🧭 Buckettrip← Back to Buckettrip

Privacy (DSGVO)

Effective date: TODO

⚠️ PLACEHOLDER — NOT LEGAL ADVICE. Every section below is a stand-in. Replace it all with content reviewed by a qualified lawyer (and translated where required) BEFORE charging customers or going live.

1. Controller

TODO: Name and contact details of the controller (see Impressum) and DPO if applicable.

2. What we process

  • Account: your email address and sign-in data (via Supabase auth).
  • Traveler profile & trip requests: taste, home base, dates, budget, generated trips.
  • Optional date of birth (only for computing a rental-car driver age).
  • Billing: subscription/credit status and Stripe customer/subscription IDs. Card data is handled by Stripe — we never see or store it.

3. Legal bases

TODO: Art. 6(1)(b) (contract), (c) (legal obligation), (f) (legitimate interests), and consent where relevant. Detail each processing purpose.

4. Processors & third parties

  • Supabase (auth + database hosting)
  • Vercel (application hosting)
  • Stripe (payments & subscriptions)
  • Anthropic (AI trip generation — prompts contain your profile & request)
  • Travelpayouts / Aviasales, Booking.com, Discover Cars, CHECK24 (flight/hotel/car search & affiliate links)
  • Open-Meteo (weather & geocoding), OpenStreetMap Nominatim (geocoding)

TODO: For each, add the purpose, whether data leaves the EU, the transfer mechanism (e.g. SCCs / adequacy), and DPA references.

5. Cookies

TODO: We currently use only essential cookies required to keep you signed in (Supabase auth). No analytics/marketing cookies are set. Confirm and update if that changes.

6. Retention

TODO: How long each category is kept, and deletion on account closure.

7. Your rights

TODO: Access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and the right to lodge a complaint with a supervisory authority.

8. Contact

TODO: How to exercise your rights (email/address).