← Back

Privacy Policy

Last updated: 2026

TripFund ("we," "us") builds a collaborative savings app for travel. This policy explains what we collect, why, how we handle it, and your choices. It applies to the TripFund mobile app and the TripFund website.

What we collect

How we use it

Sharing

We do not sell your data. We share limited data with processors we need to run the service: Stripe (payments), Amazon Web Services (hosting, email, storage), Firebase (push, analytics, crash reports), and MongoDB Atlas (database). Members of a pot see contribution amounts and chat within that pot.

Your choices

Retention

Account data lives as long as the account is active. Financial records are retained for 7 years to comply with tax and audit rules. Chat messages older than 12 months are archived and can be deleted on request.

Security

Data in transit is encrypted with TLS. Passwords are hashed with bcrypt (cost 12). Optional MFA is available on every account. We never store raw card numbers.

Children

TripFund is not intended for anyone under 13. If we learn we've collected data from a child under 13, we delete it.

California + EU rights

Residents of California (CCPA), the EU/EEA/UK (GDPR), and other privacy jurisdictions have rights to access, port, correct, or delete personal data. Email privacy@tripfund.app to exercise them.

Changes

We'll update this policy as the product evolves. Material changes will be surfaced in-app before they take effect.

Contact

privacy@tripfund.app