Privacy Policy
Last updated 2026-06-29
Triprr LTD (1 Nikokleous, Skoullis Court, 2nd Floor, Office 203, 3027 Limassol, Cyprus, reg. ΗΕ 487414) is the data controller for personal data processed through Triprr. This policy explains what we collect, why, and your rights under the GDPR.
Data we collect
Account data (email, handle, display name, password hash, language). Trip content you create (stops, photos, notes, bookings). Usage data (device, IP, pages, AI prompts). Communication preferences. Optional live-location pings when you enable tracking.
How we use it
To run the service (contractual necessity), to keep it secure and fight abuse (legitimate interest), to comply with legal obligations, and — with your consent — to send marketing emails and use analytics cookies.
Who we share it with
Subprocessors that operate the service on our behalf — see the live list at /legal/subprocessors. We don't sell your personal data.
International transfers
Some subprocessors are located outside the EEA. Where required we rely on EU Standard Contractual Clauses and additional technical safeguards.
How long we keep it
Account and trip data: until you delete your account. Auth and security logs: up to 12 months. Backups: rolling 30 days. Marketing consent records: until withdrawn plus 24 months for proof of consent.
Your rights
Under the GDPR you can access, correct, port, restrict, or delete your data, object to processing, and withdraw consent. Contact info@triprr.ai to exercise these rights. You also have the right to lodge a complaint with the Cyprus Office of the Commissioner for Personal Data Protection or your local authority.
Security
We use industry-standard encryption in transit and at rest, row-level access controls, and least-privilege secrets. No service is perfectly secure — please use a strong, unique password.
Children
Triprr is not directed to children under 16. We do not knowingly collect personal data from children. Contact us if you believe a child has signed up.
Changes
We will notify you of material changes by email or in-app at least 14 days before they take effect.