Privacy Policy
We respect your privacy and are committed to protecting your personal information. This policy explains how we collect, use, and safeguard your data.
Introduction
Tripix ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform to create and sell travel content.
By using our services, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.
Legal Identity and Jurisdiction
Data Controller
Tripix is the Data Controller responsible for processing your personal information. For the purposes of data protection laws, Tripix operates as a US-based company.
Physical Address
131 Continental Dr
Newark, Delaware 19713
United States
Governing Law
This Privacy Policy is governed by the laws of the United States and the State of Delaware. Any disputes arising from or related to this Privacy Policy or our data practices will be resolved in accordance with US federal law and Delaware state law. For users located in the European Union, additional rights and protections apply as detailed in the GDPR Compliance section below.
Creator vs. Customer Data
Two Types of Users
Our platform serves two distinct types of users, and we handle their data differently:
Creators
Travel creators who use our platform to build storefronts and sell digital products.
Our Role: Data Controller - We directly collect and process creator data for account management, payment processing, and service delivery.
End-Users (Customers)
Travelers who purchase or view travel guides created by creators on our platform.
Our Role: Data Processor - We process end-user data on behalf of creators to facilitate transactions and deliver purchased products.
Data Processing Responsibilities
- Creator Data: We are the Data Controller. We collect creator information (name, email, payment details, content) directly and process it to provide our services.
- End-User Data: We act as a Data Processor. When end-users purchase products from creators, we process transaction data (name, email, payment information) on behalf of the creator to complete the sale and deliver the product.
- Creator Responsibility: Creators are responsible for their own privacy policies regarding end-user data. We recommend creators maintain their own privacy policies that comply with applicable laws.
- Data Sharing: We share end-user transaction data with creators so they can fulfill orders and provide customer support. We do not use end-user data for our own marketing purposes without explicit consent.
Information We Collect
- Personal information (name, email, payment information)
- Travel content and storefront data
- Usage analytics and website interactions
- Communication records and support tickets
- Device and browser information
How We Use Your Information
- Provide and maintain our services
- Process payments and transactions
- Send important updates and notifications
- Improve our platform and user experience
- Provide customer support and resolve issues
- Comply with legal obligations
Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), we process your personal data based on the following legal grounds:
Information Sharing
- We do not sell your personal information
- Share with payment processors for transactions
- Comply with legal requirements when necessary
- Protect our rights and prevent fraud
- With your explicit consent
Data Security
- Encryption of data in transit and at rest
- Regular security audits and updates
- Limited access to personal information
- Secure payment processing
- Monitoring for suspicious activity
Data Retention
- Keep data as long as your account is active
- Retain data for legal compliance
- Delete data upon account closure request
- Anonymize data for analytics when possible
Your Rights
- Access your personal information
- Correct inaccurate data
- Request deletion of your data
- Opt-out of marketing communications
- Export your data
- Lodge complaints with authorities
How to Exercise Your Rights
You can exercise your privacy rights through the following mechanisms:
1. Account Settings (Recommended)
Access your account settings in the creator dashboard to:
- • View and update your personal information
- • Download a copy of your data (data export)
- • Delete your account and associated data
- • Manage your communication preferences
2. Email Request
Send an email to privacy@tripix.ai with:
- • Your full name and email address associated with your account
- • The specific right you wish to exercise
- • Any additional information needed to verify your identity
3. Response Time
We will respond to your request within 30 days (or as required by applicable law). For complex requests, we may extend this period by an additional 60 days with notification.
Note: We may need to verify your identity before processing certain requests to protect your privacy and security. This may require providing additional information or documentation.
GDPR Compliance (European Users)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR). This section outlines your rights and our compliance with GDPR requirements.
Your GDPR Rights
- Right of Access: You can request a copy of all personal data we hold about you.
- Right to Rectification: You can request correction of inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): You can request deletion of your personal data under certain circumstances.
- Right to Restrict Processing: You can request that we limit how we process your data.
- Right to Data Portability: You can request your data in a structured, machine-readable format.
- Right to Object: You can object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time.
Data Protection Officer (DPO)
We do not currently have a designated Data Protection Officer (DPO) as we do not meet the threshold requirements under GDPR Article 37. However, all privacy inquiries and data subject requests are handled by our privacy team.
For GDPR-related inquiries, please contact us at privacy@tripix.ai with "GDPR Request" in the subject line. We will respond to your request within 30 days as required by law.
Supervisory Authority
If you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection supervisory authority. For users in the EEA, you can find your supervisory authority at edpb.europa.eu.
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience, analyze usage patterns, and provide personalized content.
Cookie Consent Manager
When you first visit our website, you'll see a cookie consent banner that allows you to accept or decline non-essential cookies before they are set. This ensures compliance with privacy laws and gives you control over your data.
You can manage your cookie preferences at any time through:
- •Our cookie consent manager (accessible via the cookie settings button in the footer)
- •Your browser settings (though this may limit website functionality)
For more detailed information about our use of cookies, please see our Cookie Policy.
Essential Cookies
Required for basic functionality and security. These cannot be disabled.
Analytics Cookies
Help us understand how you use our platform. You can opt-out via our cookie consent manager.
Third-Party Services and Sub-Processors
We work with trusted third-party service providers to deliver our platform. These services act as data processors or sub-processors and help us provide payment processing, analytics, and other essential functions.
Payment Processing
Stripe - We use Stripe to process payments securely. When you make a purchase or receive payments, your payment information is processed by Stripe in accordance with their privacy policy. We do not store your full credit card details.
View Stripe Privacy Policy →Analytics Services
Amplitude - We use Amplitude to analyze how users interact with our platform. This helps us improve our services and user experience. Amplitude processes anonymized usage data.
View Amplitude Privacy Policy →Other Services
We may also use additional services for hosting, email delivery, customer support, and security. All sub-processors are contractually bound to protect your data and comply with applicable privacy laws.
Note: We carefully select our third-party service providers and ensure they meet high standards for data protection. However, we are not responsible for the privacy practices of third-party services. Please review their privacy policies before providing any personal information.
Sub-Processor List
A complete list of our sub-processors is available upon request. To request this list, please contact us at privacy@tripix.ai with the subject line "Sub-Processor List Request."
Google API Services User Data Policy
Our application's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use, share, or transfer raw or derived Google user data for training AI models.
California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). This section outlines your rights and how to exercise them.
Your California Privacy Rights
- Right to Know: You can request information about the categories and specific pieces of personal information we collect, use, disclose, and sell (if applicable).
- Right to Delete: You can request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out of Sale/Sharing: You can opt-out of the sale or sharing of your personal information for cross-context behavioral advertising.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
- Right to Correct: You can request correction of inaccurate personal information.
- Right to Limit Use of Sensitive Personal Information: You can limit how we use sensitive personal information to only what is necessary.
Do Not Sell or Share My Personal Information
We do not sell your personal information. However, we may share certain information with third parties for advertising purposes (such as retargeting cookies), which may be considered "sharing" under California law.
If you wish to opt-out of the sharing of your personal information for advertising purposes, you can:
- •Use our cookie consent manager to disable marketing cookies
- •Email us at privacy@tripix.ai with "California Opt-Out" in the subject line
- •Use the Global Privacy Control (GPC) signal if your browser supports it
Categories of Personal Information We Collect
In the past 12 months, we have collected the following categories of personal information:
- • Identifiers (name, email, IP address)
- • Commercial information (purchase history, payment information)
- • Internet activity (browsing history, interactions with our platform)
- • Geolocation data (approximate location based on IP address)
- • Professional information (for creators: business information, content created)
How to Exercise Your California Privacy Rights
To exercise your California privacy rights, please:
- 1. Email us at privacy@tripix.ai with "California Privacy Request" in the subject line
- 2. Include your full name, email address, and specify which right(s) you wish to exercise
- 3. We will verify your identity before processing your request
- 4. We will respond within 45 days (or as required by law)
You may also designate an authorized agent to make requests on your behalf. The agent must provide proof of authorization.
Children's Privacy
Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
International Data Transfers
Your information may be transferred to and processed in countries other than your own, including the United States where our servers are located. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy and applicable laws.
Data Transfer Mechanisms (GDPR)
For transfers of personal data from the European Economic Area (EEA) to countries outside the EEA, we rely on the following mechanisms to ensure adequate protection:
- •EU-US Data Privacy Framework: We rely on the EU-US Data Privacy Framework for transfers to the United States, which provides an adequate level of data protection.
- •Standard Contractual Clauses (SCCs): Where applicable, we use European Commission-approved Standard Contractual Clauses with our service providers to ensure adequate protection of your data.
- •Binding Corporate Rules: Some of our service providers maintain Binding Corporate Rules that provide additional protection for international data transfers.
If you have questions about the specific safeguards we use for international data transfers, please contact us at privacy@tripix.ai.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
Your continued use of our services after any changes constitutes acceptance of the updated Privacy Policy.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
