Triply

Privacy Policy

Last updated: 22 July 2026

Who is responsible for your data

Triply (flytriply.eu) is run by Radek Tomas, an individual based in the Czech Republic. This is not a company — there is no registered entity and no company number. Radek Tomas is the data controller for everything described here.

For anything in this policy, including exercising your rights, email hello@flytriply.eu.

What Triply does, in one paragraph

You enter a budget, dates, an origin city and a few preferences. We send those to a language model, which suggests three destinations with an itinerary and a cost breakdown. Every price shown is the model’s estimate — we do not query any flight, hotel or activity pricing service. Prices are marked with a ≈ symbol throughout the interface for that reason.

What we collect

When you use the trip planner, without an account:

  • Budget, travel dates, number of travellers, origin city, trip style, and an optional destination preference.
  • If you choose driving instead of flying: your departure city and maximum driving time.

When you create an account:

  • We use Supabase Auth. You can sign up with Google or with an email address and password.
  • If you use Google, we receive your email address, name and profile picture URL from your Google profile. We copy the picture URL into our database and load the image from Google’s servers — we do not store a copy of the image itself.
  • We store: your user ID, email address, display name, profile picture URL, account creation date, your daily trip-generation counter, whether you opted in to marketing email, and whether you have unsubscribed.
  • Your password, if you use one, is stored and verified by Supabase. We never see it.

As you use your account:

  • Destinations you save, including the trip they came from.
  • A history of the trips you generate.

Analytics:

  • We record which steps of the product you reach: landing page viewed, trip form started, trip generated, destination chosen, trip detail viewed, affiliate link clicked, account created, email captured.
  • Each event is tagged with triply_session_id, a random identifier stored in your browser that does not expire. This is not anonymous. It is a persistent pseudonymous identifier, and when you create an account we link every event previously recorded under that identifier to your account. If you want to break that link, clear your browser storage before signing up.
  • We also use Vercel Analytics for aggregate traffic measurement. It sets no cookies and does not track you across other websites.

If you send feedback: whatever you write, plus your email address if you choose to provide one. This is sent to our automation service for us to read and reply to.

Server logs:our host, Vercel, records standard request logs including IP address, user agent and timestamp. These are retained under Vercel’s own retention policy, which we do not control and therefore do not state a period for here.

Why we are allowed to process it — legal bases

  • Performance of a contract, Art. 6(1)(b). Your trip form inputs, your account, your saved destinations and your trip history. Without these the service cannot function.
  • Consent, Art. 6(1)(a). Marketing email only. Nothing else relies on consent, and you can withdraw it at any time.
  • Legitimate interests, Art. 6(1)(f). Product analytics, server logs, and the rate limits that stop the trip generator being abused. Our interest is in understanding whether the product works and keeping it running. You can object at any time using the contact address above.

Email

There are two kinds, and they are treated differently.

Service email — you cannot opt out of this, because you need it to use your account:

  • A welcome message when you sign up.
  • A confirmation when you save a destination.
  • Authentication mail: email confirmation, password reset, sign-in links, and email-change confirmation.

Marketing email — opt-in only:

  • Two reminders after you save a destination, sent one day and seven days later.
  • We only send these if you ticked the marketing checkbox when signing up. It is unchecked by default. If you did not tick it, you will never receive them.
  • Every marketing email contains a working unsubscribe link, unique to you and cryptographically signed. It also supports your mail client’s built-in unsubscribe button. Unsubscribing stops marketing email immediately and permanently; service email continues.

Email is delivered by Resend, in the United States.

Cookies and browser storage

Under the ePrivacy rules, localStorage and sessionStorage are treated the same as cookies. Everything we store on your device is listed here.

Cookies:

NamePurposeExpiryType
sb-<project-ref>-auth-tokenKeeps you signed in400 daysStrictly necessary
sb-<project-ref>-auth-token-code-verifierCompletes the secure sign-in exchangeTransient, deleted on completionStrictly necessary

localStorage:

NamePurposeExpiry
triply_session_idAnalytics identifier (see above)Never expires
Anonymous generation counterEnforces the free daily trip limit when signed outPersistent
Waitlist flagRemembers you already joined, so we stop askingPersistent
Selected currencyYour currency preferencePersistent
Exchange-rate cacheAvoids re-fetching rates24 hours

sessionStorage: a flag that records the landing page view once per browser session.

We use no advertising cookies, no cross-site tracking, and no third-party tracking scripts.

Who else processes your data

ProcessorWhat it handlesLocation
VercelHosting, server logs, aggregate analyticsUnited States (Washington, D.C.)
SupabaseDatabase and authenticationEuropean Union (Paris)
OpenAIThe language model that writes the recommendationsUnited States
ResendSending emailUnited States
n8nAutomation connecting our app to the modelEuropean Union
GoogleSign-in identity, if you use GoogleUS / global
Pexels, UnsplashDestination photography (no personal data sent)United States
photon.komoot.ioCity autocomplete — receives the city names you typeEU
open.er-api.comExchange rates (no personal data sent)Location not established

Where a processor handles your data outside the European Economic Area, the transfer relies on the European Commission’s Standard Contractual Clauses and — where the provider is certified under it — the EU–US Data Privacy Framework, together with the provider’s own data-processing terms.

Affiliate links

Some outbound links earn us a commission. This never changes what you pay, and the language model has no knowledge of which partners pay us — it cannot be influenced by them.

  • Booking.com, through the affiliate network CJ (Commission Junction). Clicking through takes you via a CJ tracking link, which records the click and forwards you to Booking.com. CJ and Booking.com set their own cookies under their own policies.
  • GetYourGuide links currently carry no affiliate tracking and earn us nothing. If that changes, this page will be updated first.

How long we keep things

DataRetention
Generated trips (shared cache, no user attached)30 days, then automatically deleted
Analytics events90 days, then automatically deleted
Your profile, saved destinations, trip historyFor as long as your account exists

Both automatic deletions run as scheduled jobs. We do not state a retention period for anything we do not actually delete on a schedule.

Feedback you send is forwarded to our automation service, n8n, and is never stored in our own database. Its retention is therefore governed by n8n rather than by us.

Deleting your account

Go to your profile page and use “Delete account”. You will be asked to type DELETE to confirm. This immediately and permanently removes your profile, your saved destinations, your trip history, your analytics events, and your login itself.

One thing is deliberately left behind: the shared cache of generated trips. Those records contain only trip parameters — budget, dates, city names — with no user ID, no email and no identifier of any kind, and they are shared across everyone using Triply. They expire on their own within 30 days.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, export it in a portable format, restrict how we use it, or object to processing based on legitimate interests. Where we rely on consent, you can withdraw it at any time. Email hello@flytriply.eu — there is no form and no process, just write to us.

If you think we have handled your data badly, you can complain to the Czech supervisory authority: Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, uoou.cz.

Changes

If this policy changes materially, we will say so on the site. The date at the top always reflects the current version.

Looking for the rules of using the service? See our Terms of Service.