tripbot/Privacy Policy
improntaTermini e condizioni
Security Passport

Privacy Policy

We take the protection of your personal data seriously. Here you can find out how we collect, process, and protect your data.

PASS-NO / 09-GDPR
In piedi2026
Legal FrameworkGlobal
Valido pertripbot (Web & App)
Contact[email protected]
Indice/navigazione rapida
1. Privacy at a Glance2. Hosting & Infrastructure3. Mandatory Information4. Core Features (LiteAPI)5. Support Infrastructure6. Newsletter DOI7. Analytics & Optimization8. Advertising Trackers9. Your GDPR Rights

1. Privacy at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you. Detailed information on data protection can be found in our privacy policy listed below.

Data Collection on Our Website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. You can find their contact details in the "Controller Information" section of this privacy policy.

How do we collect your data?

On one hand, your data is collected when you provide it to us. This could be, for example, data you enter into a contact form, when subscribing to the newsletter, or during travel booking facilitation.

Other data is collected automatically or with your consent when you visit the website through our IT systems. These are primarily technical data (e.g., internet browser, operating system, or time of page access). This data is collected automatically as soon as you enter this website.

What do we use your data for?

Part of the data is collected to ensure the error-free provision of the website and to perform the contractually owed travel facilitation. Other data may be used to analyze your user behavior.

What rights do you have regarding your data?

You have the right to receive information about the origin, recipient, and purpose of your stored personal data at any time free of charge. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can withdraw this consent at any time for the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

2. Hosting and Infrastructure-as-a-Code

Infrastructure Provider

Vercel Hosting

We host our website with Vercel. The provider is Vercel Inc., 440 Bond Street, Suite 5, Brooklyn, NY 11231, USA (hereinafter Vercel). When you visit our website, Vercel collects various log files including your IP address. The use of Vercel is based on Art. 6(1)(f) GDPR. We have a legitimate interest in the most reliable and secure presentation and provision of our website.

Data transfer to the USA is based on the EU Commission's Standard Contractual Clauses. We have concluded a Data Processing Agreement (DPA) under Art. 28 GDPR with Vercel, which ensures that Vercel only processes our users' data in accordance with our instructions and in compliance with the GDPR.

Local Provision of Google Fonts

This site uses web fonts provided by Google for the uniform display of fonts (specifically the Plus Jakarta Sans font). To maximize the protection of your privacy, we use the native next/font/google framework.

The font files are downloaded directly from Google during the build process (when compiling the page on our servers) and stored locally on our own infrastructure. When loading this website in our visitors' browsers, no external requests are sent to Google's servers. No IP addresses or cookies are transferred to Google. Delivery is entirely from our own domain (trytripbot.com). Processing is based on our legitimate interest in a design-compliant and privacy-friendly presentation of our content (Art. 6(1)(f) GDPR).

3. General Information and Mandatory Disclosures

Information regarding the Controller

The controller responsible for data processing on this website is:

Nico Neser
Moorweg 10, 91325 Adelsdorf
[email protected]

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data (e.g., names, email addresses, etc.).

Storage Period

Unless a more specific storage period has been specified in this privacy policy, your personal data will remain with us until the purpose for processing the data no longer applies. If you assert a legitimate request for deletion or withdraw your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial retention periods of 10 years for booking records); in the latter case, deletion will take place after these reasons no longer apply.

Note on Data Transfer to the USA and other Third Countries

We use tools from companies based in the USA or other countries that are not secure under data protection law. When these tools are active, your personal data may be transferred to these third countries and processed there. We point out that a level of data protection comparable to the EU cannot be guaranteed in these countries. For example, US companies are obliged to hand over personal data to security authorities without you as the data subject being able to take legal action against this.

Withdrawal of your Consent to Data Processing

Many data processing operations are only possible with your express consent. You can withdraw consent you have already given at any time. The lawfulness of data processing carried out up to the withdrawal remains unaffected by the withdrawal.

Right to Lodge a Complaint with the Competent Supervisory Authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work, or the place of the alleged violation. The right to lodge a complaint is without prejudice to other administrative or judicial remedies. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA).

4. Core Features: Flight and Hotel Search & Booking Facilitation

We offer the search and facilitation of travel services (flights, hotels) on our platform. In doing so, we work with the external technology and API interface provider LiteAPI.

Phase 1: The Search Phase (Completely Anonymous)

When you search for flights or hotels on tripbot, only non-personal, anonymous search parameters are transmitted to LiteAPI.

Processed data: departure/destination, travel dates, cabin class, number of passengers.

Privacy Guarantee: No personal data (such as name, email address, or your personal IP address) flows to LiteAPI during this phase. The search requests are executed bundled on the server side via our own Next.js backend. Your direct IP address is never passed on to LiteAPI. The legal basis for this processing is Art. 6(1)(b) GDPR (initiating a contract).

Phase 2: The Booking Phase & Pre-Booking (Personal Data)

As soon as you initiate a binding booking facilitation on our platform, personal data of the travelers must be transmitted to LiteAPI and processed for legally valid ticket issuance (flight booking / hotel voucher) and contract performance.

  • Passenger/Guest travel data: first and last name (including any middle names), date of birth, gender, and nationality.
  • Contact data: email address and phone number to transmit direct booking confirmations, tickets, and operational notifications from the executing airlines/hotels.
  • Travel documents (if legally required for the destination country): document type (e.g. passport), document number, country of issue, and validity period.

Legal basis: The processing and transfer of this data to LiteAPI is based on Art. 6(1)(b) GDPR (processing for the performance of a contract or to carry out pre-contractual measures). Without this data transmission, legally secure ticket issuance or hotel booking is technically and legally impossible.

5. Contact Form and Support Infrastructure

If you send us inquiries via the contact form, your details from the inquiry form, including the contact details you provided there, will be processed by us for the purpose of processing the inquiry and in the event of follow-up questions.

Storage in the Database (Supabase)

The data you enter (name, email address, message, and the source URL) will be stored permanently directly in our secure, encrypted support database at Supabase (provider: Spacedrive Inc., dba Supabase, 970 Summer St, Stamford, CT 06905, USA) to ensure data security and prevent data loss. A GDPR-compliant Data Processing Agreement (DPA) was concluded with Supabase.

AI features and travel memories

When you enable travel memories, we store the editable summary in your Supabase profile and use it as a soft signal for personalised responses. We use OpenRouter, Inc. as a technical gateway to selected model providers when processing AI requests. Requests are restricted to providers that do not retain the data, and use for model training is denied. You can delete or disable travel memories at any time in AI settings. This removes the active summary from your profile and it is not restored automatically. Copies may remain until the regular backup rotation expires and are not used for personalisation.

Email Infrastructure (Resend)

After saving in the database, our backend initiates the email dispatch to process the support request. For this, we use the specialized infrastructure service Resend (provider: Resend Labs Inc., 228 Park Ave S, PMB 99033, New York, NY 10003, USA) via Software Development Kit (SDK). Resend processes the data on our behalf to ensure a reliable, encrypted, and high email delivery rate.

Spam and Bot Protection (Cloudflare Turnstile)

To protect our contact form against spam, automated attacks, and bots, we use the Cloudflare Turnstile service. The provider is Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA. Turnstile is a privacy-friendly alternative to conventional systems because it analyzes user behavior purely mathematically in the background without setting personal tracking cookies, without abusing data for advertising purposes, and without violating users' privacy.

Legal basis: The processing of the data entered into the contact form is based on our legitimate interest in secure, spam-free communication and the rapid response to user inquiries (Art. 6(1)(f) GDPR) as well as, if applicable, to initiate or perform a contract (Art. 6(1)(b) GDPR).

6. Newsletter Infrastructure (Double-Opt-In)

If you would like to receive the newsletter offered on the website, we require an email address from you.

The Double-Opt-In Procedure (DOI)

To ensure that the registration is actually made by the owner of the email address, we use a secure two-step procedure (Double Opt-In) via our secure newsletter interface:

  • After registration, our backend sends a verification email via the Resend service with a unique, cryptographic token to the address provided.
  • Only when you click the confirmation link in this email will your registration be activated and your status saved as confirmed in our secure database. Only from this moment will you receive newsletter mailings.

Cancellation (Unsubscribe)

You can withdraw your email address and its use for sending the newsletter at any time. Every newsletter email contains a direct, legally compliant unsubscribe link for this purpose. One click is enough to immediately remove your data from the active mailing list and update it in the database.

Legal basis: Processing is based solely on your consent (Art. 6(1)(a) GDPR). You can withdraw this consent at any time.

7. Analysis Tools and Product Optimization

We use analysis tools to improve the user-friendliness, loading times, and performance of our platform. To protect your data as much as possible, a strict opt-in principle applies on our platform.

Consent via the Cookie Consent Banner

By default (when the page is first loaded), all non-essential tracking scripts and cookies are completely blocked. Only when the user explicitly clicks "Accept All" or actively enables the "Analytics" category in the settings will the following services be loaded dynamically. You can withdraw this consent at any time via the link in the privacy settings in the footer.

The Analysis Services Used:

PostHog (Product Analytics via Reverse Proxy)

We use PostHog to analyze product interactions. To bypass ad-blockers and maintain data sovereignty, we use a self-built reverse proxy. All event data is first routed through our own, secure Next.js backend, checked there, and only then transmitted encrypted to PostHog.

Google Analytics (Gtag)

We use Google Analytics, a web analysis service from Google Ireland Limited (Google), Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics collects anonymized or pseudonymized statistics about page access.

Vercel Analytics

We use Vercel Analytics solely to monitor the technical performance and loading times of our app (so-called Core Web Vitals) in order to keep the platform stable and fast. No profiles are created for marketing purposes.

Legal basis: Processing is based solely on your consent (Art. 6(1)(a) GDPR and § 25(1) TDDG).

8. Advertising Pixels and Personalized Advertising

We completely refrain from using third-party advertising pixels or marketing trackers on our platform.

No advertising pixels (such as the Meta Pixel, Google Ads Conversion Tracker, or TikTok Pixel) are integrated.

In the source code of our platform, the category for marketing cookies is permanently deactivated and completely blocked by default. No data collection for personalized advertising or behavioral advertising takes place.

9. Rights of the Data Subject (Your Rights under GDPR)

As a data subject affected by data processing, you have comprehensive rights against the controller under the GDPR:

Right to Information (Art. 15 GDPR)

You can request information at any time as to whether and which of your personal data we process.

Right to Rectification (Art. 16 GDPR)

If your data stored by us is incorrect or incomplete, you can request immediate correction.

Right to Deletion (Right to be Forgotten - Art. 17 GDPR)

You can request the deletion of your data, unless a statutory exception (such as statutory retention obligations) prevents this.

Right to Restriction of Processing (Art. 18 GDPR)

You have the right, under certain conditions, to request the restriction of the processing of your data.

Right to Data Portability (Art. 20 GDPR)

You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a structured, commonly used, machine-readable format.

RIGHT TO OBJECT (Art. 21 GDPR)

IF YOUR DATA IS PROCESSED ON THE BASIS OF LEGITIMATE INTERESTS (ART. 6(1)(F) GDPR), YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING AT ANY TIME, PROVIDED THAT THERE ARE REASONS ARISING FROM YOUR PARTICULAR SITUATION.

To assert your data subject rights, an informal email is sufficient to: [email protected]Invia e-mail
© 2026 tripbot. All rights reserved.
tripbot.

Viaggi, ma con trasparenza.

Segui su Instagram

Prodotti

  • Cerca
  • tripbot Intelligence (IA)

Blog di viaggio

  • Tutti gli articoli
  • Destinations soleil invernali 2026
  • Quando prenotare i voli?
  • Trovare buoni hotel

Azienda

  • Chi siamo
  • Nico Neser — Fondatore
  • Lavora con noi
  • Stampa

Supporto

  • Centro assistenza
  • Gestisci prenotazione
  • Aggiornamenti
  • Contatto
IT · EUR (€)
Pagamento sicuro con
Visa
Mastercard
Apple Pay
Google Pay
TerminiPrivacyimprontaCookie

© 2026 tripbot. Tutti i diritti riservati.

CercaBlog di Viaggiotripbot IA