Trust hub

Trust & Privacy

TripFit is a V1 product. We try to be honest about what we collect, what we don't, and what's still being built.

What we collect

  • Account: email when you sign up. Anonymous sessions get a temporary ID, no email.
  • Trip inputs you enter (destination, dates, preferences) — stored in your account, not shared with analytics.
  • Usage events (page views, button clicks) via GA4 and Amplitude — only after you grant analytics consent.

What we do not send to analytics

  • Your name, email, or phone number.
  • Free-text notes, dealbreakers, hidden gems, or warnings you write.
  • Trip-specific addresses or property details.

Strings longer than 64 chars and nested objects are also stripped before any analytics call.

Analytics consent

Current status: Not set

Before you choose, GA4 runs in Google Consent Mode v2 — cookieless pings only, no_gacookie and no advertising signals. Full measurement (and Amplitude) only start if you accept.

Data rights

To request a copy or deletion of your TripFit data, send us an inquiry from the in-app contact form. We'll respond manually during V1.

Submit a data request

Beta Automated data export and deletion endpoints are coming soon.

AI transparency

TripFit scoring (Stay Fit, Room Fit, Chillability, etc.) is computed from your inputs by deterministic rules in V1 — not generated by a large language model. Any future AI-assisted explanations will be labeled clearly.

Policies

TripFit is part of the Lumenfolk family. Centralized policies (privacy, terms, acceptable use) live here:

Open BPM Brands / Lumenfolk policies →

We do not claim GDPR, CCPA, HIPAA, SOC 2, or any other formal compliance certification at V1.