Skip to main content

Trip-ey.com

Privacy Policy

Effective date: September 12, 2026

Trip-ey.com and the Trip-ey Chrome extension are operated by Lior Ben Jashar, Sole trader (individual) in Israel, who is the data controller for the personal data described here. This policy explains what we collect, why, on what legal basis, how long we keep it, who else sees it, and what you can require us to do.

The short version: we collect what the planner needs and little else. We never sell data that identifies you. Selling aggregated statistics to travel businesses is optional, off by default, and refusing it does not restrict your use of Trip-ey in any way. Extension data is excluded from that statistics program and is not sent to Trip-ey servers.

The website planner and extension handle data differently. Sections 1–7, 9 and 11 describe the website planner. See section 14 for the extension’s local data handling. Your rights and our contact details apply to both.

What we collect, why, and on what basis

Under the GDPR and UK GDPR, every use of personal data needs a lawful basis. Ours are set out below. “Contract” means the processing is necessary to give you the service you asked for; “legitimate interests” means we have weighed our interest against your rights and privacy; “consent” means you chose it and can withdraw it at any time.

Categories of personal data, purpose, legal basis and retention
DataWhy we have itLegal basisKept for
Account data — name and email address, and the Google account identifier if you use Sign in with Google. Passwords are hashed by our authentication provider and never visible to us.To create and secure your account, sign you in, and send password and confirmation emails.ContractUntil you delete your account, then purged within 30 days
Travel preferences — planning mode, travel style, interests to seek and avoid, budget and currency, number of travellers, dates and trip length, departure airport, stop and baggage constraints, accommodation preferences, and any free-text note you write.To generate your travel brief, to keep your draft so you can return to it, and to reproduce the request if something goes wrong.ContractGuest submissions 180 days; account submissions 730 days, or until you delete them
Passport nationality — the country or countries that issued the passports you can travel on. We never ask for passport numbers, scans, expiry dates or any document identifier.To screen destinations for likely short-stay entry requirements. Nothing else.ContractWith the submission it belongs to; excluded from all aggregated statistics
Guest identifier — a random value with no name or email attached, created in your browser only at the moment you submit a search.So that a submission made without an account can be found again and deleted at your request.ContractSame as the submission; cleared when you choose Start over
Consent records — which policy version you accepted, when, by what method, and whether you opted in to aggregated insights.To prove we asked properly and to honour your choice. Required of us by law.Legal obligationFor as long as the related data exists, plus a reasonable period to evidence compliance
Technical data — IP address, browser type and request metadata in transient server logs; short-lived counters used for rate limiting.To route traffic, keep the service available, and stop abuse and automated scraping.Legitimate interests (security and availability of the service)Short-lived operational logs only; rate-limit counters expire within minutes
Aggregated travel statistics — patterns such as which travel styles or budget ranges are popular, with account identifiers removed.To understand demand, improve the product, and produce market insights that may be shared or sold to travel businesses.Consent, given separately and optionalRetained in aggregate form; you can withdraw consent for future use at any time

Two separate choices, and only one of them matters for using the site

Before Trip-ey stores a search, it shows you two distinct checkboxes. We keep them separate on purpose, because consent that is bundled with the service is not real consent.

  • Storing your submission. Trip-ey saves the validated preference profile so it can produce your brief, show it again, and let you delete it later. This is necessary to deliver the service you requested, so it happens on the contract basis. You acknowledge it; without it there is no search to run.
  • Aggregated insights. Separately and entirely optionally, you may allow your preferences to feed anonymised, aggregated statistics that we may share or sell to tourism boards and travel operators. This box is unticked by default, never required, and refusing it changes nothing about the results you get or any feature available to you. You can change your mind at any time by unticking it or by writing to us.

Anonymisation, and what we mean by it

We do not sell, rent or trade data that identifies you. That commitment is unconditional.

When you have opted in, preferences used for statistics have account identifiers — user ID, name, email and guest identifier — removed, and are combined with other users’ data before any figure leaves our systems. Passport nationality is excluded entirely and is never part of any statistic, sale or shared insight. Free-text notes are excluded entirely, because free text cannot be reliably anonymised.

We tell you plainly that aggregation reduces, rather than eliminates, the theoretical risk of re-identification in any dataset. We mitigate it by publishing only grouped figures, never row-level records, and by suppressing groups too small to be meaningful.

Please keep sensitive information out of free text

The planner has an open note field. We ask you not to use it for special category data — health conditions, disabilities, pregnancy, medication, religion, sexual life or orientation, political opinions, trade union membership, ethnic origin, or biometric and genetic data. Trip-ey does not need any of it to suggest a destination.

If you enter such information anyway, we process it only to answer your request, we exclude it from all statistics, and we delete it with the rest of your submission. You may ask us to remove it sooner at any time.

Who else processes your data

We use a small number of service providers. They act on our instructions under data processing terms, and none of them is permitted to use your data for their own purposes.

Service providers that process data on our behalf
ProviderRoleWhat they receiveLocation
SupabaseDatabase, authentication and file hostingAccount email, saved preference profiles, consent recordsEuropean Union / United States, depending on project region
Google (Sign in with Google)Optional federated sign-inName and email address released by the user's Google accountUnited States
SerpApiRetrieves current flight, accommodation and research resultsSearch parameters only (route, dates, cabin, currency). No name, email or account identifier is sent.United States
NVIDIA (build.nvidia.com)Summarises destination research in an offline jobPublic destination research text only. No user data of any kind is sent.United States
Hosting provider (Cloudflare / container host)Serves the application and terminates TLSIP address and request metadata in transient server logsGlobal edge network

Note in particular that our flight and research provider receives only search parameters — a route, dates, cabin class and currency. Your name, email, account identifier and free-text notes are never sent to it. The research summarisation model receives public destination text only, in an offline job, and no user data whatsoever.

We may also disclose data where we are legally required to, or to establish or defend legal claims. We will tell you if that happens unless we are prohibited from doing so.

International transfers

Trip-ey is operated from Israel, and some providers listed above are located in the United States. Israel has held an adequacy decision from the European Commission (opens in a new tab), so transfers of personal data from the EEA to Israel do not require additional safeguards. For transfers to providers outside the EEA and the UK, we rely on Standard Contractual Clauses or the provider’s own approved transfer mechanism. You may ask us for details of the safeguards that apply.

How long we keep things

The retention column in section 1 is the operative answer. In summary: guest submissions are deleted after 180 days; submissions attached to an account are deleted after 730 days or when you delete them, whichever is first; cached destination research is refreshed every 30 days; and deleting your account purges your account data and everything linked to it within 30 days. Drafts held in your own browser stay there until you clear them.

Your rights

Wherever you live, you may ask us to show you the data we hold about you, correct it, delete it, or stop using it, and we will not treat you differently for asking.

If the GDPR or UK GDPR applies to you, you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out. You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner’s Office; in the EEA, the authority in your country of residence or workplace.

If you are in Israel, the Privacy Protection Law, 5741-1981 gives you the right to inspect the data held about you and to request its correction or deletion, and you may complain to the Privacy Protection Authority.

If you are a California resident, you may request disclosure of the categories and specific pieces of personal information collected, the purposes, and the categories of recipients; request deletion or correction; and opt out of any “sale” or “sharing” of personal information. We do not sell or share personal information that identifies you, and we do not sell the personal information of minors. Exercising these rights never results in a worse service or a different price. You may use an authorised agent.

The fastest routes are the account page, which deletes your account and associated data, and the Start over control in the planner, which clears this browser and requests deletion of the matching saved submissions. For anything else, write to privacy@trip-ey.com. We answer within 30 days and may ask you to confirm your identity first so that we do not disclose your data to someone else.

Security

Data is transmitted over encrypted connections and stored in managed cloud infrastructure with encryption at rest. Access to production data is restricted, secrets are held server-side and never exposed to the browser, database access is governed by row-level security, and the application applies rate limiting, strict input validation and size limits on every request.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and, where the risk is high, you directly, within the timescales the law requires.

Children

Trip-ey is not directed at children under 13 and we do not knowingly collect their personal data. Users under 16 should involve a parent or guardian. If you believe a child has given us personal data, write to privacy@trip-ey.com and we will delete it promptly.

Automated decisions and profiling

Trip-ey scores and ranks destinations against the preferences you submit. This shapes what you are shown, but it produces suggestions only — it has no legal effect on you and no similarly significant effect, and a human is never replaced in any decision about you. You can change your inputs and get different results at any time.

Cookies, and changes to this policy

Cookies and browser storage are covered in full, item by item, in the Cookie Policy. Trip-ey uses no analytics, advertising or third-party tracking technology.

If we change this policy materially, we will update the effective date above and ask you to acknowledge the new version before your next website search, so your recorded consent always matches the policy you actually saw.

Contact and complaints

Lior Ben Jashar, Sole trader (individual), Israel.

Email: privacy@trip-ey.com

No data protection officer is required for an operation of this size and we have not appointed one; the operator handles privacy requests personally. Please come to us first if something is wrong — you always keep the right to go to your supervisory authority instead.

Chrome extension for Booking.com

The extension presents accommodation and room information from the Booking.com page you visit in a chooser with photos, prices, rates, previous/next navigation and temporary saved selections. It requires no Trip-ey account. It processes page content locally to provide the feature you request (contract basis where data protection law applies).

It runs on HTTPS Booking.com pages and subdomains and uses property and room elements, including titles, photos, prices, conditions and booking links. Rooms & photos follows the property’s existing Booking.com link, which may include your dates, party size and other search parameters. The extension does not collect browsing history across other websites, passwords or payment details for Trip-ey.

Booking.com site access allows the extension to present this content; active-tab and scripting permissions support the toolbar toggle; storage permission supports opening rooms in the requested new tab. The page script initializes on matching pages; the chooser opens when you enable it or request Rooms & photos.

Saved places and rooms stay in the current page’s memory. Removing a selection, reloading, navigating away or closing the tab clears it. Toggling the chooser off and on retains selections on the same page. They are not synced to your Trip-ey account or Chrome Sync.

To open rooms in a new tab, Chrome session storage holds a tab-specific handoff marker and expiry time, not the property URL. It is valid for two minutes and removed when consumed or navigation fails. Expiry makes it unusable; it does not automatically delete an unconsumed marker. Chrome clears this storage when the extension is disabled, reloaded or updated, or the browser restarts.

The extension does not transmit this data to Trip-ey servers, use analytics, send it to AI providers, sell it, share it for advertising, or include it in the website planner’s optional aggregated insights. Trip-ey’s use of information received through the extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. The website providers in section 5 do not receive extension data through the extension.

Booking.com and its content providers still receive normal browser requests to load their pages and photos. Their own privacy and cookie policies govern those requests. Enabling Trip-ey does not block their cookies or tracking. Visiting Trip-ey.com is a separate website visit governed by the website sections of this policy.

See the extension storage controls for clearing instructions. Contact privacy@trip-ey.com about your rights; we have no server copy of local room selections to retrieve or delete. Changes to extension data handling will be reflected here and in its Chrome Web Store disclosures, with any additional consent required by law or store policy obtained before the new processing begins.