This translation is provided for information only. Only the German original is legally binding.
Legal
This notice describes which personal data we process, for what purpose, on what legal basis, and who we share it with.
Personal data is any information that can identify you. Some of it you give us yourself — in the contact form or when making a booking. Other data is collected automatically when you open the site, mainly technical details such as browser, operating system and time of access.
We process data to run the platform, arrange travel services, bill our own services and keep the operation secure. Your usage behaviour is analysed only if you have expressly consented.
We do not sell your data and do not pass it to third parties for advertising.
The controller within the meaning of the GDPR is Nico Neser, Einzelunternehmer, Moorweg 10, 91325 Adelsdorf, Germany, email legal@trytripbot.com. The controller alone decides on the purposes and means of processing and is also your contact for data protection enquiries.
Unless a more specific retention period is stated, we process personal data only for as long as the respective purpose requires. We then delete or block it, unless a statutory retention obligation or the pursuit or defence of claims requires otherwise. Backups are overwritten in the course of the regular rotation.
You have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, your place of work, or the place of the alleged infringement. The authority responsible for us is the Bavarian Data Protection Authority (BayLDA).
We use services from companies based in the USA. That country does not offer a level of data protection comparable to the EU; in particular, authorities may access data without you having an effective legal remedy. We base transfers on the European Commission’s standard contractual clauses and, where applicable, on certification under the EU-US Data Privacy Framework.
The platform runs on a server operated by IONOS SE, Elgendorfer Strasse 57, 56410 Montabaur, Germany. The server location is Germany. Opening the site produces log data including your IP address. The legal basis is our legitimate interest in reliable and secure provision (Art. 6 (1) (f) GDPR).
Cloudflare (Cloudflare, Inc., USA) sits in front of delivery. Every request to our domain passes through that network before it reaches our server. IP address and connection data are processed in order to deliver the site, provide encryption and fend off attacks. The legal basis is Art. 6 (1) (f) GDPR.
To protect forms against automated attacks we additionally use Cloudflare Turnstile. IP address, browser and device information and interaction data may be processed. The legal basis is our legitimate interest in preventing abuse (Art. 6 (1) (f) GDPR).
To detect technical faults we use Sentry (Functional Software, Inc., USA) with storage located in the European Union. It records error messages and technical metadata such as the browser, the page visited and the course of the error; IP addresses, email addresses and access codes from links are removed before sending. The legal basis is our legitimate interest in fault-free operation (Art. 6(1)(f) GDPR). As a cache for search and offer results we use Cloudflare R2 (Cloudflare, Inc., USA) with storage located in the European Union; it holds search results without personal reference, and it is wired so that its failure removes only the cache.
So that you can see in your security settings where your account was signed in from, we ask ipwho.is (ipwhois.io) for the approximate location of the IP address stored for an earlier device. Only that IP address is sent, not your name or email address; we do not keep the location, we only display it. The legal basis is our legitimate interest in the security of your account (Art. 6(1)(f) GDPR). Your current location for suggestions (such as the nearest airport) is derived from the location information provided by Cloudflare, without any further service.
For consistent typography we use Plus Jakarta Sans through the next/font framework. The font files are downloaded when the site is built and served from our own domain. No requests go to Google servers when the page loads; neither IP addresses nor cookies are transmitted there.
For searching and arranging flights and accommodation we work with the interface provider LiteAPI.
During the search phase we transmit the search parameters server-side — origin and destination, travel dates, cabin class, number of travellers. These reveal travel interests but contain no names or contact details. Requests run through our backend; your browser IP is not passed on as a search parameter. The legal basis is Art. 6 (1) (b) GDPR for pre-contractual steps and, where necessary, Art. 6 (1) (f) GDPR for secure operation.
During the booking phase, personal data of the travellers is transmitted to LiteAPI so that tickets and booking confirmations can be issued: first and last name, date of birth, gender and nationality, email address and telephone number and, where the destination country requires it, the type, number, issuing country and validity of the travel document. The legal basis is Art. 6 (1) (b) GDPR. Without this transfer a booking is not possible.
There are two cases to distinguish, because two different companies receive your money.
For our own service, the tripbot Pro membership, we use the payment service Stripe (Stripe Payments Europe Ltd., Ireland, and Stripe, Inc., USA). Payment takes place on a page hosted by Stripe. You enter your payment details there; complete card details never reach our systems. Transmitted to or collected by Stripe are name, email address, payment method, billing details, amount and technical data for fraud prevention. We receive the payment status from Stripe and store, with the purchase, the declarations you made about the right of withdrawal. The legal basis is Art. 6 (1) (b) GDPR for performing the contract; for fraud prevention Stripe additionally processes as its own controller on the basis of Art. 6 (1) (f) GDPR.
For flight and hotel bookings the money is received not by tripbot but by LiteAPI. Payment runs through a payment field that LiteAPI embeds into our page. When that field loads, the payment provider’s scripts are loaded and information is stored on or read from your device, in so far as this is technically necessary to carry out the payment you requested (§ 25 (2) no. 2 TDDDG). IP address, device and browser data and your payment details may be processed. We ourselves receive no complete card details.
The payment field loads only when you actually proceed to complete a booking — not while searching or viewing offers.
Searching and booking are possible without an account. You need one for tripbot Pro and to manage your bookings permanently. We process your email address, sign-in data, profile details and the bookings assigned to your account.
Accounts, profiles, booking assignments, support and billing data are held in our database with Supabase, Inc. (USA). The legal basis is Art. 6 (1) (b) GDPR for performing the contract.
When you delete your account, we remove the account data and account link. We retain booking and payment records needed for billing and statutory duties separately for up to eight years after the end of their creation year. We erase or anonymise booking contact, traveller and raw provider data 90 days after travel ends or a cancellation, unless an overriding obligation or claim requires longer retention.
Without an account you can manage a booking using a one-time code that we send to the email address given at booking. The code is valid briefly and serves only to show that you control that address.
When you write to us through the contact form or by email, we process your details to handle the enquiry and any follow-up questions. You immediately receive an automatic acknowledgement with a reference number. The legal basis is Art. 6 (1) (b) GDPR where the enquiry concerns a contract, otherwise Art. 6 (1) (f) GDPR.
For transactional email — acknowledgements, booking confirmations, confirmations of cancellations and withdrawals — we use Resend (Resend Labs Inc., USA). Recipient address, subject, content, delivery status and technical metadata are processed.
For AI requests we process your input, the conversation context, optional attachments and technically necessary usage data. As a broker to selected model providers we use OpenRouter, Inc. (USA). Which sub-providers are involved depends on the model route chosen.
We route requests to AI models exclusively to providers that do not retain your input (zero data retention) and do not use it for model training. This restriction is enforced technically in the application and applies to every single request; a provider without that commitment is not asked. The legal basis is Art. 6 (1) (b) GDPR, because the AI feature is part of the service you use.
If the AI has to check a single fact that changes over time, such as whether a hotel pool is currently open, we send a short search phrase to the web search service Exa (Exa Labs, Inc., USA). The phrase names only the place and the question, not your name or your contact or booking details; the AI model derives it from your request. The commitment not to retain data does not apply to Exa: under Exa’s terms of use, search phrases may be stored and used to improve its services. The legal basis is Art. 6 (1) (b) GDPR.
If you use voice input, the page only accesses the microphone after you allow it in your browser. When you stop, the recording is sent to Groq (Groq, Inc., USA) and converted to text there; the text appears in your input field. We do not store the recording, and Groq does not store it (Zero Data Retention). The legal basis is Art. 6(1)(b) GDPR.
If you enable travel memories, we store the details derived from them in your profile with Supabase. You can view or delete them, or switch the feature off, in the AI settings at any time.
Please do not enter special categories of personal data — health data, for instance — and no data about other people without their knowledge.
We set technically necessary cookies without consent, because without them sign-in, checkout and security functions cannot work (§ 25 (2) no. 2 TDDDG).
For product analytics we use PostHog (PostHog, Inc., USA), operated in the EU (Frankfurt). Pseudonymised usage events are recorded, such as pages opened, features used and error paths; for signed-in users a random identifier is added, but neither name nor email address. Your IP address is not stored; only a rough location is derived from it. Requests are routed through a relay on our own domain, and no cookies are passed on to PostHog. This processing takes place only after your consent (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG). Without consent PostHog is not loaded in your browser.
With your consent we also record your session as a replay during a share of visits and throughout the booking and payment flow, so that we can trace errors and sticking points. Text and entries are masked in your browser before they leave it, and embedded payment windows are not recorded. We delete recordings after 30 days.
Regardless of your consent, we report confirmed bookings and newly created accounts to PostHog as plain counts so that we can run our business. These reports contain no name, no email address and no user identifier (Art. 6 (1) (f) GDPR).
You can withdraw your consent at any time with future effect through the cookie settings. The lawfulness of processing carried out until then is unaffected.
We use no advertising pixels and no cross-provider tracking.
Until this version, Google Analytics and Vercel Analytics also ran. Both were switched off and removed from the application.
You have the right to information about the data stored about you, its origin, recipients and purpose (Art. 15 GDPR), to rectification of inaccurate data (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18) and to data portability (Art. 20).
You also have the right to object at any time, on grounds relating to your particular situation, to processing based on legitimate interests (Art. 21 GDPR). Consent you have given can be withdrawn at any time with future effect.
An informal message to legal@trytripbot.com or through the contact form is enough to exercise your rights. You can also delete your account yourself in the account settings.