Privacy policy
This policy explains which data Tripminute uses, why it is needed and how you remain in control of your account and Trips.
Version dated August 9, 2026Controller
The publisher identified in the legal notice controls the processing performed by Tripminute. The privacy contact is published on that page.
Data processed
Tripminute processes only information required to operate the service.
- Account: email address, hashed password and preferred language.
- Profile and content: display name, drafts, itineraries, stages, budgets, media, collections and post-trip feedback.
- Security: hashed sessions, audit events and technical fingerprints used to limit abuse.
- Internal usage measurement: aggregated view, favorite, like and remix counters.
Purposes and legal bases
Account and Trip data is processed to provide the requested service. Security, abuse prevention and technical improvement rely on the legitimate interest of providing a reliable service. Strictly necessary retention obligations rely on applicable law.
Recipients and hosting
Data is hosted on OVHcloud infrastructure in France. No Trip text is sent to an external translation service until a provider and its processing terms are enabled. Tripminute does not sell personal data.
Cookies
Tripminute uses only a session cookie required for sign-in. This version has no advertising cookie, marketing tracker or third-party analytics tool.
Retention
A session expires after no more than 30 days. Account data remains available until deletion. Operational backups are retained for 14 days, so deleted data may remain temporarily in an isolated backup until automatic expiry. Minimum legal records may be retained where required by law.
Media and security
Uploaded images are re-encoded and EXIF metadata, including GPS coordinates, is not kept. Passwords use Argon2id, session tokens are stored as hashes and public traffic uses HTTPS.
Your rights
Your account lets you export your data and request deletion. You may also request access, correction, erasure, restriction or objection within the limits of the GDPR, and complain to the competent supervisory authority.
Updates
Material changes will be dated and, where they affect an account, communicated before taking effect.