TripLineup Privacy Policy
You can explore events without an account. If you choose to sign in, TripLineup can keep your saved plans, personalization, and bounded Google Flights price observations needed for account features. The extension has no advertising or client-side behavioral analytics.
What the extension reads
On google.com/travel/flights, TripLineup reads the trip currently displayed: destination, origin, travel dates, and a displayed starting flight price when Google Flights exposes one. It does not read payment details, a booked itinerary, passport information, or your broader browsing history.
Your browser or operating-system language, preferred color scheme, and event-filter preferences are used locally for the interface.
Event discovery without an account
To find events and weather, the extension sends our Cloudflare-hosted API only the destination country and city or bounded geohash, public destination coordinates where needed for weather, trip dates, event category, provider locale, attraction IDs used for optional public profiles, and bounded paging values.
During ordinary discovery, the origin airport, displayed flight price, Google Flights page URL, and account identity are not included in event or weather lookup requests. Search results are kept in Chrome session storage and normally clear when the browser session ends.
Signed-in flight-price observations
If you are signed in and Google Flights exposes a displayed price, the extension first compares the route and dates locally with your own Saved Trips. Unless the page matches exactly one account-owned Saved Trip that already contains a saved Google Flights snapshot, the displayed price and page URL do not leave the extension and no price observation is stored.
For an eligible Saved Trip, the extension sends TripLineup's first-party, trip-specific account API the displayed price and reliably detectable currency, origin and destination, travel dates, bounded price-source and page-state labels, and a random per-page visit identifier. The identifier deduplicates repeated page updates and is not placed in Google Flights content. This later observation request does not send the Google Flights page URL. TripLineup refreshes only that private Saved Trip's latest flight snapshot and appends private price history. An unsaved Top Trip does not receive or contribute an observation; after you explicitly save one as a private Saved Trip, the saved copy is treated like any other eligible Saved Trip.
This account request is separate from event and weather discovery and is not sent to Ticketmaster, Google Weather, NASA POWER, advertisers, or data brokers. Signed-out browsing does not create account price observations. These observations are captured only while the extension can read the matching open Google Flights page; they are not continuous live quotes or automatic purchase data.
Optional accounts and sign-in
TripLineup supports sign-in with an email one-time code. When a Google sign-in button is available, you may use Google instead. Supabase provides authentication and stores the account identifier, email address, basic profile name and avatar supplied by the sign-in provider, authentication timestamps, and security credentials needed to keep you signed in. Google sign-in requests only basic identity information; TripLineup does not request access to Gmail, Drive, Calendar, contacts, or other Google content.
You may edit your TripLineup display name. On an authenticated shared trip, members can see each other's display names and either the provider-supplied avatar or a locally generated initials avatar in member lists, comments, and individual vote details. A member's full email is disclosed only to that member and the trip owner for collaboration administration; it is not included in sanitized public link previews.
The extension and website keep separate credentials for the same TripLineup account. When both are available in the same Chrome profile, a content script running only on triplineup.com can relay public sign-in state and a short-lived, single-use Supabase sign-in handoff that creates a separate session on the other surface. Access and refresh credentials remain in extension-only Chrome local storage or the account website's browser storage; they are not copied between surfaces or placed in event cards or Google Flights page content. Signing out is synchronized when the paired surface is available.
Plus availability waitlist
If you ask to be notified when more TripLineup Plus spots open, TripLineup stores your normalized email address, the first-party form where you joined, the first and most recent request times, a bounded request count, and waitlist status. You do not need an account to join. Duplicate submissions update the same entry rather than creating separate records.
We use this information only to operate the Plus waitlist and send the requested availability notice, not for general marketing. We retain it only as long as reasonably necessary to run the waitlist, prevent repeated notices, and meet applicable security or legal obligations. To remove your waitlist entry, email [email protected] from that address.
Optional personalization
Signed-in users may choose a home airport, preferred trip length and weekend patterns, destination scope, and favorite artists, genres, sports, leagues, and teams. TripLineup stores the catalog-validated airport code and derived country and home-market mapping, the selected travel preferences and interest labels, and the user's choices about using them for event ordering, a weekly email, and future Top Trips suggestions. These preferences rank and curate results after your explicit filters; they do not remove events or subscribe you to email.
If you choose Import from Apple Music, Apple's MusicKit permission window authorizes a one-time browser session. During that import, TripLineup reads up to 30 recently played items, up to 30 heavy-rotation items, and up to 100 library artists so it can derive artist preferences. Apple receives the authorization and Apple Music API requests under Apple's own terms. TripLineup does not request playlists, modify your Apple Music account, or run the import in the background.
The Music User Token, short-lived developer token, raw listening responses, track titles, album titles, play times, and library contents remain in browser memory only for the import and are discarded when it finishes. If you save the draft, TripLineup stores only the normalized artist label, Apple artist ID when Apple provides one, import source, relative rank, and timestamps alongside your other personalization choices. Those artist choices may be used for event ordering and Top Trips according to the controls shown in Personalization. They are not sold, used for advertising, shared with other users, or used to train an AI model.
You can import again to replace earlier Apple-derived artists or choose Remove imported artists and save. Account deletion also removes stored imported artist preferences. TripLineup keeps privacy-safe aggregate operational counts such as whether an import succeeded or failed by a general error category; those counts contain no artist, track, listening, token, or account content. You can also continue to enter, edit, or remove interests manually.
What is stored when you choose Save
Nothing described in this section is uploaded merely because you view a search. When you select Save trip or Save event, TripLineup sends and stores:
- the origin and destination labels or airport codes, destination country, travel dates, and one-way status;
- the Google Flights search URL, displayed starting price and currency when reliably detectable, and the time the snapshot was captured;
- for each event you select: its name, date and displayed time, category, venue and city, public venue street/state/postal address when supplied, provider identity, ticket or map links, displayed price text, thumbnail link, same-day showtime options, and validated venue coordinates with a bounded source/confidence label when available;
- trip names, archive state, private trip notes, trip comments and their authors, per-event votes, collaborator names, roles and email addresses, legacy pending invitation email addresses, role-based share-link records, and account entitlements.
Saving a Google Flights trip also makes only that private Saved Trip eligible for the limited matching price refresh described above. A saved flight item and each later price observation are search snapshots, not proof of a reservation and not a guarantee of price or availability. TripLineup does not currently provide continuous monitoring, price alerts, or automatic purchasing.
Sharing
If you create a sharing link, anyone with its unlisted URL can see that trip's route, dates, flight-search snapshot, saved event cards, event map pins, reviewed destination-airport pins, and aggregate event-vote totals. This preview does not include profiles, email addresses, member lists, invitations, private notes, comments, or individual votes. New links expire after seven days and let people with confirmed TripLineup accounts choose to join in the viewer or editor role selected by the owner; multiple people may join through one active link until it is revoked, expires, or the trip reaches its member limit. A joined viewer can see collaboration data, comment, and vote but cannot edit the trip; a joined editor can also update shared trip notes. Link tokens are stored only as one-way hashes. Revoking a link prevents future previews and joins but does not remove existing members, whom the owner can remove separately.
Saved Trip maps
When this feature is enabled and a Saved Trip has at least one validated event coordinate, the account website may load Apple MapKit JS and send Apple only the public event and reviewed airport coordinates needed to draw the map. TripLineup does not request browser geolocation or send trip names, account identifiers, comments, share tokens, or member data to Apple. The short-lived Maps token is restricted to the first-party website origin and contains no TripLineup account or trip identifier.
For an older saved event without coordinates, an authenticated trip member may trigger a bounded resolver. TripLineup checks its private last-known-good registry and event catalog first and may request the exact public venue record from Ticketmaster. For a still-unresolved U.S. venue, it may send the venue's public street, city, state, and ZIP code to the U.S. Census Geocoder. Those requests contain no TripLineup account, trip, event, member, or share identifier. Apple geocoding remains disabled until its terms and transient-use requirements are approved; if enabled for a still-unresolved non-U.S. venue, Apple receives the public venue name and available street, city, state or region, postal code, and country. An accepted Apple result is used only in the current authenticated map response and is not stored or added to the reusable registry. Anonymous share views never trigger this resolver or write location data. For non-Apple results, TripLineup stores only the approved coordinate and bounded provenance fields, not a provider's full response.
Providers and infrastructure
Our API uses a rolling catalog and may query public provider services such as Ticketmaster for event and venue updates, the U.S. Census Geocoder for a public U.S. venue address, Google Weather for forecasts, and NASA POWER for climate averages. They receive only the destination, public venue address, or event request needed for that service, not your TripLineup account or saved-flight URL. The optional Apple Music import separately sends the authorization and bounded music-data requests described above directly from your browser to Apple. For an eligible Saved Trip map, Apple operates MapKit JS and receives public map coordinates and ordinary network metadata needed to deliver map tiles and controls; Apple Maps Server API receives a bounded legacy venue query only if that separate resolver is enabled. Choosing a ticket, map, music, or social-profile link takes you to that provider under its own privacy policy.
Cloudflare operates our API and website delivery. Supabase operates authentication and the account database. Like most web services, this infrastructure processes IP addresses and request metadata for delivery, security, and abuse protection. TripLineup's application-level limiter hashes an IP transiently in memory and does not retain that hash as account history.
Analytics, advertising, and selling data
The Chrome extension and authenticated account app contain no advertising SDK or third-party behavioral analytics. The extension does not emit click, scroll, keystroke, or browsing telemetry. Public pages on triplineup.com may use Cloudflare Web Analytics for cookieless aggregate page counts; the authenticated /app/ page does not load that analytics script.
TripLineup's first-party API keeps a fixed set of coarse product-operation counts so we can measure whether search, save, sharing, Top Trips, sign-in, and the Plus waitlist work. A row contains only one approved metric name, a 15-minute UTC bucket, and a count. The website may send an approved name for an action that has no existing account write, such as opening a Top Trip detail or selecting View Flights; the endpoint rejects properties and arbitrary names. These counts contain no account or share identifier, email, destination, search, trip, event, venue, airport, coordinate, URL, token, IP address, user agent, or free text. They are not used to identify people, build profiles, personalize content, or advertise, and they are deleted after 90 days. Reports return aggregate counts only.
For Plus conversion measurement, one property-free approved action records selection of a checkout offer. Aggregate reports combine that action count with milestones derived from checkout, trial, and subscription records TripLineup already needs to operate billing. These are counts of actions and billing milestones, not unique people, so repeated offer selections or checkout attempts can count more than once. Reports return no account, Paddle customer, checkout, or subscription identifier and no raw billing row.
For Saved Trip map reliability, /app/ may send a closed set of aggregate operational events such as eligible, rendered, failed, partial-location counts, or an event-versus-airport interaction kind. These events contain no account, share, trip, event, venue, airport, coordinate, URL, or free-text value and are not used to profile behavior or personalize content.
TripLineup does not sell personal information, share it with data brokers or advertisers, use saved trips for advertising profiles, or train AI models on private account and trip content.
Storage, retention, and control
Unsaved event results stay in browser session storage. Interface preferences and optional sign-in credentials persist locally until cleared, expired, or signed out. Saved account, personalization, trip, event-location, and flight-price observation data—including notes, comments, event votes, collaborator membership, sharing-link roles, and legacy invitation records—remains in Supabase while your account is active, subject to the plan limits below. Owners can revoke links or remove members; collaborators can leave a shared trip. You can also edit personalization, remove your comments and individual events, explicitly archive or restore trips, revoke shares, or permanently delete the account. Passing travel dates never automatically archives a trip; only an owner choosing Archive changes its status. A trip appears under Past after its recorded end day has finished everywhere, measured from the next midnight at UTC−12. A complete 48-hour grace period then runs before its retention cutoff. The website, extension, and database use these same boundaries. Free retains the five most recent retention-eligible owned Past trips and Plus retains the 50 most recent. No path can delete a grace-pending trip. Once the cutoff has passed, an authorized save, restore, date change, or lower-limit adoption can apply the limit immediately; natural aging is reconciled on a bounded schedule. Opening a trip list or trip detail never performs retention deletion. Before a save, restore, or date change would delete history, TripLineup warns you and offers Archive or, for Free accounts, Upgrade. When the limit applies, TripLineup automatically and permanently deletes the oldest eligible owned Past trips above it, including their saved events, coordinates, notes, comments, votes, collaborator memberships, sharing links, and linked price history. There is no recoverable trash, and upgrading later cannot restore them. Trips shared with you do not consume your owned Past-trip allowance, though they disappear if their owner deletes them. Explicitly archived trips, their saved event coordinates, and linked price history remain stored subject to the archive allowance shown for the account plan. Privacy-safe 15-minute aggregates retain only a fixed deletion reason and invocation, affected-account, and deleted-trip counts for up to 90 days; they contain no account, trip, member, email, token, or saved-content identifier.
When a save, restore, or date change needs irreversible-retention confirmation, TripLineup keeps a private, one-use confirmation hash and the minimum operation state needed to detect intervening changes. It is usable for no more than five minutes, contains no saved-trip content, is not publicly readable, and expired records are removed by bounded cleanup within 90 days.
You can permanently delete your account, saved trips, flight-price observations, event cards, and active share links from Account settings on the website or from the extension's Account panel. The confirmation requires you to type DELETE. A waitlist entry can exist without an account, so remove it separately by emailing [email protected] from the address you submitted. For a copy of your data, or if you cannot sign in to delete the account yourself, email support from the account email. We may retain limited security or legal records when required, but deleted product data is removed from active systems and then ages out of provider backups under their retention schedules.
Subscription billing
If you start or manage TripLineup Plus, Paddle acts as the merchant of record and receives the contact, billing, payment, tax-location, and transaction information needed to process the purchase, issue receipts, prevent fraud, and operate its buyer portal. Paddle handles full payment-card details; TripLineup does not receive or store them.
TripLineup stores the Paddle customer, checkout, and subscription identifiers associated with your account; the selected product and price identifiers; subscription status and billing-period dates; trial and cancellation state; bounded offer metadata; and verified webhook or bounded read-only reconciliation records needed to grant or remove Plus access. We use this information only to operate billing, recover entitlement when a provider notification is missed, support purchases, prevent duplicate trials or subscriptions, and enforce plan limits. Paddle processes buyer information under Paddle's Privacy Notice.
Permissions
| Permission | Why |
|---|---|
Access to google.com/travel/flights | Read the trip being viewed so events can be matched to it. |
Access to api.triplineup.com | Fetch event/weather data and, only after sign-in, use account and saved-trip APIs. |
Access to triplineup.com | Relay sign-in state and a single-use handoff between the first-party website and extension. |
identity | Open Google's secure OAuth window when optional Google sign-in is offered. |
storage | Keep session results, preferences, and an optional account session. |
sidePanel | Show TripLineup beside Google Flights. |
activeTab | Bind the Side Panel to the active Google Flights tab and show accurate toolbar state. |
Security and changes
We use encrypted HTTPS transport, row-level account access controls, bounded snapshots, and revocable share links. No system is risk-free. We will update this policy and Chrome Web Store disclosures before materially broader data practices ship.
Contact
Privacy questions, access requests, or help with deletion: [email protected].