Privacy Policy
Last updated August 31, 2026
TripStatus is an early beta operated by an individual. Your account and trip information are
stored with third-party providers (primarily Supabase). We use reasonable security measures, but
no system is perfectly secure, and to the maximum extent the law allows the Operator is not
liable for unauthorized access, hacking, or a data breach — including a breach of a third-party
provider. Please read the full text.
1. Who we are
TripStatus (the “App”) is operated by Harsh Gupta, an
individual (“Operator”, “we”, “us”, “our”). This
Privacy Policy explains what personal information the App collects, how it is used, and the
choices you have. It should be read together with our
Terms of Service.
Questions or requests about this policy: [email protected].
2. Acceptance
By creating an account or using the App, you acknowledge that you have read and understood this
Privacy Policy and agree to the collection and use of information as described. If you do not
agree, do not create an account and do not use the App.
3. Information we collect
-
Account information: your name, email address, and a password. Passwords are
handled by our authentication provider and stored only in hashed form; we never see your
plaintext password.
-
Trip content you enter: destinations, dates, itinerary items, transport legs
(including flight numbers, carriers, and times), lodging names and addresses, and any notes or
descriptions you add.
-
Sharing information: the friends, groups, travelers, and trackers you connect
a trip to, and the friend requests you send or accept. People you share a trip with can see
that trip’s content and the names of its other travelers.
-
Device and notification data: if you enable push notifications, a device push
token; if you open a map for a saved address, your approximate device location is used at that
moment to center the map and is not stored by us.
-
Technical and log data: IP address, timestamps, device/OS type, app version,
and error or diagnostic logs, collected by our infrastructure providers to operate and secure
the service.
4. How we use information
- To provide and operate the App: create and sync your trips, render your itinerary, and let you share trips with people you choose.
- To deliver flight-status updates and the push notifications you enable.
- To authenticate you and keep your account secure.
- To detect, prevent, and investigate abuse, fraud, and security incidents.
- To respond to your support requests and communicate service or policy changes.
- To comply with legal obligations and enforce our Terms.
5. Flight status and other third-party lookups
To show flight status, the App sends flight numbers and dates to a third-party flight-data
provider (AeroDataBox, accessed via api.market). We do not control how that provider processes
requests, and its data may be inaccurate, delayed, or unavailable. The App does not send your
name or email to that provider.
6. Where your data is stored and who processes it
Your data is stored and processed on infrastructure operated by independent third parties
(“sub-processors”), each with its own security program and privacy terms:
- Supabase — database, authentication, and backend hosting. Your account and trip data reside on Supabase infrastructure.
- Cloudflare — web hosting/CDN for our website and bot-protection on our sign-in screens.
- Apple and Google — app distribution and delivery of push notifications.
- api.market / AeroDataBox — flight status data.
- Resend — delivery of transactional email such as confirmation and password-reset messages.
- Data may be processed in the United States and other countries whose data-protection laws differ from those where you live.
7. How we share information
We do not sell your personal information and we do not use it for third-party advertising. We
share it only:
- With people you choose — the travelers, trackers, and groups you attach to a trip.
- With the sub-processors listed above, to the extent needed to run the service.
- When required by law, subpoena, or other legal process, or to protect the rights, safety, or property of the Operator, users, or the public.
- In connection with a merger, acquisition, financing, or sale of assets, in which case we will seek to ensure the recipient honors this policy.
8. Data retention and deletion
We keep your information while your account is active. You can permanently delete your account at
any time from Settings → Delete Account; this removes your account and the content only you
have access to. Trips you created remain visible to their other travelers.
After deletion, residual copies may persist for a limited period in provider backups and security
logs before being overwritten, and we may retain limited information where required for legal,
tax, or dispute-resolution purposes.
9. Your choices and rights
- Access and update: view and edit your name and trip content directly in the App.
- Delete: remove your account from Settings → Delete Account.
- Notifications and location: control push and location permissions in your device settings at any time.
-
Depending on where you live (for example the EEA, the UK, or California), you may have rights
to access, correct, delete, or port your personal information, to object to or restrict certain
processing, and to withdraw consent. California residents have the right not to receive
discriminatory treatment for exercising these rights; we do not sell or “share”
personal information as those terms are defined under California law.
- To make a request, email [email protected]. We may need to verify your identity before acting.
10. Security and disclaimer
We take reasonable, industry-standard measures to protect your information, including encryption
in transit (HTTPS), hashed password storage, database row-level security, and restricted
administrative access.
However, no method of transmission over the internet and no method of electronic storage is
completely secure. We cannot and do not guarantee the absolute security of your information. You
provide information to the App and use it at your own risk.
To the fullest extent permitted by applicable law, the Operator is not liable for any
unauthorized access to, acquisition of, disclosure of, alteration of, loss of, or misuse of your
information resulting from hacking, phishing, malware, credential theft, insider misconduct, or
any security incident or data breach affecting the App, your account, or any third-party provider
or sub-processor (including, without limitation, a breach of Supabase’s systems or
database). This limitation is subject to, and does not exclude, any liability that cannot be
excluded under applicable law.
You are responsible for keeping your password confidential and your device secure. Notify us
immediately at [email protected] if you believe your account or
data has been compromised. Where a security incident triggers a legal notification obligation, we
will provide notice as required by law.
11. Children
The App is not directed to children under 13 (or under 16 in the EEA), and we do not knowingly
collect personal information from them. If you believe a child has provided us information,
contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will update
the “Last updated” date and provide notice in the App or by email. Your continued use
of the App after an update takes effect means you accept the revised policy.
13. Contact
Harsh Gupta — [email protected]