Informații Legale

Privacy Policy

Last updated: September 6, 2026

This page explains what data the TripVaria mobile app collects, why we use it, who may receive it and what choices you have. The text reflects the active flows currently implemented in the app and backend API.

1. Scope

This policy applies to the TripVaria mobile app and the related backend services used for authentication, trip planning, place discovery, community content, bookings, AI-powered features and optional campaign measurement.

It covers the data processed when you use the app, create an account, save content, use AI-assisted or advanced features, make a booking, enable optional campaign measurement or contact us for support.

2. Data we may collect

  • Account and authentication data: Firebase UID, display name, email address, profile photo and the sign-in provider you choose, such as Google, Apple, email/password or anonymous session.
  • Profile data: display name, bio, phone number, home city, interests, user role, subscription plan, trial status, referral status, badges and relevant progress data used in the app experience.
  • Trip and usage data: origin, destination, intermediate stops, search filters, favorites, history, saved itineraries, collections, journals and packing lists.
  • Location data: precise or approximate device location only when you grant the required permission and use current-location or route-based features.
  • User-generated content: reviews, ratings, photos uploaded with reviews, pro tips, questions, answers, content reports and business or explorer contributions.
  • Commercial and subscription data: purchased product, active plan, entitlement dates, store transaction or purchase identifiers, referral redemption status and trial status. When subscriptions are paused, we may keep this data for restore, support and historical access records.
  • AI feature inputs when you choose to use them: selected places, route details, weather context, locale, prompts and generated outputs for itinerary, journal and packing flows.
  • Minimum technical data required to operate the service: authentication tokens, request metadata and information needed for security, debugging and abuse prevention.
  • Optional TikTok campaign measurement data, only after explicit consent: a hashed pseudonymous account identifier, allow-listed event types and limited public content metadata. We do not send TikTok your email, phone number, display name, raw searches, route points, notes or booking form details.
  • Booking data needed to provide the service: selected service and interval, quantity, name, email address, optional phone number, optional note, booking status and the operational history of confirmations, changes or cancellation.
  • Identifier-free first-party Booking analytics: event type, screen source, an allow-listed status or failure group, an aggregate count bucket and a replay indicator. We do not include UID, booking ID, reference, contact data, routes, tokens or free text.

3. How we use data

  • To create and manage your account and authenticate you securely.
  • To sync your profile, favorites, history, itineraries, journals, collections and other preferences across sessions and devices.
  • To calculate routes, search places, display maps, photos, place details and weather relevant to your trip.
  • To process community and business features, including reviews, uploaded images, questions, answers, moderation and place claims.
  • To activate, restore or verify subscriptions, trials, premium entitlements and store purchases when payments are active.
  • To generate AI outputs only when you explicitly invoke an AI feature in the app.
  • To protect the service, prevent fraud, enforce community rules, resolve incidents and improve reliability.
  • To measure TikTok campaign performance only when you enable the dedicated control in Profile.
  • To send the request to the selected business, show booking and voucher status, manage cancellation or changes, and provide operational support.
  • To measure the Booking funnel in aggregate and make safe rollout decisions without building an individual analytics profile.

4. What may become public

Some information may become visible to other users when you choose to publish it. Examples include public itineraries, reviews, ratings, review photos, pro tips, questions, answers and business or explorer submissions.

Favorites, history, extended profile data, private journals and packing lists are treated as private by default unless you explicitly publish or share a specific item.

5. Who may receive data

We do not sell your personal data to data brokers.

  • Identity and sign-in providers such as Firebase Authentication, Google Sign-In and Sign in with Apple.
  • Map and place providers such as Google Maps, Google Places, geocoding and routing services when you use search, maps or place details.
  • Weather providers when we request weather data for a selected place or route.
  • AI providers used through our backend when you use AI itinerary, AI journal or AI packing features.
  • TikTok for Business, only after opt-in, for limited campaign measurement events without the personal data or free text listed above.
  • App stores and payment infrastructure for in-app purchase processing and validation when payments are active. We do not store full payment card details.
  • Hosting, media storage and technical infrastructure providers used to run the API and serve user-uploaded content.
  • Authorities or relevant third parties when we are legally required to do so or when it is necessary to protect rights, safety and service integrity.
  • The business selected for a booking receives the contact and service details needed to fulfil it; the business internal note is not shown to the customer.

6. Legal bases and controls

  • Performance of the service you request: authentication, profile sync, routing, favorites, history, itineraries, journals and saved content.
  • Your consent: location access, photo uploads, optional profile fields and AI features or public content that you choose to submit.
  • Separate personalized AI-processing consent: disabled by default, granted only after the in-app disclosure, and available to withdraw at any time from Profile without disabling core planning.
  • Separate TikTok campaign measurement consent: disabled by default, available to enable or withdraw from Profile, and never required to use the app.
  • Legitimate interests: security, abuse prevention, moderation, operational stability and protection of our rights.
  • Legal obligations: retaining certain records needed for compliance, accounting, dispute resolution or valid legal requests.
  • Performance of the booking request: sending details to the chosen business and managing status, changes, cancellation and voucher access.

7. Retention

We keep personal data while your account is active and for as long as it is needed to provide the requested service. Booking data necessity is reviewed periodically, at least annually, against fulfilment, support, security, disputes and applicable legal obligations.

Account deletion removes account-linked bookings from the API, including contact snapshots, dependent history, modification responses, notes and voucher digests. Data that must be retained for a legal obligation or dispute is restricted and kept only for that purpose.

A raw voucher token is returned only when issued and is never stored by the API; only a SHA-256 digest and voucher metadata remain until the booking is deleted. CSV exports are generated on demand and are not retained by the API after the response; a downloaded copy is managed by the requesting business.

Identifier-free daily Booking aggregate counters are automatically removed during ingestion after no more than 24 months. They cannot reconstruct one user's history.

8. Your rights and choices

  • You can access and update certain profile data directly in the app.
  • You can revoke location permission from your device settings.
  • You can edit or delete certain content that you create where the feature provides those controls.
  • You can request account deletion from Profile > Delete Account.
  • You can contact support@tripvaria.ro for privacy questions, rectification requests or help exercising your rights.
  • You can view your own bookings and their history in My Bookings; the API blocks access by another customer.

9. Security and transfers

We use reasonable technical and organizational measures to protect data against unauthorized access, loss or misuse. No transmission or storage method is completely guaranteed, but we actively work to reduce security and operational risk.

Some service providers may process data outside your country of residence. When this happens, the processing is performed through the infrastructure and contractual terms of the providers used to operate the service.

10. Policy changes

We may update this policy when features, providers or data flows change. We will update the date shown at the top of this page and should publish the same updated version on the official TripVaria website.

For privacy questions or requests about your personal data, contact us at support@tripvaria.ro. The public website version of this policy is available at https://tripvaria.com/privacy and should be kept in sync with the in-app legal text.