| Data type | Purpose | Retention |
|---|---|---|
| Name & email | Account identification and authentication | Until account deleted |
| Password hash | Authentication (bcrypt, never stored in plain text) | Until account deleted |
| Trip & itinerary data | Core product functionality | Until account deleted |
| Packing list & closet | Core product functionality | Until account deleted |
| Contacts | Trip collaboration and communication | Until deleted by user |
| Session tokens | Keeping you logged in securely | 30 days or until logout |
| Phone number | Optional — contact discovery only if enabled | Until removed in Settings |
We do not sell your data to any third party. We do not use your travel or personal data for advertising, profiling, or any purpose other than providing TravelSuite to you. We do not use tracking cookies or third-party analytics. We do not share your data with other TravelSuite users except where you explicitly invite them as trip collaborators.
TravelSuite products are ad-free. No advertiser has any influence over the product or its AI responses.
-
CloudflareInfrastructure provider. Hosts the application (Pages), API (Workers), database (D1), object storage (R2), and KV storage. All data physically stored in Cloudflare's infrastructure. Provides DDoS protection, TLS termination, and edge caching.cloudflare.com/privacypolicy →
-
AnthropicAI API provider. Used for AI-powered features: entry parsing, packing suggestions, weather summaries, and screenshot import. Only the data required for each specific feature is sent — never your full account data. Users can disable AI features entirely in Settings.anthropic.com/privacy →
-
Google Places APIUsed to look up venue details (address, phone, website, rating) when you search for a location. Search queries are sent to Google's API. No personal account data is included. Used only when you trigger a location search.policies.google.com/privacy →
-
ResendTransactional email provider. Used to send password reset emails and system notifications. Only your email address is shared for the purpose of delivering that specific email.resend.com/privacy →
-
SentryError monitoring. Captures application exceptions with route and stack trace information for debugging. Error reports do not include user data, trip content, or personal information.sentry.io/privacy →
If you are in the EU or EEA, you have the right to access, correct, or delete your personal data at any time. You can request an export of all your data or permanent deletion of your account from within the app (Settings → Account). Account deletion permanently removes all associated data after a 7-day grace period.
You also have the right to object to or restrict processing, and the right to data portability. To exercise any of these rights or to raise a concern, contact us at the address below.
To report a security vulnerability, raise a privacy concern, or request your data — contact us directly. We aim to respond within 48 hours.
✉️ hello@travelsuite.world