advertising. We do not use the Facebook Pixel or any advertising-retargeting technology. We may disclose information if required by law, or as part of a merger, acquisition, or sale of assets, in which case this Policy would continue to apply to your information.
4. Sharing With Other Users (Collaboration)
If you invite collaborators to a trip, they can view the sections of that trip you grant them access to (for example itinerary, expenses, or checklist). The Documents section - where sensitive files like passports and visas live - is off by default for collaborators and only visible if you explicitly enable it for that trip. You control and can change what each collaborator can see.
5. Cookies and Similar Technologies
- Session cookie (web) - a secure, HttpOnly cookie that keeps you signed in. Essential to the Service; it cannot be disabled and is not used for tracking or advertising
- Local storage - stores your theme (light/dark) preference on your device
- Analytics cookies/identifiers - set by PostHog and Google Analytics (GA4) to measure product usage
We do not currently respond differently to browser "Do Not Track" signals, as no common industry standard for responding to them has been adopted. You can control cookies through your browser settings; disabling essential cookies will prevent you from staying signed in.
See our Cookie Policy for the full list of cookies we use and how to manage your preferences.
6. Data Retention
We retain your information for as long as your account is active, or as needed to provide the Service. If you deactivate your account, your data is retained but access is disabled, and can be reactivated within the applicable reactivation window. If you request deletion (Section 7), we delete your personal data, except that we may retain limited records where required by law - for example financial or transaction records, which we would keep for the period required for tax and accounting purposes. Residual copies may also persist in encrypted backups for a limited period before they are purged through our normal backup rotation. Session replay recordings (Section 1.d) are retained for 30 days and then automatically deleted.
7. Your Rights and Choices
You can review and update most of your information directly in Settings. In addition, you may contact us at support@mytripdude.com to:
- Request a copy of the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your account and associated personal information
- Ask questions about how your information is used or shared
We verify your identity before acting on a request and respond within 30 days. For step-by-step instructions on deleting your account and what is deleted or kept, see Delete Your Account & Data. You can also export a copy of your own trip data (expenses, documents, notes, and more) at any time from Settings.
If you are in California
Under the California Consumer Privacy Act (CCPA), California residents have the right to know what personal information we collect and how it is used, to request deletion, to request correction of inaccurate information, and to non-discrimination for exercising these rights. Because we do not sell or share personal information for cross-context behavioral advertising, there is no "Do Not Sell or Share My Personal Information" opt-out required - we simply do not engage in that activity. You can exercise your CCPA rights using the contact details above.
If you are in the European Economic Area or UK
Under the General Data Protection Regulation (GDPR), you have the right to access, correct, delete, restrict or object to our processing of your personal data, and to receive a portable copy of it. We process your data on the basis of your consent (e.g. account creation), the performance of our contract with you (providing the Service), and our legitimate interests (security and fraud prevention). MyTripDude acts as the data controller for this information. Because our infrastructure providers operate globally, your data may be processed in countries outside the EEA/UK, including the United States and India; where this occurs we rely on our providers’ standard contractual safeguards. You also have the right to lodge a complaint with your local data protection supervisory authority.
8. Children's Privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at support@mytripdude.com and we will delete it.
9. Security
We use industry-standard measures to protect your information, including encrypted storage for uploaded documents and document links, hashed passwords, and short-lived, rotated authentication tokens. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will revise the effective date above when we do, and will notify you of material changes through the Service or by email.
11. Contact Us
Questions about this Privacy Policy or your data can be sent to support@mytripdude.com, or through our Contact page.