We take the protection of your personal data seriously. Here you can find out how we collect, process, and protect your data.
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you. Detailed information on data protection can be found in our privacy policy listed below.
Data processing on this website is carried out by the website operator. You can find their contact details in the "Controller Information" section of this privacy policy.
On one hand, your data is collected when you provide it to us. This could be, for example, data you enter into a contact form, when subscribing to the newsletter, or during travel booking facilitation.
Other data is collected automatically or with your consent when you visit the website through our IT systems. These are primarily technical data (e.g., internet browser, operating system, or time of page access). This data is collected automatically as soon as you enter this website.
Part of the data is collected to ensure the error-free provision of the website and to perform the contractually owed travel facilitation. Other data may be used to analyze your user behavior.
You have the right to receive information about the origin, recipient, and purpose of your stored personal data at any time free of charge. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can withdraw this consent at any time for the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
We host our website with Vercel. The provider is Vercel Inc., 440 Bond Street, Suite 5, Brooklyn, NY 11231, USA (hereinafter Vercel). When you visit our website, Vercel collects various log files including your IP address. The use of Vercel is based on Art. 6(1)(f) GDPR. We have a legitimate interest in the most reliable and secure presentation and provision of our website.
Data transfer to the USA is based on the EU Commission's Standard Contractual Clauses. We have concluded a Data Processing Agreement (DPA) under Art. 28 GDPR with Vercel, which ensures that Vercel only processes our users' data in accordance with our instructions and in compliance with the GDPR.
This site uses web fonts provided by Google for the uniform display of fonts (specifically the Plus Jakarta Sans font). To maximize the protection of your privacy, we use the native next/font/google framework.
The font files are downloaded directly from Google during the build process (when compiling the page on our servers) and stored locally on our own infrastructure. When loading this website in our visitors' browsers, no external requests are sent to Google's servers. No IP addresses or cookies are transferred to Google. Delivery is entirely from our own domain (trytripbot.com). Processing is based on our legitimate interest in a design-compliant and privacy-friendly presentation of our content (Art. 6(1)(f) GDPR).
The controller responsible for data processing on this website is:
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data (e.g., names, email addresses, etc.).
Unless a more specific storage period has been specified in this privacy policy, your personal data will remain with us until the purpose for processing the data no longer applies. If you assert a legitimate request for deletion or withdraw your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial retention periods of 10 years for booking records); in the latter case, deletion will take place after these reasons no longer apply.
We use tools from companies based in the USA or other countries that are not secure under data protection law. When these tools are active, your personal data may be transferred to these third countries and processed there. We point out that a level of data protection comparable to the EU cannot be guaranteed in these countries. For example, US companies are obliged to hand over personal data to security authorities without you as the data subject being able to take legal action against this.
Many data processing operations are only possible with your express consent. You can withdraw consent you have already given at any time. The lawfulness of data processing carried out up to the withdrawal remains unaffected by the withdrawal.
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work, or the place of the alleged violation. The right to lodge a complaint is without prejudice to other administrative or judicial remedies. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA).
We offer the search and facilitation of travel services (flights, hotels) on our platform. In doing so, we work with the external technology and API interface provider LiteAPI.
When you search for flights or hotels on tripbot, only non-personal, anonymous search parameters are transmitted to LiteAPI.
Privacy Guarantee: No personal data (such as name, email address, or your personal IP address) flows to LiteAPI during this phase. The search requests are executed bundled on the server side via our own Next.js backend. Your direct IP address is never passed on to LiteAPI. The legal basis for this processing is Art. 6(1)(b) GDPR (initiating a contract).
As soon as you initiate a binding booking facilitation on our platform, personal data of the travelers must be transmitted to LiteAPI and processed for legally valid ticket issuance (flight booking / hotel voucher) and contract performance.
Legal basis: The processing and transfer of this data to LiteAPI is based on Art. 6(1)(b) GDPR (processing for the performance of a contract or to carry out pre-contractual measures). Without this data transmission, legally secure ticket issuance or hotel booking is technically and legally impossible.
If you send us inquiries via the contact form, your details from the inquiry form, including the contact details you provided there, will be processed by us for the purpose of processing the inquiry and in the event of follow-up questions.
The data you enter (name, email address, message, and the source URL) will be stored permanently directly in our secure, encrypted support database at Supabase (provider: Spacedrive Inc., dba Supabase, 970 Summer St, Stamford, CT 06905, USA) to ensure data security and prevent data loss. A GDPR-compliant Data Processing Agreement (DPA) was concluded with Supabase.
When you enable travel memories, we store the editable summary in your Supabase profile and use it as a soft signal for personalised responses. We use OpenRouter, Inc. as a technical gateway to selected model providers when processing AI requests. Requests are restricted to providers that do not retain the data, and use for model training is denied. You can delete or disable travel memories at any time in AI settings. This removes the active summary from your profile and it is not restored automatically. Copies may remain until the regular backup rotation expires and are not used for personalisation.
After saving in the database, our backend initiates the email dispatch to process the support request. For this, we use the specialized infrastructure service Resend (provider: Resend Labs Inc., 228 Park Ave S, PMB 99033, New York, NY 10003, USA) via Software Development Kit (SDK). Resend processes the data on our behalf to ensure a reliable, encrypted, and high email delivery rate.
To protect our contact form against spam, automated attacks, and bots, we use the Cloudflare Turnstile service. The provider is Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA. Turnstile is a privacy-friendly alternative to conventional systems because it analyzes user behavior purely mathematically in the background without setting personal tracking cookies, without abusing data for advertising purposes, and without violating users' privacy.
Legal basis: The processing of the data entered into the contact form is based on our legitimate interest in secure, spam-free communication and the rapid response to user inquiries (Art. 6(1)(f) GDPR) as well as, if applicable, to initiate or perform a contract (Art. 6(1)(b) GDPR).
If you would like to receive the newsletter offered on the website, we require an email address from you.
To ensure that the registration is actually made by the owner of the email address, we use a secure two-step procedure (Double Opt-In) via our secure newsletter interface:
You can withdraw your email address and its use for sending the newsletter at any time. Every newsletter email contains a direct, legally compliant unsubscribe link for this purpose. One click is enough to immediately remove your data from the active mailing list and update it in the database.
Legal basis: Processing is based solely on your consent (Art. 6(1)(a) GDPR). You can withdraw this consent at any time.
We use analysis tools to improve the user-friendliness, loading times, and performance of our platform. To protect your data as much as possible, a strict opt-in principle applies on our platform.
By default (when the page is first loaded), all non-essential tracking scripts and cookies are completely blocked. Only when the user explicitly clicks "Accept All" or actively enables the "Analytics" category in the settings will the following services be loaded dynamically. You can withdraw this consent at any time via the link in the privacy settings in the footer.
We use PostHog to analyze product interactions. To bypass ad-blockers and maintain data sovereignty, we use a self-built reverse proxy. All event data is first routed through our own, secure Next.js backend, checked there, and only then transmitted encrypted to PostHog.
We use Google Analytics, a web analysis service from Google Ireland Limited (Google), Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics collects anonymized or pseudonymized statistics about page access.
We use Vercel Analytics solely to monitor the technical performance and loading times of our app (so-called Core Web Vitals) in order to keep the platform stable and fast. No profiles are created for marketing purposes.
Legal basis: Processing is based solely on your consent (Art. 6(1)(a) GDPR and § 25(1) TDDG).
We completely refrain from using third-party advertising pixels or marketing trackers on our platform.
No advertising pixels (such as the Meta Pixel, Google Ads Conversion Tracker, or TikTok Pixel) are integrated.
In the source code of our platform, the category for marketing cookies is permanently deactivated and completely blocked by default. No data collection for personalized advertising or behavioral advertising takes place.
As a data subject affected by data processing, you have comprehensive rights against the controller under the GDPR:
You can request information at any time as to whether and which of your personal data we process.
If your data stored by us is incorrect or incomplete, you can request immediate correction.
You can request the deletion of your data, unless a statutory exception (such as statutory retention obligations) prevents this.
You have the right, under certain conditions, to request the restriction of the processing of your data.
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a structured, commonly used, machine-readable format.
IF YOUR DATA IS PROCESSED ON THE BASIS OF LEGITIMATE INTERESTS (ART. 6(1)(F) GDPR), YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING AT ANY TIME, PROVIDED THAT THERE ARE REASONS ARISING FROM YOUR PARTICULAR SITUATION.