Privacy Policy — TripTogether
Version 2026-09-27 · Effective 27.09.2026
This is an English translation provided for convenience. The Hebrew version is the binding original; if the two differ, the Hebrew version prevails.
This policy explains what information we collect, why, who we share it with, and your rights. It is written under the Israeli Protection of Privacy Law, 5741-1981, and its regulations, including Amendment 13.
1. Who is responsible for your information
Database controller: [to be completed before publishing], ID number [to be completed before publishing], [to be completed before publishing]. Privacy contact: [to be completed before publishing], [to be completed before publishing].
2. Providing information is voluntary
You are not legally required to give us any information. Without certain information we cannot provide some features. For example, without an email address you cannot create an account, and without an account you cannot share a trip. You can use trip planning and the wallet on your device only, without an account.
3. What information, and why
Information kept only on your device (as long as you haven't connected an account): trips, destinations, dates, participant names you typed, places, notes and expenses. It is stored in the app's protected folder and is not sent to us.
Account information (only if you create an account):
- Email and password (the password is stored encrypted by the sign-in service and we cannot see it) — for identification, sign-in and security. If you sign in with Apple or Google, we receive only an account identifier, an email address (Apple lets you hide it) and your name if you choose to share it. We never receive your password there.
- Display name, username, profile photo and bio — shown to other users according to the privacy settings you choose.
- Trips, places, expenses and trip members — to share and sync with the people you invited.
- Posts, photos, likes, comments and followers — to run the feed.
- Reports and blocks — to keep the community safe.
- The date and version of your acceptance of the terms, and your marketing consent — to record consents.
- Your referral code and who joined with it — to award points.
- Clicks on affiliate links: provider name, type of service, time of the click and account ID. We do not store where you traveled or what you booked — used to reconcile commissions and improve suggestions.
Pro purchases: Apple processes the payment, and we do not receive payment details. A subscription is checked on the device only. For a Trip Pass we store Apple's transaction ID, the product, the purchase date, the purchasing account and the trip it was assigned to, in order to activate Pro for all trip members and to prevent a transaction from being used twice.
Technical information: infrastructure providers record IP address, device type and access times in security logs. If you chose to share Apple crash reports with developers, we receive them from Apple without identifying details.
Photos: before upload we remove location (GPS) and camera data from photos. The app accesses only the photos you pick in the photo picker.
4. What we don't do
- We do not sell personal information.
- We do not use ad tracking, do not share information with ad networks, and do not ask for tracking permission (ATT).
- We do not collect precise location from your device.
- We do not receive or store payment card details.
5. Who we share information with
- Supabase Inc. — hosting of the database, files and sign-in, on servers in the European Union (Frankfurt, Germany). Acts as a processor on our behalf.
- Apple — app distribution, notifications and Sign in with Apple if you choose it. For recommendations, weather and the packing list, only the destination name, its coordinates, the dates and the kind of place you searched for are sent to Apple Maps and Apple Weather, without account details. Receipts you scan are read on the device and never sent.
- Google — Sign in with Google, only if you choose it.
- Frankfurter / the European Central Bank and ExchangeRate-API — when an exchange rate is needed, only currency codes are sent. The services see your IP address, like any website.
- Booking providers (Booking.com, Skyscanner, GetYourGuide and others) — when you open a link, the provider receives the search details in the link (destination, dates and number of travelers) and the information your browser sends. What you give the provider is subject to its own policy.
- Other users — only what you chose to share, with the audience you chose.
- Authorities — where the law requires, or to protect rights, safety or security.
6. Transfers outside Israel
The database is located in the European Union (Frankfurt, Germany). Transfers are made under the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 5761-2001. Some providers, such as Apple and booking providers, may process information in other countries under their own policies.
7. How long we keep information
- Account information: while the account is active. After account deletion the information is deleted within 30 days, except where the law requires retention.
- Content you deleted: removed from the Service immediately, and from backups within 30 days.
- Affiliate link clicks: up to 13 months, to reconcile with providers.
- Trip Pass records: while the trip exists, and afterwards as required by tax and accounting law.
- Security logs: up to 12 months.
- Device-only information: until you delete it or the app.
8. Security
We act under the Protection of Privacy (Data Security) Regulations, 5777-2017, where applicable. Among other things: encryption in transit (HTTPS), record-level access control (users see only trips they are members of), secret keys kept only on the server, and file protection on the device. No method is completely secure. If a serious security incident occurs, we will act as the law requires, including reporting to the Privacy Protection Authority and notifying you where required.
9. Your rights
- Access: to receive the information about you. In the app you can export it under Profile → My data → Export my data.
- Correction and deletion: to ask us to correct or delete information that is inaccurate, incomplete, unclear or outdated. You can also delete content, all data on the device, and your account directly in the app (Profile → My data).
- Marketing: to give or withdraw consent to marketing messages at any time. Marketing consent is separate from accepting the terms and is not a condition for use.
- Withdrawing consent to processing based on consent, without affecting the lawfulness of processing carried out before.
Contact: [to be completed before publishing]. We will reply within 30 days, as the law requires. If you are not satisfied with our reply, you can contact the Privacy Protection Authority.
10. Minors
The Service is intended for people aged 18 and over. We do not knowingly collect information about minors. If we learn of an account belonging to a minor, we will delete it.
11. Updates
We will announce material changes to this policy in the app in advance and ask for your consent again where the law requires. The version and effective date appear at the top of this document.