🔒 Privacy & Data Protection
Your privacy matters to us. Manage your data and consent preferences below.
Cookie Consent Settings
We use cookies and similar technologies to enhance your experience on TripGoGo. You can manage your cookie preferences at any time.
Manage Cookie PreferencesYour Data Rights (GDPR)
Under GDPR and other privacy regulations, you have the right to:
- Access your data: Request a copy of all personal data we hold about you
- Delete your data: Request deletion of your account and associated data
- Withdraw consent: Change your cookie and tracking preferences at any time
Submit a Data Request
To exercise your rights, please submit a request below. We'll send a verification email to confirm your identity before processing.
Privacy Policy
1. Who we are
TripGoGo is operated by Zach Scott, trading as TripGoGo, a sole proprietorship (eenmanszaak) registered in the Netherlands.
- Data controller: Zach Scott, h/o TripGoGo
- KvK number: 99491249
- Contact: privacy@tripgogo.ai
We are in the process of incorporating as a Dutch private limited company (besloten vennootschap, B.V.). When that completes, TripGoGo B.V. becomes the controller and we will update this policy and notify registered users.
Because we are established in the Netherlands, our lead supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). You can lodge a complaint with them at autoriteitpersoonsgegevens.nl, or with the authority in your own country of residence.
2. What this policy covers
TripGoGo has three parts, and this policy covers all of them:
- The trip planner - the consumer product where you create, share and collaborate on trips.
- TripGoGo for Business - the partner and widget product.
- Creator Studio - an invite-only area where selected creators upload photos and videos from real trips, which we may show on TripGoGo and, with their permission, use in our marketing.
Section 6 is specific to Creator Studio. If you are not a creator, it does not apply to you.
3. What we collect
From everyone
| Data | Why |
|---|---|
| Email address, name, password hash (or Google sign-in identifier) | To create and secure your account |
| Profile details you choose to add, including a profile picture | To show you to collaborators |
| Trips you create: destinations, dates, itinerary items, notes, your text prompts to the trip builder | To provide the product |
| Collaboration data: who you invite, suggestions, reactions, messages | To run shared trips |
| Technical data: IP address, browser and device information, pages visited | Security, abuse prevention, and to keep the service working |
| Cookie and consent choices, including a hashed IP and a timestamp | To honour and evidence your choices |
From creators, additionally
See section 6.
What we do not collect
We do not ask for or knowingly collect special categories of personal data (health, religion, political opinions, biometric identifiers, sexual orientation) and we do not use facial recognition on uploaded photos. TripGoGo is not intended for anyone under 18 and we do not knowingly collect data from children.
4. Why we process it, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating your account and providing the trip planner | Contract (Art. 6(1)(b)) |
| Running Creator Studio and using creator content as licensed | Contract (Art. 6(1)(b)) - the creator licence is the agreement |
| Showing a creator's face or name (likeness) | Consent (Art. 6(1)(a)), separately given and withdrawable |
| Security, fraud and abuse prevention, service reliability | Legitimate interests (Art. 6(1)(f)) |
| Analytics and marketing cookies | Consent (Art. 6(1)(a)) |
| Marketing emails | Consent (Art. 6(1)(a)) |
| Keeping records of consent and licence acceptance as evidence | Legal claims (Art. 9(2)(f) / Art. 17(3)(e)) |
Where we rely on consent, you can withdraw it at any time and that is as easy as giving it. Withdrawal does not affect processing that already happened.
5. Automated processing and AI
TripGoGo uses large language models to generate trip itineraries and related content. When you use the trip builder:
- Your prompt text and trip parameters are sent to our AI providers (see section 9) to generate the itinerary.
- We log token counts, latency and cost for each request so we can operate the service. These logs are linked to your account.
- We do not use your content to train third-party models, and our providers are instructed not to.
This is not automated decision-making that produces legal or similarly significant effects about you (GDPR Art. 22). A generated itinerary is a suggestion you are free to change or ignore.
6. Creator Studio (creators only)
This section describes processing that only applies to accounts we have invited into Creator Studio.
6.1 What creators give us
- Photos and videos you upload, in their original resolution, plus a smaller thumbnail your browser generates.
- Metadata read from those files (EXIF), including the date and time the photo was taken and, where present, the GPS coordinates of where it was taken. We use these to place your photos on a map and to group them into trips automatically.
- Labels you add: captions, locations, tags, and whether a photo is "personal" (you are identifiable in it) or "faceless".
- Your publicity choices: whether to appear on Explore, in featured profiles or trips, whether we may use your content in social and marketing posts, and whether you want to be credited by name.
- A record of the terms you accepted: which version of which licence, when, your self-declared country, and a one-way hash of your IP address and browser identifier. We store hashes, never the values themselves.
6.2 What we do with it
- Show your photos on your own trips, and on TripGoGo surfaces you have enabled (your profile, Explore, featured collections).
- Where you have granted it, use your content in TripGoGo's marketing: our website, our social accounts, and our emails.
- Build trips automatically from your photos, using the dates and locations in them.
Every one of these uses is controlled by a per-photo switch, defaulted from your profile settings, and every switch defaults to off. A photo is only shown on a surface you have granted for that photo. There is a single point in our code that every public display passes through, and it checks those switches every time it renders.
6.3 Precise location
Photo GPS coordinates are precise personal data and we treat them carefully:
- When we create a map location from a photo, we round the coordinates to roughly 100 metres before storing them on the trip, so a photo taken at your home does not pin a public map to your front door.
- Your original photo metadata is retained at full precision in your own library and is included in your data export.
- Location is never shown on a public surface unless the photo itself is granted for that surface.
6.4 Withdrawing
You can withdraw your consent or terminate your licence at any time from your Creator Studio settings, or by emailing privacy@tripgogo.ai.
When you do, we immediately: switch off every usage permission on your photos, switch off your profile publicity settings, and remove your photos from anywhere they were being used as a trip cover image. They stop appearing on TripGoGo.
What withdrawal does not undo: material we already published before you withdrew - a social media post that is already live, an email already sent - may remain. We will remove already-published material on request wherever we still control it, and we will always try. Section 10 explains what we keep and why.
6.5 Credit
If you have asked to be credited, your display name appears alongside your photos wherever we use them. If you have not, we do not name you. This is a separate choice from whether we may use the photo at all, in both directions.
7. Who can see your data
- Other users, where you choose: trip collaborators see the trip; anyone with a share link sees a shared trip; Explore is public.
- Our staff, where necessary to run and support the service. Access to Creator Studio content is limited to accounts that need it.
- Our service providers ("processors"), listed in section 9.
- Legal authorities, where we are legally required to disclose.
We do not sell personal data, and we do not share it with advertisers for their own purposes.
8. Where your data is stored
Your account data and content are stored in the European Union - our databases and file storage are hosted in the EU, AWS eu-north-1 (Stockholm).
Some of our service providers are established in the United States (see section 9). Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
9. Service providers
We use the following providers. The full, current list lives at tripgogo.ai/privacy/subprocessors and is updated in the same change that adds or removes a provider. The version at the time of this policy is:
Infrastructure and storage - Amazon Web Services (S3) - file and image storage, EU region eu-north-1 (Stockholm)
AI providers (trip generation and content enrichment) - Google (Gemini) - OpenAI
Accounts, email and support - Google (sign-in, email delivery) - Brevo (transactional and marketing email, EU-hosted)
Analytics and security (only with your consent, where consent applies) - Google Analytics - Hotjar (usage analytics). Hotjar is disabled inside Creator Studio, so creators' photos and captions are never captured in session recordings. - Cloudflare Turnstile (bot protection)
Travel and content partners (used to find places, prices and images) - Stay22, GetYourGuide, Travelpayouts, Amadeus, Viator, Tiqets, Nuitee/LiteAPI - Unsplash, Pexels, Flickr, Wikidata, OpenStreetMap (Nominatim, Overpass, Photon)
10. How long we keep things
What we delete, and when. If you delete your account or ask us to, we act on it: your account, profile, trips and creator content go, and the photo and video files themselves are erased from our storage. That erasure is immediate in practice and within 30 days at the outside.
| Data | What happens |
|---|---|
| Account and profile | Deleted when you delete your account |
| Trips and itineraries | Deleted when you delete them, or your account |
| Creator photos and videos, and their metadata | Deleted when you delete them, or your account. The files are erased from storage, not just de-listed. If an erasure fails we record it and retry rather than losing track of it |
| Licence and consent records | Kept after account deletion, in pseudonymised form, as evidence that a use was permitted (GDPR Art. 17(3)(e)). Our policy is to keep these no longer than 7 years |
| Cookie consent logs | Anonymised when your account is deleted. Policy is no longer than 7 years |
| Technical and security logs | Policy is no longer than 12 months |
Being straight about the limits of this. Where the table says "policy", that is a period we have set and will honour on request. We have not yet built the scheduled job that ages those records out automatically, so until we do, assume anything not covered by a deletion request is still stored. We would rather tell you that than publish a number we are not yet enforcing. Ask us at privacy@tripgogo.ai and we will delete what we are able to delete.
Licence records are kept after account deletion because they are the evidence that content we used was licensed at the time. They no longer contain your name or email - only a one-way hash that links your own events together. This is pseudonymised data, not anonymous, and it remains within scope of your other rights.
11. Your rights
Under the GDPR you can:
- Access the personal data we hold about you
- Correct anything inaccurate
- Delete your data ("right to be forgotten"), subject to section 10
- Export your data in a machine-readable format (portability)
- Object to processing based on legitimate interests
- Restrict processing while a dispute is resolved
- Withdraw consent at any time
Use the tools at tripgogo.ai/privacy to export or delete your data, or email privacy@tripgogo.ai. We verify your identity by email before acting on a request, and we respond within one month.
For creators, an export includes your profile settings, every photo record with its metadata (including the capture time and any GPS coordinates), and your full licence and consent history including withdrawals. It does not yet bundle the image and video files themselves; if you want those, email privacy@tripgogo.ai and we will get them to you.
12. Cookies
We use strictly necessary cookies to keep you signed in and secure. Analytics and marketing cookies are used only if you agree. You can change your choices at any time via the cookie settings link in our footer.
13. Security
We use encrypted connections (HTTPS), hashed passwords, access controls on administrative tools, and time-limited signed URLs for file uploads. IP addresses and browser identifiers in consent records are stored only as one-way hashes.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Autoriteit Persoonsgegevens within 72 hours and tell you directly where the risk is high.
14. Changes
If we make a material change we will update the version number above and notify registered users by email before it takes effect. Creators are separately notified of any change to the licence terms, and a new licence version never applies retroactively to content already licensed under an earlier one.