Privacy notice
Your data, plainly accounted for.
Ruje Alfon, the owner and operator of TripFindHere, is the personal information controller for this service. This notice explains what we process, how and why we process it, who may receive it, how long we keep it, and how to exercise your rights. The privacy contact is info@tripfindhere.com.
Data inventory
What we store and for how long
We collect data directly from you when you register, manage your User profile, create an Itinerary, enable sharing, submit Itinerary Feedback, or contact us. The service also creates the operational records described below.
User record
Email, display name, Argon2id password hash, verification state, identifiers, record timestamps, and the Registration Agreement acceptance time plus the accepted Terms and Privacy Notice versions.
Kept: Kept until you ask us to delete your User data, subject to any retention required by law or needed to resolve a claim.
Email credentials
Hashed Email Verification Tokens and Password Reset Tokens, their expiry, use state, and timestamps. Raw tokens are not stored.
Kept: Usable once until expiry. Used and expired records are removed during later token cleanup or when the User is deleted.
Sessions
A Session identifier, User identifier, creation time, and expiry. The production cookie is secure and httpOnly.
Kept: A Session is valid for up to seven days unless revoked by logout or password reset. Expired records are removed during later Session cleanup.
Itineraries
The details you submit, generated output, selected Destination IDs, sharing state, Share Token, Knowledge Version, and timestamps.
Kept: Kept until you delete the Itinerary or ask us to delete your User data. Revoking sharing removes the active Share Token.
Itinerary Feedback
A 1–5 usefulness score, optional comment, User and Itinerary identifiers, and submission time.
Kept: Kept until the related Itinerary or User is deleted.
Generation operations
User ID, Destination IDs, outcome, model and routed-provider identifiers, Knowledge Version, timing, token counts, retrieval and Generation Cache fields, estimated and billed cost, and timestamps. Notes, prompts, retrieved Knowledge Chunk contents, and generated output are excluded from this telemetry record.
Kept: Itinerary Generation Events remain after an individual Itinerary is deleted and are removed when the related User is deleted.
Correspondence
Your email address, message, attachments, and our response when you contact support or make a privacy request.
Kept: Kept while needed to resolve and document the request, then deleted when no longer needed, subject to any legal obligation or legal claim.
Service operation
Cookies, cache, rate limits, and logs
Signing in sets a session cookie carrying a signed JWT with the Session ID and User ID. The production cookie is secure, httpOnly, same-site, and unavailable to page scripts. Every authenticated request checks it against the revocable Session record. We do not attach IP address or device information to that database record.
Redis may hold short-lived rate-limit counters derived from request or User identifiers and validated Generation Cache output. Generation Cache entries expire automatically, with a configured maximum lifetime of 24 hours. Requests containing free-form notes are scoped to the requesting User when cached.
Application and infrastructure logs may contain request time, URL, status, IP address, User or Destination IDs for specific operations, and error details. We exclude credentials, raw prompts, free-form notes, retrieved Knowledge Chunk contents, and generated Itinerary contents from our structured operational logs. We keep application logs only while needed to secure and diagnose the service, then delete them or allow them to expire. Infrastructure copies follow each hosting and delivery provider's configured retention settings; we do not create a separate long-term copy for advertising or profiling.
AI-assisted generation
What generating an Itinerary sends
The starting point, selected Destination IDs, dates or season, duration, budget, traveler details, interests, constraints, and optional notes you submit are combined with reviewed reference material and sent through OpenRouter to the selected generation endpoint. AI-assisted rewrites also send the current generated Itinerary and your rewrite instruction through the same path. When retrieval is enabled, a subset of the original details — starting point, Destination IDs, duration, interests, budget, constraints, and optional notes — forms a text query sent through OpenRouter to the selected embedding endpoint.
TripFindHere requires Zero Data Retention routing for every inference and embedding request. This limits processing to endpoints that OpenRouter designates as not retaining or training on submitted content. It does not mean TripFindHere stores nothing: a successful, validated result is stored as an Itinerary. Every attempt also creates a User-linked Itinerary Generation Event with the operational fields listed above, but without your notes, prompt, retrieved Knowledge Chunk contents, or generated content.
Sharing
A Share Token exposes one Itinerary
Enabling sharing creates a Share Token that anyone with the public URL can use without signing in. The public response contains that Itinerary's generated contents and excludes its User ID, raw input fields, sharing-management fields, and your other Itineraries. Because the generated contents are based on the details you submitted, they may reflect those details; review the Itinerary before sharing it. Disabling sharing revokes the Share Token; enabling it again creates a new one.
Purposes
Why we process this data
- To register and authenticate Users, document the Registration Agreement, and deliver requested User and security notices.
- To generate, save, retrieve, delete, share, and receive feedback about Itineraries.
- To secure the service, enforce rate limits, diagnose failures, and measure reliability and cost.
- To respond to support, access, correction, portability, objection, and deletion requests.
We process data to provide the service you request and for our legitimate interest in operating and protecting it. Where processing depends on consent, you may withdraw that consent without affecting processing already completed lawfully. We do not sell personal data or use it for third-party advertising.
Service providers
Who may process the data
Hosting and delivery
Vercel hosts the site, application, and API. Cloudflare delivers and protects the public site. They may process request and network metadata, including IP address, according to their service settings.
AI generation and retrieval
OpenRouter and the selected generation or embedding endpoint receive the prompt, reference material, or retrieval query needed to provide the requested feature. We require OpenRouter to route these inference and embedding requests only to endpoints it designates as Zero Data Retention. Those endpoints do not retain or train on the submitted content. OpenRouter keeps limited non-content operational metadata, such as model and provider identifiers, token counts, latency, and cost.
Destination research
Operator-only Destination research may send public Destination search queries through OpenRouter to its Exa-backed web-search tool. OpenRouter's inference Zero Data Retention control does not cover this tool path, so it is kept separate from traveler Itinerary Requests and does not receive their details or notes.
Email delivery
Resend receives the destination email address and email contents needed to deliver verification, duplicate-registration, and password-reset notices.
Data and cache hosting
Our configured PostgreSQL and Redis operators store application records, short-lived Generation Cache entries, and rate-limit counters. We do not send User data to a separate vector-store provider.
These providers may process data outside the Philippines. We remain responsible for selecting providers and using contractual and technical safeguards appropriate to their roles. We may also disclose data when required by law or needed to protect Users, the service, or legal rights.
Your controls
Exercise your data-subject rights
Under the Philippine Data Privacy Act, you may ask to be informed, access a copy of your data, correct inaccurate data, object to or withdraw consent for applicable processing, request erasure or blocking when legally available, obtain portable electronic data, or raise a concern. You may also lodge a complaint with the National Privacy Commission and seek damages where the law allows. We may verify your identity before acting on a request and may retain information where a legal obligation or legal claim requires it.
We may update this notice when the service or its providers change. Material changes will be identified here and notified separately when required by law.
Account eligibility and service-use rules are in the Terms and Conditions .
Version 2026-08-28 · Last updated August 28, 2026.

