TTripminute
HomeExploreTrip in 1 minuteBefore you go
FRSign in+Free creation
HomeExploreTrip in 1 minuteBefore you goProfile
Data protection

Privacy policy

This policy explains which data Tripminute uses, why it is needed and how you remain in control of your account and Trips.

Version dated August 23, 2026

Controller

The publisher identified in the legal notice controls the processing performed by Tripminute. The privacy contact is published on that page.

Data processed

Tripminute processes only information required to operate the service.

  • Account: email address, hashed password when you choose one, preferred language and, when you use Google, the technical Google account identifier and display name shared with your permission. Tripminute never receives your Google password.
  • Profile and content: display name, drafts, itineraries, stages, budgets, media, collections and post-trip feedback.
  • Reports and moderation: reason, explanation, exact content address, reporting account identity, decisions, rationale and the history needed to handle an appeal.
  • Acceptance evidence: document version and acceptance date, together with an irreversible fingerprint of the IP address where available.
  • Security: hashed sessions, audit events and technical fingerprints used to limit abuse.
  • Internal usage measurement: aggregated view, favorite, like and remix counters.
  • Audience: viewed pages, referrer, device type and aggregate technical data, without an account identifier or URL search parameters.

Purposes and legal bases

Account and Trip data is processed to provide the requested service. Security, abuse prevention and technical improvement rely on the legitimate interest of providing a reliable service. Strictly necessary retention obligations rely on applicable law.

Recipients and hosting

Data is hosted on OVHcloud infrastructure in France. When you choose “Continue with Google”, Google processes the authentication step under its own terms and then shares the verified identity you authorise with Tripminute. No Trip text is sent to Google for this sign-in. No Trip text is sent to an external translation service until a provider and its processing terms are enabled. Tripminute does not sell personal data.

Cookies and audience measurement

Tripminute uses a session cookie required for sign-in. During Google sign-in, short-lived technical cookies, limited to ten minutes, protect the request against forgery and correctly match Google’s response; they are not used for advertising or tracking. Audience measurement uses a self-hosted Umami instance on Tripminute infrastructure, without advertising cookies, account matching or transfer to an advertising network. URL search parameters and fragments are excluded, and the browser’s Do Not Track signal is respected.

Retention

A session expires after no more than 30 days. Account data remains available until deletion. Daily operational backups are retained for seven days, so deleted data may remain temporarily in an isolated backup until automatic expiry. Reports, moderation decisions and minimum legal evidence are kept only as long as needed for handling, appeals and legal obligations, then deleted or anonymised.

Media and security

Uploaded images are re-encoded and EXIF metadata, including GPS coordinates, is not kept. Passwords use Argon2id, session tokens are stored as hashes and public traffic uses HTTPS.

Your rights

Your account lets you export your data and request deletion. You may also request access, correction, erasure, restriction or objection within the limits of the GDPR, and complain to the competent supervisory authority.

Updates

Material changes will be dated and, where they affect an account, communicated before taking effect.

TTripminute

Credible itineraries that are easy to read and adapt.

ExploreTrip in 1 minuteBefore you goPrivacyTerms of useLegal noticeCookieless audience measurement