tripstat

Tripstat — Privacy Policy

Last updated: 15 July 2026

In short (informal summary; the full text below is what applies): We collect only what is needed to run Tripstat — your account details, the content you post, and technical data. Everything is stored on servers in the European Union. We don't sell your data, we don't run ads, and we don't send marketing emails. Analytics cookies are set only if you opt in; before that, analytics run without cookies and without persistent identifiers. New accounts are "restricted" by default — not indexed by search engines and not findable in internal search. You can delete your account yourself at https://tripstat.io/settings.

1. Who Is Responsible for Your Data

The data controller for personal data processed in connection with the Tripstat website (https://tripstat.io) and the Tripstat mobile apps (together, the "Service") is:

Dmitrii Nikolaevich Korovin, an individual (natural person) applying the special tax regime "Tax on Professional Income" (self-employed) under the laws of the Russian Federation, Taxpayer Identification Number (INN) 622901627255, registered in Ryazan Oblast, Russian Federation (the "Operator", "we", "us").

Contact for all privacy matters: korovindn@proton.me

This Policy applies to all users of the Service. It is written primarily with users in the European Union / European Economic Area and the United States in mind. The Service is not offered to persons located in the Russian Federation.

2. Data We Collect

Account data (you provide it):

Google sign-in. If you sign in with Google, we receive your Google account email address and, with your permission, your profile picture. The imported picture becomes your avatar and can be removed in Settings at any time. We do not receive your Google password.

Content you create: posts, photos, travel maps, places and dates you enter manually, and other materials you submit. Travel statistics shown in the Service are computed from data you enter. Note: photos can contain embedded metadata (for example, camera details and the location where the photo was taken). If you do not want such metadata to be processed or potentially visible with a public photo, remove it before uploading.

AI feature inputs: queries and content you submit to AI-powered features (see Section 5).

Technical and usage data (collected automatically): IP address, approximate location derived from IP (country/city level), device and browser type, operating system, interface language, referrer, pages/screens viewed, timestamps, and similar log data; error and crash reports (which may include IP address, device information, and the state of the application at the time of the error); and, in the mobile apps, a push notification token if you enable push notifications.

Communications: messages you send us (for example, support requests or content reports) and our replies.

We do not collect precise GPS location. Places on your maps are entered by you manually. We do not knowingly collect data from children under 16 (see Section 12).

3. Why We Process Your Data and on What Legal Basis

PurposeDataLegal basis (GDPR)
Creating and operating your account; hosting and displaying your content according to your visibility settings; providing travel statistics; providing AI features you invokeAccount data, content, AI inputsPerformance of a contract, Art. 6(1)(b)
Sending push notifications about events you subscribed to; sending transactional (service and security) emailsPush token, email, subscription settingsPerformance of a contract, Art. 6(1)(b)
Security, fraud and abuse prevention, enforcing our Terms, moderating reported contentTechnical data, content, account data, reportsLegitimate interests, Art. 6(1)(f) (keeping the Service safe and lawful); legal obligation, Art. 6(1)(c), where applicable
Diagnosing and fixing errors and outagesError/crash reports, logsLegitimate interests, Art. 6(1)(f) (providing a working service)
Understanding aggregate usage of the Service before you consent to analytics cookiesEvent data processed without cookies or persistent identifiers, in aggregateLegitimate interests, Art. 6(1)(f) (measuring and improving the Service with minimal privacy impact)
Analytics after you opt in to analytics cookiesAnalytics cookie identifier, usage eventsConsent, Art. 6(1)(a) — withdrawable at any time
Complying with legal obligations and responding to lawful requestsAs requiredLegal obligation, Art. 6(1)(c)
Establishing, exercising, or defending legal claimsAs requiredLegitimate interests, Art. 6(1)(f)

Where we rely on legitimate interests, we have assessed that the processing is necessary and that our interests are not overridden by your rights and freedoms; you can object at any time (Section 10).

We do not use your data for marketing, advertising, or profiling for advertising purposes, and we do not carry out automated decision-making that produces legal or similarly significant effects on you (Art. 22 GDPR). AI features generate informational content only.

4. Visibility of Your Profile and Content

Your visibility is controlled by settings described in our Terms of Service:

Each map has its own private/public setting controlling whether other users (including signed-out visitors) can view it.

Content you make public can be seen, copied, and cached by anyone, including search engines. Switching content to private or deleting it removes it from the Service but cannot recall copies already made by third parties or held in external caches.

5. AI Features and Your Data

Some features use AI models (Google Gemini) accessed through Google Cloud Vertex AI with processing configured in an EU region. When you use an AI feature, your query and the minimum context needed to answer it are sent to Google Cloud, which processes them on our behalf as a data processor. Under the applicable Google Cloud terms, content submitted through Vertex AI is not used by Google to train its foundation models.

Please do not enter sensitive personal data (such as health, religious, or political information) or other people's personal data into AI features. AI outputs are labeled in the interface and are reference material only — see the Terms of Service for the relevant disclaimers.

6. Who Receives Your Data

We do not sell personal data and do not share it with third parties for advertising. We share data only with service providers (data processors) who process it on our instructions, and in the limited situations listed below.

ProviderRoleData location
Vercel Inc.Hosting of the application and content deliveryApplication hosting configured in the EU; the content delivery network operates globally and may process technical request data (such as IP addresses) at edge locations near you
Neon (Neon, Inc.)DatabaseEuropean Union
Google Cloud (Google LLC / Google Ireland Ltd.) — Cloud StorageStorage of uploaded files (photos, media)European Union
Google Cloud — Vertex AI (Gemini)AI featuresEuropean Union
Sentry (Functional Software, Inc.)Error and crash monitoringEuropean Union
PostHog Inc.Product analyticsEuropean Union
Transactional email delivery providerSending account and security emailsEuropean Union

We may also disclose data: to competent authorities where required by law or a binding request; to establish, exercise, or defend legal claims; and, if the Service is transferred to a legal entity or acquirer continuing its operation, to that successor under this Policy (with notice to you).

7. International Data Transfers

Your data is stored on servers located in the European Union (see the table above). Some of our providers are headquartered in the United States; where their provision of services involves transfers of personal data to the US, those transfers are protected by the EU–U.S. Data Privacy Framework certification of the provider and/or the European Commission's Standard Contractual Clauses, as applicable.

The Operator is a natural person who may administer the Service, and therefore access personal data remotely, from countries outside the EEA that have not received an EU adequacy decision (including, where applicable, the Russian Federation, the Operator's jurisdiction of registration). Such access is limited to what is necessary to operate, secure, and moderate the Service; it takes place over encrypted connections, data remains stored with the EU providers listed above (which encrypt it in transit and at rest), and no copies of the user database are maintained outside those providers. To the extent such remote access constitutes a transfer under Chapter V GDPR, it is necessary for the performance of the contract between you and us (Art. 49(1)(b) GDPR). You can request more information about transfer safeguards at korovindn@proton.me.

8. How Long We Keep Data

DataRetention
Account data and contentFor the life of your account. After account deletion: removed from active systems within 30 days; residual copies purged from backups within 90 days
Server and access logsUp to 30 days
Error and crash reportsUp to 90 days
Consent-based analytics eventsUp to 12 months; aggregated statistics that no longer identify anyone may be kept longer
Support and report correspondenceUp to 24 months after resolution
Records needed to comply with law, enforce our Terms, or handle legal claims (e.g., records of abuse or of a deletion request)For the applicable limitation period

9. Cookies and Similar Technologies

We use a small number of strictly necessary first-party cookies (authentication, security, interface language) that are set without consent, and optional analytics cookies (PostHog) that are set only if you opt in. Before consent, analytics run in a cookieless mode without persistent identifiers. Details, including a full cookie table and how to change your choice, are in our Cookie Policy: https://tripstat.io/cookies.

10. Your Rights (EEA/GDPR and Similar Laws)

You have the right to: access your data and obtain a copy; rectify inaccurate data; erase your data; restrict processing; data portability (receive data you provided in a machine-readable format); object to processing based on legitimate interests; and withdraw consent at any time where processing is based on consent (this does not affect processing before withdrawal).

To exercise your rights, email korovindn@proton.me or use the in-Service tools (profile editing, visibility settings, account deletion). We respond within one month, extendable by two further months for complex requests, and may need to verify your identity. Exercising these rights is free of charge.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU/EEA member state of your habitual residence, place of work, or place of an alleged infringement.

11. United States Residents

For residents of US states with consumer privacy laws (such as California): we do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months; we do not use or disclose sensitive personal information for purposes requiring a right to limit; and we do not process personal data for targeted advertising. Because we do not sell or share personal information, there is nothing to opt out of, including via the Global Privacy Control.

The categories of information we collect and our purposes are described in Sections 2–3; recipients in Section 6; retention in Section 8. You may request access to, correction of, or deletion of your personal information, or ask questions about this Policy, at korovindn@proton.me. You may use an authorized agent where the law provides for it; we will not discriminate against you for exercising your rights.

12. Children

The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child under 16 has created an account, contact korovindn@proton.me and we will delete the account and associated data.

13. Security

We protect data using measures appropriate to the risk, including: TLS encryption of data in transit; encryption at rest by our storage providers; password hashing; HttpOnly and SameSite cookie attributes for session cookies; access on a least-privilege basis; and EU-region data residency with the providers listed in Section 6. No method of transmission or storage is completely secure; please use a strong, unique password and keep your credentials confidential.

14. Push Notifications and Emails

Push notifications cover only events you have subscribed to (for example, changes to maps you follow or new posts from members you follow). You can disable them in your device settings and manage individual subscriptions in the Service settings at any time. We send transactional emails only (account, security, and service messages) and no marketing; essential service and security messages cannot be opted out of while your account exists.

15. Deleting Your Account

You can delete your account yourself at https://tripstat.io/settings (sign-in required). This link works for accounts created on the website and in the mobile apps. Deletion removes your profile and content from the Service; data is then erased on the schedule in Section 8, except for limited records we must keep for legal compliance, security, or the defense of legal claims. Copies of previously public content made by third parties or held in external caches are outside our control.

16. Changes to This Policy

We may update this Policy from time to time. For material changes we will notify you by email or through the Service before the changes take effect. The "Last updated" date at the top reflects the current version.

17. Contact

Dmitrii Nikolaevich Korovin · korovindn@proton.me · https://tripstat.io