Privacy

Last updated

Your journey is your private narrative.

We collect only what we need to run your workspace, measure product health with consent, and connect you to booking partners—with clear limits on resale and retention.

No selling

We do not sell personal data or trip narratives to data brokers.

Purpose-bound

Analytics and AI run on documented purposes with opt-in where required.

Your agency

Export, correct, or request deletion of account data subject to legal retention.

Data collection

We collect information you provide: account credentials (via Supabase Auth), profile details, trip itineraries, City Pulse saves, collaboration invites, comments, concierge messages, and billing identifiers linked to Stripe.

We also collect technical data: device/browser type, approximate region from IP, product events (when analytics consent is granted), and security logs for abuse prevention.

Guest and anonymous users may store trips locally in the browser until they create an account; migrating a local trip sends that payload to our servers when you check out or sign up.

Usage & analytics

We use data to operate the workspace, authenticate users, process subscriptions, deliver exports, run collaboration features, and improve reliability.

Analytics (conversion funnels, error rates) runs only after you opt in via the cookie banner. We use pseudonymous identifiers—not your email—for product metrics.

External partners

Maps, place photos, and routing may use Google APIs. Affiliate booking links send you to partner sites that set their own cookies when you click through.

We do not sell your personal data. Partners process purchases under their own privacy policies.

Transfers & subprocessors

We process data primarily in the European Economic Area. Some subprocessors are located in the United States or other countries. Where required, we rely on appropriate safeguards such as EU Standard Contractual Clauses or adequacy decisions.

Subprocessors at launch (categories): authentication and database (Supabase), payments (Stripe), maps and places (Google), AI inference (OpenAI), transactional email (Resend), and rate limiting/cache (Upstash).

We maintain a list of subprocessors for counsel review and will update this section when vendors change materially.

AI & automation

Copilot, itinerary generation, and City Pulse enrichment may send trip context to AI providers to produce drafts. We minimize what is sent and do not use your trips to train public models unless we explicitly say otherwise in product UI.

You can edit or delete AI-assisted content in your workspace. Automated outputs may be logged briefly for abuse prevention and quality monitoring.

Cookies

The table below lists cookies and similar storage we use or that may be set when you use TravelNestHub. Analytics storage is off by default until you consent in the cookie banner.

  • Supabase auth session cookies

    Category
    Essential
    Purpose
    Sign-in, session security, and account access.
    Storage
    HTTP cookie
    Duration
    Session / auth lifetime
    Consent
    Not required (strictly necessary)
  • tnh_anon_id

    Category
    Analytics
    Purpose
    Pseudonymous product analytics and conversion measurement.
    Storage
    HTTP cookie (httpOnly)
    Duration
    Up to 12 months
    Consent
    Required before set
  • tnh_analytics_consent_v1

    Category
    Essential (preference)
    Purpose
    Stores your analytics consent choice.
    Storage
    localStorage (+ same-named preference cookie mirror)
    Duration
    Until you change preference (cookie up to 12 months)
    Consent
    Not required (records your choice)
  • tnh_billing_legal_acceptance_v1

    Category
    Essential (contract)
    Purpose
    Records Terms/Privacy acceptance at checkout.
    Storage
    localStorage
    Duration
    Until policy version changes
    Consent
    Not required (contract/legal obligation)
  • tnh_legal_locale_v1

    Category
    Essential (preference)
    Purpose
    Remembers your legal-page language preference.
    Storage
    HTTP cookie
    Duration
    12 months
    Consent
    Not required (UI preference)
  • Anonymous trip / UI state

    Category
    Functional
    Purpose
    Temporary itinerary and workspace UI state for guests.
    Storage
    localStorage
    Duration
    Until sign-in or browser clear
    Consent
    Not required; not sold or used for ads
  • Partner attribution (on click)

    Category
    Third-party
    Purpose
    Affiliate referral when you open a partner booking link.
    Storage
    Set by partner site
    Duration
    Partner-defined
    Consent
    Disclosed at handoff; governed by partner policy

What we don't do

We do not sell personal information. We do not use your trip content for third-party advertising profiles.

Affiliate links may attribute a referral to us when you complete a partner purchase; that is separate from selling your data.

Retention

We retain personal data while your account is active and as needed to provide the service, meet legal obligations, resolve disputes, and enforce our agreements.

After an approved account deletion, we remove app-owned data listed under “Your choices”. Some records must or may be retained:

  • Stripe payment and invoicing records (tax and commercial law; retained by Stripe as processor).
  • Minimized erasure and security audit logs (pseudonymized identifiers, limited retention for abuse prevention).
  • Completed erasure request metadata anonymized (reason redacted; subject IDs replaced with tombstones).

Your choices

You may contact us to access, correct, or delete information where applicable. Account deletion is request-based: submit from your profile; authorized admins review and execute erasure.

We respond to privacy requests within 30 days. After approval, erasure is typically executed within 5–10 business days, subject to complexity and legal obligations.

When erasure runs, we delete or anonymize the following app-owned categories:

  • Auth account (Supabase) and owned trips
  • Notifications, global Pulse collection, and profile
  • Concierge inquiries and traveler feedback you submitted
  • Trip collaboration rows directly keyed to you (members, invites as inviter, comments as author)
  • Billing linkage in our database (user_billing, checkout attempts, consumption events)
  • Product funnel events keyed to your authenticated actor ID
  • Early access redemption rows

This Privacy Policy describes our product practices. It is not legal advice.