Privacy Policy
WeddingCraftr ("WeddingCraftr", "we", "us", or "our") provides a collaborative travel-planning application available on the web at app.weddingcraftr.com and through our mobile apps for iOS and Android, along with our marketing site at www.weddingcraftr.com and our journal at blog.tripcraftr.com (together, the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have.
This policy applies to everyone who interacts with the Service, including trip collaborators, participants who respond to an invitation or vote by email without creating an account, and travelers who view or interact with a shared itinerary through a secure link.
1. Information we collect
We run three different things at three different addresses, and what is collected differs sharply between them. The app is where your account and your trips live. The marketing site sets no cookies at all. The journal is the only place that greets you with a cookie question, and the only place where anyone else's scripts run. This section is split the same way, so you can read the part that applies to you rather than assembling it from clauses.
The app
app.weddingcraftr.com and our iOS and Android apps.
Information you provide
- Account information: name, email address, password (stored hashed), and optional profile photo.
- Trip content: trips, itineraries, destinations, dates, notes, documents, photos, expenses (including business-trip details such as the trip's purpose and whether an expense is billable), and other content you or your collaborators add.
- Communications: messages you send through the in-app assistant, support requests, and feedback.
- Information about others: when you invite a collaborator, ask trip participants to vote by email, or share an itinerary with a client or traveler by secure link, we collect the email addresses (and any names) you provide so we can deliver the invitation, ballot, or itinerary and record responses. Travelers without an account may also give us their own contact and travel-document details (such as a phone number, date of birth, passport number, or nationality) through a secure details page so the trip can be planned around them. Anyone whose information was shared with us this way can ask us to remove it at privacy@weddingcraftr.com.
- Profile preferences: optional details you set to personalize planning: your home city, home airport, preferred currency, assistant settings, and email preferences (such as trip reminders).
- Payment information: if you subscribe to a paid plan, our payment processor (Stripe) collects your payment-card and billing details directly. We do not receive or store your full card number; we keep only a customer reference, subscription status, and renewal date.
Information collected automatically
- Device and usage data: IP address, browser or device type, operating system, app version, language, and time-zone.
- Approximate location: a city-level estimate derived from your IP address by Cloudflare, our hosting provider, as it serves the request, together with your device locale and time-zone. Your IP address is not sent to any separate geolocation service. We use this to set sensible defaults (such as your home region and currency), and we keep a dated record of these city-level estimates so the app can tell where you were during a trip.
- Your device's location: we ask for this only when you have asked our assistant for something that needs to know where you are — for example, somewhere to eat nearby. When that happens, the assistant shows you a card explaining why, and your device only asks for permission if you tap it. We then take a single, approximate reading and record the day and place. We never collect your location in the background, we do not track your movements, and we do not ask for this when you open the app or sign up. You can refuse, and you can revoke the permission at any time in your device settings.
- Diagnostic data: crash reports and performance logs to help us keep the Service stable.
- Push notifications: if you enable notifications, your device shares a push token with us so we (through our push delivery provider) can send you trip alerts and other notifications you have turned on. You can switch notifications off at any time in your device settings.
- Product usage events: first-party records of how the Service is used (such as a trip being created, an invitation being accepted, or a feature being used) tied to your account and used to measure and improve the product.
- Analytics: in the web app, and only with your consent, we use aggregate, privacy-first web analytics (Cloudflare Web Analytics) that record metrics such as page views, referrers, and country. This service does not use cookies, does not fingerprint your device, and does not track you across other websites.
- Essential browser storage: session and preference storage used to keep you signed in and remember your choices. No advertising cookies are set here, or anywhere else on the Service.
Information from third parties
- Sign-in providers: if you sign in with Apple or Google, we receive the name, email address, and (for Google) profile photo the provider shares. With Apple you may hide your email address, in which case we receive a private relay address instead.
- Content you import: when you forward booking confirmations or upload PDFs and photos, we extract trip details from those documents.
The marketing site
www.weddingcraftr.com, our public pages and our shortened links.
The quietest of the three. No cookie banner appears here because there is nothing to ask about: we set no cookies, and no third-party script runs on these pages.
- Request counts: a cookieless, server-side count that records only the page visited, campaign tags, the referring site's domain, and country. No identifier, IP address, or user agent is stored, and nothing is tied to you.
- Referral and campaign attribution: if you arrive through a partner referral link or an advertising campaign, we record the referral code or campaign parameters (such as the source and campaign name) in your browser's local storage and attach them to your profile if you go on to sign up. This tells us how you found WeddingCraftr; no cookies are used and your activity on other sites is not tracked.
The journal
blog.tripcraftr.com, where we publish articles.
This is the only surface that asks you a cookie question, and the only one where scripts belonging to other companies run. Nothing in this subsection loads until you accept. Decline, or dismiss the banner without answering, and none of it is loaded, nothing is sent, and nothing is stored. If your browser sends a Global Privacy Control signal we treat that as a decline and do not ask you at all. You can change your answer at any time; see section 5.
Analytics
- Google Analytics measures which articles are read. Unlike the analytics in the app, it is not cookieless: it stores a randomly generated identifier in first-party cookies on our own domain (named _ga and _ga_ followed by a property id), and sends Google the address of the page you are reading, the site you arrived from, your approximate location derived from your IP address, and details of your device and browser. Google processes that data on our behalf and under their own terms. Withdraw consent later and we delete those cookies as well as stopping the script.
Booking attribution
Scripts belonging to two booking partners, which exist so that something you book after reading an article is credited to us.
- GetYourGuide's partner analytics script covers tours and activities. Once loaded, it sends GetYourGuide the address of the page you are reading together with our partner identifier, and it may store a randomly generated identifier in a first-party cookie and in your browser's session storage. Because the request is made with credentials, GetYourGuide can also set and read their own cookies on their domain, which is how a booking is matched back to the visit.
- Travelpayouts' link converter covers the wider range of travel brands we write about, such as flights, stays and transport. It works differently: rather than reporting the page to us or to a single merchant, it rewrites links in the article to travel partners' sites as you read, so that the partner can see the visit began here. To do that it reads the addresses of the links on the page, sends the page address to Travelpayouts, and may store an identifier in your browser and set cookies on Travelpayouts' own domains. Travelpayouts is an affiliate network that works with roughly a hundred travel brands, so the merchant that ultimately receives a click depends on the link you follow.
- Travelpayouts search boxes. Some articles carry a search box for a particular brand, which loads on the same consent and, when you submit it, sends what you entered (such as a country) to Travelpayouts in order to hand you off to that brand.
Cookies on the journal
- Cookies are set here, and only here, and only after you accept: by Google Analytics and by the two booking partners, as described above. We set no advertising cookies. Your answer to the banner itself is kept in your browser's local storage rather than in a cookie, so that we can remember it without tracking you.
2. How we use information
We use the information we collect to:
- Provide, operate, and improve the Service.
- Sync your trips across your devices and with people you've explicitly invited as collaborators.
- Generate itinerary suggestions, tour recommendations, and assistant responses based on the context of your trip.
- Monitor your upcoming trips (for example, checking forecasts and looking for booking conflicts) and alert you when something needs your attention.
- Share itineraries and trip details with clients or travelers you choose, including by secure link, and let them confirm or correct their own travel details.
- Send transactional emails (invitations, password resets, security notifications), trip reminders, digests, and assistant tips you can opt out of, a single reminder to invitees who have not yet answered an invitation, and, with your consent, occasional product updates.
- Process subscriptions and payments, including billing, renewals, and receipts for paid plans.
- Search for tours, lodging, flights, and places on your behalf when you ask the assistant, which means sharing the relevant trip parameters (such as destination and dates) with the providers listed in section 3.
- Detect, investigate, and prevent abuse, fraud, or security incidents.
- Comply with legal obligations.
Where the GDPR or similar laws apply, we process your information as needed to perform our contract with you (providing the Service), with your consent where required (for example, optional emails or device location), to comply with legal obligations, and for our legitimate interests in keeping the Service secure and improving it.
3. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share it only as described below.
With collaborators and teammates
When you invite someone to a trip, the content of that trip, including your name and profile photo, becomes visible to those collaborators.
If you join an agent team, every member of that team can view and edit the trips owned by any member (including itineraries, chat, expenses, and traveler details) and the team's lead can reassign ownership of a trip to another member. Joining a team is always your choice: you join by accepting an invitation, and you can leave once you have transferred ownership of any trips you own.
With people you share trips with outside the app
- Client links: if you share an itinerary with a client or traveler by secure link, the recipient can view the trip without an account (including released itinerary items, booking references, costs, and their own seat or ticket assignments) and can supply or correct their own contact and travel-document details. Links are time-limited (they expire after about 90 days), and anyone who holds a link can open it, so share carefully.
- Public itineraries: you may choose to publish a trip as a public itinerary. The published page shows the trip title, destinations, dates, and itinerary items, but never your name or profile, and published pages are credited anonymously. Published trips are visible to anyone and may be indexed by search engines. Unpublishing removes the page at once, though we cannot control copies a search engine may already have cached.
- Invitation previews: anyone who holds a trip invitation link can see the inviter's name and the trip's title, destination, and dates before deciding whether to join.
With service providers
We rely on a small set of vendors to operate the Service. They process information on our behalf under contractual confidentiality obligations:
- Hosting & database: Supabase (PostgreSQL, Auth, Storage).
- Compute & AI workers: Cloudflare Workers, which also supplies the coarse, city-level location described in section 1 as it serves each request.
- AI model providers: third-party large-language-model providers used to power the in-app assistant, itinerary generation, and document parsing, plus web-search providers the assistant uses to look things up. We send these providers only the trip context needed to answer a request, and inputs are processed under each provider's terms. If a primary provider is unavailable, requests fall back to additional model providers under the same constraints. We do not use your trip content to train models of our own.
- Payments: Stripe, used to process paid subscriptions. Stripe handles your card details under its own privacy policy; we receive only a customer reference and subscription status.
- Maps & places: Google Maps Platform (Places) for city and place search, Mapbox for maps in our mobile apps, and OpenStreetMap data (served via CARTO) for web map tiles and geocoding. Search queries and, where applicable, approximate location are sent to these providers to render results.
- Travel-data partners: tour search (currently Viator), lodging search and booking links (currently Stay22, which routes you to online booking sites such as Booking.com, Expedia, and Vrbo), and flight search (currently FlightAPI.io, with booking hand-off to Skyscanner). We share only the trip parameters needed to run a search (such as destination, dates, and party size) not your account identity. If you complete a booking, the provider's own terms and privacy policy govern it.
- Booking retrieval: when you ask us to fetch a booking from a pasted link (for example, an online travel agency page), a page-extraction provider (currently scrape.do) reads the page on our behalf. If you use confirmation-number retrieval, the booking reference and access code you provide are used by that provider to load your booking page.
- Affiliate partners: when you follow a tour or lodging link, we pass a click identifier to the partner so we can attribute any resulting booking. Partners do not receive your name or email from us; any booking you make is governed by the partner's own privacy policy.
- Push notifications: Expo's push service, which delivers notifications through Apple's and Google's push infrastructure. Expo receives your device's push token and the notification content.
- Weather & imagery: a weather-forecast provider receives the coordinates and dates of your trip legs to power forecasts and weather alerts, and photo-search providers receive destination-derived search terms to generate trip cover photos. Neither receives your account identity.
- Email delivery: a transactional email provider (MailerSend) used for sign-up, invitations, password resets, digests, and tips.
- Error & performance monitoring: Sentry, used to capture crash reports and diagnostics, and Axiom, used to store service logs, so we can keep the app stable.
- Analytics: Cloudflare Web Analytics, a cookieless, privacy-first analytics service that aggregates visit metrics without identifying individual visitors or tracking them across sites, and Cloudflare Analytics Engine, which stores the cookieless landing-page and link request counts described in section 1. On our journal only, and only with your consent, Google Analytics, which is not cookieless and which receives the page addresses, approximate location and device details described in section 1.
- Booking attribution: GetYourGuide, whose partner analytics script runs on our journal only with your consent and tells them that a booking on their site began with an article on ours, and Travelpayouts, whose link converter runs on the same consent and attributes bookings made with the travel brands in their network. What each receives is described in section 1; their handling of it is governed by their own privacy policies.
- Internal operations: a self-hosted internal communications tool used by our own team, which receives account-signup notifications (name, email, and sign-in method) and aggregate usage metrics. It is used only for internal operations and support.
For legal reasons
We may disclose information if required by law, subpoena, or other legal process, or if we believe in good faith that disclosure is necessary to protect rights, property, or safety.
In a business transfer
If WeddingCraftr is involved in a merger, acquisition, or sale of assets, we will notify you before your information becomes subject to a different privacy policy.
4. Data retention
We keep your account information for as long as your account is active. You can delete a trip at any time. When you delete your account, we delete or anonymize associated personal data within a reasonable period, except where we are required to retain it for legal, accounting, or security reasons.
A few records are kept in aggregate form even after deletion: product-usage event logs retain only a bare identifier that can no longer be resolved to you, and affiliate click records are de-linked from your account.
5. Your choices and rights
Depending on where you live, you may have rights under laws such as the GDPR (EU/UK) or the CCPA/CPRA (California) to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your information.
- Object to or restrict certain processing.
- Receive a portable copy of your data.
- Withdraw consent where processing is based on consent.
To exercise any of these rights, email us at privacy@weddingcraftr.com. We will respond within the time periods required by applicable law. You also have the right to lodge a complaint with your local data-protection authority.
You can also manage the emails you receive (including trip reminders, digests, and product updates) from your account settings, or by using the unsubscribe link in any email we send.
To change your answer to the cookie banner on our journal, use the Cookies link in the footer of any page on blog.tripcraftr.com. It reopens the banner so you can accept or decline, and withdrawing takes effect immediately: no partner script and no analytics script is loaded again, and the Google Analytics cookies on our own domain are deleted. Cookies already set by Google, GetYourGuide or Travelpayouts on their domains are cleared through your browser's settings, as we cannot reach them.
6. Security
We use industry-standard safeguards, including encryption in transit (HTTPS), at-rest encryption for stored data, row-level access controls, and audited third-party infrastructure, to protect your information. No method of transmission or storage is 100% secure, however, and we cannot guarantee absolute security.
7. International transfers
The Service is operated from the United States and our vendors may process data in countries other than your own, including the United States, the European Union, and other countries where our infrastructure and AI providers operate. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
8. Children's privacy
The Service is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
9. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service or by email before the changes take effect. The "Last updated" date at the top of this page indicates when this policy was last revised.
10. Contact us
If you have questions about this Privacy Policy or our data practices, email us at privacy@weddingcraftr.com.
Rodrigues Consulting LLC
1207 Delaware Ave #2945
Wilmington, DE 19806, USA