Intro
I want to make it straightforward for both you and I as much as possible. Thank you for trusting me in handling your data with care. By using our services you accept this privacy policy.
This policy applies to Daytrip's app and website, wherever you're using them from — but the app itself is currently built and offered for people in the United States and Canada. Gilbert Fung is the owner of Daytrip and you can reach him at hello@getdaytrip.app for anything privacy-related. You must be at least 13 years old to use Daytrip.
What We Collect
Should you enter/enable the following information/services, Daytrip will collect and store for these purposes:
- Email address: stored securely for signing in and serving features. You can choose to opt-in to marketing communication, and unsubscribe to marketing via the Unsubscribe link.
- Name and profile picture: stored to show your profile publicly in the app.
- Location access: used while using the app in travel mode to place you on the map and guide navigation. We do not keep a history of everywhere you've been. The only thing we keep tied to your account is an aggregate count of stops you've reached on a trip, which we use for trip-quality signals, not tracking.
- Camera and Photos: used to save and share photos publicly should you choose to submit them.
- Trips: stored stop data and notes privately as drafts or publicly if published.
- Social handles: stored to show your profile publicly in the app, and to attribute you to submitted trips.
- Trip history, saves: stored to privately show your past trips and saved trips.
- Trips taken, likes, ratings: stored privately to show your interactions, and publicly to aggregates of trips likes and ratings.
- Comments: stored to show in public reviews of trips.
- Technical information: stored tokens to keep you logged in and send you notifications.
How long we keep things, and who else sees them
New section — the original policy never stated retention periods or named a single vendor. Canadian privacy law (PIPEDA, see below) requires both, so this table is the actual compliance content; everything above it is scene-setting.
| What | How long we keep it | Who else sees it |
|---|---|---|
| Email address | Until you delete your account | Nobody, except Resend, our email-sending provider, used only to deliver mail to you |
| Login session tokens | Short-lived (about an hour), refreshed automatically, invalidated the moment you log out or delete your account | Nobody — held by Supabase, our authentication provider, on our behalf |
| Name, profile picture, social handles | Until you remove them or delete your account | Shown publicly in the app, exactly as you set it |
| Location | Used live; never stored as a history. Only an aggregate "stops reached" count is kept, tied to your account | Nobody |
| Photos you upload | Until you delete them or your account | Shown publicly wherever you chose to attach them |
| Saves, likes, ratings, comments, trips taken | Until you remove the individual item or delete your account | Saves, likes, and trips-taken are private to you. Ratings, comments, and any trip you publish are shown publicly, attributed to your profile |
| Trips you author | Kept per your publish setting — drafts stay private, published trips are public | See "What happens to your content if you delete your account," below |
| Device and usage info (app version, OS, feature usage, crash reports) | Up to 12 months, on a rolling basis | Stays inside PostHog, our analytics and crash-reporting provider — never sold or shared further |
| Purchases (membership, token packs) | We keep a lightweight record of what you own and when it expires, for as long as your account exists | RevenueCat, our billing provider, and Apple App Store — they hold the actual payment details; we never see your card |
The people we share data with, in full: Supabase (our database and login provider), PostHog (analytics and crash reporting), RevenueCat (purchase and subscription management, which in turn talks to the Apple App Store depending on where you bought), and Resend (delivers your sign-in and notification emails). Each of these has agreed to protect your data under a standard data-processing agreement. We don't use any other data processors right now.
Analytics
Daytrip collects anonymous statistics, such as the percentage of users who use particular features, to improve the app. If you provide your email address to Daytrip, such that your anonymous usage is de-anonymized, we will only use it to provide service to you and improve the app. (Never sell or share it.)
This runs through PostHog, which also automatically captures crashes and errors so we can fix bugs — that's app-health data (what broke, on what device/OS), not personal content. Usage and crash data is kept for 12 months on a rolling basis.
Ads
Daytrip's app collects nothing for, or related to, ads.
How Information is Used
We use the information collected to operate and improve our website, apps, and customer support. We do not share personal information with outside parties except to the extent necessary to accomplish Daytrip's functionality. We may disclose your information in response to subpoenas, court orders, or other legal requirements; to exercise our legal rights or defend against legal claims; to investigate, prevent, or take action regarding illegal activities, suspected fraud or abuse, violations of our policies; or to protect our rights and property. In the future, we may sell to, buy, merge with, or partner with other businesses. Any company that joins Daytrip would remain bound by this same privacy policy for data collected under it.
How We Protect Information
We use measures to help keep your information secure. All communication between the app, our website, and our servers is encrypted in transit using HTTPS/TLS. Access to systems holding your data is limited to what's needed to run the service. That said, no method of transmission or storage is 100% secure, and we can't guarantee absolute security.
Your Rights
Email hello@getdaytrip.app to ask what data we hold about you, correct it, or delete it — we'll respond within 30 days. Deleting your account triggers a full, permanent deletion of your personal data within that same window. You can also ask us to turn off analytics collection for your account at any time, from the same address. What happens to your content if you delete your account: your personal data is deleted, but trips you've published stay up and stay attributed to "Deleted User" rather than being pulled down — this keeps trips other people are relying on intact. If you'd rather your published trips come down entirely, say so in your deletion request and we'll handle it manually. A self-serve way to download a copy of your data isn't built yet — for now, email us and we'll send you a summary.
Canadian Privacy Law (PIPEDA)
If you're in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) gives you specific rights, and we've built Daytrip to respect them:
- A named privacy officer. Gilbert Fung is responsible for Daytrip's privacy practices. Reach him at hello@getdaytrip.app.
- Access requests. You can ask what personal information we hold about you at any time; we'll respond within 30 days, as described above.
- Consent for location. We only use your precise location while you're actively using the app or Travel Mode, for the stated purpose of placing you on the map and guiding navigation — never anything broader, and the permission prompt you see on your phone reflects exactly that.
- Our processors are held to the same standard. Supabase, PostHog, RevenueCat, and Resend have each agreed to data-processing terms that require them to protect your information comparably to how PIPEDA requires us to.
- If something goes wrong. We keep an internal log of every security incident, however minor. If a breach creates a real risk of significant harm to you, we'll notify the Office of the Privacy Commissioner of Canada and you directly, as soon as feasible.
California Consumer Privacy Act (CCPA)
If you're a California resident, the CCPA gives you the right to know what personal information we've collected about you, request its deletion, and correct inaccuracies — email hello@getdaytrip.app for any of these. We do not sell or share your personal information with third parties for money or anything else, so there's no "opt out of sale" toggle to offer. You won't be discriminated against (different pricing, reduced service, etc.) for exercising any of these rights.
Children's Online Privacy Protection Act Compliance
We never collect or maintain information in our app or at our website from those we actually know are under 13, and no part of Daytrip is structured to attract anyone under 13.
Information for European Union Customers
By using our services and providing your information, you authorize us to collect, use, and store your information outside of the European Union.
Daytrip is currently built and offered for people in the United States and Canada. We haven't yet built the specific protections GDPR requires for EU/UK users (like a formal EU representative or the data-portability tooling GDPR expects) — if you're accessing Daytrip from the EU or UK ahead of an official expansion, be aware those protections aren't in place yet. We'll put this section through a proper GDPR-specific rewrite before we expand there intentionally.
International Transfers of Information
Information may be processed, stored, and used outside of the country in which you are located. Data privacy laws vary across jurisdictions, and different laws may be applicable to your data depending on where it is processed, stored, or used.
We prefer to keep Canadian users' data hosted in Canada where possible, to minimize cross-border transfer. Where that isn't available, data may be hosted in the United States instead, under our provider's standard data-protection agreement.
Maps and Location Data Sources
Daytrip's maps and points of interest draw on OpenStreetMap contributors (under the Open Database License), OpenFreeMap, and, for some points of interest, Apple MapKit. Each is credited in the app itself. Using these sources doesn't involve sharing your personal data with them — they provide map and place data to us, not the other way around.
Governing Law
This policy, and any dispute relating to it or to how we handle your personal information, is governed by the laws of the Province of British Columbia, Canada, consistent with our Terms of Service.
Future Changes
We can and likely will update our privacy policy in the future. Visit this page to be aware of the policy you are agreeing to by using our services.